<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD with OASIS Tables with MathML3 v1.4 20241031//EN" "https://jats.nlm.nih.gov/archiving/1.4/JATS-archive-oasis-article1-4-mathml3.dtd">
<!-- собрано плагином nlj-issue-importer -->
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:ali="http://www.niso.org/schemas/ali/1.0/" dtd-version="1.4" article-type="research-article" xml:lang="en"><front><journal-meta><journal-title-group><journal-title xml:lang="ru">Всероссийский научный журнал "Вопросы права"</journal-title></journal-title-group><issn publication-format="electronic">2949-0871</issn></journal-meta><article-meta><article-id pub-id-type="doi">10.24412/2949-0871-2026-4-23-30</article-id><article-categories><subj-group><subject>Other</subject></subj-group></article-categories><title-group><article-title xml:lang="ru">Применение зарубежного опыта правового регулирования защиты персональных данных в российской правовой системе</article-title><trans-title-group xml:lang="en"><trans-title>Application of foreign experience in the legal regulation of personal data protection within the Russian legal system</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author"><name-alternatives><name xml:lang="ru"><surname>Рочева</surname><given-names>София Сергеевна</given-names></name><name xml:lang="en"><surname>Rocheva</surname><given-names>Sofia Sergeyevna</given-names></name></name-alternatives><xref ref-type="aff" rid="aff1"/><xref ref-type="aff" rid="aff2"/><email>snrchv@gmail.com</email></contrib><aff-alternatives id="aff1"><aff><institution xml:lang="en">Bachelor, Higher School of Jurisprudence and Forensic Technical Expertise, Peter the Great St. Petersburg Polytechnic University, St. Petersburg, Russia</institution></aff></aff-alternatives><aff-alternatives id="aff2"><aff><institution xml:lang="ru">бакалавр Высшей школы юриспруденции и судебно-технической экспертизы, Санкт-Петербургский политехнический университет Петра Великого, Санкт-Петербург, Россия</institution></aff></aff-alternatives></contrib-group><pub-date pub-type="epub" iso-8601-date="2026-09-16"><day>16</day><month>09</month><year>2026</year></pub-date><issue>4</issue><fpage>23</fpage><lpage>30</lpage><history><date date-type="received" iso-8601-date="2026-06-05"><day>05</day><month>06</month><year>2026</year></date><date date-type="accepted" iso-8601-date="2026-09-11"><day>11</day><month>09</month><year>2026</year></date></history><abstract xml:lang="ru"><p>В статье рассматриваются пределы и условия применения зарубежного опыта правового регулирования защиты персональных данных в российской правовой системе после законодательных изменений 2025 г., затронувших согласие субъекта, локализацию баз данных, обезличивание сведений, административную ответственность операторов и правовой режим высокорисковой цифровой обработки. Особое внимание уделено соотношению российских реформ с зарубежными механизмами подотчетности контролера, оценки воздействия на защиту данных, трансграничных гарантий, алгоритмической прозрачности и риск-ориентированного надзора. Методологическую основу исследования составили формально-юридический, сравнительно-правовой, системный методы и элементы функционального анализа правовых конструкций. Формально-юридический метод использован для оценки действующих обязанностей оператора по Федеральному закону от 27 июля 2006 г. № 152-ФЗ «О персональных данных» в редакции с учетом изменений 2024-2025 гг.; сравнительно-правовой метод позволил сопоставить российскую модель регулирования с подходами Европейского союза, Совета Европы, Бразилии, Калифорнии и Китайской Народной Республики; системный метод применен для определения места зарубежных механизмов в российской системе конституционных гарантий, информационного законодательства, административного надзора и локального регулирования деятельности операторов. Научная новизна выражается в обосновании постреформенной модели функциональной адаптации зарубежного опыта, при которой иностранные правовые механизмы оцениваются не как образцы для законодательного копирования, а как инструменты восполнения конкретных пробелов российского регулирования. Обоснован вывод о том, что после реформ 2025 г. перспективными направлениями развития остаются риск-профилирование операций обработки, методически оформленная оценка воздействия при высокорисковой обработке, внутреннее заключение о допустимости трансграничной передачи, содержательная алгоритмическая прозрачность и специальные гарантии против повторной идентификации обезличенных данных.