Data Protection in Russia

Breach notification in Russia

Under the recently adopted amendments, in case of establishing the fact of unlawful or occasional transfer or dissemination of personal data, that caused a violation of data subject rights, the data controller must:

  • within 24 hours notify Roskomnadzor about:
    • the incident;
    • believed reasons that caused violation of data subject rights;
    • estimated harm inflicted to data subject rights;
    • measures taken to cure consequences of the incident; and
    • details of the contact person to communicate with Roskomnadzor.
  • within 72 hours notify Roskomnadzor about the results of internal investigation of the incident as well as to provide the information on the parties, if any, whose actions caused the incident.

The above timeframes are very short that may cause significant practical difficulties in complying with them.

Continue reading

  • no results

Previous topic
Back to top