HabrAugust 30, 2026🇷🇺Translated from Russian

Costly Mistakes: How Russian Businesses Risk Millions in Fines for Personal Data Violations

A year after new fines for personal data protection violations came into force in Russia, many entrepreneurs still risk multimillion-ruble penalties from Roskomnadzor. The most frequent breaches involve improper collection, storage, and processing of personal data of Russian citizens.

Violation 1: Using Google Forms

Despite repeated warnings at conferences and webinars, businesses continue to use Google Forms. All personal data must be recorded, systematized, accumulated, stored, and processed using databases located on Russian territory under Part 5 of Article 18 of the Law on Personal Data. Google’s servers are located outside Russia, violating localization requirements. Recommended fix: replace with domestic alternatives such as Yandex Forms. Fines range from 30,000–50,000 rubles for citizens and 1–6 million rubles for individual entrepreneurs and legal entities under Part 8 of Article 13.11 of the Code of Administrative Offenses.

Violation 2: Missing Cookie Banner

If a website uses cookies without displaying a proper banner, it violates the law because cookies qualify as personal data. The recommended banner text informs users about cookie usage for analytics and links to the privacy policy. Fines start at 10,000–15,000 rubles for citizens and reach 150,000–300,000 rubles for legal entities.

Violation 3: No Consent Under Data Collection Forms

Many sites lack valid consent for processing personal data or link only to a privacy policy instead. Consent must meet requirements of Article 9, including specific purpose, list of data, and validity period, plus a checkbox with linked consent text. Fines are identical to those for missing cookie banners.

Violation 4: Publishing Reviews Without Distribution Consent

Publishing reviews containing personal data without separate consent for dissemination violates Article 10.1. Consent must follow the form approved by Order No. 18, and the privacy policy must disclose processing conditions and any prohibitions set by the data subject.

Violation 5: Missing or Non-Compliant Privacy Policy

Every operator must publish a privacy policy in the site footer and under every data collection form, detailing categories of data, purposes, retention periods, destruction procedures, and third-party recipients per Part 2 of Article 18.1. Fines range from 1,500–3,000 rubles for citizens to 30,000–60,000 rubles for legal entities.

Violation 6: No Notification or Outdated Notification to Roskomnadzor

Operators must notify Roskomnadzor before processing personal data and keep the notification current using the form from Order No. 180 of 28 October 2022. Fines reach 100,000–300,000 rubles for legal entities.

Violation 7: Transferring Employee Data Without Separate Written Consent

Employers may not disclose employee personal data to third parties without written consent for each specific purpose, as required by Article 88 of the Labor Code and Part 4 of Article 9. Fines range from 100,000–300,000 rubles for individual entrepreneurs and 300,000–700,000 rubles for legal entities.

Violation 8: No Data Processing Agreement with Third Parties

When personal data are entrusted to third parties (mailing services, etc.), a separate agreement must list the data, operations, purposes, and confidentiality obligations per Part 3 of Article 6. Fines are the same as for missing cookie banners.

Violation 9: No Document on Paper Data Storage Locations

Operators must maintain a document specifying storage locations of paper-based personal data carriers and the list of persons with access, according to Government Resolution No. 687 of 15 September 2008. Fines range from 1,500–4,000 rubles for citizens to 50,000–100,000 rubles for legal entities.

Violation 10: Failure to Respond to Data Subject or Roskomnadzor Requests

Operators must respond within statutory deadlines under Article 21. Appointing a responsible person and maintaining clear internal instructions helps ensure timely replies. Fines range from 2,000–4,000 rubles for citizens to 50,000–90,000 rubles for legal entities.

A comprehensive audit followed by development and implementation of all required documents remains the most reliable way to eliminate these risks and protect profits in 2026.

Related articles

HabrPolicy & Regulation

Alfa-Bank Balances Cloud Trust and Zero Trust Models During Migration to Yandex Cloud

Alfa-Bank's head of container and cloud security, Sasha Chertok, detailed how the bank migrated regulated workloads to Yandex Cloud while preserving existing Zero Trust controls. The organization mapped on-premises network segmentation, Active Directory authentication, and firewall policies directly onto Yandex Cloud resources using interconnect links secured with GOST encryption. Responsibility for managed services is shared under a Cloud Trust model, yet the bank retains oversight through Terraform-managed Security Groups, custom CSPM checks, and internal CI/CD gates. User access continues to authenticate via on-premises Active Directory and KeyCloak federations, while authorization leverages granular Yandex Cloud IAM roles. Logging and detection rely on a combination of Yandex Cloud Audit Trail, Cloud Logging, and the YCDR service to compensate for incomplete control-plane visibility. The resulting hybrid architecture now supports 1,500 virtual machines, 100 managed services, and 1,000 identities across multiple environments without disrupting established security processes.

HabrPolicy & Regulation

EnvSpec Naming Standard Introduces Strict Six-Environment Hierarchy for Zero Trust Infrastructure

The EnvSpec Naming 1.0.0 standard proposes replacing ad-hoc hostnames with a strict hierarchical naming system based on environment, perimeter, system, slot and node. It defines exactly six environments—dev, test, stage, prod, infrastructure and workplace—and treats any test or pilot system processing real data as prod. The model projects names into SPIFFE IDs, Kubernetes namespaces, cloud projects and mandatory tags for automated policy enforcement. Rules prohibit direct communication between different linear environments and require all access from workplace devices through dedicated gateways. The standard is published under CC BY-SA 4.0 and includes machine-checkable criteria for compliance.

AntiMalwarePolicy & Regulation

Russian Woman Fined 30,000 Rubles and Loses iPhone 11 for Posting AI-Generated Bear Photo

A resident of Duldurga village in Zabaykalsky Krai was fined 30,000 rubles under part 9 of article 13.15 of the Russian Code of Administrative Offenses for publishing an AI-generated image of a bear presented as authentic. The court also ordered confiscation of her iPhone 11 as the instrument of the administrative violation. The woman knew the photograph was fake before posting it, yet the image spread widely online and was even shared by a local Ministry of Natural Resources channel on 10 September. Local authorities used the case to warn residents that publishing neural-network-generated fake images carries real legal consequences. The incident highlights ongoing enforcement of Russian legislation against the distribution of knowingly false socially significant information under the guise of credible reports. Meanwhile, wildlife specialists continue to investigate separate reports of actual bears near populated areas in the region.

HabrPolicy & Regulation

Inserting Contracts into ChatGPT Risks Major Fines Under Russia's 152-FZ Personal Data Law

A detailed analysis examines the legal consequences of uploading contracts containing personal data into foreign AI services such as ChatGPT under Russian Federal Law 152-FZ. The article clarifies that even standard supply agreements include names, positions, passport details, INN numbers, phones and emails that qualify as personal data. It breaks down applicable administrative penalties from Article 13.11 of the Code of Administrative Offenses, including 150-300 thousand rubles for processing without a proper legal basis and separate fines for failing to notify Roskomnadzor. Cross-border transfer rules under Article 12 require a dedicated notification to the regulator before sending data to services hosted in the United States or European Union. The piece also reviews recent court practice, including a Moscow district court ruling that treated uploading commercial information to DeepSeek as disclosure of trade secrets. No criminal liability under Article 272.1 of the Criminal Code applies to ordinary business use, yet the absence of a data processing agreement with OpenAI or similar providers creates ongoing compliance exposure.