Outstaffing medical reps in russian pharma just got riskier. Seven zones the man must cover now.
When a pharmaceutical company moves its medical representatives off-staff, it looks like the risk stays with the agency. In practice the opposite is true: an external employee’s mistake almost always lands on the Marketing Authorization Holder (MAH). Since 30 May 2025, that mistake has become far more expensive, because Russia overhauled the fines for personal data leaks.
Outstaffing of medical representatives has long been a mainstream HR tool. Companies cut payroll costs and rapidly scale up field teams to launch a drug or run a regional project. Along with that flexibility, they take on seven independent risk zones that are rarely counted together: labor, tax, advertising and antitrust, pharmacovigilance, operational and financial, ethical, and personal data protection.
How External Staff Risks Used to Be Assessed
Chapter 53.1 of the Labor Code of the Russian Federation (LC RF) has been in force since 2016 and effectively bans agency labor, leaving a narrow corridor of legal exceptions. Only a Private Employment Agency (PEA) accredited by Rostrud, the Federal Service for Labor and Employment, may supply personnel. Part 2 of Article 341.2 of the LC RF allows a company to bring in external staff in three cases only: personal services for individuals, covering for an employee who is temporarily absent, and a knowingly temporary expansion of production or services for no more than nine months.
For a pharma company’s compliance team, this long stayed a checklist item: confirm the entry in the PEA register, sign the contract, log the assignment period, close the file. Personal data protection sat at the bottom of that checklist. The fine for processing data without proper consent, under Part 1 of Article 13.11 of the Code of Administrative Offenses of the Russian Federation (CAO RF), ran from 60,000 to 100,000 rubles for a legal entity, and an agency-issued device with CRM access looked like a minor detail.
Government oversight has shifted over the same period. Labor inspectors and courts have moved from checking paperwork to examining actual working conditions: who assigns the medical representative’s weekly tasks, who signs off on the visit report, whose corporate email address appears in the signature line. Once an external employee is indistinguishable from a staff member on these points, the agency contract risks being reclassified as an employment contract from the date work actually began. The date of the court ruling doesn’t change that; the court is simply confirming a relationship that already existed.
Seven Risk Zones Now Counted Together
The legal framework hasn’t changed: Chapter 53.1 of the LC RF still governs contracts for the supply of labor. The everyday word «outstaffing» doesn’t appear in the law at all; lawyers use it purely for convenience. What has changed is the scale of the fallout from a single mistake. These seven areas used to be checked by different people at different times: a lawyer looked at labor risk, an accountant at tax risk, the quality department at pharmacovigilance. Now regulators can pursue a fine on each front at once, and a single incident involving an external medical representative can hit three of them simultaneously.
Labor risk. Working with an unaccredited agency counts as illegal use of agency labor. Courts and labor inspectors increasingly look past the paperwork to actual working conditions: does the external representative follow the client’s internal schedule, does he take instructions directly from the client’s managers? For avoiding a proper employment contract, or dressing one up as a civil-law agreement, Part 4 of Article 5.27 of the CAO RF sets a fine for legal entities of 50,000 to 100,000 rubles; a repeat violation under Part 5 of the same article raises it to 100,000-200,000 rubles.
Tax risk. Article 54.1 of the Tax Code of the Russian Federation (TC RF) bars reducing the tax base by misrepresenting the facts of economic activity. A classic audit trigger: full-time medical representatives are dismissed and the same people are hired back through an agency within a day or two. The Federal Tax Service treats this as artificial fragmentation aimed at cutting insurance contributions or keeping eligibility for the simplified tax regime. Once the scheme is proven, the tax authority restores the client’s liabilities in full, assesses back insurance contributions and personal income tax with penalties, and disallows the agency fees as an expense for profit tax purposes. A further red flag for auditors: shared beneficial owners between the client and the agency, or an agency set up shortly before a major contract was signed.
Advertising and antitrust risk. A medical representative speaks for the pharmaceutical company even when not formally on its payroll. Federal Law No. 38-FZ «On Advertising» puts the liability for what he says on the MAH. For violations of drug advertising requirements, Part 5 of Article 14.3 of the CAO RF sets fines of 2,000-2,500 rubles for individuals, 10,000-20,000 rubles for officers, and 200,000-500,000 rubles for legal entities. If an external representative spreads false claims about a competing drug, the case falls under Article 14.33 of the CAO RF on unfair competition, with a fine for legal entities of 100,000-500,000 rubles.
