Personal data breach fines in Russia: what companies face and how to reduce the risk
Since 2025 a personal data breach in Russia is not a reputational nuisance but a direct financial risk: turnover-based fines are tied to company revenue. Meanwhile most fines actually issued are not for breaches but for procedural violations that take weeks to fix. Here is what companies face and in what order to reduce the risk.
What a breach costs
- ◇First major breach: fixed fines growing with volume — up to 15M RUB depending on the number of data subjects and data categories.
- ◇Repeat breach: a turnover-based fine — up to 3% of annual revenue, ranging from 20M to 500M RUB. This is the clause that moved security from an IT expense line into a CEO-level conversation.
- ◇Breach of special categories (health, biometrics) is an aggravating factor: higher fines, closer inspection.
- ◇Concealing an incident: the operator must notify the regulator (RKN) within 24 hours of discovering a breach, and report the internal investigation results within 72. Silence is a separate violation that turns the incident into a losing position.
What actually gets fined most often (not breaches)
A breach is a rare event; procedural violations are found in almost every inspection:
- ◇No processing notification filed with RKN — a baseline requirement a notable share of SMBs forget.
- ◇No proper consents: the website form collects data without a checkbox, consent is buried in the offer, no consent per specific purpose (marketing ≠ contract fulfilment).
- ◇The processing policy is not published or does not match real processes.
- ◇No data-processing agreements with contractors: CRM, mailing service, cloud, call center — every processor needs one.
- ◇Cross-border transfer without notification: data in foreign services (analytics, hosting, SaaS) is already cross-border and requires a separate notification.
How companies end up inspected
Three typical scenarios. A data subject complaint: an unhappy customer or ex-employee writes to RKN — the most frequent trigger of an unscheduled inspection. An incident: the data surfaces publicly or on the dark web, and the regulator arrives with the fact in hand. A counterparty requirement: enterprise customers and banks increasingly request confirmed 152-FZ compliance before signing — not a fine, but a lost deal.
An important 2025–2026 shift: RKN actively monitors breach publications and comes on its own, without waiting for complaints. "We're too small to notice" no longer works.
What to do: the order of actions before an incident
- ◇Start with an assessment: a personal data map — what data, in which systems, who has access, which contractors receive it. Without the map, any documents are a formality.
- ◇Close the procedural minimum: RKN notification, per-purpose consents, policy, processor agreements. This is cheap and removes the most probable fines.
- ◇Evaluate technical protection for your required protection level: access control, encryption, logging, backups — per FSTEC requirements.
- ◇Prepare an incident response plan: who notifies RKN within 24 hours, who runs the investigation, who communicates with data subjects. During a breach it is too late to figure this out.
- ◇Verify real security with a pentest: compliance documents describe processes, but breaches are caused by holes in the perimeter or the web application, not by missing paperwork.
FAQ
A personal data processing map, a 152-FZ compliance checklist and a prioritized remediation plan. From $2,200, the price is fixed before work starts.
Get a quote in 24 hours