SlideShare uma empresa Scribd logo
1 de 24
Processing of Personal Data. 
What’s new? 
by Anton Kabakov 
Hellevig, Klein & Usov 
November 21, 2014 
1
2 2 
From 1.1.2015 all Russian citizens’ 
personal data should be stored 
only in Russia!
3 3 
Amendments to the law: 
Russian citizens’ personal 
data need to be recorded, 
compiled, stored, refined 
(updated, modified), extracted 
using databases located in 
Russia with certain 
exceptions.
1. What is considered to be “personal data” and what is 
not? 
2. Is it currently allowed to transfer personal data abroad? 
3. What are the changes to the law and what do they really 
state? 
4. When these changes are expected to come into force? 
4 4
• Russian definition of "personal data" is "broad" and borrowed from 
European Union law 
5 5 
Russia 
(Art. 3 (1)(1) of the Federal Law On Personal Data 
dated July 27, 2006) 
European Union 
(Art. 2 Directive 95/46/EC of the European Parliament and of 
the Council of 24 October 1995 on the protection of 
individuals with regard to the processing of personal data 
and on the free movement of such data) 
Any information related to directly 
or indirectly identified or identifiable 
natural person. 
Any information relating to an identified 
or identifiable natural person. An 
identifiable person is one who can be 
identified, directly or indirectly, in 
particular by reference to an identification 
number or to one or more factors specific 
to his physical, psychological, mental, 
economic, cultural or social identity.
 Vadim Ampelonsky (official representative of state controlling body 
- Roskomnadzor): "The minimum set of personal data necessary for 
the identification of the person is a combination of the first and last 
name and photograph of the subject”. 
(http://lenizdat.ru/articles/1124854/). 
 Physiological and biological features of a person on the basis of 
which one can identify him (Part 1, Art. 11 of the Law On Personal 
Data). 
 Can a person be identified by the IP-address of his computer, his e-mail 
account, or Skype account? 
6 6 
Which data are sufficient to 
identify a person?
7 7 
Mr. Homer JMayr. SHimoMmprs.e oSrn iJm,a Sypa sSfoiemntyp Isnosnpector at the 
Springfield Nuclear Power Plant
Information considered to be personal data identifying a person: 
 Passport data 
 Fingerprinting information 
 Name together with photograph 
 Name together with the date of birth, and information about the parents 
and their dates of birth 
Information not sufficient to identify a person and not considered personal 
data: 
 Solely the name or registered address of the person 
 Blood group, etc. 
 Nationality 
8 8
Public 
Biometric 
Special ("sensitive"), i.e., data relating to racial or ethnic 
origin, political opinions, religious or philosophical beliefs, 
health, private life 
Depersonalized? Is it still personal data if the natural 
person is not any longer identifiable? 
NEW REGULATION WILL APPLY TO ALL KINDS OF PERSONAL 
DATA 
9 9 
Kinds of personal data.
10 
Law On Personal Data: 
Cross-border transfer of personal data to foreign states that are parties to 
the Convention for the Protection of Individuals with regard to Automatic 
Processing of Personal Data, as well as other foreign countries ensuring 
adequate protection of the rights of subjects of personal data is carried out 
in accordance with this federal law, and may be prohibited or limited in 
order to protect the constitutional system of the Russian Federation, 
morality, health, rights and lawful interests of citizens, national defense 
and state security. 
Convention on the Protection of Individuals with regard to 
Automatic Processing of Personal Data: 
A party shall not prohibit or subject to special authorization cross-border 
flows of personal data going to the territory of another party, for the sole 
purpose of protecting privacy.
a) Parties to the on the Protection of Individuals with regard to Automatic 
b) Ensuring adequate protection of the rights of the subjects of the personal 
11 
Sure, if personal data is transferred in foreign countries: 
Processing of Personal Data (which Russia is a party to) OR 
Ministry of 
Labor guidelines 
Amendments to 
Administrative Offenses 
and Criminal Codes 
data OR 
c) Any of the countries with the written consent of the individual 
Exceptions: Race, political opinion, religious convictions or other beliefs, health or 
private life, criminal record.
Russian citizens’ personal data will need to 
be recorded, compiled, stored, refined 
(updated, modified), extracted using 
databases located in Russia. 
12 12 
Companies will be required to notify the 
state agency of the location database with 
personal data. 
State authorities will be entitled to block 
the site violating the law On Personal Data.
 When are these changes expected to come into force? 
 Who fall under its scope? Territorial or extraterritorial 
principle of operation of the new law? 
 Are all categories of personal data of Russian citizens (public, 
biometric, special) prohibited from being stored using a 
database located abroad? 
 Will it not be possible to store personal data abroad 
duplicating if on the Russian databases (mirrors)? 
 If personal data is stored on mobile device (phone, laptop) 
how to comply with the requirement to keep it in Russia? 
13 13
Personal data may recorded and stored abroad in cases where 
processing of personal data is necessary for inter alia: 
achieving the goals of an international treaty of the Russian 
Federation or the law, for fulfillment of operator’s obligations / 
function set out by law 
Does this mean that mandatory HR information may be stored 
abroad as previously? 
14
If data is transferred cross border, apparently it 
will be stored abroad. 
As long as cross-border transfer of personal data 
is allowed, there could be no prohibition to 
store data abroad. 
It is possible to have solely mirror-databases in 
Russia 15
Questions Responses 
How do the restrictions correlate 
with the Convention of the Council 
of Europe? 
Can be personal data be stored in 
Russia and abroad? 
Can one store depersonalized 
personal data abroad? 
Opinion of Roskomnadzor: 
- Personal data may be transmitted 
abroad. After use it must be 
deleted; 
- Personal data may not be stored 
abroad. 
Opinion of presidential 
administration: No. It must be stored 
only in Russia. 
Technically, yes. 
16
A public authority may require the hosting 
provider to block the site on the basis of a 
court decision. 
Fine on the offending company of up to RUB 
10,000 
17 17
18 
Individual files a claim 
together with the court 
decision to state 
Получение 
объяснений 
Применение 
дисциплинарного 
взыскания 
agency 
Court rules that site 
violates Law on Personal 
Data 
Hosting provider sends 
notice to owner of 
resource 
State agency 
sends notice to 
hosting provider 
Owner of resource must 
remove the violation 
Hosting provider limits 
access
19 
State agency opens access 
Owner of resource or 
hosting provider contacts 
Применение 
дисциплинарного 
взыскания 
state agency 
Owner of resource 
removes violation/ 
Court cancels earlier 
decision
American and European models of cross-border transfer of personal data 
The Russian model for cross-border transfer of personal data leans toward 
that of the EU. 
20 20 
USA European Union 
 There are no restrictions on 
cross-border transfer of 
personal data 
 Is not a country that 
provides the appropriate 
level of protection of 
personal data from the EU 
perspective 
 Safe Harbor Regulations 
 Cross-border transfer of personal data is 
allowed only in countries that ensure an 
adequate level of protection of these data 
 Requirements for the cross-border transfer 
of personal data can be applied to their 
subsequent transfer (art. 40 of the Proposal 
for a General Data Protection Regulation) 
 Planned transition from territorial to 
extraterritorial model (item 19 of the 
Preamble of the Proposal for a General Data 
Protection Regulation)
Recommendation: 
 Notify state authorities of personal data processing. If the 
company plans to process personal data, we recommend that 
prior to the entry into force of the law it notify the state authority. 
In that case, it does not need to specify the location of the 
databases with personal data. 
 Duplicate personal data in Russia, keeping original data abroad? 
 Transfer depersonalized data abroad? 
 Audit HR documents to identify those which may be stored 
21 
abroad 
 Duplicate personal data stored on mobile devices on servicers 
located in Russia?
• Measures must be necessary and sufficient to protect personal data against unauthorized access, 
destruction, copying, distribution or other misuse. 
• The operator independently determines the composition and the list of measures that are 
necessary and sufficient to fulfill the requirements of the Law. 
22 22 
Legal and organizational Technical 
 Consent to process personal data, 
 Local policy documents in relation to the 
processing of personal data, 
 Evaluation of the harm that may be caused to 
citizens in the case of the processing of their 
personal data in violation of the law, 
 Ensure unlimited access to policy documents of 
the operator in respect of the processing of 
personal data which meet the requirements for 
the protection of personal data. 
Accounting for machine storage devices of 
personal data, 
Application of approved procedures for 
assessment of means of information protection, 
Recovery of personal data, modified or destroyed 
by unauthorized access to it.
15.1.2012 23 
Offices in 3 countries: 
Russia 
Ukraine 
Finland 
150 professionals 
at your service 
Partnerships: 
AEB 
AmCham 
AHK 
SVKK 
SPIBA
Anton Kabakov 
Anton.Kabakov@awaragroup.com 
+7 (921) 397 1193 
Call-center for all offices: 
+7 495 225 30 38 
24

