SlideShare a Scribd company logo
1 of 17
Download to read offline
Doing Business in Russia:
Privacy Law Risk Update
Anastasia Zagorodnaya
Of Counsel
Dentons St. Petersburg, Russia
Privacy Laws & Business
29th Annual International Conference
July 5, 2016
Cambridge
1. rather advanced (based on the 1981
Convention) and developing
2. localization (HIGH RISK!)
3. specific security measures prescribed by law
4. claims may be submitted at the data
subject’s place of residence
5. cultural aspects are of importance
2
5 key things you need to know about Russian
DP law and practice
3
1981
Convention,
in force for
RU since
01.09.2013
RF
Constitution
Arts. 23&24
Special
provisions
in various
laws
Data
Protection
Law No.
152-FZ оf
27.07.2006
Law on
Information
No. 149-FZ
of
27.07.2006
Civil, Labor
and Criminal
Codes, Code
on Admin
Offences
Civil
Procedure
Code
Overview: Legal framework
rules on certain
categories of
data and data
subjects (e.g.
Labor Code on
HR data)
right to
privacy
jurisdiction
over
disputes
general
regulations,
bloggers,
open data,
RTF
liability
• Government
Resolutions
• Roscomnadzor Orders
• Orders of other
Authorities (Federal
Security Service,
Federal Service for
Tech and Export
Control, etc.)
Overview: Notification to Roscomnadzor
4
• Prior to processing
• Key exemptions:
• Paper or electronic, to include information on operator, data
categories, means and purposes of processing, security
measures, local database, etc.
• No fees
• Obligation to update (including in view of localization) within 10
business days
HR data
agreement
conclusion and
performance
publicly
available data
full names only
manual
processing
Overview: Consent
5
• required unless limited grounds for processing apply
• specific, informed and freely given
• any provable form, EXCEPT FOR:
sensitive data
data to be made
publicly available
HR data transfer to
third parties
cross-border transfer
to “unsafe” countries
automatic processing
results in legal
consequences
WRITTEN
consent subject to specific
requirements
bio data
Overview: Cross-border transfer
6
• Parties to the 1981
Convention
• Countries from the list
approved by the
regulator (17, including
Australia, Argentina,
Korea, New Zealand,
Canada, Mexico)
Subject to the general
provisions of the Data
Protection Law
• Everybody else: e.g.
USA
• Written consent,
EXCEPT FOR:
 international treaties
 federal laws (state
and personal security)
 contract performance
 protection of
health/life of the data
subject or third parties
vs.
7
Overview: Sanctions (1)*
•ADMINISTRATIVE: fine up
to 65 EUR, disqualification
for up to 3 years
Company
CIVIL: Compensation of
damages or moral sufferings
Company officer
• ADMINISTRATIVE :
• fine up to 130 EUR
draft bill to
significantly
increase
fines
•CRIMINAL: fine of up to
4,000 EUR, imprisonment of
up to 2 years or other
punishment
Other negative consequences
• visa issues for foreign
nationals
• order to terminate allegedly illegal
processing (?)
• license suspension (?)
* Liability may vary depending on the applicable legal provision.
AND/OR
AND/OR
AND/OR
Website blocking
• Data subject may file a lawsuit at his/her place of residence and
based on the court’s decision to apply to Roscomnadzor in order
to promptly limit access to information processed in violation of DP
legislation on the Internet
• Roscomnadzor will notify the web owner/hosting provider. If they
fail to limit access to the information in dispute, access to the
entire website will be blocked
• Interpretation – only websites where personal data is made
publicly available, may be blocked, but risks of broader
interpretation by local courts exist
8
Overview: Sanctions (2)
Localization requirement
9
‘While collecting personal data, including by
means of the Internet, the operator must ensure
that recording, systemization, compilation,
storage, modification (updating, alteration), and
retrieval of personal data of the Russian citizens
is done using databases located on the territory
of the Russian Federation, except for …’
Federal Law of 21 July 2014 No. 242-FZ (aka “Localization law”) added the following
provision to the Data Protection Law:
Localization requirement: Exceptions
Generally NOT applicable to business:
• journalist, scientific and creative activities
• judicial and enforcement purposes
• state and municipal services
• international treaty requirements or performance of
functions imposed by Russian law
(!) General obligation to keep HR and accounting records
DOES NOT serve as grounds for exemption
10
Localization requirement: Ministry Guidance (1)
Ministry of Telecom and Mass Communications clarifications
http://minsvyaz.ru/ru/personaldata/#1438548328715
1. Jurisdiction
• Russian companies or representative offices registered in Russia
• Foreign companies that have no Russian presence but “target” (direct their
activities at) the Russian market. “Directed at” concept for websites:
(!) + at least one of the following in addition to the above :
• payments available in RUB
• contract performance on the territory of Russia (goods/service delivery, use of
digital content)
• ads in Russian promoting website
• other circumstances evidencing that Russian market is part of the business
strategy
UNLESS exceptions apply
11
.moscow, etc.)
Use of domain names
associated with Russia (.ru,
.moscow, etc.)
A website version (or page) in
Russianand /or
Localization requirement: Ministry Guidance (2)
2. Application
• Collection: “intentional” from data subject directly or via specifically
engaged third parties.
• employee/representative contact data exchanged in the course of business
not covered.
• Consent effect: none (but reduces risk of claims from a data subject)
• Cross-border transfer: not affected; Russian citizens’ data entered into a
local Russian database (“primary database”) may be further transferred to a
database abroad (“secondary database”), with applicable formalities.
• Database: initially broad concept, now favoring a narrower approach (!)
• No retroactive effect: data collected before entry into force is not covered;
yet, mentioned operations with old data (e.g. update) trigger the need to
comply.
• Citizenship: no rules, operator can define itself. If no procedure established,
amendment may be applied to all data collected in Russia.
Guidance status: non-binding, but all we have
12
• Roscomnadzor is mostly interested in mass processing (online
retailers, social networks, insurance companies, banks, etc.)
• Scheduled inspections:
• Over 640 companies already inspected including major online retailers
(wildberries.ru, OZON.ru, Lamoda.ru, KupiVIP.ru).
• 4 companies found non-compliant, must comply within 6 months
• Over 900 more companies are scheduled for inspection in 2016,
including: British American Tobacco, HP, Raiffeisenbank,
McDonalds.
• Unscheduled inspections possible (including at the data subject’s
request).
13
Localization requirement: Enforcement
Localization requirement: practical approaches
14
Main solutions depending on business features and “starting
points”:
• Changing the set of data processed
or steps to anonymize
• Delegation of processing
• “Primary database”
localization in Russia
•Roscomnadzor strategy paper
•Creation of a single online register of PD
submitted by data subjects via websites, when
visiting business centers and similar venues with
controlled admission
•Big data regulation
•Employee surveillance
•…
15
Latest news/initiatives/trends
THANK YOU!
QUESTIONS?
16
Contacts
17
Anastasia Zagorodnaya
Of Counsel, St. Petersburg
phone: + 7 812 325 84 44
fax: + 7 812 325 84 54
е-mail: anastasia.zagorodnayaa@dentons.com
Nick Graham
Partner, London
phone: + 44 20 7320 6907
fax: + 44 20 7246 7777
е-mail: nick.graham@dentons.com

