Personal Data Localization Under 152-FZ Mandates Pharma Companies to Store Patient Records in Russia


A company running a patient support program through a European headquarters cloud can receive a penalty order in 2026 without a single data leak. It is enough that a website form sends a patient’s name and diagnosis directly to a foreign database. The maximum sanction for a first offense is 6,000,000 ₽, and 18,000,000 ₽ for a repeat offense.
Before 2025, the localization requirement read as an operator’s duty to ensure that data was stored in Russia, and lawyers found room in that wording for transit schemes. An intermediate server in Russia that instantly forwarded data onward formally satisfied the requirement. Amendments that took effect on 1 July 2025 closed this loophole and turned the duty into a direct prohibition.
For the pharmaceutical industry, the rule touches day-to-day practice directly. Patient support programs, apps for individual compliance packaging, and mobile scanners for marking codes collect specific people’s health data. Under the new fine schedule, this is the costliest category of personal data to get wrong.

How Companies Worked Around Localization Before 2025

Before 1 July 2025, Part 5 of Article 18 of Federal Law No. 152-FZ of 27 July 2006 «On Personal Data» (Law No. 152-FZ) framed the operator’s duty as a positive requirement: to record, accumulate, and store Russian citizens’ personal data in a Russian database. The word «ensure» left operators room for interpretation.
In practice, some international companies used an «interceptor» architecture. A technical server in Russia accepted data from a website form, then immediately forwarded it to a global cloud without keeping a copy for business purposes. The data formally passed through Russian territory, and the operator considered the requirement met.
The same logic applied to off-the-shelf foreign services. Companies connected global CRM platforms for patient support programs, Google Analytics, and WhatsApp and Telegram messenger widgets directly on their websites. These tools collected visitors’ IP addresses and device fingerprints before any data reached a Russian system.
Roskomnadzor (RKN) warned about the risks of this practice for years. Holding an operator liable under the old rule was not easy: regulators had to prove a failure to «ensure» storage, which took more effort than simply establishing the fact of the transfer abroad.
By 2026, manual checks have given way to automated ones. RKN now uses AI-based tools to scan company websites, checking for feedback forms, consent checkboxes, and signs of foreign analytics scripts without an inspector involved. For a pharmaceutical company with a public patient support program website, a localization violation can now be flagged automatically, before any patient complaint or leak incident.

A Direct Ban From 1 July 2025 and a New Fine Schedule

Federal Law No. 23-FZ of 28 February 2025 (FZ No. 23-FZ) rewrote Part 5 of Article 18 of Law No. 152-FZ. The new wording took effect on 1 July 2025 and reads as a direct ban.
When collecting personal data, including collection over the internet, recording, systematizing, accumulating, storing, updating, and retrieving Russian citizens’ data using databases located outside Russia is not permitted. The exceptions cover a narrow list of cases: processing carried out under an international treaty or a law, court proceedings, the provision of state and municipal services, and the professional work of journalists, scientists, writers, or other creative work. None of these exceptions apply to commercial pharmaceutical activity.
The rule separates two processes. The initial collection of a Russian citizen’s data must happen in a Russian database. Subsequent cross-border transfer of already-collected data remains a separate procedure: Part 5 of Article 18 does not list transfer among the prohibited acts, and it is governed separately by Article 12 of Law No. 152-FZ. The new rule does not restrict transferring data already collected in Russia abroad.

ParameterBefore 1 July 2025After 1 July 2025
Statutory dutyOperator must «ensure» recording and storage of personal data in RussiaDirect ban on collection through foreign databases (Part 5, Art. 18)
«Interceptor» transit architectureFormally satisfied the requirementDoes not shield the operator from liability
Consent to process personal dataCould be part of a general contract or questionnaireMust be a standalone document since 1 September 2025
Liability for a data leak, legal entityGeneral rule, fine up to 700,000 ₽3,000,000-15,000,000 ₽ depending on scale, plus a turnover fine for repeat offenses
RKN breach notificationNo dedicated deadline24 hours to notify, 72 hours for investigation results
Data center registryDid not existMaintained by the Ministry of Digital Development from 1 March 2026

Liability for localization violations has grown sharply. Federal Law No. 420-FZ of 30 November 2024 (FZ No. 420-FZ) tightened Article 13.11 of Russia’s Code of Administrative Offenses (KoAP RF) from 30 May 2025.