Mais conteúdo relacionado

Mais procurados

RTI Sikkim Rules ppt
RTI  Sikkim Rules pptRTI  Sikkim Rules ppt
RTI Sikkim Rules pptBhim Thatal
 
Bulletin - US-EU Data Privacy Safe Harbor Program Invalidated
Bulletin - US-EU Data Privacy Safe Harbor Program InvalidatedBulletin - US-EU Data Privacy Safe Harbor Program Invalidated
Bulletin - US-EU Data Privacy Safe Harbor Program InvalidatedCohenGrigsby
 
Bmc pio by shailesh gandhi
Bmc pio by shailesh gandhiBmc pio by shailesh gandhi
Bmc pio by shailesh gandhiDr Rita
 
Rti beginners 5 nov '12 by shailesh gandhi
Rti  beginners 5 nov '12 by shailesh gandhiRti  beginners 5 nov '12 by shailesh gandhi
Rti beginners 5 nov '12 by shailesh gandhiDr Rita
 
Overview of the Egyptian Personal Data Protection Law
Overview of the Egyptian Personal Data Protection LawOverview of the Egyptian Personal Data Protection Law
Overview of the Egyptian Personal Data Protection LawFatmaAkram2
 
Breve sintesi della "Personal Information Protection Law" cinese
Breve sintesi della "Personal Information Protection Law" cineseBreve sintesi della "Personal Information Protection Law" cinese
Breve sintesi della "Personal Information Protection Law" cineseEdoardo Ferraro
 
RTI request to MOLAJ dated 14.08.2016
RTI request to MOLAJ dated 14.08.2016 RTI request to MOLAJ dated 14.08.2016
RTI request to MOLAJ dated 14.08.2016 Om Prakash Poddar
 
Second Appeal dated 21.04.2017 before CIC New Delhi against Non-disclosure of...
Second Appeal dated 21.04.2017 before CIC New Delhi against Non-disclosure of...Second Appeal dated 21.04.2017 before CIC New Delhi against Non-disclosure of...
Second Appeal dated 21.04.2017 before CIC New Delhi against Non-disclosure of...Om Prakash Poddar
 
Surveillance and data retention in Poland
Surveillance and data retention in PolandSurveillance and data retention in Poland
Surveillance and data retention in PolandRemigiuszRosicki
 
интерпол
интерполинтерпол
интерполnalianalia
 
Oig cbp holding rooms
Oig cbp holding roomsOig cbp holding rooms
Oig cbp holding roomsBryan Johnson
 
First Appeal to MOLAJ dated 03.09.2016
 First Appeal to MOLAJ dated 03.09.2016 First Appeal to MOLAJ dated 03.09.2016
First Appeal to MOLAJ dated 03.09.2016Om Prakash Poddar
 
Bombay high court suo moto pil
Bombay high court suo moto pilBombay high court suo moto pil
Bombay high court suo moto pilsabrangsabrang
 
Pra Primer 04072010
Pra Primer 04072010Pra Primer 04072010
Pra Primer 04072010dslunceford
 