More Related Content

What's hot

Customs and mail procedures in lithuania
Customs and mail procedures in lithuaniaCustoms and mail procedures in lithuania
Customs and mail procedures in lithuaniaMindaugas Jocius
 
Belgium Business Register (KBO BCE) in Open Data
Belgium Business Register (KBO BCE) in Open DataBelgium Business Register (KBO BCE) in Open Data
Belgium Business Register (KBO BCE) in Open DataFrank De Saer
 
ЄС-Росія
ЄС-РосіяЄС-Росія
ЄС-РосіяBabelNews
 
Europeanization in the Western Balkans
Europeanization in the Western Balkans Europeanization in the Western Balkans
Europeanization in the Western Balkans Elmir Badalov
 
2020 ukraine association_implementation_report_final1
2020 ukraine association_implementation_report_final12020 ukraine association_implementation_report_final1
2020 ukraine association_implementation_report_final1Pravotv
 
Cross Border Infringement On The Internet
Cross Border Infringement On The InternetCross Border Infringement On The Internet
Cross Border Infringement On The InternetWouter Pors
 
How hackers collate information about employees
How hackers collate information about employees How hackers collate information about employees
How hackers collate information about employees begmohsin
 
Moj criticised over forging documents
Moj criticised over forging documentsMoj criticised over forging documents
Moj criticised over forging documentsEvidence_Complicit
 
