Gartner, Inc. said that organizations need to prepare contingency plans for business processes and IT systems to store some or all data in Russia. In just over two weeks, Russia will implement a new personal data law (242-FZ Law) requiring that the personal data of Russian citizens be stored in Russia from September 1 2015.
"By the same date, all companies processing personal data of Russian citizens in databases located outside Russia need to make their systems compliant with the new requirements," said Carsten Casper, managing vice president at Gartner. "We positioned this matter at the peak of this year's Gartner Hype Cycle for Privacy as this should be key priority for the chief data officer and the CIO."
This new law will have a major effect on Internet organizations, as well as online stores, online resources used for booking airline tickets and hotels, insurance companies and other organizations, as they will have to change the way they store information on Russian citizens.
A Gartner survey conducted in April 2015 across seven countries (U.S., U.K., Canada, Brazil, India, Australia and Germany), which surveyed 357 large organizations (at least $50 million in revenue, a minimum of 100 employees), found that 37 percent of respondents would like to obtain certification to comply with the new requirements – although such certification does not exist today. A third of surveyed organizations will appoint a local IT provider to manage data storage and processing, while 28 percent will simply look to place a copy of the relevant data onto a local server in Russia.
While those three options will incur additional costs for organizations, they may be the most effective way to comply at such short notice. Others are planning to withdraw business from Russia (19 percent) or expect to ignore the law until they are investigated by the local authorities (18 percent).
"Although more clarifications are needed around the law, we advise companies that process Russian citizens' personal data to make their business executives aware of the upcoming legal and investment requirements," said Petr Gorodetskiy, senior research analyst at Gartner. "They also need to seek clarification from Russian authorities, where possible, and prepare plans for moving data (or data centers) to Russian soil or find alternative ways to mitigate this compliance risk."
More detailed analysis is available in the Gartner reports "Data Protection Law in Russia: Intricacies and IT Users' Successful Compliance" and "Data Protection Law Amendment in Russia: A Business Opportunity for IT Providers?".
Privacy issues will be discussed at the Gartner Security & Risk Management Summit 2015, September 14-15, in London, U.K. More information on the event is available at www.gartnerevent.com/eu/security.
Additional information from the event will be shared on Twitter at http://twitter.com/Gartner_inc and using #GartnerSEC.
About Gartner Security & Risk Management Summit 2015
Security and risk leaders must embrace new approaches to digital business while maintaining proven control architecture that mitigates enterprise risk for success. At the Summit, Gartner analysts will discuss the skills and strategies needed to maintain cost-effective security and risk management programs in order to support digital business and drive enterprise success.