Data Privacy - Rights of the Data Subject
Data Privacy - Rights of the Data SubjectData Privacy - Rights of the Data Subject
Data Privacy - Rights of the Data SubjectJDP Consulting
 
Freedom on the Net 2015 - Russia (Freedom House)
Freedom on the Net 2015 - Russia (Freedom House)Freedom on the Net 2015 - Russia (Freedom House)
Freedom on the Net 2015 - Russia (Freedom House)Artem Kozlyuk
 

Mais procurados (20)

RTI Sikkim Rules ppt
RTI  Sikkim Rules pptRTI  Sikkim Rules ppt
RTI Sikkim Rules ppt
 
Bulletin - US-EU Data Privacy Safe Harbor Program Invalidated
Bulletin - US-EU Data Privacy Safe Harbor Program InvalidatedBulletin - US-EU Data Privacy Safe Harbor Program Invalidated
Bulletin - US-EU Data Privacy Safe Harbor Program Invalidated
 
Bmc pio by shailesh gandhi
Bmc pio by shailesh gandhiBmc pio by shailesh gandhi
Bmc pio by shailesh gandhi
 
Rti beginners 5 nov '12 by shailesh gandhi
Rti  beginners 5 nov '12 by shailesh gandhiRti  beginners 5 nov '12 by shailesh gandhi
Rti beginners 5 nov '12 by shailesh gandhi
 
Justice raja judgment
Justice raja judgmentJustice raja judgment
Justice raja judgment
 
Cia fy2017 foia_annual_report
Cia fy2017 foia_annual_reportCia fy2017 foia_annual_report
Cia fy2017 foia_annual_report
 
Overview of the Egyptian Personal Data Protection Law
Overview of the Egyptian Personal Data Protection LawOverview of the Egyptian Personal Data Protection Law
Overview of the Egyptian Personal Data Protection Law
 
Breve sintesi della "Personal Information Protection Law" cinese
Breve sintesi della "Personal Information Protection Law" cineseBreve sintesi della "Personal Information Protection Law" cinese
Breve sintesi della "Personal Information Protection Law" cinese
 
RTI request to MOLAJ dated 14.08.2016
RTI request to MOLAJ dated 14.08.2016 RTI request to MOLAJ dated 14.08.2016
RTI request to MOLAJ dated 14.08.2016
 
Second Appeal dated 21.04.2017 before CIC New Delhi against Non-disclosure of...
Second Appeal dated 21.04.2017 before CIC New Delhi against Non-disclosure of...Second Appeal dated 21.04.2017 before CIC New Delhi against Non-disclosure of...
Second Appeal dated 21.04.2017 before CIC New Delhi against Non-disclosure of...
 
Surveillance and data retention in Poland
Surveillance and data retention in PolandSurveillance and data retention in Poland
Surveillance and data retention in Poland
 
интерпол
интерполинтерпол
интерпол
 
Oig cbp holding rooms
Oig cbp holding roomsOig cbp holding rooms
Oig cbp holding rooms
 
RTI ACT 2005 PART-III
RTI ACT 2005 PART-IIIRTI ACT 2005 PART-III
RTI ACT 2005 PART-III
 
First Appeal to MOLAJ dated 03.09.2016
 First Appeal to MOLAJ dated 03.09.2016 First Appeal to MOLAJ dated 03.09.2016
First Appeal to MOLAJ dated 03.09.2016
 
2020 Global Review of Constitutional Law. Ukraine
2020 Global Review of Constitutional Law. Ukraine2020 Global Review of Constitutional Law. Ukraine
2020 Global Review of Constitutional Law. Ukraine
 
Bombay high court suo moto pil
Bombay high court suo moto pilBombay high court suo moto pil
Bombay high court suo moto pil
 
Pra Primer 04072010
Pra Primer 04072010Pra Primer 04072010
Pra Primer 04072010
 
Data Privacy - Rights of the Data Subject
Data Privacy - Rights of the Data SubjectData Privacy - Rights of the Data Subject
Data Privacy - Rights of the Data Subject
 
Freedom on the Net 2015 - Russia (Freedom House)
Freedom on the Net 2015 - Russia (Freedom House)Freedom on the Net 2015 - Russia (Freedom House)
Freedom on the Net 2015 - Russia (Freedom House)
 

Destaque

Constraintsand challenges
Constraintsand challengesConstraintsand challenges
Constraintsand challengesjyotikhadake
 
Noggin - World's first marketplace for Personal Data
Noggin - World's first marketplace for Personal DataNoggin - World's first marketplace for Personal Data
Noggin - World's first marketplace for Personal DataNoggin Asia
 
My Data, My Value: 6 Sense Making Diagrams from the Personal Data Ecosystem.
My Data, My Value: 6 Sense Making Diagrams from the Personal Data Ecosystem.My Data, My Value: 6 Sense Making Diagrams from the Personal Data Ecosystem.
My Data, My Value: 6 Sense Making Diagrams from the Personal Data Ecosystem.Kaliya "Identity Woman" Young
 
Data protection act
Data protection act Data protection act
Data protection act Iqbal Bocus
 
Data Privacy and Protection Presentation
Data Privacy and Protection PresentationData Privacy and Protection Presentation
Data Privacy and Protection Presentationmlw32785
 
Data protection ppt
Data protection pptData protection ppt
Data protection pptgrahamwell
 

Destaque (8)

Constraintsand challenges
Constraintsand challengesConstraintsand challenges
Constraintsand challenges
 
Noggin - World's first marketplace for Personal Data
Noggin - World's first marketplace for Personal DataNoggin - World's first marketplace for Personal Data
Noggin - World's first marketplace for Personal Data
 
My Data, My Value: 6 Sense Making Diagrams from the Personal Data Ecosystem.
My Data, My Value: 6 Sense Making Diagrams from the Personal Data Ecosystem.My Data, My Value: 6 Sense Making Diagrams from the Personal Data Ecosystem.
My Data, My Value: 6 Sense Making Diagrams from the Personal Data Ecosystem.
 