Enforcement of foreign judgments in Russia - Chapter in Getting the Deal Trou...
Enforcement of foreign judgments in Russia - Chapter in Getting the Deal Trou...Enforcement of foreign judgments in Russia - Chapter in Getting the Deal Trou...
Enforcement of foreign judgments in Russia - Chapter in Getting the Deal Trou...Andrey Zelenin
 
Odf financial-statement-2017-eng-final
Odf financial-statement-2017-eng-finalOdf financial-statement-2017-eng-final
Odf financial-statement-2017-eng-finalodfoundation
 
Facebook_a privacy defender or a privacy traitor
Facebook_a privacy defender or a privacy traitorFacebook_a privacy defender or a privacy traitor
Facebook_a privacy defender or a privacy traitorAlexia-Nefeli Dumas
 
20 deliverables of Eastern Partnership for 2020: Ukraine’s progress with the ...
20 deliverables of Eastern Partnership for 2020: Ukraine’s progress with the ...20 deliverables of Eastern Partnership for 2020: Ukraine’s progress with the ...
20 deliverables of Eastern Partnership for 2020: Ukraine’s progress with the ...Centre of Policy and Legal Reform
 
Effects of macro environmental factors- running a micro distillery in the cze...
Effects of macro environmental factors- running a micro distillery in the cze...Effects of macro environmental factors- running a micro distillery in the cze...
Effects of macro environmental factors- running a micro distillery in the cze...Alexander Decker
 
Венецианская комиссия рекомендует назначать судей КСУ после внедрения в проце...
Венецианская комиссия рекомендует назначать судей КСУ после внедрения в проце...Венецианская комиссия рекомендует назначать судей КСУ после внедрения в проце...
Венецианская комиссия рекомендует назначать судей КСУ после внедрения в проце...Pravotv
 
Estimating The Size of the Irish Population
Estimating The Size of the Irish PopulationEstimating The Size of the Irish Population
Estimating The Size of the Irish PopulationAlan McSweeney
 
Newsletter LPA Legal Albania - November - 2018
Newsletter LPA Legal Albania - November - 2018Newsletter LPA Legal Albania - November - 2018
Newsletter LPA Legal Albania - November - 2018Oltjan Hoxholli
 
2012 KIMBERLEY PROCESS CERTIFICATION SCHEME European Union Annual Report
2012 KIMBERLEY PROCESS CERTIFICATION SCHEME European Union Annual Report  2012 KIMBERLEY PROCESS CERTIFICATION SCHEME European Union Annual Report
2012 KIMBERLEY PROCESS CERTIFICATION SCHEME European Union Annual Report Dr Lendy Spires
 

What's hot (20)

Customs and mail procedures in lithuania
Customs and mail procedures in lithuaniaCustoms and mail procedures in lithuania
Customs and mail procedures in lithuania
 
Belgium Business Register (KBO BCE) in Open Data
Belgium Business Register (KBO BCE) in Open DataBelgium Business Register (KBO BCE) in Open Data
Belgium Business Register (KBO BCE) in Open Data
 
ЄС-Росія
ЄС-РосіяЄС-Росія
ЄС-Росія
 
Europeanization in the Western Balkans
Europeanization in the Western Balkans Europeanization in the Western Balkans
Europeanization in the Western Balkans
 
2020 ukraine association_implementation_report_final1
2020 ukraine association_implementation_report_final12020 ukraine association_implementation_report_final1
2020 ukraine association_implementation_report_final1
 
Cross Border Infringement On The Internet
Cross Border Infringement On The InternetCross Border Infringement On The Internet
Cross Border Infringement On The Internet
 
How hackers collate information about employees
How hackers collate information about employees How hackers collate information about employees
How hackers collate information about employees
 
bokeng
bokengbokeng
bokeng
 
Moj criticised over forging documents
Moj criticised over forging documentsMoj criticised over forging documents
Moj criticised over forging documents
 
Enforcement of foreign judgments in Russia - Chapter in Getting the Deal Trou...
Enforcement of foreign judgments in Russia - Chapter in Getting the Deal Trou...Enforcement of foreign judgments in Russia - Chapter in Getting the Deal Trou...
Enforcement of foreign judgments in Russia - Chapter in Getting the Deal Trou...
 
