General Data Protection Regulation (GDPR)

The GDPR regulates how personal data is collected and processed for individuals in the European Economic Zone. Designed to enhance personal data protection, it is the legal bedrock ensuring transparency for data collection, storage, and processing.

Yandex Cloud focuses on the GDPR as a global framework in the area of data protection and privacy. If our customer is subject to the GDPR, we make sure that provision of Yandex Cloud platform is in line with legal needs of the customer. We’re completely committed to privacy, with procedures in place for informing our customers when incidents occur.

Other certificates and standards

Federal Law 152-FZ

The federal law regulating how personal data is stored and processed.

ISO

A global system of quality standards developed by the International Organization for Standardization.

PCI

Standards for secure usage of credit cards from the Payment Card Industry Security Standards Council.

GOST R 57580

The Russian national security standard for banking and financial operations, required for all credit and non-credit financial organizations.

Cloud Security Alliance

An international organization promoting IS best practices for cloud services.

Register of Russian Software

The unified register of Russian software programs.