ViolationFine for a legal entity, first offenseFine for a legal entity, repeat offense
Collecting personal data via foreign databases (Parts 8-9, Art. 13.11 KoAP)1,000,000-6,000,000 ₽6,000,000-18,000,000 ₽
Data leak affecting 1,000-10,000 people (Part 12)3,000,000-5,000,000 ₽turnover fine
Data leak affecting 10,000-100,000 people (Part 13)5,000,000-10,000,000 ₽turnover fine
Data leak affecting over 100,000 people (Part 14)10,000,000-15,000,000 ₽turnover fine
Failing to notify RKN of a leak within 24 hours (Part 11)1,000,000-3,000,000 ₽—

For a repeat leak of personal data of any category, a legal entity faces a turnover fine of 1-3% of annual revenue. The calculated amount cannot fall below 20,000,000 ₽ and cannot exceed 500,000,000 ₽. A leak of special categories of data, including health information, carries a fine of 10,000,000-15,000,000 ₽ for a legal entity regardless of how many patients were affected. As of mid-2026, the first cases involving repeat leaks and turnover fines are already before Russia’s commercial courts, confirming that the rule has moved from statute to enforcement practice.
Separately, an operator must notify RKN of a leak within 24 hours of discovering it and submit the results of its internal investigation within 72 hours, under Part 3.1 of Article 21 of Law No. 152-FZ. Missing this deadline is a separate violation.
Moving primary data collection to Russian infrastructure and replacing foreign SaaS tools takes a one-time investment. For a patient support database of over 100,000 people, one leak costs more than several years of that modernization. A compliance lead should present that difference to the quality director and the finance director in the same figures: it changes the payback calculation for both.

What Primary Collection Means for Websites, CRMs, and Patient Support Programs

The primary-collection requirement changes IT architecture. The legal wording alone does not tell the whole story: a website form for a patient support program (PSP), a CRM used by medical representatives, and a mobile app for individual compliance packaging must all write patient data to a Russian database at the moment it is captured.
Legal advisers agree on one reading: if a system even briefly logs a user’s data on a foreign server, without keeping it for business purposes, this already counts as collection. The «interceptor» architecture described above no longer protects the operator from a fine.
The practical risk for pharmaceutical companies sits at a few specific points. PSP platforms are often built on a headquarters’ global CRM, Salesforce among them, and send diagnosis and prescription data straight to a foreign cloud. Mobile apps that scan Drug Traceability System (MDLP) codes at the point of sale in a pharmacy can link a purchase to a loyalty card and pass that data to the app’s developer abroad.
Individual compliance packaging adds another layer of sensitive data. To assemble a blister pack sorted by day of the week, the system processes a delivery address alongside a list of prescribed drugs, and the law treats that list as a special category of personal data: health information. A leak of that database triggers the higher fine tier regardless of how many patients were affected.
Web analytics and bot protection add another point of risk. Google Analytics, Google reCAPTCHA, and WhatsApp and Telegram messenger widgets installed directly on a website collect visitor IP addresses and device fingerprints before the data reaches Russian infrastructure. Switching to a domestic alternative, such as Yandex Metrica with localization enabled, removes this risk.
In practice, this rebuild is described through the idea of a «master database.» Every data-collection form is configured so that the first record lands in a database on Russian territory, hosted in a Russian cloud or a local data center. Only after that initial record is confirmed can data synchronize with the headquarters’ global CRM through a separate cross-border transfer process. It is worth documenting this split in the company’s register of processing activities, so an RKN inspection can show which process handles primary collection and which handles the later transfer abroad.

Cross-Border Transfer, Patient Consent, and the Data Center Registry

Once data has been properly collected in a Russian database, a company may transfer it abroad, for instance to a global pharmacovigilance center or for clinical trial analysis. This is governed by Article 12 of Law No. 152-FZ and requires a separate notification to RKN before the transfer begins.
The notification must state the data being transferred, the categories of subjects, the legal basis, and the list of destination countries. If the country is not on RKN’s list of states with adequate data protection, the operator must wait 10 business days from the date of filing before starting the transfer (Parts 9 and 11, Article 12 of Law No. 152-FZ). If RKN requests additional information about the destination country’s legal regime during that period, the 10-day clock pauses until the operator answers, and the operator has up to 15 business days to respond.
De-identifying data for a clinical trial does not automatically remove this duty. If, after pseudonymization, the data can still directly or indirectly identify the patient, it remains personal data under the definition in Article 3 of Law No. 152-FZ, and the cross-border transfer notification is still required.
A patient’s consent to a cross-border transfer must name the destination countries and the purpose of the transfer directly, for example, safety analysis at a global pharmacovigilance center. Since 1 September 2025, there is one more requirement for the consent form. Federal Law No. 156-FZ of 24 June 2025 amended Part 1 of Article 9 of Law No. 152-FZ and requires operators to draw up consent to process personal data as a standalone document. A clause inside a contract or a patient support program questionnaire no longer satisfies this requirement.
The infrastructure picture is changing too. Since 1 March 2026, a data center registry has operated under the Ministry of Digital Development, based on amendments to the Federal Law «On Communications» and Government Decree No. 1932 of 28 November 2025. For a pharmaceutical company choosing a cloud provider, this adds a checkable criterion: the provider must be listed in the Ministry’s registry.