Identity 101: Boot Camp for Identity North 2016
Identity 101: Boot Camp for Identity North 2016Identity 101: Boot Camp for Identity North 2016
Identity 101: Boot Camp for Identity North 2016
 
Personal Data Ecosystem - NSTIC Privacy Workshop
Personal Data Ecosystem - NSTIC Privacy WorkshopPersonal Data Ecosystem - NSTIC Privacy Workshop
Personal Data Ecosystem - NSTIC Privacy Workshop
 
Data protection act
Data protection act Data protection act
Data protection act
 
Data Privacy and Protection Presentation
Data Privacy and Protection PresentationData Privacy and Protection Presentation
Data Privacy and Protection Presentation
 
Data protection ppt
Data protection pptData protection ppt
Data protection ppt
 

Semelhante a Processing of Personal Data. What’s new?

Judgment of the Court_ the right to be forgotten
Judgment of the Court_ the right to be forgottenJudgment of the Court_ the right to be forgotten
Judgment of the Court_ the right to be forgottenMonica Lupașcu
 
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...Dr. Oliver Massmann
 
General Data Protection Regulation (GDPR) | Privacy Law in India |
General Data Protection Regulation (GDPR) | Privacy Law in India |General Data Protection Regulation (GDPR) | Privacy Law in India |
General Data Protection Regulation (GDPR) | Privacy Law in India |Bivas Chatterjee
 
Jamaica's Data Protection Act: Compliance required from the business community
Jamaica's Data Protection Act: Compliance required from the business communityJamaica's Data Protection Act: Compliance required from the business community
Jamaica's Data Protection Act: Compliance required from the business communityEmerson Bryan
 
Sovereignty: the state of data
Sovereignty: the state of dataSovereignty: the state of data
Sovereignty: the state of datadan hyde
 
Curia case c‑131-12 gonzalez versus google
Curia   case c‑131-12 gonzalez versus googleCuria   case c‑131-12 gonzalez versus google
Curia case c‑131-12 gonzalez versus googleJan Husar
 
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIADR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIADr. Oliver Massmann
 
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfAll_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfJakeAldrinDegala1
 
English заключение закон-о_блогерах
English заключение закон-о_блогерахEnglish заключение закон-о_блогерах
English заключение закон-о_блогерахSarkis Darbinyan
 
DollarPesa - User Agreement.pdf
DollarPesa - User Agreement.pdfDollarPesa - User Agreement.pdf
DollarPesa - User Agreement.pdfDOLLARPESA LTD
 
Data Privacy Act of 2012 (R.A. 10173) Briefing 2017
Data Privacy Act of 2012 (R.A. 10173) Briefing 2017Data Privacy Act of 2012 (R.A. 10173) Briefing 2017
Data Privacy Act of 2012 (R.A. 10173) Briefing 2017Jay Castillo
 
PERSONAL-DATA-PROTECTION-BILL-2018.pptx
PERSONAL-DATA-PROTECTION-BILL-2018.pptxPERSONAL-DATA-PROTECTION-BILL-2018.pptx
PERSONAL-DATA-PROTECTION-BILL-2018.pptxssuser36d167
 
2014-04-16 Protection of Personal Information Act Readiness Workshop
2014-04-16 Protection of Personal Information Act Readiness Workshop2014-04-16 Protection of Personal Information Act Readiness Workshop
2014-04-16 Protection of Personal Information Act Readiness WorkshopPaul Jacobson
 
Asia Counsel Insights May 2023
Asia Counsel Insights May 2023Asia Counsel Insights May 2023
Asia Counsel Insights May 2023Minh Duong
 
NEW DECREE ON PERSONAL DATA PROTECTION - WHAT YOU MUST KNOW
NEW DECREE ON PERSONAL DATA PROTECTION - WHAT YOU MUST KNOWNEW DECREE ON PERSONAL DATA PROTECTION - WHAT YOU MUST KNOW
NEW DECREE ON PERSONAL DATA PROTECTION - WHAT YOU MUST KNOWDr. Oliver Massmann
 

Semelhante a Processing of Personal Data. What’s new? (20)

Judgment of the Court_ the right to be forgotten
Judgment of the Court_ the right to be forgottenJudgment of the Court_ the right to be forgotten
Judgment of the Court_ the right to be forgotten
 
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
NEW DECREE ON PERSONAL DATA PROTECTION AND CROSS-BORDER PROVISION OF DATA THE...
 
GDPR and Copyright Law
GDPR and Copyright LawGDPR and Copyright Law
GDPR and Copyright Law
 
General Data Protection Regulation (GDPR) | Privacy Law in India |
General Data Protection Regulation (GDPR) | Privacy Law in India |General Data Protection Regulation (GDPR) | Privacy Law in India |
General Data Protection Regulation (GDPR) | Privacy Law in India |
 
Jamaica's Data Protection Act: Compliance required from the business community
Jamaica's Data Protection Act: Compliance required from the business communityJamaica's Data Protection Act: Compliance required from the business community
Jamaica's Data Protection Act: Compliance required from the business community
 
Sovereignty: the state of data
Sovereignty: the state of dataSovereignty: the state of data
Sovereignty: the state of data
 
Curia case c‑131-12 gonzalez versus google
Curia   case c‑131-12 gonzalez versus googleCuria   case c‑131-12 gonzalez versus google
Curia case c‑131-12 gonzalez versus google
 
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIADR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
 
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdfAll_you_need_to Know_About_the_Data_Privacy_Act.pdf
All_you_need_to Know_About_the_Data_Privacy_Act.pdf
 
China-PIPL.pdf
China-PIPL.pdfChina-PIPL.pdf
China-PIPL.pdf
 
GDPR and Personal Data Transfers 1.1.pdf
GDPR and Personal Data Transfers 1.1.pdfGDPR and Personal Data Transfers 1.1.pdf
GDPR and Personal Data Transfers 1.1.pdf
 
GDPR, Data Privacy.
GDPR, Data Privacy.GDPR, Data Privacy.
GDPR, Data Privacy.
 