Odf financial-statement-2017-eng-final
Odf financial-statement-2017-eng-finalOdf financial-statement-2017-eng-final
Odf financial-statement-2017-eng-final
 
Facebook_a privacy defender or a privacy traitor
Facebook_a privacy defender or a privacy traitorFacebook_a privacy defender or a privacy traitor
Facebook_a privacy defender or a privacy traitor
 
20 deliverables of Eastern Partnership for 2020: Ukraine’s progress with the ...
20 deliverables of Eastern Partnership for 2020: Ukraine’s progress with the ...20 deliverables of Eastern Partnership for 2020: Ukraine’s progress with the ...
20 deliverables of Eastern Partnership for 2020: Ukraine’s progress with the ...
 
Republic of Moldova at the European Court of Human Rights in 2019
Republic of Moldova at the European Court of Human Rights in 2019Republic of Moldova at the European Court of Human Rights in 2019
Republic of Moldova at the European Court of Human Rights in 2019
 
Effects of macro environmental factors- running a micro distillery in the cze...
Effects of macro environmental factors- running a micro distillery in the cze...Effects of macro environmental factors- running a micro distillery in the cze...
Effects of macro environmental factors- running a micro distillery in the cze...
 
Венецианская комиссия рекомендует назначать судей КСУ после внедрения в проце...
Венецианская комиссия рекомендует назначать судей КСУ после внедрения в проце...Венецианская комиссия рекомендует назначать судей КСУ после внедрения в проце...
Венецианская комиссия рекомендует назначать судей КСУ после внедрения в проце...
 
Estimating The Size of the Irish Population
Estimating The Size of the Irish PopulationEstimating The Size of the Irish Population
Estimating The Size of the Irish Population
 
Default
DefaultDefault
Default
 
Newsletter LPA Legal Albania - November - 2018
Newsletter LPA Legal Albania - November - 2018Newsletter LPA Legal Albania - November - 2018
Newsletter LPA Legal Albania - November - 2018
 
2012 KIMBERLEY PROCESS CERTIFICATION SCHEME European Union Annual Report
2012 KIMBERLEY PROCESS CERTIFICATION SCHEME European Union Annual Report  2012 KIMBERLEY PROCESS CERTIFICATION SCHEME European Union Annual Report
2012 KIMBERLEY PROCESS CERTIFICATION SCHEME European Union Annual Report
 

Viewers also liked

Using functional questionnaires to get medicare compliance
Using functional questionnaires to get medicare complianceUsing functional questionnaires to get medicare compliance
Using functional questionnaires to get medicare complianceCharles Richardson
 
Governance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management SolutionGovernance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management SolutionRishabh Software
 
Trading Partner SLAs: Managing Ten Compliance Risks
Trading Partner SLAs: Managing Ten Compliance RisksTrading Partner SLAs: Managing Ten Compliance Risks
Trading Partner SLAs: Managing Ten Compliance RisksCleo
 
Network View to Market Risk
Network View to Market RiskNetwork View to Market Risk
Network View to Market RiskKimmo Soramaki
 
A Custom Agency Model for Kimberly-Clark
A Custom Agency Model for Kimberly-ClarkA Custom Agency Model for Kimberly-Clark
A Custom Agency Model for Kimberly-ClarkOgilvyAction
 
Keys To Trade Compliance
Keys To Trade ComplianceKeys To Trade Compliance
Keys To Trade ComplianceJim Chester
 
kimberly clark marketing assngmt
kimberly clark marketing assngmtkimberly clark marketing assngmt
kimberly clark marketing assngmtmeghna
 
Tieto - Transfer of International Companies’ Corporate IT Systems to Russia a...
Tieto - Transfer of International Companies’ Corporate IT Systems to Russia a...Tieto - Transfer of International Companies’ Corporate IT Systems to Russia a...
Tieto - Transfer of International Companies’ Corporate IT Systems to Russia a...Accountor Russia and Ukraine
 
Risk Advisory Group - Sanctions & Business in Russia: Today & Tomorrow
Risk Advisory Group - Sanctions & Business in Russia: Today & TomorrowRisk Advisory Group - Sanctions & Business in Russia: Today & Tomorrow
Risk Advisory Group - Sanctions & Business in Russia: Today & TomorrowAccountor Russia and Ukraine
 
Enterprise Governance, Risk and Compliance
Enterprise Governance, Risk and ComplianceEnterprise Governance, Risk and Compliance
Enterprise Governance, Risk and ComplianceAxis Technology, LLC
 
problem-solution essay -
 problem-solution essay -  problem-solution essay -
problem-solution essay - Guler Ekincier
 
