Habr•August 24, 2026•🇷🇺Translated from Russian

Russia's Data Leak Penalties: 2.6 Million Rubles in Fines Despite 1.58 Billion Records Exposed in 2025

Half a year before May 30, 2025, the economics of data leaks in Russia were straightforward: the maximum fine for a legal entity stood at 100,000 rubles, rising to 300,000 rubles for repeat offenses. Implementing effective protection against leaks through DLP systems, audits, dedicated staff, and processes cost tens of millions of rubles annually, making breaches cheaper than prevention.

Federal Law 420-FZ of November 30, 2024, linked fines to the number of affected data subjects and introduced a turnover-based component for repeat violations under CoAP RF Article 13.11. Storage of unnecessary records suddenly carried direct financial risk because each excess entry became a line item in potential penalty calculations.

In the 18 months since the norm took effect, authorities conducted 52 administrative investigations, drew up 40 protocols, and imposed a total of 2.6 million rubles in fines. Not a single turnover fine has been applied. These figures stand against 1.581 billion leaked records in 2025, equating to roughly one-sixth of a thousandth of a kopeck per record.

The volume of fresh data leaks from Russian companies fell noticeably in the first half of 2026, yet activity on shadow marketplaces increased by almost 60 percent. Several non-exclusive explanations exist: operators now sell databases privately rather than publishing them openly to protect reputation; businesses have learned to conceal incidents because disclosure became costlier than silence; and some real reduction occurred as companies began questioning data retention periods instead of simply buying more DLP tools.

The core insight is that investment decisions are driven by expected loss rather than actual penalties paid. When the potential damage figure L in the risk equation p × L increased by two orders of magnitude, budgets were approved regardless of enforcement statistics. This effect has a limited shelf life: without turnover fines materializing in the next two to three years, the modeled probability will approach zero and budgets will follow.

Direct costs include the administrative fine, external forensics starting at 1.5 million rubles per medium incident, subject notification campaigns, and legal defense against individual claims. Indirect costs, often larger, encompass customer churn, increased customer acquisition expenses, service downtime, diverted team time, and higher future insurance and audit premiums. In a modeled service with 3 billion rubles annual revenue and an 800,000-client base, a conservative 2 percent churn already dwarfs all other loss categories combined.

Over-collection now appears on the balance sheet as an unhedged liability. Reducing retention periods from three years to six months directly lowers both risk exposure and infrastructure spend, delivering measurable ROI that most organizations still overlook in favor of additional security tooling.

Related articles

Habr•Policy & Regulation

How to Complete the Roskomnadzor Personal Data Notification Form in 2026: Field-by-Field Analysis

The article provides a detailed walkthrough of the current Roskomnadzor notification form for operators processing personal data under Russian law. It explains that the form is an extract from existing internal documents rather than a questionnaire, requiring operators to reference their data processing policy, inventory results, appointment orders, and protection level acts. Key prerequisites include confirming that notification is mandatory after the 2022 amendments removed most exemptions, preparing five core documents, and understanding that the form pulls data directly from those records. The guide covers every section, from operator identification and processing regions to data categories, protection measures, geography, and post-submission obligations. It also addresses common mistakes, the option to save drafts, auto-population features, and liability for non-compliance or inaccurate information. The piece concludes with a checklist mapping each form field to its source document.

Habr•Policy & Regulation

OBEP Raids on Russian IT Firms: How to Safeguard Source Code, Servers and Blockchain Assets During Searches

Russian IT companies, Web3 projects and fintech services now face frequent visits from OBEP operatives conducting pre-investigative checks or searches under criminal cases. The article details the legal distinction between operational-search measures and formal searches, emphasizing article 164.1 of the UPK RF that prohibits seizure of physical servers in economic crime investigations. It explains how companies can demand data mirroring instead of hardware removal and how to invoke article 51 of the RF Constitution when pressured for encryption keys. Commercial secret regimes are presented as a tool to raise criminal liability for leaks and to request closed court proceedings. Practical checklists cover document verification, staff instructions, password retention and immediate calls to specialized criminal counsel. The guidance aims to prevent business paralysis while preserving evidence integrity during raids.

Habr•Policy & Regulation

RWB Deploys Enterprise-Wide Database Access Control with Trino and Open Policy Agent

RWB has replaced fragmented manual database access processes with a centralized architecture built on Trino as the single entry point and Open Policy Agent for policy enforcement. The system enforces least-privilege access, mandatory auditing, and automated revocation tied to HR records while eliminating anonymous and password-based logins. Access requests now complete in 3–10 minutes instead of an average of four days, with 92 percent handled automatically. Key components include Keycloak for OIDC authentication, Vault for secrets, Kafka for security event streaming to SOC, and Kubernetes orchestration. Responsibility is split across AI & Data Security, Core DevOps, Access Management, SOC, and Trust & Safety teams. More than 1,250 PostgreSQL clusters and 90 projects are now connected, with real-time dashboards tracking adoption and policy health.

AntiMalware•Policy & Regulation

Russia Moves to Allow Biometric Data Processing for Suspects and Convicts Without Consent

Russian law enforcement agencies may soon gain the legal right to process biometric data of suspects, accused individuals, and convicted persons without requiring their personal consent. A corresponding draft bill has already been submitted to the government and is scheduled for review at the next cabinet meeting, according to TASS. The measure covers fingerprints, facial images, voice recordings, and other physiological or behavioral characteristics used for identification. If approved, prior permission from the individual will no longer be needed when biometrics are used in criminal proceedings. The change applies not only to those already convicted but also to suspects and accused persons whose guilt has not yet been established by a court. For ordinary citizens, enrollment in the Unified Biometric System remains voluntary and is used for remote identity verification when accessing financial and government services.