Russia's Federal Law 152-FZ requires that personal data of Russian citizens be recorded and primarily stored in databases located in Russia, and a JUSTG Moscow Cloud VPS (from $19.99/mo) or JUSTG Moscow Dedicated Server (from $299/mo) in Moscow, Russia is a straightforward way to host that primary database. This guide explains the rules in plain language, who they affect, and practical architecture patterns — Russian database + global app, replication direction and backups inside Russia — with a checklist.
- Location: Moscow, Russia — servers physically in Russia with native Russian IPs.
- Products: JUSTG Moscow Cloud VPS from $19.99/mo (1 core / 512 MB up to 7 cores / 24 GB RAM / 320 GB SSD); JUSTG Moscow Dedicated Server from $299/mo.
- Network: 1 IPv4 + free IPv6, typically 500 Mbps port; China Telecom CN2 GIA route to mainland China.
- Setup: cloud VPS auto-deployed after payment; KVM, Linux or Windows.
- Support: 24/7 via ticket.
What 152-FZ requires, in plain language
In short: collect Russian users' personal data into a database in Russia first, tell the regulator you process personal data, and have a lawful basis such as consent.
- Localization (Article 18, part 5). Since 1 September 2015, when collecting personal data of Russian citizens — including online — the operator must record, systematize, accumulate, store, update and retrieve it using databases located in Russia. Amendments in force from 1 July 2025 make it explicit that these operations must not be done in databases abroad.
- Roskomnadzor notification. Operators generally must notify Roskomnadzor (the Russian data-protection regulator) before they start processing personal data, and separately notify cross-border transfers. The notification includes where the databases are located.
- Consent and lawful basis. Processing needs a lawful basis, most often the data subject's consent; publish a privacy policy and collect consent on forms (a checkbox linked to the policy is common practice).
- Security and incidents. Operators must protect data and report leaks to Roskomnadzor on short deadlines (initial report within 24 hours, follow-up within 72 hours under the 2022 amendments).
- Penalties. Fines for localization breaches and leaks were raised significantly in 2025 and can reach millions of rubles; resources can also be restricted in Russia.
Who is affected
Any business that collects personal data of people in Russia through a website or app is likely in scope, even if the company is registered abroad.
| Business type | Typical personal data | Why it matters |
|---|---|---|
| Online shop selling to Russia | Name, phone, delivery address, email, order history | Every checkout collects personal data of Russian citizens |
| SaaS / web app with Russian users | Account email, name, IP logs, billing contacts | The user database is the primary store |
| Lead-generation sites, contact forms | Name, phone, company, message | Even a simple form counts as collection |
| Mobile apps, loyalty programs, CRM | Device IDs, phone numbers, purchase data | Often synced to a foreign CRM — check where the first write happens |
Anonymous analytics without identifiers, or B2B data that does not identify individuals, may be treated differently — this is exactly where legal advice is needed.
Architecture pattern 1: everything in Russia
The simplest compliant-by-design setup is to run the whole application and its database on servers in Moscow.
- Web app, database and file storage all on a JUSTG Moscow Cloud VPS or JUSTG Moscow Dedicated Server.
- Good for Russia-focused shops, local SaaS and corporate sites.
- Bonus: Russian users get low latency from a native Russian IP, and Chinese partners can still reach the site over CN2 GIA.
Architecture pattern 2: Russian database + global application
If your application runs elsewhere (for example in Tokyo, Japan or Seoul, South Korea), keep the database that receives Russian users' data in Moscow and have the app write to it first.
- Place the primary database (PostgreSQL or MySQL) on a JUSTG Moscow server.
- Connect the foreign app servers to it through a private WireGuard tunnel; never expose port 5432/3306 to the internet.
- Route sign-ups, orders and profile edits from Russian users to the Moscow database — the first write must land in Russia.
- If a copy abroad is needed (e.g. for global reporting), replicate from Russia outward, and only after checking the cross-border transfer rules and notifying Roskomnadzor where required.
