bg
News
20:53, 28 July 2026
views
4

FSTEC Proposes Three-Tier Framework for Personal Data Protection

Russia's Federal Service for Technical and Export Control (FSTEC) has published a draft order introducing updated requirements for protecting personal data. The new rules are scheduled to take effect on September 1, 2026, and will apply to all organizations that process personal data. More than 2.6 million such operators are currently registered.

Photo: arsis.ru

The proposed framework would replace the fixed list of mandatory security measures, in force since 2013, with a three-tier protection model. Each tier defines a baseline set of requirements that organizations can adapt to their own information systems before assessing whether the resulting safeguards adequately address current threats.

The draft also introduces specific requirements for protecting personal data in environments that use AI, the Internet of Things, cloud computing, virtualization, mobile devices, and remote access. Organizations would be required to assess the effectiveness of their security measures using a cybersecurity maturity model before beginning data processing, at least once every three years, and after every security incident. Operators of significant critical infrastructure facilities would also be required to maintain continuous interaction with GosSOPKA (State System for Detecting, Preventing, and Eliminating the Consequences of Computer Attacks).

Experts say the new framework will make personal data protection more flexible, but it is also expected to increase compliance requirements for organizations. They also note that common approaches to securing AI systems have yet to be established.

like
heart
fun
wow
sad
angry
Latest news
Important
Recommended
previous
next