</p></abstract><abstract xml:lang="en" abstract-type="summary"><p>The article examines the limits and conditions for applying foreign experience regarding the legal regulation of personal data protection within the Russian legal system following the legislative changes of 2025. These changes affected data subject consent, database localization, data anonymization, the administrative liability of data controllers (operators), and the legal regime governing high-risk digital processing. Particular attention is paid to the relationship between Russian reforms and foreign mechanisms concerning controller accountability, data protection impact assessments, cross-border safeguards, algorithmic transparency, and risk-based supervision. The methodological framework of the study comprises formal-legal, comparative-legal, and systemic methods, alongside elements of the functional analysis of legal constructs. The formal-legal method was used to assess the current obligations of data controllers under Federal Law No.</p></abstract><kwd-group xml:lang="ru"><kwd>персональные данные</kwd><kwd>защита данных</kwd><kwd>российское право</kwd><kwd>зарубежный опыт</kwd><kwd>реформа 2025 года</kwd><kwd>подотчетность оператора</kwd><kwd>оценка воздействия</kwd><kwd>обезличенные данные</kwd><kwd>трансграничная передача</kwd><kwd>автоматизированная обработка</kwd></kwd-group><kwd-group xml:lang="en"><kwd>personal data</kwd><kwd>data protection</kwd><kwd>Russian law</kwd><kwd>foreign experience</kwd><kwd>2025 reform</kwd><kwd>controller accountability</kwd><kwd>impact assessment</kwd><kwd>anonymized data</kwd><kwd>cross-border transfer</kwd><kwd>automated processing</kwd></kwd-group></article-meta></front><back><ref-list><ref id="ref1"><mixed-citation publication-type="other" xml:lang="ru">Талапина Э. В. Защита персональных данных в цифровую эпоху: российское право в европейском контексте // Труды Института государства и права Российской академии наук. 2018. Т. 13. № 5. С. 117-150.</mixed-citation></ref><ref id="ref2"><mixed-citation publication-type="other" xml:lang="ru">Минбалеев А. В. Перспективные направления правового регулирования персональных данных // Вестник Университета имени О. Е. Кутафина. 2024. № 1. С. 83-91.</mixed-citation></ref><ref id="ref3"><mixed-citation publication-type="other" xml:lang="ru">Шелудченко И. А. Защита персональных данных в Российской Федерации сквозь призму делегированного правотворчества // Вестник Московского университета. Серия 11. Право. 2025. № 1. С. 77-99.</mixed-citation></ref><ref id="ref4"><mixed-citation publication-type="other" xml:lang="ru">Быстрякова С. А. Развитие правового регулирования персональных данных в условиях формирования экономики данных в России // Право и государство: теория и практика. 2024. № 2 (230). С. 179-182.</mixed-citation></ref><ref id="ref5"><mixed-citation publication-type="other" xml:lang="ru">Legrand P. The Impossibility of Legal Transplants // Maastricht Journal of European and Comparative Law. 1997. Vol. 4. № 2. P. 111-124.</mixed-citation></ref><ref id="ref6"><mixed-citation publication-type="other" xml:lang="ru">Bygrave L. A. Data Privacy Law: An International Perspective. Oxford: Oxford University Press, 2014.</mixed-citation></ref><ref id="ref7"><mixed-citation publication-type="other" xml:lang="ru">Lynskey O. The Foundations of EU Data Protection Law. Oxford: Oxford University Press, 2015.</mixed-citation></ref><ref id="ref8"><mixed-citation publication-type="other" xml:lang="ru">Calvi A. Data Protection Impact Assessment under the EU General Data Protection Regulation: A Feminist Critique // Computer Law &amp;amp; Security Review. 