Pharmacovigilance risk. Medical representatives are the first link in the chain that collects adverse-reaction reports. The Good Pharmacovigilance Practice (GVP) rules of the Eurasian Economic Union, approved by EEC Council Decision No. 87 of 3 November 2016, place full responsibility for the pharmacovigilance system on the MAH, including any work handed off to an outside contractor. Inspections by the member states’ competent authorities cover not just the MAH but any organization it has engaged for pharmacovigilance work. The rules require an organization to have enough competent, trained specialists for pharmacovigilance, with training that includes an induction course and ongoing instruction for the whole time someone is on the job. If an external representative isn’t trained to log safety reports, or the agency contract has no firm deadline for passing on that data, the MAH risks an order following an inspection, and in cases of systematic gaps in safety data, suspension of the marketing authorization.
Operational and financial risk. Staff turnover at agencies runs higher than in-house, and an external representative who sees the job as temporary is less likely to build long-term relationships with physicians. Losing accreditation, or the agency going bankrupt, is a sharper version of the same problem: hundreds of representatives lose their legal basis to work in a single day, leaving the MAH without a field force in the middle of a marketing push. If the agency falls behind on salaries or insurance contributions, its staff can bring labor claims that pull in the client as the de facto employer.
Ethical risk. The Code of Ethics of the Association of International Pharmaceutical Manufacturers (AIPM) requires a physician to know clearly which company’s interests the person in front of them represents, regardless of how that person is formally employed. Transfers of Value disclosure rules require publishing spend on events, honoraria, and educational grants for physicians, and routing the payments through an outstaffing agency doesn’t exempt the MAH from consolidating them in its report. Opaque payments of this kind risk breaching anti-corruption law, including the US FCPA and the UK Bribery Act for companies with a foreign parent. The AIPM Code treats using an agency to place sham specialists who pose as independent voices to shape opinion on a drug as a serious breach, one that can bring public censure and expulsion from the association.
Personal data protection risk. Medical representatives work from tablets and phones loaded with CRM systems holding physicians’ contact details and, in patient support programs, health information. Under outstaffing, the device and the login often sit outside the client’s IT department’s control. This is the risk zone that has changed the most.
What Changed for Data Protection on 30 May 2025
Federal Law No. 420-FZ of 30 November 2024 rewrote Article 13.11 of the CAO RF, tying the fine for the first time to the scale of the leak, and adding a turnover-based fine tied to annual revenue for repeat violations. In parallel, Federal Law No. 421-FZ of 30 November 2024 added Article 272.1 to the Criminal Code of the Russian Federation (CC RF), introducing criminal liability, including up to ten years’ imprisonment for aggravating circumstances, for the illegal collection, storage, and distribution of personal data. Handing data to a contractor doesn’t relieve the MAH of liability as the data controller: under Federal Law No. 152-FZ «On Personal Data» (hereinafter, 152-FZ), it’s the controller, not the processor, who sets the purposes for processing physicians’ contact details and patient data, and the agency is only a technical processor acting on instruction.
| Indicator | Before 30 May 2025 | After 30 May 2025 |
|---|---|---|
| Processing without proper consent | 60,000-100,000 ₽ (Part 1, Art. 13.11 CAO) | Unchanged |
| Leak affecting 1,000 to 10,000 data subjects | No standalone provision | 3,000,000-5,000,000 ₽ |
| Leak affecting more than 100,000 data subjects | No standalone provision | 10,000,000-15,000,000 ₽ |
| Leak of biometric or special-category data | No standalone provision | Up to 20,000,000 ₽ |
| Repeat leak | No standalone provision | 1-3% of annual revenue, 20,000,000-500,000,000 ₽ |
| Failure to notify Roskomnadzor within 24 hours | 3,000-5,000 ₽ (Art. 19.7 CAO) | 1,000,000-3,000,000 ₽ |
| Criminal liability for the officer in charge | None | Art. 272.1 CC RF, up to 10 years’ imprisonment for aggravating circumstances |
Health information that representatives collect through patient support programs counts as a special category of personal data. A leak of that data set through an external employee’s unsecured tablet lands in the top row of the table.