English заключение закон-о_блогерах
English заключение закон-о_блогерахEnglish заключение закон-о_блогерах
English заключение закон-о_блогерах
 
DollarPesa - User Agreement.pdf
DollarPesa - User Agreement.pdfDollarPesa - User Agreement.pdf
DollarPesa - User Agreement.pdf
 
Data Privacy Act of 2012 (R.A. 10173) Briefing 2017
Data Privacy Act of 2012 (R.A. 10173) Briefing 2017Data Privacy Act of 2012 (R.A. 10173) Briefing 2017
Data Privacy Act of 2012 (R.A. 10173) Briefing 2017
 
PERSONAL-DATA-PROTECTION-BILL-2018.pptx
PERSONAL-DATA-PROTECTION-BILL-2018.pptxPERSONAL-DATA-PROTECTION-BILL-2018.pptx
PERSONAL-DATA-PROTECTION-BILL-2018.pptx
 
Data Protection Factsheet
Data Protection FactsheetData Protection Factsheet
Data Protection Factsheet
 
2014-04-16 Protection of Personal Information Act Readiness Workshop
2014-04-16 Protection of Personal Information Act Readiness Workshop2014-04-16 Protection of Personal Information Act Readiness Workshop
2014-04-16 Protection of Personal Information Act Readiness Workshop
 
Asia Counsel Insights May 2023
Asia Counsel Insights May 2023Asia Counsel Insights May 2023
Asia Counsel Insights May 2023
 
NEW DECREE ON PERSONAL DATA PROTECTION - WHAT YOU MUST KNOW
NEW DECREE ON PERSONAL DATA PROTECTION - WHAT YOU MUST KNOWNEW DECREE ON PERSONAL DATA PROTECTION - WHAT YOU MUST KNOW
NEW DECREE ON PERSONAL DATA PROTECTION - WHAT YOU MUST KNOW
 

Mais de Awara Direct Search

Обзор заработных плат в сфере фармацевтического производства в Москве.
Обзор заработных плат в сфере фармацевтического производства в Москве.Обзор заработных плат в сфере фармацевтического производства в Москве.
Обзор заработных плат в сфере фармацевтического производства в Москве.Awara Direct Search
 
Обзор зарплат в Санкт-Петербурге в 2015 году
Обзор зарплат в Санкт-Петербурге в 2015 годуОбзор зарплат в Санкт-Петербурге в 2015 году
Обзор зарплат в Санкт-Петербурге в 2015 годуAwara Direct Search
 
Зарплаты в москве в период санкций и девальвации рубля
Зарплаты в москве в период санкций и девальвации рубляЗарплаты в москве в период санкций и девальвации рубля
Зарплаты в москве в период санкций и девальвации рубляAwara Direct Search
 
Обзор заработных плат в сфере HR в Москве
Обзор заработных плат в сфере HR в МосквеОбзор заработных плат в сфере HR в Москве
Обзор заработных плат в сфере HR в МосквеAwara Direct Search
 
Personal Data Processing in Russia
Personal Data Processing in RussiaPersonal Data Processing in Russia
Personal Data Processing in RussiaAwara Direct Search
 
Leadership and Employee Engagement 07.12.2014
Leadership and Employee Engagement 07.12.2014Leadership and Employee Engagement 07.12.2014
Leadership and Employee Engagement 07.12.2014Awara Direct Search
 
Laki henkilötietojen ja asiakastietojen pakollisesta sijoittamisesta Venäjälle
Laki henkilötietojen ja asiakastietojen pakollisesta sijoittamisesta VenäjälleLaki henkilötietojen ja asiakastietojen pakollisesta sijoittamisesta Venäjälle
Laki henkilötietojen ja asiakastietojen pakollisesta sijoittamisesta VenäjälleAwara Direct Search
 
Johtaminen ja uuden ajan organisaatio Venäjällä
Johtaminen ja uuden ajan organisaatio VenäjälläJohtaminen ja uuden ajan organisaatio Venäjällä
Johtaminen ja uuden ajan organisaatio VenäjälläAwara Direct Search
 
Обзор уровня заработных плат в Санкт-Петербурге в 2013 году
Обзор уровня заработных плат в Санкт-Петербурге в 2013 годуОбзор уровня заработных плат в Санкт-Петербурге в 2013 году
Обзор уровня заработных плат в Санкт-Петербурге в 2013 годуAwara Direct Search
 
Исследование Совокупного Налогового Бремени на Оплату Труда – 2014
Исследование Совокупного Налогового Бремени на Оплату Труда – 2014Исследование Совокупного Налогового Бремени на Оплату Труда – 2014
Исследование Совокупного Налогового Бремени на Оплату Труда – 2014Awara Direct Search
 
Обзор заработных плат в области подбора персонала в Казани
Обзор заработных плат в области подбора персонала в КазаниОбзор заработных плат в области подбора персонала в Казани
Обзор заработных плат в области подбора персонала в КазаниAwara Direct Search
 
Обзор заработных плат в области подбора персонала в Санкт-Петербурге
Обзор заработных плат в области подбора персонала в Санкт-ПетербургеОбзор заработных плат в области подбора персонала в Санкт-Петербурге
Обзор заработных плат в области подбора персонала в Санкт-ПетербургеAwara Direct Search
 
Обзор заработных плат в области подбора персонала в Краснодаре
Обзор заработных плат в области подбора персонала в КраснодареОбзор заработных плат в области подбора персонала в Краснодаре
Обзор заработных плат в области подбора персонала в КраснодареAwara Direct Search
 
Обзор заработных плат в Астане
Обзор заработных плат в АстанеОбзор заработных плат в Астане
Обзор заработных плат в АстанеAwara Direct Search
 
Обзор заработных плат в Баку
Обзор заработных плат в БакуОбзор заработных плат в Баку
Обзор заработных плат в БакуAwara Direct Search
 
Salary Survey in Construction Sphere in Kazan
Salary Survey in Construction Sphere in KazanSalary Survey in Construction Sphere in Kazan
Salary Survey in Construction Sphere in KazanAwara Direct Search
 
Salary Survey in Construction Sphere in Sochi
Salary Survey in Construction Sphere in SochiSalary Survey in Construction Sphere in Sochi
Salary Survey in Construction Sphere in SochiAwara Direct Search
 

Mais de Awara Direct Search (20)

Обзор заработных плат в сфере фармацевтического производства в Москве.
Обзор заработных плат в сфере фармацевтического производства в Москве.Обзор заработных плат в сфере фармацевтического производства в Москве.
Обзор заработных плат в сфере фармацевтического производства в Москве.
 