2024. Vol. 53. P. 1-20.</mixed-citation></ref><ref id="ref9"><mixed-citation publication-type="other" xml:lang="ru">Kuner C. Reality and Illusion in EU Data Transfer Regulation Post Schrems // German Law Journal. 2017. Vol. 18. № 4. P. 881-918.</mixed-citation></ref><ref id="ref10"><mixed-citation publication-type="other" xml:lang="ru">Bradford L., Aboy M., Liddell K. Standard Contractual Clauses for Cross-Border Transfers of Health Data after Schrems II // Journal of Law and the Biosciences. 2021. Vol. 8. № 1. P. 1-35.</mixed-citation></ref><ref id="ref11"><mixed-citation publication-type="other" xml:lang="ru">Schwartz P. M., Solove D. J. The PII Problem: Privacy and a New Concept of Personally Identifiable Information // New York University Law Review. 2011. Vol. 86. P. 1814-1894.</mixed-citation></ref><ref id="ref12"><mixed-citation publication-type="other" xml:lang="ru">Ушаков А. С. К вопросу о правах субъекта персональных данных при принятии решений на основании автоматизированной обработки информации // Образование и право. 2024. № 10. С. 108- 112.</mixed-citation></ref><ref id="ref13"><mixed-citation publication-type="other" xml:lang="ru">Окишев Б. А. Особенности правовой охраны персональных данных, обрабатываемых с использованием технологий искусственного интеллекта // Проблемы экономики и юридической практики. 2024. Т. 20. № 2. С. 70-75.</mixed-citation></ref><ref id="ref14"><mixed-citation publication-type="other" xml:lang="ru">Škorjanc Ž. A Holistic Approach under the GDPR, AI Act, and Directive 2023/2225 to the Right to Explanation of Credit Scores // Global Privacy Law Review. 2025. Vol. 6. № 3. P. 222-240.</mixed-citation></ref><ref id="ref15"><mixed-citation publication-type="other" xml:lang="ru">Жирнова Н. А., Солдаткина О. Л. К вопросу о правовом режиме обезличенных персональных данных // Вестник Воронежского государственного университета. Серия: Право. 2024. № 4 (59). С. 44-51.</mixed-citation></ref><ref id="ref16"><mixed-citation publication-type="other" xml:lang="ru">Туранин В. Ю. Обезличивание персональных данных как правовой эксперимент: риски и возможности // Юридическая техника. 2025. № 19. С. 641-646.</mixed-citation></ref><ref id="ref17"><mixed-citation publication-type="other" xml:lang="ru">Полуянова Е. В. Актуальные вопросы правового регулирования обезличивания персональных данных // Вестник науки. 2025. Т. 4. № 2. С. 421-426.</mixed-citation></ref><ref id="ref18"><mixed-citation publication-type="other" xml:lang="ru">Solove D. J. The Digital Person: Technology and Privacy in the Information Age. New York: New York University Press, 2004.</mixed-citation></ref><ref id="ref19"><mixed-citation publication-type="other" xml:lang="ru">Cate F. H., Mayer-Schönberger V. Notice and Consent in a World of Big Data // International Data Privacy Law. 2013. Vol. 3. № 2. P. 67-73.</mixed-citation></ref><ref id="ref20"><mixed-citation publication-type="other" xml:lang="ru">Rubinstein I. S. Big Data: The End of Privacy or a New Beginning? // International Data Privacy Law. 2013. Vol. 3. № 2. P. 74-87.</mixed-citation></ref><ref id="ref21"><mixed-citation publication-type="other" xml:lang="en">Talapina E. V. Personal Data Protection in the Digital Age: Russian Law in a European Context // Proceedings of the Institute of State and Law of the Russian Academy of Sciences. 2018. Vol. 13. No. 5. P. 117-150.</mixed-citation></ref><ref id="ref22"><mixed-citation publication-type="other" xml:lang="en">Minbaleev A. V. Promising Directions for the Legal Regulation of Personal Data // Bulletin of the O. E. Kutafin University. 2024. No. 1. P. 83-91.</mixed-citation></ref><ref id="ref23"><mixed-citation publication-type="other" xml:lang="en">Sheludchenko I. A. Personal Data Protection in the Russian Federation through the Prism of Delegated Law-Making // Bulletin of Moscow University. Series 11. Law. 2025. No. 1. P. 77-99.</mixed-citation></ref><ref id="ref24"><mixed-citation publication-type="other" xml:lang="en">Bystryakova S. A. Development of Legal Regulation of Personal Data Amidst the Formation of a Data Economy in Russia // Law and State: Theory and Practice. 