What problem would this feature solve, if any?
Cap’s compliance page currently mentions GDPR, CCPA/CPRA, HIPAA, PIPEDA/CPPA, LGPD, DPDPA, PIPL, and accessibility standards, but it does not mention Russia’s Federal Law No. 152-FZ “On Personal Data”.
For companies or developers operating websites for users in Russia, this creates uncertainty about whether Cap can be used in a deployment that is compatible with Russian personal data requirements. Since Cap is privacy-first, self-hosted, does not use cookies or tracking, and avoids third-party calls in the verification flow, it may already be suitable for many Russian deployments, but this is not clearly documented.
Describe the solution you’d like
Please add Russia’s Federal Law No. 152-FZ “On Personal Data” to the compliance documentation, similar to the existing entries for GDPR, LGPD, PIPL, and other privacy laws.
The page could clarify that Cap can be self-hosted in the operator’s own infrastructure, including inside Russia if required, and that the verification flow does not rely on third-party tracking, profiling, cookies, or external data sharing.
Suggested wording:
152-FZ — Russia
Federal Law No. 152-FZ “On Personal Data”
Cap can be self-hosted on the operator’s own infrastructure, including in-region deployments. No cookies, tracking, profiling, or third-party calls are required in the verification flow, helping operators keep personal data processing under their own control.
It would also be helpful to include the same disclaimer used elsewhere on the page: that this is not legal advice and that final compliance depends on how Cap is deployed and how the rest of the application processes personal data.
Describe alternatives you’ve considered
An alternative would be to rely only on the existing general privacy-first and self-hosted claims, but that does not directly answer the question for Russian companies or developers who specifically need to evaluate 152-FZ requirements.
Another alternative would be for each project using Cap to write its own legal/compliance explanation, but having a short official note in the documentation would make evaluation easier and reduce uncertainty.
Additional context
This would make Cap easier to adopt for projects targeting Russian users or Russian organizations. The current compliance page already lists several regional privacy laws, so adding 152-FZ would make the list more complete and useful for international deployments.
What problem would this feature solve, if any?
Cap’s compliance page currently mentions GDPR, CCPA/CPRA, HIPAA, PIPEDA/CPPA, LGPD, DPDPA, PIPL, and accessibility standards, but it does not mention Russia’s Federal Law No. 152-FZ “On Personal Data”.
For companies or developers operating websites for users in Russia, this creates uncertainty about whether Cap can be used in a deployment that is compatible with Russian personal data requirements. Since Cap is privacy-first, self-hosted, does not use cookies or tracking, and avoids third-party calls in the verification flow, it may already be suitable for many Russian deployments, but this is not clearly documented.
Describe the solution you’d like
Please add Russia’s Federal Law No. 152-FZ “On Personal Data” to the compliance documentation, similar to the existing entries for GDPR, LGPD, PIPL, and other privacy laws.
The page could clarify that Cap can be self-hosted in the operator’s own infrastructure, including inside Russia if required, and that the verification flow does not rely on third-party tracking, profiling, cookies, or external data sharing.
Suggested wording:
152-FZ — Russia
Federal Law No. 152-FZ “On Personal Data”
Cap can be self-hosted on the operator’s own infrastructure, including in-region deployments. No cookies, tracking, profiling, or third-party calls are required in the verification flow, helping operators keep personal data processing under their own control.
It would also be helpful to include the same disclaimer used elsewhere on the page: that this is not legal advice and that final compliance depends on how Cap is deployed and how the rest of the application processes personal data.
Describe alternatives you’ve considered
An alternative would be to rely only on the existing general privacy-first and self-hosted claims, but that does not directly answer the question for Russian companies or developers who specifically need to evaluate 152-FZ requirements.
Another alternative would be for each project using Cap to write its own legal/compliance explanation, but having a short official note in the documentation would make evaluation easier and reduce uncertainty.
Additional context
This would make Cap easier to adopt for projects targeting Russian users or Russian organizations. The current compliance page already lists several regional privacy laws, so adding 152-FZ would make the list more complete and useful for international deployments.