Skip to content
RU
← All articles

Russia's Personal Data Operators Registry: Check and File

A laptop showing a registry notification form with a stack of printed papers

Russia's personal data operators registry is a public list kept by Roskomnadzor (RKN) of every company, sole proprietor and public body that has notified the regulator it processes personal data under Article 22 of Federal Law No. 152-FZ. You can search it for free by tax number (INN) or name on pd.rkn.gov.ru.

What the Roskomnadzor operators registry is

Roskomnadzor, the Russian communications regulator, is also the data protection authority. Unlike the GDPR, which dropped general registration in favour of internal records of processing, Russian law still runs a notification regime: an operator must tell the regulator, before it starts, that it intends to process personal data. Roskomnadzor then enters the details into a public registry.

An "operator" in Federal Law No. 152-FZ "On Personal Data" is roughly what the GDPR calls a controller: the party that decides why and how personal data is processed. Each registry entry shows the purposes of processing, the categories of data and data subjects, the legal basis, the processing operations, and where the database is physically located. Everything except the description of security measures is public.

Who has to file a notification

Article 22(1) makes notification the default. The exemptions in Article 22(2) were cut back significantly by Federal Law No. 266-FZ, effective 1 September 2022. Before that, processing employee data under labour law and processing data received under a contract with the data subject did not require notification, which covered most small businesses. Both exemptions are gone.

What remains is narrow: membership data of public associations and religious organisations used for their statutory purposes, certain state information systems, manual (non-automated) processing where a federal law specifically provides for it, and some transport-security cases. Check the current wording of the law before relying on any of them, because summaries online often describe the pre-2022 list.

In practice, if you employ people in Russia or collect customer data from Russian users, assume you must file. A website is usually enough on its own: contact forms, sign-ups, checkout, newsletters and analytics tags that set cookies and send visitor identifiers and IP addresses to third parties all count as collecting personal data. Our overview of website monitoring and Russia's 152-FZ covers how those obligations apply to a typical site.

Foreign companies should note two related rules. Article 18(5) requires that personal data of Russian citizens collected by the operator be recorded and stored in databases located in Russia, and since 1 March 2023 cross-border transfers require a separate notification under Article 12. Whether a particular foreign business falls under Russian jurisdiction is a legal question worth taking to local counsel; the registry itself only reflects what operators declare.

How Russia compares with other regimes

RegimeRegistration with the regulatorPublic listWhat you maintain internally
Russia, 152-FZNotification to Roskomnadzor before processing startsYes, searchable operators registryProcessing policy, appointed responsible person, security measures
EU, GDPRNo general registration; DPO contact details go to the supervisory authority where a DPO is requiredNo general register of controllersRecords of processing activities (Article 30)
United KingdomData protection fee paid to the ICO unless exemptYes, register of fee payersRecords of processing under UK GDPR

How to check a company in the registry

  1. Open the operators list on the Roskomnadzor personal data portal. The interface is in Russian: "Реестр операторов" means operators registry and "Перечень операторов" is the list.
  2. Search by INN, the Russian taxpayer number, rather than by name. Names are stored with legal-form prefixes and quotation marks that rarely match what you type.
  3. If the company publishes its registration number in its privacy policy, search by that for an exact match.
  4. Open the entry to see the notification date, purposes, data categories, legal basis and database location.

When reading the result, the useful question is not only "is the company listed?" but "does the entry describe what the company actually does?". A 2014 notification that mentions neither a website nor online payments is technically a listing and practically out of date. An absent entry may also mean the website belongs to one group company while another processes the data, so compare the INN in the site's privacy policy with the one you searched.

How to file or update a notification

The notification is prepared on a Roskomnadzor form. The simplest route is the electronic forms section of pd.rkn.gov.ru: fill it in, then either sign it with a qualified electronic signature and submit online, or print it, have the director sign it, and send it to the regional Roskomnadzor office. The same service is available on the Gosuslugi public services portal for organisation accounts. Filing is free, and the regulator enters the data within 30 days of receipt.

Article 22(3) defines the content. For a website owner the fields that usually go wrong are:

  • Purposes. List them separately: order fulfilment, replying to enquiries, newsletters, traffic analytics, HR.
  • Data categories. Include technical data such as cookie identifiers and IP addresses if your analytics collects them.
  • Third parties. Delivery services, payment providers, CRM and email platforms.
  • Database location. The data centre address of your hosting or cloud provider, not your office.
  • Cross-border transfer. Any foreign SaaS that receives visitor data.

Keep the entry current. Under Article 22(7), changes must be reported no later than the 15th day of the month following the month in which they occurred, and termination of processing within 10 working days. Separately, since September 2022 a personal data breach must be reported to Roskomnadzor within 24 hours, with the results of the internal investigation within 72 hours (Article 21(3.1)). The declared purposes should also match your public privacy notice; see how to write a website privacy policy.

Failing to file is an administrative offence under Article 19.7 of the Russian Code of Administrative Offences (failure to submit information to a state body). The larger exposure usually comes afterwards: a missing entry prompts questions about consent, policies and data localisation, and substantive violations fall under Article 13.11, which carries heavier penalties. Check current amounts in the code itself, as they have been revised several times.

Not to be confused with the blocklist

People searching for "the RKN registry" often mean the unified register of prohibited information, which is what Russian ISPs use to block domains, URLs and IP addresses. The operators registry has nothing to do with blocking: being absent from it does not make a site unreachable. If your site is not loading for users in Russia, run a Roskomnadzor blocking check and read how Roskomnadzor blocking works.

How to check what your website collects

Before filing, build an honest inventory. Third-party scripts added by marketing teams are the usual blind spot.

  • Website technology detection lists analytics tags, chat widgets, CRM forms and payment scripts, each of which is a recipient of visitor data.
  • IP address lookup shows which country and provider host your web server, a starting point for the database location field.
  • SSL certificate check confirms that forms submit over HTTPS, one of the baseline security measures you describe.

From a terminal, list the cookies the home page sets and the external hosts it loads:

curl -sI https://example.com | grep -i set-cookie
curl -s https://example.com | grep -oE 'https?://[a-zA-Z0-9.-]+' | sort -u

In PowerShell:

(Invoke-WebRequest -Uri https://example.com -UseBasicParsing).Headers['Set-Cookie']
Resolve-DnsName example.com -Type A

Cookie attributes matter too if you describe them as a security measure; HttpOnly, Secure and SameSite explained covers what to check.

FAQ

Does a sole proprietor need to file?

Yes, if they process data about customers, employees or website visitors. Being a sole proprietor is not an exemption.

Is there a fee?

No. Filing is free. Companies offering to "register you" charge for preparing the documents, not for the registration.

How long until the entry appears?

Roskomnadzor enters the details within 30 days of receiving the notification. Add postal time if you file on paper.

My site runs on a hosted platform. Who is the operator?

You are. The platform processes data on your behalf; you decide the purposes. Mention the transfer to the platform and where its servers are located.

Can a missing registry entry get my site blocked?

No. The operators registry and the blocklist are separate. A missing notification is an administrative offence, not grounds for blocking.

Check your website right now

Check your site's security →
More articles: Security
Security
How to Check a Website for Malware: 4 Layers and a Cleanup
01.04.2026 · 1 217 views
Security
Cookie Security Flags: HttpOnly, Secure, SameSite
14.03.2026 · 621 views
Security
Web Server Security Hardening Checklist: Nginx and Apache
16.03.2026 · 616 views
Security
How to Check a Website for Fraud: 12 Signs of a Phishing Site
18.07.2026 · 524 views