Russia Severs Data Adequacy Framework from Council of Europe Convention (Effective July 26)
Federal Law No. 265-FZ was published and entered force on July 26, 2026, amending Article 12 of Russia's Federal Law on Personal Data (152-FZ). The law removes all references to the Council of Europe Convention 108 from Russian data protection legislation, eliminating the presumption that European servers provide adequate protection for Russian personal data. Roskomnadzor now has explicit authorit
BY FRONTIER DESK · JULY 30, 2026 · 1 MIN READ
Federal Law No. 265-FZ was published and entered force on July 26, 2026, amending Article 12 of Russia's Federal Law on Personal Data (152-FZ). The law removes all references to the Council of Europe Convention 108 from Russian data protection legislation, eliminating the presumption that European servers provide adequate protection for Russian personal data. Roskomnadzor now has explicit authority to block data transfers to any country in the world — the Council of Europe participation framework is no longer the baseline. Transfers to countries with adequate data protection are still permissible, but the list of adequate countries will now be determined by new criteria set by Russian authorities, not by CoE participation status. For law firms or businesses with operations in Russia or clients who process Russian personal data: the July 26 change fundamentally alters the compliance framework for cross-border data transfers involving Russia. Any transfer mechanism that was premised on CoE Convention participation as an adequacy indicator needs to be reassessed against the new regulatory criteria.