Costly Mistakes: How Russian Businesses Risk Millions in Fines for Personal Data Violations
A year after new fines for personal data protection violations came into force in Russia, many entrepreneurs still risk multimillion-ruble penalties from Roskomnadzor. The most frequent breaches involve improper collection, storage, and processing of personal data of Russian citizens.
Violation 1: Using Google Forms
Despite repeated warnings at conferences and webinars, businesses continue to use Google Forms. All personal data must be recorded, systematized, accumulated, stored, and processed using databases located on Russian territory under Part 5 of Article 18 of the Law on Personal Data. Googleβs servers are located outside Russia, violating localization requirements. Recommended fix: replace with domestic alternatives such as Yandex Forms. Fines range from 30,000β50,000 rubles for citizens and 1β6 million rubles for individual entrepreneurs and legal entities under Part 8 of Article 13.11 of the Code of Administrative Offenses.
Violation 2: Missing Cookie Banner
If a website uses cookies without displaying a proper banner, it violates the law because cookies qualify as personal data. The recommended banner text informs users about cookie usage for analytics and links to the privacy policy. Fines start at 10,000β15,000 rubles for citizens and reach 150,000β300,000 rubles for legal entities.
Violation 3: No Consent Under Data Collection Forms
Many sites lack valid consent for processing personal data or link only to a privacy policy instead. Consent must meet requirements of Article 9, including specific purpose, list of data, and validity period, plus a checkbox with linked consent text. Fines are identical to those for missing cookie banners.
Violation 4: Publishing Reviews Without Distribution Consent
Publishing reviews containing personal data without separate consent for dissemination violates Article 10.1. Consent must follow the form approved by Order No. 18, and the privacy policy must disclose processing conditions and any prohibitions set by the data subject.
Violation 5: Missing or Non-Compliant Privacy Policy
Every operator must publish a privacy policy in the site footer and under every data collection form, detailing categories of data, purposes, retention periods, destruction procedures, and third-party recipients per Part 2 of Article 18.1. Fines range from 1,500β3,000 rubles for citizens to 30,000β60,000 rubles for legal entities.
Violation 6: No Notification or Outdated Notification to Roskomnadzor
Operators must notify Roskomnadzor before processing personal data and keep the notification current using the form from Order No. 180 of 28 October 2022. Fines reach 100,000β300,000 rubles for legal entities.
Violation 7: Transferring Employee Data Without Separate Written Consent
Employers may not disclose employee personal data to third parties without written consent for each specific purpose, as required by Article 88 of the Labor Code and Part 4 of Article 9. Fines range from 100,000β300,000 rubles for individual entrepreneurs and 300,000β700,000 rubles for legal entities.
Violation 8: No Data Processing Agreement with Third Parties
When personal data are entrusted to third parties (mailing services, etc.), a separate agreement must list the data, operations, purposes, and confidentiality obligations per Part 3 of Article 6. Fines are the same as for missing cookie banners.
Violation 9: No Document on Paper Data Storage Locations
Operators must maintain a document specifying storage locations of paper-based personal data carriers and the list of persons with access, according to Government Resolution No. 687 of 15 September 2008. Fines range from 1,500β4,000 rubles for citizens to 50,000β100,000 rubles for legal entities.
Violation 10: Failure to Respond to Data Subject or Roskomnadzor Requests
Operators must respond within statutory deadlines under Article 21. Appointing a responsible person and maintaining clear internal instructions helps ensure timely replies. Fines range from 2,000β4,000 rubles for citizens to 50,000β90,000 rubles for legal entities.
A comprehensive audit followed by development and implementation of all required documents remains the most reliable way to eliminate these risks and protect profits in 2026.
Related articles
Rethinking SSO: Centralized User Data Provision and Authorization Processing in Corporate Systems
The article examines Single Sign-On systems not merely as authentication gateways but as architectural hubs for delivering user attributes and executing additional authorization logic. It highlights how SSO can aggregate data from sources like Active Directory, HR systems, and IDM platforms, then deliver it via OIDC claims to downstream applications. The discussion covers the shift from fragmented integrations across dozens of apps to a single trusted enforcement point using standards such as aggregated and distributed claims. It also explores the authorization pipeline where SSO acts as a Policy Enforcement Point querying external Policy Decision Points via the AuthZEN Authorization API 1.0. Practical examples include electronic business cards, role assignment, access routing, and mandatory MFA checks before token issuance. The piece stresses maintaining data ownership with source systems while establishing SSO as the single point of trust for applications.
Bitrix24 Releases Fully On-Premise BI Constructor for Regulated Enterprises
Bitrix24 has introduced a new delivery model for its BI Constructor that allows complete deployment inside a customer's own infrastructure. The update eliminates any requirement for external servers, cloud APIs, or internet connectivity, ensuring that all corporate data remains within the organization's closed perimeter. Previously, even the boxed version of the platform needed access to external infrastructure for updates and auxiliary services, creating conflicts with internal security policies and regulatory demands in highly regulated sectors. The new on-premise variant performs all data processing and storage exclusively on customer servers, giving organizations full control over access rights, backups, updates, and integration with internal protection tools. The solution is compatible with the boxed edition of Bitrix24 running on PostgreSQL and does not connect to external CDNs or cloud services. Bitrix24 expects strong interest from large enterprises and organizations handling restricted-access data that must stay inside the corporate network. Pilot implementations have already been completed, with broader customer pilots planned in the coming months.
Russia's Data Leak Penalties: 2.6 Million Rubles in Fines Despite 1.58 Billion Records Exposed in 2025
Russia introduced turnover-based fines for personal data leaks through Federal Law 420-FZ in late 2024, fundamentally altering the economics of information security investments. Over the first 18 months, Roskomnadzor opened 52 administrative investigations and issued 40 protocols totaling just 2.6 million rubles in penalties, with zero turnover fines applied. This occurred against a backdrop of 1.58 billion compromised records in 2025 alone. Public data leaks dropped fourfold in the first half of 2026, yet trading activity on underground forums rose nearly 60 percent as operators shifted to private sales. The law now ties penalties directly to the number of affected individuals and adds a turnover component for repeat violations under Article 13.11 of the Code of Administrative Offenses. Analysts note that the mere threat of larger fines has prompted companies to reassess data retention policies and risk models even without actual enforcement precedents.
Russia Authorizes Temporary State Takeover of Unprotected Critical Infrastructure
President Vladimir Putin has signed a decree that empowers the Russian government to appoint temporary managers for critical infrastructure facilities whose owners have failed to ensure adequate security. The measure directly targets operators of objects classified as critical infrastructure who have not met protection requirements. Under the new rules, the state can intervene by installing an interim administrator to oversee operations until security standards are satisfied. This approach aims to prevent potential disruptions or threats arising from insufficiently defended assets. The decree provides a legal mechanism for rapid governmental response without permanent nationalization of the facilities. It reflects ongoing efforts to strengthen oversight of sectors deemed essential to national security and stability.