Skip to content

Face recognition in Russia

Russia has a data localisation requirement. Under Article 18(5) of Federal Law 152-FZ, an operator collecting personal data about Russian citizens must record, systematise, accumulate, store, amend and retrieve it using databases located in the Russian Federation. Biometric data carries an additional consent requirement under Article 11.

What does the Russian data localisation rule require?

Article 18(5) of Federal Law No. 152-FZ 'On Personal Data' obliges an operator, when collecting personal data about citizens of the Russian Federation, to carry out a specific list of operations using databases physically located in Russia. The listed operations are recording, systematisation, accumulation, storage, amendment and retrieval.

The rule is about the primary database rather than about secrecy. Transfer abroad is not categorically prohibited, and a copy may exist elsewhere under the cross-border transfer rules; what may not happen is that the authoritative record of a Russian citizen's personal data sits only outside the country.

Roskomnadzor is the supervisory authority and maintains the register of operators. Its enforcement history on localisation includes blocking access to services that held Russian users' data only abroad, so this is a provision with observed consequences rather than a dormant one.

How does Russian law treat biometric data specifically?

Article 11 of 152-FZ defines biometric personal data as information about physiological and biological characteristics which allows a person's identity to be established, and which the operator uses to establish it. A face template used for recognition is squarely inside that definition. As a general rule, processing it requires the written consent of the person, with exceptions set out in the law for specified state functions.

A separate instrument, Federal Law No. 572-FZ of 2022, governs identification using biometric data and established the Unified Biometric System as a state information system. It sets rules for how biometric data may be collected into and used through that system, which is a different question from a private operator running recognition on its own premises for its own purposes.

How does an on-premise deployment meet the requirement?

By construction rather than by undertaking. If the database that records and stores the templates is a server inside the operator's own facility in Russia, the listed operations happen on Russian territory as a matter of physical fact, and the localisation question has a demonstrable answer instead of a contractual one.

  1. The camera feed stays on the operator's own network.
  2. Detection and template extraction run on hardware at the site β€” an ATLAS BOX appliance, the operator's servers, or edge hardware beside the camera.
  3. The template database is created and held on that hardware, inside the Russian Federation.
  4. Matching happens locally, so no identity query leaves the site.
  5. In an air-gapped configuration there is no network route out at all, which removes the cross-border question entirely.

Ayonix supplies software and the ATLAS BOX appliance; it does not operate a service that holds customer biometric data. That is the property that makes the architecture above available rather than theoretical.

What should a Russian buyer establish before deployment?

  • Where the template database physically sits, and that it is the authoritative copy rather than a cache.
  • The form of written consent used, and the exception relied on where consent is not obtained.
  • Registration with Roskomnadzor as an operator of personal data, where required.
  • The retention period for templates and for match records, and what enforces it.
  • Whether any component calls out to a vendor service, and what it sends if it does.
  • How the system's accuracy was measured on the operator's own cameras rather than on a vendor's benchmark.

Export control, sanctions and import rules apply to software and hardware independently of data protection law, and they change. They are a separate assessment, made against the rules in force at the time of supply.

This page describes what the named laws require, with each instrument cited so it can be checked. It is not legal advice, and it is not a statement that any particular deployment complies: that assessment belongs to your own counsel and your data protection authority.

Frequently asked questions

Does Russia require personal data to be stored in Russia?
Yes. Article 18(5) of Federal Law 152-FZ requires an operator collecting personal data about Russian citizens to record, systematise, accumulate, store, amend and retrieve it using databases located in the Russian Federation. The authoritative record must be in the country.
Is written consent needed for face recognition in Russia?
As a general rule yes. Article 11 of 152-FZ requires written consent for processing biometric personal data used to establish identity, with exceptions specified in the law for certain state functions.
Can Ayonix be deployed entirely inside Russia?
Yes. Ayonix face recognition runs on the operator's own hardware β€” the ATLAS BOX appliance, existing servers or edge devices β€” so detection, template extraction, storage and matching all occur on equipment at the site. An air-gapped configuration has no network route out at all.
Does Ayonix hold Russian customers' biometric data?
No. Ayonix supplies software and appliances; it does not operate a service that stores customer biometric data. The template database belongs to the operator and sits on the operator's hardware.
What is the Unified Biometric System?
A state information system established under Federal Law 572-FZ of 2022, which governs identification using biometric data at national level. It is a separate regime from a private operator running face recognition on its own premises for its own purposes.
Who enforces personal data law in Russia?
Roskomnadzor, the Federal Service for Supervision of Communications, Information Technology and Mass Media. It maintains the register of personal data operators and has enforced the localisation requirement against services holding Russian users' data only abroad.

Jan Mocary β€” Chief Technology Officer, Ayonix AI

Leads engineering for Ayonix face recognition and the ATLAS agent platform, including their on-premise and air-gapped deployment modes.