Systematic monitoring of the Russian Data Protection Authority
Further to our previous alert relating to inspections of the Russian Data Protection Authority (‘DPA’) we would like to draw your attention that DPA is also entitled to undertake measures of so-called systematic monitoring in order to supervise compliance of data controllers with the Russian legislation on personal data.
These measures mainly cover checking websites and information placed in a public domain. In frames of such monitoring the Russian DPA will randomly look at websites of companies within particular industries for compliance with general requirements of the Russian laws on personal data protection such as published privacy policies, registration forms, reference to a Russian server (localization law requirement), etc.
According to the clarifications of DPA officials the most frequent violation revealed in the course of such systematic monitoring is absence of privacy/data processing policies available on the websites for users as well as non-compliance of such policies with the requirements of the Russian law.