2024. No. 2 (230). P. 179-182.</mixed-citation></ref><ref id="ref25"><mixed-citation publication-type="other" xml:lang="en">Legrand P. The Impossibility of Legal Transplants // Maastricht Journal of European and Comparative Law. 1997. Vol. 4. No. 2. P. 111-124.</mixed-citation></ref><ref id="ref26"><mixed-citation publication-type="other" xml:lang="en">Bygrave L. A. Data Privacy Law: An International Perspective. Oxford: Oxford University Press, 2014.</mixed-citation></ref><ref id="ref27"><mixed-citation publication-type="other" xml:lang="en">Lynskey O. The Foundations of EU Data Protection Law. Oxford: Oxford University Press, 2015.</mixed-citation></ref><ref id="ref28"><mixed-citation publication-type="other" xml:lang="en">Calvi A. Data Protection Impact Assessment under the EU General Data Protection Regulation: A Feminist Critique // Computer Law &amp;amp; Security Review. 2024. Vol. 53. P. 1-20.</mixed-citation></ref><ref id="ref29"><mixed-citation publication-type="other" xml:lang="en">Kuner C. Reality and Illusion in EU Data Transfer Regulation Post Schrems // German Law Journal. 2017. Vol. 18. No. 4. P. 881-918.</mixed-citation></ref><ref id="ref30"><mixed-citation publication-type="other" xml:lang="en">Bradford L., Aboy M., Liddell K. Standard Contractual Clauses for Cross- Border Transfers of Health Data after Schrems II // Journal of Law and the Biosciences. 2021. Vol. 8. No. 1. P. 1-35.</mixed-citation></ref><ref id="ref31"><mixed-citation publication-type="other" xml:lang="en">Schwartz P. M., Solove D. J. The PII Problem: Privacy and a New Concept of Personally Identifiable Information // New York University Law Review. 2011. Vol. 86. P. 1814-1894.</mixed-citation></ref><ref id="ref32"><mixed-citation publication-type="other" xml:lang="en">Ushakov A. S. On the Rights of the Data Subject Regarding Decisions Based on Automated Information Processing // Education and Law. 2024. No. 10. P. 108-112.</mixed-citation></ref><ref id="ref33"><mixed-citation publication-type="other" xml:lang="en">Okishev B. A. Specifics of Legal Protection for Personal Data Processed Using Artificial Intelligence Technologies // Problems of Economics and Legal Practice. 2024. Vol. 20. No. 2. P. 70-75.</mixed-citation></ref><ref id="ref34"><mixed-citation publication-type="other" xml:lang="en">Škorjanc Ž. A Holistic Approach under the GDPR, AI Act, and Directive 2023/2225 to the Right to Explanation of Credit Scores // Global Privacy Law Review. 2025. Vol. 6. No. 3. P. 222-240.</mixed-citation></ref><ref id="ref35"><mixed-citation publication-type="other" xml:lang="en">Zhirnova N. A., Soldatkina O. L. On the Legal Regime of Anonymized Personal Data // Bulletin of Voronezh State University. Series: Law. 2024. No. 4 (59). P. 44-51.</mixed-citation></ref><ref id="ref36"><mixed-citation publication-type="other" xml:lang="en">Turanin V. Yu. Anonymization of Personal Data as a Legal Experiment: Risks and Opportunities // Legal Technique. 2025. No. 19. P. 641-646.</mixed-citation></ref><ref id="ref37"><mixed-citation publication-type="other" xml:lang="en">Poluyanova E. V. Current Issues in the Legal Regulation of Personal Data Anonymization // Bulletin of Science. 2025. Vol. 4. No. 2. P. 421–426.</mixed-citation></ref><ref id="ref38"><mixed-citation publication-type="other" xml:lang="en">Solove D. J. The Digital Person: Technology and Privacy in the Information Age. New York: New York University Press, 2004.</mixed-citation></ref><ref id="ref39"><mixed-citation publication-type="other" xml:lang="en">Cate F. H., Mayer-Schönberger V. Notice and Consent in a World of Big Data // International Data Privacy Law. 2013. Vol. 3. No. 2. P. 67–73.</mixed-citation></ref><ref id="ref40"><mixed-citation publication-type="other" xml:lang="en">Rubinstein I. S. Big Data: The End of Privacy or a New Beginning? // International Data Privacy Law. 2013. Vol. 3. No. 2. P. 74–87.</mixed-citation></ref></ref-list></back></article>