Обзор зарплат в Санкт-Петербурге в 2015 году
Обзор зарплат в Санкт-Петербурге в 2015 годуОбзор зарплат в Санкт-Петербурге в 2015 году
Обзор зарплат в Санкт-Петербурге в 2015 году
 
Зарплаты в москве в период санкций и девальвации рубля
Зарплаты в москве в период санкций и девальвации рубляЗарплаты в москве в период санкций и девальвации рубля
Зарплаты в москве в период санкций и девальвации рубля
 
Обзор заработных плат в сфере HR в Москве
Обзор заработных плат в сфере HR в МосквеОбзор заработных плат в сфере HR в Москве
Обзор заработных плат в сфере HR в Москве
 
Personal Data Processing in Russia
Personal Data Processing in RussiaPersonal Data Processing in Russia
Personal Data Processing in Russia
 
Leadership and Employee Engagement 07.12.2014
Leadership and Employee Engagement 07.12.2014Leadership and Employee Engagement 07.12.2014
Leadership and Employee Engagement 07.12.2014
 
Laki henkilötietojen ja asiakastietojen pakollisesta sijoittamisesta Venäjälle
Laki henkilötietojen ja asiakastietojen pakollisesta sijoittamisesta VenäjälleLaki henkilötietojen ja asiakastietojen pakollisesta sijoittamisesta Venäjälle
Laki henkilötietojen ja asiakastietojen pakollisesta sijoittamisesta Venäjälle
 
Johtaminen ja uuden ajan organisaatio Venäjällä
Johtaminen ja uuden ajan organisaatio VenäjälläJohtaminen ja uuden ajan organisaatio Venäjällä
Johtaminen ja uuden ajan organisaatio Venäjällä
 
Обзор уровня заработных плат в Санкт-Петербурге в 2013 году
Обзор уровня заработных плат в Санкт-Петербурге в 2013 годуОбзор уровня заработных плат в Санкт-Петербурге в 2013 году
Обзор уровня заработных плат в Санкт-Петербурге в 2013 году
 
Исследование Совокупного Налогового Бремени на Оплату Труда – 2014
Исследование Совокупного Налогового Бремени на Оплату Труда – 2014Исследование Совокупного Налогового Бремени на Оплату Труда – 2014
Исследование Совокупного Налогового Бремени на Оплату Труда – 2014
 
Salary Survey in Perm, 2014
Salary Survey in Perm, 2014Salary Survey in Perm, 2014
Salary Survey in Perm, 2014
 
Salary Survey in Astana, 2014
Salary Survey in Astana, 2014Salary Survey in Astana, 2014
Salary Survey in Astana, 2014
 
Обзор заработных плат в области подбора персонала в Казани
Обзор заработных плат в области подбора персонала в КазаниОбзор заработных плат в области подбора персонала в Казани
Обзор заработных плат в области подбора персонала в Казани
 
Salary Survey Baku 2014
Salary Survey Baku 2014Salary Survey Baku 2014
Salary Survey Baku 2014
 
Обзор заработных плат в области подбора персонала в Санкт-Петербурге
Обзор заработных плат в области подбора персонала в Санкт-ПетербургеОбзор заработных плат в области подбора персонала в Санкт-Петербурге
Обзор заработных плат в области подбора персонала в Санкт-Петербурге
 
Обзор заработных плат в области подбора персонала в Краснодаре
Обзор заработных плат в области подбора персонала в КраснодареОбзор заработных плат в области подбора персонала в Краснодаре
Обзор заработных плат в области подбора персонала в Краснодаре
 
Обзор заработных плат в Астане
Обзор заработных плат в АстанеОбзор заработных плат в Астане
Обзор заработных плат в Астане
 
Обзор заработных плат в Баку
Обзор заработных плат в БакуОбзор заработных плат в Баку
Обзор заработных плат в Баку
 
Salary Survey in Construction Sphere in Kazan
Salary Survey in Construction Sphere in KazanSalary Survey in Construction Sphere in Kazan
Salary Survey in Construction Sphere in Kazan
 
Salary Survey in Construction Sphere in Sochi
Salary Survey in Construction Sphere in SochiSalary Survey in Construction Sphere in Sochi
Salary Survey in Construction Sphere in Sochi
 

Último

MOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptx
MOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptxMOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptx
MOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptxRRR Chambers
 
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual serviceCALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual serviceanilsa9823
 
589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdfSUSHMITAPOTHAL
 
Relationship Between International Law and Municipal Law MIR.pdf
Relationship Between International Law and Municipal Law MIR.pdfRelationship Between International Law and Municipal Law MIR.pdf
Relationship Between International Law and Municipal Law MIR.pdfKelechi48
 
INVOLUNTARY TRANSFERS Kenya school of law.pptx
INVOLUNTARY TRANSFERS Kenya school of law.pptxINVOLUNTARY TRANSFERS Kenya school of law.pptx
INVOLUNTARY TRANSFERS Kenya school of law.pptxnyabatejosphat1
 
Appeal and Revision in Income Tax Act.pdf
Appeal and Revision in Income Tax Act.pdfAppeal and Revision in Income Tax Act.pdf
Appeal and Revision in Income Tax Act.pdfPoojaGadiya1
 
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881mayurchatre90
 
Transferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptxTransferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptx2020000445musaib
 
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptxKEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptxRRR Chambers
 