# On the Moscow primary (PostgreSQL 16), /etc/postgresql/16/main/postgresql.conf
listen_addresses = '10.8.0.1' # WireGuard address only
wal_level = replica
max_wal_senders = 5
# pg_hba.conf — allow only the replica over the private tunnel
hostssl replication replicator 10.8.0.2/32 scram-sha-256
A minimal firewall on the Moscow database server:
ufw default deny incoming
ufw allow 22/tcp
ufw allow 51820/udp # WireGuard
ufw allow in on wg0 to any port 5432 proto tcp
ufw enable
Replication direction: get this right
The Russian database must be the source of truth; data flows out of Russia, never into Russia as an afterthought.
| Design | Direction | Assessment |
|---|---|---|
| Primary in Moscow, read replica abroad | Russia → abroad | Commonly used; cross-border transfer rules apply to the copy |
| Primary abroad, nightly copy to Russia | Abroad → Russia | Problematic: first collection happens outside Russia |
| Russian users' PII in Moscow; non-personal data global | Split by data type | Good option; store only tokens/IDs abroad |
| Everything in Moscow | None | Simplest to explain and audit |
A useful technique is pseudonymization: the global app stores only an internal user ID, while names, phones and addresses stay in the Moscow database and are fetched over the tunnel when needed.
Backups inside Russia
Backups of Russian personal data are part of the database too, so keep them on servers in Russia and encrypt them.
# Nightly encrypted backup to a second server inside Russia
pg_dump -Fc shopdb | gpg --encrypt --recipient [email protected] \
> /backup/shopdb-$(date +%F).dump.gpg
rsync -a /backup/ [email protected]:/srv/backups/shopdb/
find /backup -name '*.gpg' -mtime +14 -delete
- Keep at least two copies inside Russia: the primary server plus a second Moscow VPS or dedicated server (the documentation IP 198.51.100.20 above is a placeholder).
- Encrypt backups and restrict who holds the keys.
- Test restores regularly; a backup you have never restored is not a backup.
- Do not sync raw dumps to foreign cloud storage unless your lawyer confirms the transfer is permitted.
Compliance checklist
Use this table as a technical starting point and review it with your legal advisor.
| # | Item | Technical action | Done |
|---|---|---|---|
| 1 | Map personal data | List every form, API and table that stores data about Russian users | ☐ |
| 2 | Primary DB in Russia | Database on a server in Moscow, Russia; first write lands there | ☐ |
| 3 | Replication direction | Russia → abroad only; document what is copied and why | ☐ |
| 4 | Roskomnadzor notification | Submit/update notification including database location and cross-border transfers | ☐ |
| 5 | Consent and privacy policy | Consent checkbox on forms; policy published in Russian | ☐ |
| 6 | Security | Firewall, SSH keys, encrypted tunnels, TLS, access logs | ☐ |
| 7 | Backups in Russia | Encrypted, second Russian location, restore tested | ☐ |
| 8 | Incident response | Procedure to report leaks to Roskomnadzor within 24/72 hours | ☐ |
Which JUSTG plan fits
Choose by database size and load: a JUSTG Moscow Cloud VPS for most shops and SaaS, a JUSTG Moscow Dedicated Server for large or sensitive databases.
- JUSTG Moscow Cloud VPS — plans from 1 core / 512 MB / 10 GB SSD ($19.99/mo) to 7 cores / 24 GB RAM / 320 GB SSD / 6 TB traffic ($169.99/mo). A database server is comfortable from 2–4 GB RAM.
- JUSTG Moscow Dedicated Server — from $299/mo, with options up to a full /24; for heavy databases or when you want hardware isolation.
- Custom configurations — CPU, RAM, disk, bandwidth, extra IPs or IP blocks on request; contact sales via ticket for a custom quote. See all JUSTG data centers.
FAQ
Where can I host a database in Russia to comply with 152-FZ?
You need a server physically located in Russia. JUSTG offers the JUSTG Moscow Cloud VPS from $19.99/mo and the JUSTG Moscow Dedicated Server from $299/mo in Moscow, Russia, both with native Russian IPs. Hosting is only one part of compliance; notification, consent and security still apply.
Does 152-FZ apply to foreign companies?
It is generally applied to anyone collecting personal data of Russian citizens through sites targeting Russia, including foreign companies. Whether your specific case is in scope is a legal question — consult a lawyer.
Can I keep a copy of Russian users' data outside Russia?
Typically the primary collection and storage must be in Russia, and copies abroad fall under cross-border transfer rules and notification requirements. Design replication from Russia outward and confirm with legal counsel.
Is a Moscow VPS suitable for calling OpenAI or Claude APIs?
No. OpenAI, Anthropic (Claude) and Google Gemini APIs are not available in Russia. Keep personal data in Moscow and run AI API calls from a JUSTG Tokyo or Seoul server, sending only data you are allowed to transfer.
Need a primary database in Russia? Deploy a JUSTG Moscow Cloud VPS or a JUSTG Moscow Dedicated Server, and open a ticket if you want help sizing it.