Advantages of an integrated governance, risk and compliance environment
Advantages of an integrated governance, risk and compliance environmentAdvantages of an integrated governance, risk and compliance environment
Advantages of an integrated governance, risk and compliance environmentIBM Analytics
 
Governance, risk and compliance framework
Governance, risk and compliance frameworkGovernance, risk and compliance framework
Governance, risk and compliance frameworkCeyeap
 

Viewers also liked (16)

Managing Business Risk in Nigeria
Managing Business Risk in NigeriaManaging Business Risk in Nigeria
Managing Business Risk in Nigeria
 
Investment oil russia
Investment oil russiaInvestment oil russia
Investment oil russia
 
Using functional questionnaires to get medicare compliance
Using functional questionnaires to get medicare complianceUsing functional questionnaires to get medicare compliance
Using functional questionnaires to get medicare compliance
 
Governance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management SolutionGovernance, Risk & Compliance Management Solution
Governance, Risk & Compliance Management Solution
 
Trading Partner SLAs: Managing Ten Compliance Risks
Trading Partner SLAs: Managing Ten Compliance RisksTrading Partner SLAs: Managing Ten Compliance Risks
Trading Partner SLAs: Managing Ten Compliance Risks
 
Network View to Market Risk
Network View to Market RiskNetwork View to Market Risk
Network View to Market Risk
 
Marketing In Russia
Marketing In RussiaMarketing In Russia
Marketing In Russia
 
A Custom Agency Model for Kimberly-Clark
A Custom Agency Model for Kimberly-ClarkA Custom Agency Model for Kimberly-Clark
A Custom Agency Model for Kimberly-Clark
 
Keys To Trade Compliance
Keys To Trade ComplianceKeys To Trade Compliance
Keys To Trade Compliance
 
kimberly clark marketing assngmt
kimberly clark marketing assngmtkimberly clark marketing assngmt
kimberly clark marketing assngmt
 
Tieto - Transfer of International Companies’ Corporate IT Systems to Russia a...
Tieto - Transfer of International Companies’ Corporate IT Systems to Russia a...Tieto - Transfer of International Companies’ Corporate IT Systems to Russia a...
Tieto - Transfer of International Companies’ Corporate IT Systems to Russia a...
 
Risk Advisory Group - Sanctions & Business in Russia: Today & Tomorrow
Risk Advisory Group - Sanctions & Business in Russia: Today & TomorrowRisk Advisory Group - Sanctions & Business in Russia: Today & Tomorrow
Risk Advisory Group - Sanctions & Business in Russia: Today & Tomorrow
 
Enterprise Governance, Risk and Compliance
Enterprise Governance, Risk and ComplianceEnterprise Governance, Risk and Compliance
Enterprise Governance, Risk and Compliance
 
problem-solution essay -
 problem-solution essay -  problem-solution essay -
problem-solution essay -
 
Advantages of an integrated governance, risk and compliance environment
Advantages of an integrated governance, risk and compliance environmentAdvantages of an integrated governance, risk and compliance environment
Advantages of an integrated governance, risk and compliance environment
 
Governance, risk and compliance framework
Governance, risk and compliance frameworkGovernance, risk and compliance framework
Governance, risk and compliance framework
 

Similar to PLB Conference_Doing Business in Russia_Privacy Law Risk Update_July 5 2016

The New Russian Law on Personal Data. Latest Developments. Dmitry Marinichev
The New Russian Law on Personal Data. Latest Developments. Dmitry MarinichevThe New Russian Law on Personal Data. Latest Developments. Dmitry Marinichev
The New Russian Law on Personal Data. Latest Developments. Dmitry MarinichevGalina Aristova
 
Personal Data in Russia
Personal Data in RussiaPersonal Data in Russia
Personal Data in RussiaAdrien Henni
 
Awara legal seminar on anti-corruption. Anton Kabakov. 27.08.2014
Awara legal seminar on anti-corruption. Anton Kabakov. 27.08.2014Awara legal seminar on anti-corruption. Anton Kabakov. 27.08.2014
Awara legal seminar on anti-corruption. Anton Kabakov. 27.08.2014Awara Direct Search
 
CEE CMS Data Protection webinar series - Part 1
CEE CMS Data Protection webinar series - Part 1CEE CMS Data Protection webinar series - Part 1
CEE CMS Data Protection webinar series - Part 1CMSLondon
 
