HabrJuly 25, 2026🇷🇺Translated from Russian

How Russia's Article 10.1 on Personal Data Dissemination Emerged: Legislative History and Reform Flaws

The Russian personal data protection regime underwent significant change with the introduction of Article 10.1 in Federal Law No. 152-FZ. The reform, formally enacted through Federal Law No. 519-FZ, took effect on 1 March 2021 and required separate consent for processing personal data that a subject permits to be disseminated.

Author Anton Gorelk in, First Deputy Chairman of the State Duma Committee on Information Policy, Information Technology and Communications, sponsored the original bill 1057337-7 on 17 November 2020. The explanatory note claimed that once data appeared on websites, operators could freely accumulate, supplement and analyse it for purposes such as targeted advertising, without further control by the data subject.

This framing overlooked existing judicial practice. In case No. A40-5250/2017, courts upheld Roskomnadzor positions that data from open profiles on VKontakte, Odnoklassniki, Twitter and Avito did not automatically become publicly available personal data under Article 8. The Supreme Court refused to review the case. A further Tagansky District Court ruling on 3 March 2020 ordered an internet page that provided unrestricted access to personal data without consent to be included in the register of violators under Article 15.5 of the Law on Information.

The initial draft proposed a detailed consent mechanism: subjects would list specific categories of data, name the exact internet resources where data could appear, and set conditions or prohibitions. Two distinct prohibitions were envisaged—one preventing the operator from transferring data to an unlimited circle of persons (except providing access), and another preventing that circle from further processing (except receiving access). The draft also allowed subjects to demand cessation of processing at any time without proving a violation.

During the first reading on 9 December 2020, the responsible committee itself stated that the bill’s declared objectives were not achieved by its provisions. The Legal Department warned that the bill’s use of the term “access” conflicted with the definition already contained in 152-FZ, where processing includes transfer and transfer includes access. The committee nevertheless recommended passage, promising corrections before the second reading.

The final text preserved the broad definitions of processing, transfer and dissemination while adding new exceptions and a lengthy new category of data alongside the existing Article 8. The resulting framework mixes several legal models without adequate reconciliation, rendering consistent practical application extremely difficult for operators.

Related articles

AntiMalwarePolicy & Regulation

Ideco NGFW Novum Earns Highest Customer Rating in Quadrant Technologies Import Substitution Study

Ideco NGFW Novum achieved the top customer score of 6.9 out of 10 in the Matrix of Import Substitution 2026: NGFW research conducted by Quadrant Technologies, surpassing the market average of 6.3 and outperforming seven competing Russian solutions. The study evaluated vendors based on specialized revenue alongside 18 criteria covering product quality and functionality, with ratings provided directly by specialists who deploy and operate the firewalls in production environments. Ideco excelled in 11 parameters above seven points, including administration convenience at 7.9, technical support and partner network at 7.6, Zero Trust segmentation at 7.3, and both integration capabilities and core NGFW functionality at 7.2. Despite strong product scores, Ideco remains in the Development quadrant rather than Leadership due to lower profile revenue volume, positioning the company as a prime candidate for advancement with increased sales and large-scale deployments. Complementary testing by Infosystems Jet laboratory showed Ideco NGFW Novum passing 189 of 242 checks under Methodology 3.0 and becoming the sole participant to complete an eight-hour stress test. The broader Russian NGFW market is shifting away from emergency import substitution toward demands for real-world stability, updates, documentation, support, and usability, with product cost cited as a rejection factor by 37.5 percent of respondents.

HabrPolicy & Regulation

Kubernetes Audit Policy Review: Checklist Targets Common Blind Spots in Rules

An experienced Kubernetes administrator shared a detailed review process for audit policies that often remain untouched for years after initial deployment. The 580-line policy was rebuilt using the Kubernetes Threat Matrix from RedGuard as the primary reference. The author highlights recurring issues such as outdated exceptions, missing coverage for new components, and legacy comments that obscure actual security intent. The resulting checklist focuses on principles rather than cluster-specific findings to help other teams perform effective policy audits. Key recommendations address rule completeness, exception management, and periodic full-scale reviews instead of incremental patching. The approach aims to restore audit policies as active security controls rather than accumulated technical debt.

HabrPolicy & Regulation

Avoiding a Leaky Kubernetes Audit Policy: Real-World Configuration Breakdown

Kubernetes Audit Policy is typically configured once during cluster setup and then left untouched for years while accumulating exceptions for new components. Over time the policy stops functioning as a security control and instead becomes an archaeological layer of outdated comments such as "# temporary, TODO remove" that date back three years or more. The author recently reviewed their own 580-line configuration file that had been assembled from multiple sources. Primary reference was the Kubernetes Threat Matrix, which explains why many rules are designed to detect security-relevant actions rather than simply reduce log noise. Examples include targeted monitoring of RBAC modifications and deletion of events. The article emphasizes the need for periodic full reviews instead of incremental patching to maintain effective detection coverage.

AntiMalwarePolicy & Regulation

CryptoPro Develops CryptoPro-Browser with Russian Cryptography for FSB Compliance

CryptoPro is creating its own browser called CryptoPro-Browser as part of the CryptoPro CSP 6.0 cryptographic information protection system. The product will include built-in cryptographic tools, support for the company's plugin, and TLS connections using Russian cryptographic algorithms. The development follows Google's removal of the CryptoPro extension from the Chrome Web Store in February 2025, which left new users without an easy installation method. The project has been coordinated with the FSB of Russia and targets scenarios requiring compliance with Russian information security regulations. CryptoPro plans to incorporate experience from its earlier Chromium-Gost project started in 2017, while also recommending Yandex Browser as an alternative. Analysts estimate the development cost at several tens of millions of rubles, with the main focus on corporate customers needing certificate management and specialized support.