Stricter Liability for Violation of Personal Data Legislation
FBK Legal’s team has prepared a review of an increased liability for violation of the personal data legislation.
On 30 November, amendments were made to the Code of Administrative Offences of the Russian Federation (the ‘CAO RF’) and the Criminal Code of the Russian Federation (the ‘CC RF’), toughening the liability for personal data leaks.
The amendments to the CAO RF establish a new fine for unlawful transfer or provision of personal data. The amount of the fine will depend on the leak volume. The maximum fine for a primary offence for legal entities totals 15 mln roubles and for a repeated offence - 500 mln roubles.
The amendments to the CC RF introduce a new Article 272.1, establishing liability for use, transfer, collection and storage of personal data in respect of which the operator lacks a legal basis for processing (e.g., consent of the subject of personal data).
The minimum sanction is a fine of up to 300,000 roubles or imprisonment for up to 4 years. The legislator singles out a special offence - cross-border transfer of unlawfully obtained data.
You can read more via the following link.