What to Check With Contractors and the Cloud Provider

The law holds the operator responsible for its contractors’ actions. If a pharmaceutical company hands off personal data processing to a courier service, a PSP agency, or a cloud provider, it must put a data processing agreement in place under Part 3 of Article 6 of Law No. 152-FZ.
The agreement should spell out the scope of personal data, the operations performed on it, the purpose of processing, and the contractor’s duty to keep it confidential. A separate clause should record the Part 5, Article 18 requirement for primary recording in a Russian database, and the contractor’s duty to notify the operator of incidents within the timeframes set by Part 3.1 of Article 21.
A data center’s presence in the Ministry’s registry is not enough on its own for a pharmaceutical company. Industry quality standards (GxP) add their own layer of checks: site audit access for quality representatives, computerized system validation, a business continuity plan, and adherence to the ALCOA+ data integrity principles. The data center registry is only a starting point when choosing a provider. It does not replace this check.
For a regulatory manager, it makes sense to combine both layers of requirements into a single vendor checklist: listing in the Ministry’s registry, physical server location in Russia, ISO 27001 or an equivalent information security certification, willingness to undergo a site audit, and contractual commitments on incident notification timing. This checklist works equally well for onboarding new contractors and for scheduled reviews of existing ones.
Foreign developers of mobile apps for patient support programs and MDLP code scanning deserve particular attention. If an app’s backend is physically hosted abroad, the company, as the personal data operator, is liable for the localization violation regardless of which country the contractor itself is registered in.

What to Do

Take an inventory of every personal data collection point. List every website form, mobile PSP and MDLP-scanning app, CRM, and analytics widget. Note, for each one, where the data physically lands the moment it is submitted.
Replace or reconfigure foreign tools. Remove foreign scripts from websites that record visitor data before it is written to the Russian database, including Google Analytics, Google reCAPTCHA, and WhatsApp and Telegram widgets. Set up primary recording to a Russian cloud or a local data center from the Ministry’s registry.
Update consent forms by 1 September 2025. Separate consent to process personal data into a standalone document, apart from the contract, questionnaire, and patient support program rules.
File a cross-border transfer notification with RKN if data is transferred to a global pharmacovigilance center or for a clinical trial. Budget 10 business days for review, plus another 5 business days if RKN requests additional information.
Approve a data-breach response procedure by internal order. Set out the duty to notify RKN within 24 hours of discovering an incident, submit investigation results within 72 hours, and name who is responsible for each step.

A rule that used to read as a recommendation now works, for the pharmaceutical industry in 2026, as a condition of market access. A patient support program, a compliance packaging app, or a loyalty system linked to MDLP codes remain lawful tools for working with a patient only if that person’s first record appears on a server in Russia. Companies that made this change ahead of time pass RKN inspections without incident, while those that put off the audit risk a fine that, for a leak of special-category health data, starts at 10,000,000 ₽ for a single incident.


Regulatory Framework:

1. Federal Law No. 152-FZ of 27 July 2006 «On Personal Data» (as amended 24 June 2025)
2. Federal Law No. 23-FZ of 28 February 2025 «On Amending the Federal Law ‘On Personal Data’ and Certain Legislative Acts of the Russian Federation»
3. Federal Law No. 156-FZ of 24 June 2025 (amendments to Article 9 of Law No. 152-FZ)
4. Federal Law No. 420-FZ of 30 November 2024 (amendments to Article 13.11 of the Administrative Offenses Code)
5. Code of the Russian Federation on Administrative Offenses, Article 13.11
6. Federal Law No. 126-FZ of 7 July 2003 «On Communications» (data center registry provisions effective 1 March 2026)
7. Government Decree No. 1932 of 28 November 2025

This page in Russian→