Habrβ€’August 30, 2026β€’πŸ‡·πŸ‡ΊTranslated from Russian

Costly Mistakes: How Russian Businesses Risk Millions in Fines for Personal Data Violations

A year after new fines for personal data protection violations came into force in Russia, many entrepreneurs still risk multimillion-ruble penalties from Roskomnadzor. The most frequent breaches involve improper collection, storage, and processing of personal data of Russian citizens.

Violation 1: Using Google Forms

Despite repeated warnings at conferences and webinars, businesses continue to use Google Forms. All personal data must be recorded, systematized, accumulated, stored, and processed using databases located on Russian territory under Part 5 of Article 18 of the Law on Personal Data. Google’s servers are located outside Russia, violating localization requirements. Recommended fix: replace with domestic alternatives such as Yandex Forms. Fines range from 30,000–50,000 rubles for citizens and 1–6 million rubles for individual entrepreneurs and legal entities under Part 8 of Article 13.11 of the Code of Administrative Offenses.

Violation 2: Missing Cookie Banner

If a website uses cookies without displaying a proper banner, it violates the law because cookies qualify as personal data. The recommended banner text informs users about cookie usage for analytics and links to the privacy policy. Fines start at 10,000–15,000 rubles for citizens and reach 150,000–300,000 rubles for legal entities.

Violation 3: No Consent Under Data Collection Forms

Many sites lack valid consent for processing personal data or link only to a privacy policy instead. Consent must meet requirements of Article 9, including specific purpose, list of data, and validity period, plus a checkbox with linked consent text. Fines are identical to those for missing cookie banners.

Violation 4: Publishing Reviews Without Distribution Consent

Publishing reviews containing personal data without separate consent for dissemination violates Article 10.1. Consent must follow the form approved by Order No. 18, and the privacy policy must disclose processing conditions and any prohibitions set by the data subject.

Violation 5: Missing or Non-Compliant Privacy Policy

Every operator must publish a privacy policy in the site footer and under every data collection form, detailing categories of data, purposes, retention periods, destruction procedures, and third-party recipients per Part 2 of Article 18.1. Fines range from 1,500–3,000 rubles for citizens to 30,000–60,000 rubles for legal entities.

Violation 6: No Notification or Outdated Notification to Roskomnadzor

Operators must notify Roskomnadzor before processing personal data and keep the notification current using the form from Order No. 180 of 28 October 2022. Fines reach 100,000–300,000 rubles for legal entities.

Violation 7: Transferring Employee Data Without Separate Written Consent

Employers may not disclose employee personal data to third parties without written consent for each specific purpose, as required by Article 88 of the Labor Code and Part 4 of Article 9. Fines range from 100,000–300,000 rubles for individual entrepreneurs and 300,000–700,000 rubles for legal entities.

Violation 8: No Data Processing Agreement with Third Parties

When personal data are entrusted to third parties (mailing services, etc.), a separate agreement must list the data, operations, purposes, and confidentiality obligations per Part 3 of Article 6. Fines are the same as for missing cookie banners.

Violation 9: No Document on Paper Data Storage Locations

Operators must maintain a document specifying storage locations of paper-based personal data carriers and the list of persons with access, according to Government Resolution No. 687 of 15 September 2008. Fines range from 1,500–4,000 rubles for citizens to 50,000–100,000 rubles for legal entities.

Violation 10: Failure to Respond to Data Subject or Roskomnadzor Requests

Operators must respond within statutory deadlines under Article 21. Appointing a responsible person and maintaining clear internal instructions helps ensure timely replies. Fines range from 2,000–4,000 rubles for citizens to 50,000–90,000 rubles for legal entities.

A comprehensive audit followed by development and implementation of all required documents remains the most reliable way to eliminate these risks and protect profits in 2026.

Related articles

AntiMalwareβ€’Policy & Regulation

VK Files Lawsuit in EU Court Seeking to Overturn Sanctions Imposed in July

Russian internet company VK has submitted a formal challenge to the European Union's sanctions regime by filing a case with the Court of Justice of the European Union. The company argues that the restrictions placed on VK and its subsidiary Communication Platform LLC are both unjustified and unlawful. The lawsuit, registered under case number T-664/26 on 7 October, directly contests the July sanctions that targeted the developer of the MAX messenger. Earlier restrictions had already led to the removal of multiple VK ecosystem applications from Apple App Store and Google Play, forcing users toward alternative distribution channels such as RuStore, Huawei AppGallery, Samsung Galaxy Store and Xiaomi GetApps. While installed Android applications continue to function and receive updates, iOS users face disrupted push notifications after the apps were delisted. The legal action itself does not automatically restore app availability in the affected stores.

Securitylabβ€’Policy & Regulation

VPN Rules in Russia 2026: No Fine for Ordinary Users but Strict Penalties for Advertising and Extremist Content Access

As of September 2026, Russia maintains no separate administrative fine for ordinary citizens simply connecting to a VPN service. Responsibility arises only for specific actions such as deliberately searching for known extremist materials, advertising tools to bypass restrictions, or failing to comply with Roskomnadzor demands as a service operator. Corporate VPNs used for remote access to company networks remain fully legal under exceptions in Article 15.8 of Law No. 149-FZ. New provisions in the Code of Administrative Offenses, including Articles 13.53, 13.52 and 14.3 introduced by Laws 281-FZ and 282-FZ, impose fines ranging from 3,000 to 500,000 rubles depending on the violation and the offender category. The rules distinguish clearly between end users, service owners and advertisers. VPN technology itself is not banned, yet public services face ongoing blocking and operators must integrate with state filtering systems. The material reflects the regulatory situation on 24 September 2026.

Habrβ€’Policy & Regulation

Troubleshooting Erroneous TSPU Blocks: How Admins Can Collaborate with Russian Regulators

A Moneta client outage traced back to erroneous filtering on Russia's TSPU system rather than internal infrastructure or DDoS protection. Engineers used curl, traceroute, nping, and custom Python scripts to confirm TCP payload-based blocking after the handshake. The team submitted a request via the VTS personal account, received partial acceptance status, then escalated to DCOA and SSOP to obtain the specific TSPU site number. Detailed network traces and active traffic were required for diagnostics. The case highlights coordination challenges between operators, DCOA, and SSOP when erroneous blocks occur on information resources.

AntiMalwareβ€’Policy & Regulation

Security Vision Unveils Self-Assessment Portal for Unified Information Security Evaluation Across Corporate Holdings

Security Vision has launched a new Self-Assessment portal designed to consolidate information security self-evaluations for entire corporate groups and holdings. The platform addresses common challenges where subsidiaries maintain inconsistent compliance records, with some requirements fulfilled while others remain unresolved for years in scattered emails and spreadsheets. Security Vision SA covers the complete workflow from defining requirements and distributing questionnaires to calculating results and tracking remediation actions. Parent organizations gain a consolidated view of subsidiary compliance status along with detailed breakdowns by individual systems. The system supports requirement templates, version control, scheduled assessments, automated metric-based answers, and conversion of gaps into actionable plans with assigned owners and deadlines. Additional features include internal policy document management and interactive dashboards for analysis. The first public demonstration is scheduled for the SOC Forum on October 27-28.