Anti-corruption compliance in Russia. Overview and Implementation
Anti-corruption compliance in Russia. Overview and ImplementationAnti-corruption compliance in Russia. Overview and Implementation
Anti-corruption compliance in Russia. Overview and ImplementationAwara Direct Search
 
Russia to block access to LinkedIn for violating Personal Data Law
Russia to block access to LinkedIn  for violating Personal Data LawRussia to block access to LinkedIn  for violating Personal Data Law
Russia to block access to LinkedIn for violating Personal Data LawPwC Russia
 
Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016
Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016
Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016bhalasz
 
Russian Legal Seminar 2014 - Legal advice for foreigners doing business in Ru...
Russian Legal Seminar 2014 - Legal advice for foreigners doing business in Ru...Russian Legal Seminar 2014 - Legal advice for foreigners doing business in Ru...
Russian Legal Seminar 2014 - Legal advice for foreigners doing business in Ru...PwC Suomi
 
Data Localisation in Russia - A Self-imposed Sanction
Data Localisation in Russia - A Self-imposed SanctionData Localisation in Russia - A Self-imposed Sanction
Data Localisation in Russia - A Self-imposed SanctionArtem Kozlyuk
 
The GDPR, Brexit, the UK and adequacy
The GDPR, Brexit, the UK and adequacyThe GDPR, Brexit, the UK and adequacy
The GDPR, Brexit, the UK and adequacyLilian Edwards
 
GDPR - a view for the non experts
GDPR - a view for the non expertsGDPR - a view for the non experts
GDPR - a view for the non expertsClaudio Bolla, CISM
 
Doing Business In Russia
Doing Business In RussiaDoing Business In Russia
Doing Business In RussiaSv3t1anaf
 
CCSP_Self_Domain_6.ppt
CCSP_Self_Domain_6.pptCCSP_Self_Domain_6.ppt
CCSP_Self_Domain_6.pptSamir Jha
 
State regulation of information protection in the cloud - international and K...
State regulation of information protection in the cloud - international and K...State regulation of information protection in the cloud - international and K...
State regulation of information protection in the cloud - international and K...Vsevolod Shabad
 
Special Challenges of Doing Business in Russia
Special Challenges of Doing Business in RussiaSpecial Challenges of Doing Business in Russia
Special Challenges of Doing Business in RussiaEthisphere
 

Similar to PLB Conference_Doing Business in Russia_Privacy Law Risk Update_July 5 2016 (20)

The New Russian Law on Personal Data. Latest Developments. Dmitry Marinichev
The New Russian Law on Personal Data. Latest Developments. Dmitry MarinichevThe New Russian Law on Personal Data. Latest Developments. Dmitry Marinichev
The New Russian Law on Personal Data. Latest Developments. Dmitry Marinichev
 
The Dutch Lesson (the SyRI Case)
The Dutch Lesson (the SyRI Case)The Dutch Lesson (the SyRI Case)
The Dutch Lesson (the SyRI Case)
 
Personal Data in Russia
Personal Data in RussiaPersonal Data in Russia
Personal Data in Russia
 
Cross-Border Internet Sales to Russia
Cross-Border Internet Sales to RussiaCross-Border Internet Sales to Russia
Cross-Border Internet Sales to Russia
 
Awara legal seminar on anti-corruption. Anton Kabakov. 27.08.2014
Awara legal seminar on anti-corruption. Anton Kabakov. 27.08.2014Awara legal seminar on anti-corruption. Anton Kabakov. 27.08.2014
Awara legal seminar on anti-corruption. Anton Kabakov. 27.08.2014
 
CEE CMS Data Protection webinar series - Part 1
CEE CMS Data Protection webinar series - Part 1CEE CMS Data Protection webinar series - Part 1
CEE CMS Data Protection webinar series - Part 1
 
GDPR
GDPRGDPR
GDPR
 
Anti-corruption compliance in Russia. Overview and Implementation
Anti-corruption compliance in Russia. Overview and ImplementationAnti-corruption compliance in Russia. Overview and Implementation
Anti-corruption compliance in Russia. Overview and Implementation
 
Russia to block access to LinkedIn for violating Personal Data Law
Russia to block access to LinkedIn  for violating Personal Data LawRussia to block access to LinkedIn  for violating Personal Data Law
Russia to block access to LinkedIn for violating Personal Data Law
 
Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016
Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016
Fintech and Data Protection by Balint Halasz and Zoltan Tarjan 25 10 2016
 
Russian Legal Seminar 2014 - Legal advice for foreigners doing business in Ru...
Russian Legal Seminar 2014 - Legal advice for foreigners doing business in Ru...Russian Legal Seminar 2014 - Legal advice for foreigners doing business in Ru...
Russian Legal Seminar 2014 - Legal advice for foreigners doing business in Ru...
 
