Russia's Article 10.1 on Personal Data Dissemination: Apparent and Real Contradictions in Federal Law 152-FZ
Part II of the series examines whether the text of Article 10.1 of Federal Law 152-FZ is workable after the concept was completely rewritten between the first and second readings without public discussion. The analysis focuses on three questions that any operator must answer: the meaning of the key terms 'access', 'dissemination' and 'provision'; the legal basis on which a person who obtained data from an open source may process them; and how restrictions set by the data subject reach that person and what happens when they are violated.
The author compares the terminology of 152-FZ with the general information law 149-FZ, both adopted on the same day in 2006. While 152-FZ defines both dissemination and provision through the undefined term 'disclosure', 149-FZ supplies a usable definition of 'access' as the possibility of obtaining information and using it. This definition is treated as a state rather than an action, which helps explain some provisions but creates new contradictions elsewhere.
Part 9 of Article 10.1 allows the data subject to prohibit an operator from transferring data to an unlimited circle of persons except by providing access, and to prohibit that circle from processing the data except by obtaining access. The first prohibition is coherent: the operator may keep data publicly available where consent permits but may not sell arrays, fulfil individual requests or otherwise transfer the data. The second prohibition, however, leads to an irresolvable collision because the word 'use' appears both in the definition of access and in the list of processing operations, making any consistent reading either ban reading the published data or permit almost all forms of processing.
The original draft by deputy Gorelkin had preserved the ground of public availability under Article 6 while conditioning it on the subject's conditions and prohibitions. This ground was removed during the second reading, and the special regime moved to Article 10.1 without a corresponding processing basis for subsequent operators. Judicial practice, including cases such as А40-5250/2017 and several 2022–2024 decisions, confirms that openness alone does not authorise processing; each subsequent operator must establish its own ground under Article 6.
Two readings of the special consent are possible. Under the 'portable consent' reading, the consent would authorise further processing by an unlimited circle within the recorded limits; under the narrower reading, it only authorises the primary operator's disclosure and every other person must find an independent ground. Courts appear to favour the narrower view, leaving the conditions and prohibitions without a legal foundation that would make them effective.
Parts 11 and 15 expressly exclude processing in state, public or other legally defined public interests and processing by state and municipal bodies from the operation of the article. These carve-outs were deliberately retained and expanded during the second reading. The resulting structure therefore preserves the subject's ability to set conditions while simultaneously removing the legal basis those conditions were intended to regulate.
Related articles
Bank of Russia Publishes Methodological Recommendations No. 3-MR on AI Security for Financial Market Participants
The Bank of Russia has released methodological recommendations No. 3-MR dated 16 June 2026, providing detailed guidance on ensuring information security during the development and use of artificial intelligence systems in the financial sector. The document builds on the earlier Code of Ethics for AI in finance and integrates with existing risk management, operational resilience, and data protection frameworks already familiar to credit institutions and other market participants. It introduces standardized terminology for AI-specific threats such as hallucinations, data drift, and poisoned datasets while outlining six risk categories and a four-stage AI system lifecycle model. Organizations are advised to apply threat modeling based on FSTEC methodology, implement proportional controls across data preparation, development, training, and operation phases, and maintain human oversight for high-risk automated processes. Special attention is given to supply chain risks involving third-party vendors and open-source components, requiring due diligence, provenance tracking, and contractual safeguards aligned with existing outsourcing standards. The recommendations remain non-binding yet signal clear regulatory expectations that are likely to influence future compliance checks and audits.
Aladdin Obtains New FSB Certificate for CryptoFlash Encrypted USB Drive Valid Until 2029
Aladdin has received a new FSB Russia certificate for its Aladdin CryptoFlash hardware-encrypted USB drive. The certificate number СФ/124-5574 confirms compliance with cryptographic protection requirements for classes KS1 and KS2 and remains valid until 16 July 2029. The device now supports additional Russian Linux distributions including RED OS 7.3 and 8, Alt 8 SP Workstation, Alt Workstation 10, and the OS of the Moscow Electronic School. Read and write speeds have been increased to 11 MB/s while the graphical interface received improvements. The product uses the Magma encryption algorithm in hardware and operates as a clientless solution that requires no additional drivers or software. The previous certificate remains active until December 2028, allowing both versions of the device to be used in parallel for storing and transferring official and confidential information marked DSP.
Microsoft Tightens Corporate Windows Activation with TPM-Bound KMS Servers
Microsoft is strengthening its corporate Windows licensing controls by introducing new requirements for KMS servers used in volume activation. The changes will bind KMS hosts to TPM hardware attestation, preventing cloned or fake servers from issuing licenses to unlicensed devices. Warnings will begin appearing in Windows Server 2025 in August 2026, with mandatory enforcement planned for the next LTSC release. Existing KMS systems will continue operating normally until the new rules take effect. The update targets enterprise environments with on-premises KMS infrastructure and does not affect individual consumer devices or common non-KMS activation bypass methods. Administrators can already verify TPM support on physical servers using the Get-TpmSupportedFeature command.
Why Deep Packet Inspection Overestimates Its Reach in Encrypted Networks
Modern encryption has fundamentally limited the effectiveness of Deep Packet Inspection systems, leaving network monitors with only metadata and behavioral patterns rather than actual content. DPI tools can still classify traffic types and apply policies based on visible flow characteristics, but they cannot read messages, files, or credentials inside properly encrypted sessions without explicit TLS inspection. The article details how TLS 1.3, Encrypted Client Hello, and QUIC further reduce passive visibility while corporate inspection remains possible only when endpoint devices trust an organizational certificate. Russian regulatory requirements around TSPU systems are discussed separately from corporate DPI use, with emphasis on the need for technical confirmation rather than assumptions. The piece also clarifies distinctions between DPI, IDS, IPS, and DLP, and explains why machine learning cannot convert metadata into decrypted payloads. Overall, the analysis shows that DPI remains useful for traffic management and known-threat detection where visibility exists, but it cannot serve as a complete security foundation.