Federal Law 152 "On Personal Data Protection" applies to all existing subjects: individuals and legal entities, federal government bodies, and local government. In fact, this law applies to any organizations processing information and personal data of Russian citizens, regardless of ownership structure and organization size.
Sometimes an organization may unexpectedly discover initially implicit personal data information systems (PDIS). For example, a company is considered an operator of personal data if its website has feedback forms, registration and authorization forms, and other data collection forms that can identify the subject.
Control and supervision of compliance with the requirements of the Federal Law "On Personal Data" are carried out by regulators:
- Roskomnadzor regarding the protection of the rights of personal data subjects;
- FSB of Russia in terms of compliance with requirements in the field of cryptography;
- FSTEC of Russia concerning compliance with requirements for protecting information from unauthorized access and leakage through technical channels.
Since the Federal Law "On Personal Data" is only the basis for the legal provision of personal data protection, its requirements have been further specified in acts of the Government of the Russian Federation, the Ministry of Communications, and other regulatory and methodological documents.
Federal bodies regulating activities in the field of personal data processing
- Roskomnadzor (Federal Service for Supervision of Communications and Mass Media) - oversees and monitors compliance of personal data processing with legal requirements.
- FSTEC of Russia (Federal Service for Technical and Export Control) - establishes methods and means of information protection using technical means.
- FSB of Russia (Federal Security Service of Russia) - establishes methods and means of information protection within its authority (scope of use of cryptographic means of information protection).
Every organization that processes personal data faces the challenge of aligning its information systems with legal requirements. Protecting personal data is one of the most pressing issues, not only in Russia but also in other countries.Ā

Types of Personal Data
According to Federal Law 152, personal data is any information related to an identified or identifiable natural person (the subject of personal data). For example: name, date and place of birth, address, family, social, property status, education, etc.
Personal data is divided into several categories:
Special Categories
Personal data related to racial or ethnic origin, political views, religious or philosophical beliefs, health status, intimate life
Biometric Data
Personal data that characterizes the physiological and biological characteristics of a person, based on which their identity can be established, and which is used by the operator for identifying the subject of personal data
Other
Personal data relating to a directly or indirectly identified or identifiable natural person, not falling into the above categories
Publicly Available Data
Personal data obtained from publicly available sources where the data was published with the written consent of the subject of personal data
Processing of personal data is any action (operation) or a set of actions with personal data using automated means or not, including:
- collection,
- recording,
- systematization,
- accumulation,
- storage,
- clarification (updating, modification),
- extraction,
- use,
- transfer (distribution, provision, access),
- depersonalization,
- blocking,
- deletion,
- destruction of personal data.
Liability for Violations
According to Article 24 of Federal Law 152, individuals bear responsibility for violations of the law in accordance with the legislation of the Russian Federation.
When inspecting a company, regulators are guided by Federal Law 152 and a number of subordinate acts. Inspections can be both scheduled and unscheduledābased on violations as well as to monitor previously issued orders for their correction.
Individuals who violate the requirements for personal data protection may face not only civil and disciplinary liability, but also administrative and even criminal liability.
Ā
How to comply with the requirements of FZ-152?
Thus, a company or organization processing personal data or other restricted access information must protect this information in accordance with the law. This not only requires serious expertise, knowledge, and experience, but also involves technical complexities and significant costs.
According to the official definition approved by the FSTEC, '... The security of personal data is the state of protection of personal data, characterized by the ability of users, technical means, and information technologies to ensure the confidentiality, integrity, and availability of personal data during their processing in personal data information systems...'

To meet the organizational, legal, and technical requirements of FZ-152 independently, one must study not only the law itself but also its subordinate acts, and understand which specific measures need to be taken. Outsourced specialists can examine the processes for processing personal data within the company, create the necessary documents, implement protection measures, etc.
A comprehensive information protection system includes:
- Intrusion detection systems (IDS).
- Firewalls (FW).
- Protection against malware.
- A security event monitoring and logging system.
- A cryptographic protection system for communication channels (encryption).
- Protection measures for virtual environments, a system for preventing unauthorized access (UAC), identification, and access management.