一比一原版西澳大学毕业证学位证书
 一比一原版西澳大学毕业证学位证书 一比一原版西澳大学毕业证学位证书
一比一原版西澳大学毕业证学位证书SS A
 
CAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction FailsCAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction FailsAurora Consulting
 
THE FACTORIES ACT,1948 (2).pptx labour
THE FACTORIES ACT,1948 (2).pptx   labourTHE FACTORIES ACT,1948 (2).pptx   labour
THE FACTORIES ACT,1948 (2).pptx labourBhavikaGholap1
 
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptxPamelaAbegailMonsant2
 
一比一原版旧金山州立大学毕业证学位证书
 一比一原版旧金山州立大学毕业证学位证书 一比一原版旧金山州立大学毕业证学位证书
一比一原版旧金山州立大学毕业证学位证书SS A
 
PPT- Voluntary Liquidation (Under section 59).pptx
PPT- Voluntary Liquidation (Under section 59).pptxPPT- Voluntary Liquidation (Under section 59).pptx
PPT- Voluntary Liquidation (Under section 59).pptxRRR Chambers
 
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...Finlaw Associates
 
Human Rights_FilippoLuciani diritti umani.pptx
Human Rights_FilippoLuciani diritti umani.pptxHuman Rights_FilippoLuciani diritti umani.pptx
Human Rights_FilippoLuciani diritti umani.pptxfilippoluciani9
 
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptxCOPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptxRRR Chambers
 

Último (20)

Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...
Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...
Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...
 
MOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptx
MOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptxMOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptx
MOCK GENERAL MEETINGS (SS-2)- PPT- Part 2.pptx
 
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual serviceCALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
CALL ON ➥8923113531 🔝Call Girls Singar Nagar Lucknow best sexual service
 
589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf
 
Relationship Between International Law and Municipal Law MIR.pdf
Relationship Between International Law and Municipal Law MIR.pdfRelationship Between International Law and Municipal Law MIR.pdf
Relationship Between International Law and Municipal Law MIR.pdf
 
INVOLUNTARY TRANSFERS Kenya school of law.pptx
INVOLUNTARY TRANSFERS Kenya school of law.pptxINVOLUNTARY TRANSFERS Kenya school of law.pptx
INVOLUNTARY TRANSFERS Kenya school of law.pptx
 
Appeal and Revision in Income Tax Act.pdf
Appeal and Revision in Income Tax Act.pdfAppeal and Revision in Income Tax Act.pdf
Appeal and Revision in Income Tax Act.pdf
 
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
 
Transferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptxTransferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptx
 
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptxKEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
 
一比一原版西澳大学毕业证学位证书
 一比一原版西澳大学毕业证学位证书 一比一原版西澳大学毕业证学位证书
一比一原版西澳大学毕业证学位证书
 
CAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction FailsCAFC Chronicles: Costly Tales of Claim Construction Fails
CAFC Chronicles: Costly Tales of Claim Construction Fails
 
THE FACTORIES ACT,1948 (2).pptx labour
THE FACTORIES ACT,1948 (2).pptx   labourTHE FACTORIES ACT,1948 (2).pptx   labour
THE FACTORIES ACT,1948 (2).pptx labour
 
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
8. SECURITY GUARD CREED, CODE OF CONDUCT, COPE.pptx
 
一比一原版旧金山州立大学毕业证学位证书
 一比一原版旧金山州立大学毕业证学位证书 一比一原版旧金山州立大学毕业证学位证书
一比一原版旧金山州立大学毕业证学位证书
 
PPT- Voluntary Liquidation (Under section 59).pptx
PPT- Voluntary Liquidation (Under section 59).pptxPPT- Voluntary Liquidation (Under section 59).pptx
PPT- Voluntary Liquidation (Under section 59).pptx
 
Russian Call Girls Rohini Sector 7 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
Russian Call Girls Rohini Sector 7 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...Russian Call Girls Rohini Sector 7 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
Russian Call Girls Rohini Sector 7 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
 
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
How do cyber crime lawyers in Mumbai collaborate with law enforcement agencie...
 
Human Rights_FilippoLuciani diritti umani.pptx
Human Rights_FilippoLuciani diritti umani.pptxHuman Rights_FilippoLuciani diritti umani.pptx
Human Rights_FilippoLuciani diritti umani.pptx
 
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptxCOPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
 

Processing of Personal Data. What’s new?

