Inserting Contracts into ChatGPT Risks Major Fines Under Russia's 152-FZ Personal Data Law
A Russian operator registered in the Roskomnadzor personal data registry (number 24-26-055344) has published a detailed breakdown of risks that arise when contracts are pasted into foreign AI chatbots. The author notes that ordinary supply or transportation agreements routinely contain ФИО of signatories, passport data of individual entrepreneurs, INN numbers, phone numbers and emails of managers and drivers.
These elements remain personal data even when the information is already published in the Unified State Register of Legal Entities. Russian regulator practice holds that public availability does not convert the data into “publicly accessible” for the purposes of the law.
Updated administrative fines after 420-FZ
From 30 May 2025 the following penalties under Article 13.11 of the Code of Administrative Offenses apply to legal entities:
- Part 1 – processing without legal basis or for incompatible purposes: 150–300 thousand rubles
- Part 1.1 – repeated violation: 300–500 thousand rubles
- Part 10 – failure to notify Roskomnadzor of processing: 100–300 thousand rubles
- Part 8 – storage of Russian citizens’ data outside Russia: 1–6 million rubles
Individual entrepreneurs are treated as legal entities for most of these provisions. Million-ruble “leak” fines under parts 12–18 do not apply to a single contract or even several dozen contracts per month.
Cross-border transfer obligations
Any transmission of personal data to an entity located in another country constitutes a cross-border transfer under Article 12 of 152-FZ. Providing access to ChatGPT, Claude, Gemini or DeepSeek is sufficient; no physical file transfer is required. Since 1 March 2023 a separate notification must be filed with Roskomnadzor before such transfers begin. For the United States and the European Union a ten-working-day waiting period applies, during which the regulator may prohibit or restrict the transfer.
In addition, Russian law requires a data-processing agreement with any third party that receives personal data. Standard user agreements of OpenAI, Anthropic or Google do not satisfy this requirement.
Court practice and real incidents
No administrative cases specifically concerning AI chatbots have yet reached public court records. However, on 27 July 2026 the Babushkinsky District Court in Moscow upheld the dismissal of a sales director who uploaded transaction reports and financial data to DeepSeek, ruling that the action amounted to disclosure of trade secrets.
Earlier incidents at Samsung in 2023 demonstrated that source code, meeting transcripts and test sequences were uploaded to ChatGPT within weeks of internal approval, prompting the company to ban external AI tools on corporate devices. A U.S. federal court order in the New York Times v. OpenAI litigation temporarily required preservation of all ChatGPT logs, including deleted conversations, for five months in 2025.
Related articles
MTS, MegaFon and Beeline Must Temporarily Suspend Radio Equipment at FSO Request Under Extended Frequency Licenses
Russian telecom operators MTS, MegaFon and VimpelCom (Beeline) have received extensions for their radio frequency allocations until 31 December 2027, but the licenses now include a binding requirement to pause operations of radio-electronic equipment upon demand from the Federal Security Service (FSO). The State Commission for Radio Frequencies (GKRCH) added this condition during its 31 August meeting, directly linking compliance with FSO instructions to the continued use of spectrum originally allocated in 2006. The measure applies during security operations, high-priority state activities and special FSO events, potentially causing temporary loss of mobile connectivity for subscribers in affected areas. Although FSO powers to request such suspensions have existed since 2011, the new decision embeds the obligation explicitly into the frequency license terms. At the same time, the operators retain earlier commitments to expand network coverage to all settlements with at least 2,000 residents by 31 March 2027. The dual requirements illustrate how spectrum policy now balances nationwide connectivity goals with operational readiness for temporary shutdowns ordered by security authorities.
Russia Discusses Extra Fees for International Traffic Over 50 GB in 5G Networks
The Russian Ministry of Digital Development is again in talks with mobile operators about introducing charges for international data traffic exceeding 50 GB per month, but only within 5G networks. The measure would potentially apply to VPN services and other foreign resources, adding to users' mobile bills. No final decision has been reached and the exact fee amount remains unspecified. Sources indicate a possible launch in October, though timelines are subject to change. Technical challenges arise because current 5G deployments rely on LTE infrastructure, requiring new traffic separation, network handover tracking, and billing system adjustments. Average monthly mobile data usage stood at 24 GB in 2025, making the 50 GB international 5G threshold a narrow scenario. Headlines claiming VPNs will become paid services overstate the current discussions, which focus solely on international traffic classification.
Fonts, CDNs, and Hosting: The Cross-Border Data Transfers No One Notices
A Russian developer building a contract-processing service discovered that his website was silently sending visitor data to foreign companies despite keeping all contract data on Russian servers. The site used Vercel for hosting, Google Fonts across 33 pages, and Cloudflare's cdnjs for PDF and Word libraries, exposing IP addresses, browsers, and browsing history. Under Russia's 152-FZ, such transfers require a separate notification to Roskomnadzor, and the United States and EU are not on the list of countries with adequate protection. The developer migrated fonts and libraries to his own Russian server, moved hosting domestically, and updated his privacy policy after a single console command revealed the external domains. The case highlights how common web practices like loading Google Fonts or using CDNs can trigger strict data localization and notification rules, with fines reaching millions of rubles for violations.
How to Complete the Roskomnadzor Personal Data Notification Form in 2026: Field-by-Field Analysis
The article provides a detailed walkthrough of the current Roskomnadzor notification form for operators processing personal data under Russian law. It explains that the form is an extract from existing internal documents rather than a questionnaire, requiring operators to reference their data processing policy, inventory results, appointment orders, and protection level acts. Key prerequisites include confirming that notification is mandatory after the 2022 amendments removed most exemptions, preparing five core documents, and understanding that the form pulls data directly from those records. The guide covers every section, from operator identification and processing regions to data categories, protection measures, geography, and post-submission obligations. It also addresses common mistakes, the option to save drafts, auto-population features, and liability for non-compliance or inaccurate information. The piece concludes with a checklist mapping each form field to its source document.