On 26 July 2026, a law was signed tightening the rules for the cross-border transfer of personal data (Federal Law No. 265-FZ “On Amendments to Article 12 of the Federal Law ‘On Personal Data’ and Certain Legislative Acts of the Russian Federation”). The state is consistently taking various measures to ensure the security of personal data, and personal data protection legislation is undergoing significant changes.
As of now, the law has already entered into force, with the exception of the provisions on the creation and operation of information systems of the state bodies of the city of Moscow — these will enter into force on 1 September 2027.
What is the main essence of the changes?
The legislator has clarified the criteria for including foreign states in the list of countries whose measures for the protection of personal data are recognised as adequate. Whereas previously the decision was mostly based on the formal existence of legal regulation in the field of personal data corresponding to the provisions of the 1981 Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (de facto based on membership in the Convention), the approach has now fundamentally changed. It is no longer sufficient that the state to which personal data is planned to be transferred has laws on the protection of personal data — there must be real and effective measures for their enforcement.
What does this mean in practice?
Even if the state receiving the personal data of Russian citizens has a sufficient regulatory and legal framework, if in practice the authorised bodies of the foreign state fail to ensure the protection of personal data, that state may not be included in the list of states ensuring adequate protection of the rights of personal data subjects. The existing list (see Order of Roskomnadzor of 05.08.2022 No. 128 “On Approval of the List of Foreign States Ensuring Adequate Protection of the Rights of Personal Data Subjects”), in connection with the adoption of the new law, is likely to be revised in the foreseeable future, and we further expect its periodic updating.
We remind you that the inclusion of foreign states in the list of those ensuring adequate protection of the rights of personal data subjects allows the operator to carry out the cross-border transfer of personal data immediately after submitting a notification to Roskomnadzor. If the foreign state is not included in the said list, the cross-border transfer of personal data is possible only upon the expiry of 10 working days from the date of receipt of the notification by Roskomnadzor.
Therefore, in order to avoid violation of the legislation, before a cross-border transfer it is mandatory to check whether the status of the state to which personal data is planned to be transferred has changed.
What does this mean for personal data subjects?
For citizens — personal data subjects — the guarantees of ensuring the security of the transfer will only increase. The clarification of the criteria helps to prevent the transfer of personal data to those countries where there is a high risk of their unlawful dissemination and processing.
