5/24/2019
CLFR - Russia | Global Network Initiative
Under the requirements in the Rules of Cooperation, the Network Operators must ensure that their networks
are capable of transferring data to the SIAs. To do this, the Network Operator must connect its network to a
control hub managed by the competent SIA. The exact requirements of the connecting link between the control hub and the relevant telecommunications network are designated on a regional basis by the Federal Security Services.
Similar provisions apply to unlicensed Pure Internet Service Providers under the Rules of Cooperation for
Pure Internet Service Providers. However, the specific technical requirements applicable to both equipment
and software have not yet been published and it is unclear precisely when they will be finalised.
DISCLOSURE OF COMMUNICATIONS DATA
FEDERAL LAW NO. 144-FZ DATED 12 AUGUST 1995 (THE “LAW ON INVESTIGATIVE
ACTIVITIES”)
Under article 8 of the Law of Investigative Activities, state investigatory authorities (see paragraph 1.1 above,
the “SIA“s) may access metadata held by licensed operators of telecommunications networks (“Network Operators“) as part of their investigations. The procedure for accessing such data differs from that for intercepting private communications, however, because article 8 of the Law on Investigative Activities is limited to the
content of communications. Therefore, the SIA does not require a court order to access this communications
data.
FEDERAL LAW NO. 149-FZ DATED 27 JULY 2006 (THE “LAW ON INFORMATION”) AND RULES
APPROVED BY THE DECREE OF THE GOVERNMENT OF THE RUSSIAN FEDERATION NO.
538 DATED 27 AUGUST 2005 (THE “RULES OF COOPERATION”)
Article 10.1 of the Law on Information, point 14 of the Rules of Cooperation, points 7 and 8 of the requirements adopted by the Order of the Ministry of Information Technologies and Communications No. 6 dated
16 January 2008 and point 3 of the requirements adopted by Order of the Ministry of Information Technologies and Communications No. 73 dated 27 May 2010 state that the laws relating to interception activities also
apply to the access to communications data. Furthermore, they set out a non-exhaustive list of what is defined as communications data, and therefore may be accessed by the SIAs. This includes data relating to the
identity of all parties to a communication, the time and duration of a communication, and the geographical
position from where the communication was made.
Under Section 12 of the Rules of Cooperation, all communications data should be kept up to date and should
be retained by Network Operators for three years. As set out in paragraph 1.3 above, article 10.1 of the Law
on Information sets out a similar provision for unlicensed internet service providers and Network Operators
providing internet services outside the scope of their licence. They are only required to retain communications data for six months. During this period of retention this data may be accessed by an SIA in accordance
with the procedures set out in paragraphs 1.1 to 1.4 above.
https://globalnetworkinitiative.org/clfr-russia/
3/9