Skip to content
RU

Cross-border transfer of personal data

Key idea:

Cross-border transfer is passing personal data into a foreign state's territory: to a foreign company, server or authority. Since March 2023 a notification regime applies: before the transfer starts, the operator files a dedicated notification with Roskomnadzor — distinct from the base processing notification. For countries with adequate data protection the transfer may proceed once filed; for the rest, RKN may prohibit it after review. On a website, cross-border transfer usually comes not from "database exports" but from everyday things: foreign analytics, CRMs and forms.

Check your site →

What counts as a transfer

  • A foreign counter or pixel receiving visitor identifiers
  • A CRM, mail service or spreadsheets with customer data on a foreign platform
  • Forms sending submissions to a foreign service
  • Database hosting outside Russia — simultaneously a localisation issue

The criterion is where the data actually lands, not where the contract is registered. Loading a script from a foreign CDN is not yet a transfer by itself; sending visitor data there is.

The notification regime

The dedicated cross-border notification is filed before the transfer begins. Countries then split in two: those ensuring adequate protection of subjects' rights (Convention 108 parties plus the RKN-approved list) — transfer is allowed once the notification is filed; other countries — Roskomnadzor reviews the filing and may prohibit or restrict the transfer. The practical takeaway: the recipient-country list is not a reference line in the policy but a parameter the scheme's very legality depends on.

Finding your own cross-border flows

Most operators do not know their full list of foreign recipients — it accretes from counters, widgets and integrations. The compliance scanner builds that list automatically: every third-party service on the pages is identified against a catalogue with vendor and jurisdiction, foreign ones flagged separately — including those loading before consent. With that list, the notification is filled from facts, not from memory.

Related

Cookies Before ConsentWhat is written without permission
Consent BannerIs there an equal Reject option
PII FormsConsent and policy at the form
Projections152-FZ and GDPR grades

Why teams trust us

A–F
grade + 152-FZ/GDPR
3
browser sessions per page
PDF
integrity-signed report
Free
scan without signup

How it works

1

Enter your site URL

2

The scanner opens pages in a browser

3

Get a grade and a fix list

Why check your site for privacy compliance?

Regulators fine sites for processing personal data without consent — and a site starts processing earlier than it seems: analytics, pixels and widgets write cookies the moment the page loads. The scanner shows the auditor's view: what leaves for third parties before consent, whether the banner works, and whether forms collect data correctly.

Real Browser

Three sessions per page: no action, banner accepted, banner rejected.

Trackers and Jurisdiction

Service catalogue: who receives visitor data and in which country.

Policy at Collection Point

The policy link and consent element are checked next to the form, not in the footer.

Signed PDF

Report with an HMAC integrity stamp — hand it to your lawyer or contractor.

Who uses this

Business

preparing for an audit

Lawyers

technical facts for an opinion

Web Studios

client site handover

DevOps

consent regression monitoring

Common Mistakes

Loading analytics before consentA counter in writes cookies before any banner. This is exactly what an audit records.
Banner without a Reject buttonConsent is voluntary only when refusing is as easy as agreeing.
Policy only in the footerThe visitor must see who receives their data at the moment of submission — next to the form itself.
Checking once and forgettingA new widget or tag manager quietly adds trackers. Only a re-check catches the regression.

Best Practices

Delay trackers until consentInitialise analytics from the CMP accept callback, not on page load.
Offer an equal RejectAccept and Reject buttons — same size, same level.
Consent checkbox at every formUnchecked by default, with the processing policy linked right there.
Turn on monitoringA standing watch alerts you when the grade drops — before an auditor notices.

Monitor compliance automatically

Scheduled re-checks with an alert when pre-consent trackers appear on your site.

Sign up free

Learn more

Frequently Asked Questions

Does visitor consent replace the cross-border notification?

No, they are independent requirements: consent legalises the processing, the notification covers the transfer abroad itself. Both are needed.

Is an intra-group transfer cross-border too?

Yes, when the recipient is abroad: corporate affiliation does not cancel the data crossing the border.

We moved to Russian services — is the notification still needed?

If no foreign recipients remain — no. But verify the actual picture: a forgotten pixel or a backup on a foreign server brings the duty back.

Try the live tool that powered this guide

Free plan — 10 monitors, checks every 5 min, no card required. Upgrade for 1-minute interval and multi-region monitoring.