Help Center

Step-by-step guides for servers, networks and your account.

Use Cases & Solutions

Russian Personal Data Localization (152-FZ): Hosting Your Database in Moscow, Explained

Russia's Federal Law 152-FZ requires that personal data of Russian citizens be recorded and primarily stored in databases located in Russia, and a JUSTG Moscow Cloud VPS (from $19.99/mo) or JUSTG Moscow Dedicated Server (from $299/mo) in Moscow, Russia is a straightforward way to host that primary database. This guide explains the rules in plain language, who they affect, and practical architecture patterns — Russian database + global app, replication direction and backups inside Russia — with a checklist.

Not legal advice. This article is general technical information, not legal advice. Russian data-protection law is amended frequently and its interpretation depends on your exact situation. Consult a lawyer qualified in Russian law before relying on any architecture for compliance.
Key facts
  • Location: Moscow, Russia — servers physically in Russia with native Russian IPs.
  • Products: JUSTG Moscow Cloud VPS from $19.99/mo (1 core / 512 MB up to 7 cores / 24 GB RAM / 320 GB SSD); JUSTG Moscow Dedicated Server from $299/mo.
  • Network: 1 IPv4 + free IPv6, typically 500 Mbps port; China Telecom CN2 GIA route to mainland China.
  • Setup: cloud VPS auto-deployed after payment; KVM, Linux or Windows.
  • Support: 24/7 via ticket.

What 152-FZ requires, in plain language

In short: collect Russian users' personal data into a database in Russia first, tell the regulator you process personal data, and have a lawful basis such as consent.

  • Localization (Article 18, part 5). Since 1 September 2015, when collecting personal data of Russian citizens — including online — the operator must record, systematize, accumulate, store, update and retrieve it using databases located in Russia. Amendments in force from 1 July 2025 make it explicit that these operations must not be done in databases abroad.
  • Roskomnadzor notification. Operators generally must notify Roskomnadzor (the Russian data-protection regulator) before they start processing personal data, and separately notify cross-border transfers. The notification includes where the databases are located.
  • Consent and lawful basis. Processing needs a lawful basis, most often the data subject's consent; publish a privacy policy and collect consent on forms (a checkbox linked to the policy is common practice).
  • Security and incidents. Operators must protect data and report leaks to Roskomnadzor on short deadlines (initial report within 24 hours, follow-up within 72 hours under the 2022 amendments).
  • Penalties. Fines for localization breaches and leaks were raised significantly in 2025 and can reach millions of rubles; resources can also be restricted in Russia.

Who is affected

Any business that collects personal data of people in Russia through a website or app is likely in scope, even if the company is registered abroad.

Business typeTypical personal dataWhy it matters
Online shop selling to RussiaName, phone, delivery address, email, order historyEvery checkout collects personal data of Russian citizens
SaaS / web app with Russian usersAccount email, name, IP logs, billing contactsThe user database is the primary store
Lead-generation sites, contact formsName, phone, company, messageEven a simple form counts as collection
Mobile apps, loyalty programs, CRMDevice IDs, phone numbers, purchase dataOften synced to a foreign CRM — check where the first write happens

Anonymous analytics without identifiers, or B2B data that does not identify individuals, may be treated differently — this is exactly where legal advice is needed.

Architecture pattern 1: everything in Russia

The simplest compliant-by-design setup is to run the whole application and its database on servers in Moscow.

  • Web app, database and file storage all on a JUSTG Moscow Cloud VPS or JUSTG Moscow Dedicated Server.
  • Good for Russia-focused shops, local SaaS and corporate sites.
  • Bonus: Russian users get low latency from a native Russian IP, and Chinese partners can still reach the site over CN2 GIA.

Architecture pattern 2: Russian database + global application

If your application runs elsewhere (for example in Tokyo, Japan or Seoul, South Korea), keep the database that receives Russian users' data in Moscow and have the app write to it first.

  1. Place the primary database (PostgreSQL or MySQL) on a JUSTG Moscow server.
  2. Connect the foreign app servers to it through a private WireGuard tunnel; never expose port 5432/3306 to the internet.
  3. Route sign-ups, orders and profile edits from Russian users to the Moscow database — the first write must land in Russia.
  4. If a copy abroad is needed (e.g. for global reporting), replicate from Russia outward, and only after checking the cross-border transfer rules and notifying Roskomnadzor where required.
# On the Moscow primary (PostgreSQL 16), /etc/postgresql/16/main/postgresql.conf
listen_addresses = '10.8.0.1'        # WireGuard address only
wal_level = replica
max_wal_senders = 5

# pg_hba.conf — allow only the replica over the private tunnel
hostssl replication replicator 10.8.0.2/32 scram-sha-256

A minimal firewall on the Moscow database server:

ufw default deny incoming
ufw allow 22/tcp
ufw allow 51820/udp            # WireGuard
ufw allow in on wg0 to any port 5432 proto tcp
ufw enable

Replication direction: get this right

The Russian database must be the source of truth; data flows out of Russia, never into Russia as an afterthought.