  • 1. Processing of Personal Data. What’s new? by Anton Kabakov Hellevig, Klein & Usov November 21, 2014 1
  • 2. 2 2 From 1.1.2015 all Russian citizens’ personal data should be stored only in Russia!
  • 3. 3 3 Amendments to the law: Russian citizens’ personal data need to be recorded, compiled, stored, refined (updated, modified), extracted using databases located in Russia with certain exceptions.
  • 4. 1. What is considered to be “personal data” and what is not? 2. Is it currently allowed to transfer personal data abroad? 3. What are the changes to the law and what do they really state? 4. When these changes are expected to come into force? 4 4
  • 5. • Russian definition of "personal data" is "broad" and borrowed from European Union law 5 5 Russia (Art. 3 (1)(1) of the Federal Law On Personal Data dated July 27, 2006) European Union (Art. 2 Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data) Any information related to directly or indirectly identified or identifiable natural person. Any information relating to an identified or identifiable natural person. An identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to his physical, psychological, mental, economic, cultural or social identity.
  • 6.  Vadim Ampelonsky (official representative of state controlling body - Roskomnadzor): "The minimum set of personal data necessary for the identification of the person is a combination of the first and last name and photograph of the subject”. (http://lenizdat.ru/articles/1124854/).  Physiological and biological features of a person on the basis of which one can identify him (Part 1, Art. 11 of the Law On Personal Data).  Can a person be identified by the IP-address of his computer, his e-mail account, or Skype account? 6 6 Which data are sufficient to identify a person?
  • 7. 7 7 Mr. Homer JMayr. SHimoMmprs.e oSrn iJm,a Sypa sSfoiemntyp Isnosnpector at the Springfield Nuclear Power Plant
  • 8. Information considered to be personal data identifying a person:  Passport data  Fingerprinting information  Name together with photograph  Name together with the date of birth, and information about the parents and their dates of birth Information not sufficient to identify a person and not considered personal data:  Solely the name or registered address of the person  Blood group, etc.  Nationality 8 8
  • 9. Public Biometric Special ("sensitive"), i.e., data relating to racial or ethnic origin, political opinions, religious or philosophical beliefs, health, private life Depersonalized? Is it still personal data if the natural person is not any longer identifiable? NEW REGULATION WILL APPLY TO ALL KINDS OF PERSONAL DATA 9 9 Kinds of personal data.
  • 10. 10 Law On Personal Data: Cross-border transfer of personal data to foreign states that are parties to the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, as well as other foreign countries ensuring adequate protection of the rights of subjects of personal data is carried out in accordance with this federal law, and may be prohibited or limited in order to protect the constitutional system of the Russian Federation, morality, health, rights and lawful interests of citizens, national defense and state security. Convention on the Protection of Individuals with regard to Automatic Processing of Personal Data: A party shall not prohibit or subject to special authorization cross-border flows of personal data going to the territory of another party, for the sole purpose of protecting privacy.
  • 11. a) Parties to the on the Protection of Individuals with regard to Automatic b) Ensuring adequate protection of the rights of the subjects of the personal 11 Sure, if personal data is transferred in foreign countries: Processing of Personal Data (which Russia is a party to) OR Ministry of Labor guidelines Amendments to Administrative Offenses and Criminal Codes data OR c) Any of the countries with the written consent of the individual Exceptions: Race, political opinion, religious convictions or other beliefs, health or private life, criminal record.
  • 12. Russian citizens’ personal data will need to be recorded, compiled, stored, refined (updated, modified), extracted using databases located in Russia. 12 12 Companies will be required to notify the state agency of the location database with personal data. State authorities will be entitled to block the site violating the law On Personal Data.
  • 13.  When are these changes expected to come into force?  Who fall under its scope? Territorial or extraterritorial principle of operation of the new law?  Are all categories of personal data of Russian citizens (public, biometric, special) prohibited from being stored using a database located abroad?  Will it not be possible to store personal data abroad duplicating if on the Russian databases (mirrors)?  If personal data is stored on mobile device (phone, laptop) how to comply with the requirement to keep it in Russia? 13 13
  • 14. Personal data may recorded and stored abroad in cases where processing of personal data is necessary for inter alia: achieving the goals of an international treaty of the Russian Federation or the law, for fulfillment of operator’s obligations / function set out by law Does this mean that mandatory HR information may be stored abroad as previously? 14
  • 15. If data is transferred cross border, apparently it will be stored abroad. As long as cross-border transfer of personal data is allowed, there could be no prohibition to store data abroad. It is possible to have solely mirror-databases in Russia 15
  • 16. Questions Responses How do the restrictions correlate with the Convention of the Council of Europe? Can be personal data be stored in Russia and abroad? Can one store depersonalized personal data abroad? Opinion of Roskomnadzor: - Personal data may be transmitted abroad. After use it must be deleted; - Personal data may not be stored abroad. Opinion of presidential administration: No. It must be stored only in Russia. Technically, yes. 16
  • 17. A public authority may require the hosting provider to block the site on the basis of a court decision. Fine on the offending company of up to RUB 10,000 17 17
  • 18. 18 Individual files a claim together with the court decision to state Получение объяснений Применение дисциплинарного взыскания agency Court rules that site violates Law on Personal Data Hosting provider sends notice to owner of resource State agency sends notice to hosting provider Owner of resource must remove the violation Hosting provider limits access
  • 19. 19 State agency opens access Owner of resource or hosting provider contacts Применение дисциплинарного взыскания state agency Owner of resource removes violation/ Court cancels earlier decision
  • 20. American and European models of cross-border transfer of personal data The Russian model for cross-border transfer of personal data leans toward that of the EU. 20 20 USA European Union  There are no restrictions on cross-border transfer of personal data  Is not a country that provides the appropriate level of protection of personal data from the EU perspective  Safe Harbor Regulations  Cross-border transfer of personal data is allowed only in countries that ensure an adequate level of protection of these data  Requirements for the cross-border transfer of personal data can be applied to their subsequent transfer (art. 40 of the Proposal for a General Data Protection Regulation)  Planned transition from territorial to extraterritorial model (item 19 of the Preamble of the Proposal for a General Data Protection Regulation)
  • 21. Recommendation:  Notify state authorities of personal data processing. If the company plans to process personal data, we recommend that prior to the entry into force of the law it notify the state authority. In that case, it does not need to specify the location of the databases with personal data.  Duplicate personal data in Russia, keeping original data abroad?  Transfer depersonalized data abroad?  Audit HR documents to identify those which may be stored 21 abroad  Duplicate personal data stored on mobile devices on servicers located in Russia?
  • 22. • Measures must be necessary and sufficient to protect personal data against unauthorized access, destruction, copying, distribution or other misuse. • The operator independently determines the composition and the list of measures that are necessary and sufficient to fulfill the requirements of the Law. 22 22 Legal and organizational Technical  Consent to process personal data,  Local policy documents in relation to the processing of personal data,  Evaluation of the harm that may be caused to citizens in the case of the processing of their personal data in violation of the law,  Ensure unlimited access to policy documents of the operator in respect of the processing of personal data which meet the requirements for the protection of personal data. Accounting for machine storage devices of personal data, Application of approved procedures for assessment of means of information protection, Recovery of personal data, modified or destroyed by unauthorized access to it.
  • 23. 15.1.2012 23 Offices in 3 countries: Russia Ukraine Finland 150 professionals at your service Partnerships: AEB AmCham AHK SVKK SPIBA
  • 24. Anton Kabakov Anton.Kabakov@awaragroup.com +7 (921) 397 1193 Call-center for all offices: +7 495 225 30 38 24