Associate of Corporate practice Vadim Kovalev speaks for SecureNews on amendments to the Personal Data Law and consequences for small and medium businesses

Данного материала не существует на русском языке

The State Duma Committee on Constitutional Legislation and State Construction approved the amendments to the law “On personal data” in the first reading. The authors are planning to oblige personal data operators to inform the authorized body on information leakages. However, is everybody content with the draft law? What are the consequences of the law for the information security market? A word to the industry experts.

THE LAW COULD BECOME A BURDEN FOR SMALL AND MEDIUM BUSINESSES

The proposed amendments are consistent with the general trends in development of foreign legislation in this area. In particular, in the European Union, communication services providers are required to notify clients and authorized bodies of security violations which adversely affect personal data of such users. In addition, in autumn 2018, the General Data Protection Regulation takes effect in the EU, which not only directly obliges to notify authorities and users of leakages, but also contains strict punishment for companies that conceal the data disclosure. Almost all US states provide for the obligation to notify of personal data leakages.

The Russian draft law also obliges the operator to notify the Federal Service for Supervision of Communications, Information Technology, and Mass Media (Roskomnadzor) of the fact of user personal data leakage to the public. At the same time, the current draft law does not oblige the operators to notify the users directly of the leakages, which is undoubtedly a substantial omission, as the user does not have an opportunity to take the appropriate measures on minimizing the consequences of the personal data disclosure. Among the weakness of the draft law is also the absence of procedure and specific timeframes for notifying Roskomnadzor of leakages. Nevertheless, it has been told that the authors intend to amend the draft law and make the respective amendments by the second reading.

In general, the idea of the draft law can be assessed as a positive one, and the draft law finalization and its course of examination at the State Duma can be monitored in the future.

This draft law, if adopted, should not substantially influence the Russian information security market. Major and technologically advanced companies spend substantial money on ensuring data security, including personal data of their clients, employees and users. Furthermore, many companies understand the value of data protection, as its leakage or unauthorized access to it is fraught with high reputational risks.

For small and medium businesses, this draft law can be more burdensome; however, due to the small volume of personal data being processed, it is unlikely to be valuable for criminals, and as compared to the large organizations, they are less exposed to the leakage risks.

In general, we can speak to the point on the consequences of the draft law being adopted after the amendments and additions are made, and the procedure and timeframes for notifying of personal data leakage are specified.

For more details see the article at https://securenews.ru/personal_data_operators/





Также вас может заинтересовать

Аналитика

Legal Brief: 20-й пакет санкций ЕС. Новые ограничения в сфере интеллектуальной собственности

23 апреля 2026 года Совет ЕС принял 20-й пакет ограничительных мер в отношении России. Пакет включает санкционные меры не только в энергетике, финансовом секторе, торговле и цифровой сфере, но и в сфере права…

СМИ о нас

Виктор Калужский для ЭЖ-Юрист: в Госдуму внесен законопроект, закладывающий основы отраслевого регулирования

Впервые на законодательном уровне предлагается урегулировать отношения, связанные с созданием, эксплуатацией и оборотом…

Новость

Партнер CLS Елена Степанова - в числе юристов-лидеров рынка коммерческой недвижимости CRE100 Legal

Елена Степанова седьмой год подряд входит в рейтинг самых влиятельных персон рынка коммерческой недвижимости России CRE100 (Top…

СМИ о нас

Импортеры начнут платить косвенные налоги авансом с 1 июня: что нужно знать бизнесу

С 1 июня импортеры из стран Евразийского экономического союза начнут платить НДС и акциз с поставки еще до ввоза товаров…