Data Localisation in Russia - A Self-imposed Sanction
Data Localisation in Russia - A Self-imposed SanctionData Localisation in Russia - A Self-imposed Sanction
Data Localisation in Russia - A Self-imposed Sanction
 
The GDPR, Brexit, the UK and adequacy
The GDPR, Brexit, the UK and adequacyThe GDPR, Brexit, the UK and adequacy
The GDPR, Brexit, the UK and adequacy
 
Are you compliant?
Are you compliant?Are you compliant?
Are you compliant?
 
GDPR - a view for the non experts
GDPR - a view for the non expertsGDPR - a view for the non experts
GDPR - a view for the non experts
 
Doing Business In Russia
Doing Business In RussiaDoing Business In Russia
Doing Business In Russia
 
CCSP_Self_Domain_6.ppt
CCSP_Self_Domain_6.pptCCSP_Self_Domain_6.ppt
CCSP_Self_Domain_6.ppt
 
State regulation of information protection in the cloud - international and K...
State regulation of information protection in the cloud - international and K...State regulation of information protection in the cloud - international and K...
State regulation of information protection in the cloud - international and K...
 
Special Challenges of Doing Business in Russia
Special Challenges of Doing Business in RussiaSpecial Challenges of Doing Business in Russia
Special Challenges of Doing Business in Russia
 
The GDPR for Techies
The GDPR for TechiesThe GDPR for Techies
The GDPR for Techies
 