The typical scenario is unremarkable: an employee leaves for a competitor and takes a physician database export on a personal phone, or an agency keeps login credentials in a shared inbox with no access controls. Before 30 May 2025, an incident like that risked a fine of around 100,000 rubles and wasn’t treated as a serious project risk. Now, the same incident can bring a fine in the tens of millions of rubles and a criminal case against the officer responsible.
What to Do
Before signing a contract with an outstaffing agency, run a check across five areas at once. Accreditation alone isn’t enough.
| Audit criterion | What to request | Risk indicator |
|---|---|---|
| Rostrud status | Extract from the register of accredited PEAs | Missing entry or accreditation about to expire |
| Financial health | Balance sheet and profit-and-loss statement | Tax arrears, operating losses |
| Industry experience | References from other pharma companies | No familiarity with GVP or the AIPM Code |
| Liability insurance | Agency’s professional liability policy | No cover for professional errors |
| IT security | Description of data protection and access-control systems | Use of public email instead of a corporate CRM |
Once the partner check is done, six actions remain inside the company itself.
Check the agency’s accreditation in the Rostrud register. A missing entry or an accreditation close to expiry rules out that PEA, whatever the price. Repeat the check at least once a quarter, since accreditation can be revoked while a contract is still running.
Cap the staff-expansion period at nine months. Set a hard limit in the contract on how long personnel can be assigned for a temporary expansion of the field team, and keep a calendar of renewals and re-registrations. That cap doesn’t apply when covering for an employee on maternity leave, but the link to that specific absent employee should be written down separately.
Add a pharmacovigilance clause to the contract. Require the agency to train representatives on how to log adverse-reaction reports, with a deadline of no more than 24 hours from receipt for passing on safety data. Reserve the MAH’s right to run unscheduled audits of the agency’s processes.
Set up technical protection on the devices. Roll out multi-factor authentication, data encryption, and remote wipe on the tablets and phones external staff use to connect to the CRM. Restrict access to patients’ health data on a need-to-know basis.
Run a compliance audit of the agency before signing. Ask the prospective provider for its PEA register extract, financial statements, liability insurance policy, and a description of its personal data protection procedures. Put the audit findings in writing so they can be shown to a regulator on request.
Prepare a plan for the agency losing its accreditation. Decide in advance where the field team would move if the provider stopped operating, and keep a backup PEA’s contact details on hand. Have the main agency commit in the contract to a set deadline for notifying you of any accreditation problems.
As recently as three years ago, vetting an outstaffing agency came down to a call to Rostrud and a look at its accounts. The personal data reform has changed that math: a single leak through an unsecured medical representative’s tablet can now cost the MAH more than the annual budget for its entire field force. Companies still picking an agency on price alone should run those numbers again. A functional outsourcing model, paid for the end result rather than for headcount supplied, cuts the risk of the relationship being reclassified as employment and makes data protection easier to control, because accountability for a given process stays with one vendor.
Regulatory framework:
1. Eurasian Economic Commission Council Decision No. 87 of 3 November 2016 «On Approval of the Good Pharmacovigilance Practice Rules of the Eurasian Economic Union»
2. Labor Code of the Russian Federation, Chapter 53.1 (Arts. 341.1-341.5)
3. Code of Administrative Offenses of the Russian Federation, Art. 5.27, Art. 13.11, Art. 14.3, Art. 14.33, Art. 19.7
4. Criminal Code of the Russian Federation, Art. 272.1 (introduced by Federal Law No. 421-FZ of 30 November 2024)
5. Tax Code of the Russian Federation, Art. 54.1
6. Federal Law No. 152-FZ of 27 July 2006 «On Personal Data» (as amended by Federal Law No. 420-FZ of 30 November 2024, in force from 30 May 2025)
7. Federal Law No. 38-FZ of 13 March 2006 «On Advertising»
8. Federal Law No. 135-FZ of 26 July 2006 «On Protection of Competition»