DesignDirectionAssessment
Primary in Moscow, read replica abroadRussia → abroadCommonly used; cross-border transfer rules apply to the copy
Primary abroad, nightly copy to RussiaAbroad → RussiaProblematic: first collection happens outside Russia
Russian users' PII in Moscow; non-personal data globalSplit by data typeGood option; store only tokens/IDs abroad
Everything in MoscowNoneSimplest to explain and audit

A useful technique is pseudonymization: the global app stores only an internal user ID, while names, phones and addresses stay in the Moscow database and are fetched over the tunnel when needed.

Backups inside Russia

Backups of Russian personal data are part of the database too, so keep them on servers in Russia and encrypt them.

# Nightly encrypted backup to a second server inside Russia
pg_dump -Fc shopdb | gpg --encrypt --recipient [email protected] \
  > /backup/shopdb-$(date +%F).dump.gpg
rsync -a /backup/ [email protected]:/srv/backups/shopdb/
find /backup -name '*.gpg' -mtime +14 -delete
  • Keep at least two copies inside Russia: the primary server plus a second Moscow VPS or dedicated server (the documentation IP 198.51.100.20 above is a placeholder).
  • Encrypt backups and restrict who holds the keys.
  • Test restores regularly; a backup you have never restored is not a backup.
  • Do not sync raw dumps to foreign cloud storage unless your lawyer confirms the transfer is permitted.

Compliance checklist

Use this table as a technical starting point and review it with your legal advisor.

#ItemTechnical actionDone
1Map personal dataList every form, API and table that stores data about Russian users☐
2Primary DB in RussiaDatabase on a server in Moscow, Russia; first write lands there☐
3Replication directionRussia → abroad only; document what is copied and why☐
4Roskomnadzor notificationSubmit/update notification including database location and cross-border transfers☐
5Consent and privacy policyConsent checkbox on forms; policy published in Russian☐
6SecurityFirewall, SSH keys, encrypted tunnels, TLS, access logs☐
7Backups in RussiaEncrypted, second Russian location, restore tested☐
8Incident responseProcedure to report leaks to Roskomnadzor within 24/72 hours☐

Which JUSTG plan fits

Choose by database size and load: a JUSTG Moscow Cloud VPS for most shops and SaaS, a JUSTG Moscow Dedicated Server for large or sensitive databases.

  • JUSTG Moscow Cloud VPS — plans from 1 core / 512 MB / 10 GB SSD ($19.99/mo) to 7 cores / 24 GB RAM / 320 GB SSD / 6 TB traffic ($169.99/mo). A database server is comfortable from 2–4 GB RAM.
  • JUSTG Moscow Dedicated Server — from $299/mo, with options up to a full /24; for heavy databases or when you want hardware isolation.
  • Custom configurations — CPU, RAM, disk, bandwidth, extra IPs or IP blocks on request; contact sales via ticket for a custom quote. See all JUSTG data centers.

FAQ

Where can I host a database in Russia to comply with 152-FZ?

You need a server physically located in Russia. JUSTG offers the JUSTG Moscow Cloud VPS from $19.99/mo and the JUSTG Moscow Dedicated Server from $299/mo in Moscow, Russia, both with native Russian IPs. Hosting is only one part of compliance; notification, consent and security still apply.

Does 152-FZ apply to foreign companies?

It is generally applied to anyone collecting personal data of Russian citizens through sites targeting Russia, including foreign companies. Whether your specific case is in scope is a legal question — consult a lawyer.

Can I keep a copy of Russian users' data outside Russia?

Typically the primary collection and storage must be in Russia, and copies abroad fall under cross-border transfer rules and notification requirements. Design replication from Russia outward and confirm with legal counsel.

Is a Moscow VPS suitable for calling OpenAI or Claude APIs?

No. OpenAI, Anthropic (Claude) and Google Gemini APIs are not available in Russia. Keep personal data in Moscow and run AI API calls from a JUSTG Tokyo or Seoul server, sending only data you are allowed to transfer.

Need a primary database in Russia? Deploy a JUSTG Moscow Cloud VPS or a JUSTG Moscow Dedicated Server, and open a ticket if you want help sizing it.

Was this answer helpful?
Help Center
AlipayUnionPayVISAMastercardPayPalUSDTstripe