PLB Conference_Doing Business in Russia_Privacy Law Risk Update_July 5 2016

  • 1. Doing Business in Russia: Privacy Law Risk Update Anastasia Zagorodnaya Of Counsel Dentons St. Petersburg, Russia Privacy Laws & Business 29th Annual International Conference July 5, 2016 Cambridge
  • 2. 1. rather advanced (based on the 1981 Convention) and developing 2. localization (HIGH RISK!) 3. specific security measures prescribed by law 4. claims may be submitted at the data subject’s place of residence 5. cultural aspects are of importance 2 5 key things you need to know about Russian DP law and practice
  • 3. 3 1981 Convention, in force for RU since 01.09.2013 RF Constitution Arts. 23&24 Special provisions in various laws Data Protection Law No. 152-FZ оf 27.07.2006 Law on Information No. 149-FZ of 27.07.2006 Civil, Labor and Criminal Codes, Code on Admin Offences Civil Procedure Code Overview: Legal framework rules on certain categories of data and data subjects (e.g. Labor Code on HR data) right to privacy jurisdiction over disputes general regulations, bloggers, open data, RTF liability • Government Resolutions • Roscomnadzor Orders • Orders of other Authorities (Federal Security Service, Federal Service for Tech and Export Control, etc.)
  • 4. Overview: Notification to Roscomnadzor 4 • Prior to processing • Key exemptions: • Paper or electronic, to include information on operator, data categories, means and purposes of processing, security measures, local database, etc. • No fees • Obligation to update (including in view of localization) within 10 business days HR data agreement conclusion and performance publicly available data full names only manual processing
  • 5. Overview: Consent 5 • required unless limited grounds for processing apply • specific, informed and freely given • any provable form, EXCEPT FOR: sensitive data data to be made publicly available HR data transfer to third parties cross-border transfer to “unsafe” countries automatic processing results in legal consequences WRITTEN consent subject to specific requirements bio data
  • 6. Overview: Cross-border transfer 6 • Parties to the 1981 Convention • Countries from the list approved by the regulator (17, including Australia, Argentina, Korea, New Zealand, Canada, Mexico) Subject to the general provisions of the Data Protection Law • Everybody else: e.g. USA • Written consent, EXCEPT FOR:  international treaties  federal laws (state and personal security)  contract performance  protection of health/life of the data subject or third parties vs.
  • 7. 7 Overview: Sanctions (1)* •ADMINISTRATIVE: fine up to 65 EUR, disqualification for up to 3 years Company CIVIL: Compensation of damages or moral sufferings Company officer • ADMINISTRATIVE : • fine up to 130 EUR draft bill to significantly increase fines •CRIMINAL: fine of up to 4,000 EUR, imprisonment of up to 2 years or other punishment Other negative consequences • visa issues for foreign nationals • order to terminate allegedly illegal processing (?) • license suspension (?) * Liability may vary depending on the applicable legal provision. AND/OR AND/OR AND/OR
  • 8. Website blocking • Data subject may file a lawsuit at his/her place of residence and based on the court’s decision to apply to Roscomnadzor in order to promptly limit access to information processed in violation of DP legislation on the Internet • Roscomnadzor will notify the web owner/hosting provider. If they fail to limit access to the information in dispute, access to the entire website will be blocked • Interpretation – only websites where personal data is made publicly available, may be blocked, but risks of broader interpretation by local courts exist 8 Overview: Sanctions (2)
  • 9. Localization requirement 9 ‘While collecting personal data, including by means of the Internet, the operator must ensure that recording, systemization, compilation, storage, modification (updating, alteration), and retrieval of personal data of the Russian citizens is done using databases located on the territory of the Russian Federation, except for …’ Federal Law of 21 July 2014 No. 242-FZ (aka “Localization law”) added the following provision to the Data Protection Law:
  • 10. Localization requirement: Exceptions Generally NOT applicable to business: • journalist, scientific and creative activities • judicial and enforcement purposes • state and municipal services • international treaty requirements or performance of functions imposed by Russian law (!) General obligation to keep HR and accounting records DOES NOT serve as grounds for exemption 10
  • 11. Localization requirement: Ministry Guidance (1) Ministry of Telecom and Mass Communications clarifications http://minsvyaz.ru/ru/personaldata/#1438548328715 1. Jurisdiction • Russian companies or representative offices registered in Russia • Foreign companies that have no Russian presence but “target” (direct their activities at) the Russian market. “Directed at” concept for websites: (!) + at least one of the following in addition to the above : • payments available in RUB • contract performance on the territory of Russia (goods/service delivery, use of digital content) • ads in Russian promoting website • other circumstances evidencing that Russian market is part of the business strategy UNLESS exceptions apply 11 .moscow, etc.) Use of domain names associated with Russia (.ru, .moscow, etc.) A website version (or page) in Russianand /or
  • 12. Localization requirement: Ministry Guidance (2) 2. Application • Collection: “intentional” from data subject directly or via specifically engaged third parties. • employee/representative contact data exchanged in the course of business not covered. • Consent effect: none (but reduces risk of claims from a data subject) • Cross-border transfer: not affected; Russian citizens’ data entered into a local Russian database (“primary database”) may be further transferred to a database abroad (“secondary database”), with applicable formalities. • Database: initially broad concept, now favoring a narrower approach (!) • No retroactive effect: data collected before entry into force is not covered; yet, mentioned operations with old data (e.g. update) trigger the need to comply. • Citizenship: no rules, operator can define itself. If no procedure established, amendment may be applied to all data collected in Russia. Guidance status: non-binding, but all we have 12
  • 13. • Roscomnadzor is mostly interested in mass processing (online retailers, social networks, insurance companies, banks, etc.) • Scheduled inspections: • Over 640 companies already inspected including major online retailers (wildberries.ru, OZON.ru, Lamoda.ru, KupiVIP.ru). • 4 companies found non-compliant, must comply within 6 months • Over 900 more companies are scheduled for inspection in 2016, including: British American Tobacco, HP, Raiffeisenbank, McDonalds. • Unscheduled inspections possible (including at the data subject’s request). 13 Localization requirement: Enforcement
  • 14. Localization requirement: practical approaches 14 Main solutions depending on business features and “starting points”: • Changing the set of data processed or steps to anonymize • Delegation of processing • “Primary database” localization in Russia
  • 15. •Roscomnadzor strategy paper •Creation of a single online register of PD submitted by data subjects via websites, when visiting business centers and similar venues with controlled admission •Big data regulation •Employee surveillance •… 15 Latest news/initiatives/trends
  • 17. Contacts 17 Anastasia Zagorodnaya Of Counsel, St. Petersburg phone: + 7 812 325 84 44 fax: + 7 812 325 84 54 е-mail: anastasia.zagorodnayaa@dentons.com Nick Graham Partner, London phone: + 44 20 7320 6907 fax: + 44 20 7246 7777 е-mail: nick.graham@dentons.com