A new federal amendment that took effect on 1 July 2025 bans storing Russian citizens’ personal data on servers outside Russia. All stages of collection, processing and storage must occur on infrastructure located within Russia. Russia now requires that the collection, processing and storage of personal data of Russian citizens occur on infrastructure located inside Russia. The rule is explicit and broad. Email addresses, mailing lists, message archives and other identifiers count as “personal data.” Organisations that fail to comply risk fines and regulatory action. Whilst many believe Western orgs do not deliver services into Russia due to sanctions, services like Yahoo, Gmail and others remain readily accessible.
What changed, in plain terms
- Effective date: 1 July 2025.
- Scope: The amended wording tightens localisation duties and removes prior gray areas. It applies to both operators and processors and covers recording, systematisation, storage, updating and retrieval of personal data collected on or from Russian citizens. “Personal data” includes names, phone numbers, addresses, passport details, email addresses and other identifiers.
- Enforcement and penalties: Administrative fines for localisation breaches have been increased under recent legislative changes. In addition, Russian authorities have broader powers to impose revenue-based penalties for serious breaches in related provisions. Reporting has linked potential revenue-based caps up to several hundred million rubles in the most serious scenarios. Check counsel and regulator guidance for precise exposure in your case.
Does this matter to email professionals?
Not universally however it will to many.
- Subscriber records are personal data. Mailing lists, CRM records, campaign archives, SMTP logs and raw message content that identify Russian individuals are captured by the law. Storing that material on non-Russian cloud infrastructure is now a compliance risk.
- ESP and webmail exposure. Multinational ESPs and global webmail providers that keep Russian user data outside Russia may face blocking, fines or operational restrictions. Russia has previously blocked foreign services over localisation violations (LinkedIn is a precedent).
- Deliverability and routing impact. If foreign infrastructure is restricted, mail routed via non-local IPs or third-party relays could suffer deliverability degradation or blocking for Russian recipients. Reputation alone will not remove the legal requirement to host Russian personal data in Russia.
- Operational complexity. Compliance will likely require geo-segregated databases, in-country backups, revised retention and access controls, and changes to cross-border processing agreements. Expect higher operational cost and engineering workloads.
Strategic considerations
- Product decisions for global ESPs. Providers must choose between deploying Russia-region infrastructure, excluding Russian personal data, or limiting service availability. Each choice changes product scope and market access.
- Segmentation becomes mandatory. If you deal with Russian recipients, treat Russian recipients as a compliance bucket. Apply separate architecture, consent flows and retention policies.
- Expect market migration. Domestic mail platforms and self-hosted solutions within Russia will gain adoption among organisations that must remain operational in-country.
Bottom line
The 1 July 2025 amendments make Russia’s localisation requirement explicit, broader and enforceable in practical terms. For email teams this is immediate operational and legal work. Map your flows, consult counsel, and prepare either a lawful localisation pathway or an exit strategy for Russian personal data. Failure to act invites regulatory, financial and deliverability risk.