- A vulnerability analysis/protection system, etc.
In addition, comprehensive information security involves not only technical but also organizational measures.
Cloud FZ-152: Implementation features
A number of Russian providers offer cloud infrastructure services for hosting information systems in accordance with federal legislation regarding personal data. When placing client systems in the cloud, the provider takes on many cybersecurity responsibilities, including those related to personal data protection. During the migration to the cloud, they will ensure the security of the IT infrastructure, relieving some responsibilities from the client. For example, the provider meets the requirements of Federal Law 152 concerning the protection of the virtualization environment.
Providers may also offer clients expert support in solving data protection issues: determining the required level of security and proposing implementation options accordingly; developing documentation to comply with Russian law.
A secure cloud will help optimize the organization's costs by reducing expenses on the creation and maintenance of IT infrastructure and internal information protection systems. Generally, qualified experts provide comprehensive technical support, including consulting and the development of documentation packages for certification with regulatory authorities, and the service platform meets strict technical standards and satisfies necessary organizational requirements. Clients can benefit from services for preparing the necessary documentation and protection of personal data information systems at the application and operating system levels.
Processes for managing risks and vulnerabilities, incident investigation, internal and external security audits, as well as regular monitoring and testing of the network, systems, and information security processes, are also provided. Qualified specialists ensure round-the-clock support for the IT infrastructure.
Together, these measures ensure compliance with federal legislation regarding personal data protection.
Certified platform
IBS DataFort provides such a service based on . All technical components, administration, and virtualization tools of this platform comply with the norms and requirements of Federal Law 152.
Architecture of the secure cloud by IBS DataFort.
The platform provides guaranteed protection of personal data (up to level 1 of security inclusive), GIS (up to class 1 of security inclusive), and secure data storage in a Tier III data center. The platform employs certified firewalls, intrusion detection and prevention systems (IDS/IPS), encryption of communication channels (GOST VPN), antivirus protection, measures against unauthorized access, virtualization environment protection, and vulnerability scanning tools.
ā also a suitable solution for those who have high requirements for privacy and data protection, want to strengthen their business reputation, or gain a competitive advantage such as a verified high level of information security.
How to 'move' to such a cloud? Is 'seamless migration' possible? Absolutely. For example, IBS DataFort carries out a secure transfer of personal data to its protected cloud, minimizing downtime and impact on the company's business processes (including from foreign sites).
Aligning IT infrastructure with Federal Law 152
The process of aligning the client's IT infrastructure with the requirements of Federal Law 152 begins with an audit and assessment of the current level of security.
The client's IT infrastructure audit includes an examination of data processing and protection processes and an assessment of the client's personal data. A report of the assessment is compiled, detailing the data processing procedures from a technical standpoint.
The work also includes threat modeling and perpetrator analysis, as well as compiling a report defining the level of security for personal data. Based on the audit findings, a specific technical assignment for the personal data protection system is formulated, outlining the requirements for the designed system.
A set of policies, instructions, regulations, and other documents for personal data protection is developed. Meanwhile, specialists aim to optimize the client's costs on implementing protection measures.
IBS DataFort provides services for preparing documentation and protecting personal data to comply with federal legislation on personal data protection and can assist in the preparation and passage of certification (personal data, GIS, AS).
Certification is conducted by independent auditors licensed by FSTEC and the FSB of Russia. Passing this certification confirms the reliable protection of the personal data of the company's partners and clients from external threats, ensuring comprehensive compliance with regulatory requirements. Importantly, clients benefit from a 'one-stop shop' convenience: everything is provided by one company ā IBS DataFort.
For the data operator, this means readiness for inspections by Roskomnadzor, FSTEC, and the FSB, eliminating the risks of resource blocking, and avoiding claims and penalties from regulators.
This service is relevant for many categories of clients in the state and corporate sectors and may be in demand by data operators who wish to align their activities with legislation. Hosting information systems in a closed segment of the provider's infrastructure, certified to all necessary standards and requirements, relieves the client of the need to independently organize all operations.
Source: habr.com
