In short: Russia's turnover fines for repeated personal data breaches have been in force since May 2025 — but on August 14, 2026, Roskomnadzor Deputy Head Milosh Wagner confirmed publicly that not a single company has been hit with the toughest penalty. Here is what this enforcement gap means for your privacy.
What Roskomnadzor actually said
Speaking at Roskomnadzor's open-day event on August 14, 2026, Wagner disclosed the figures for the period since January 2025: 52 administrative investigations, 5 unscheduled inspections, and 40 protocols drawn up under Article 13.11 of Russia's Code of Administrative Offences. Total fines collected: 2.6 million rubles. This covers the standard data-processing violation provisions, which carry a maximum of 15 million rubles for a first incident.
Part 15 of the same article — which took effect May 30, 2025 — is an entirely different instrument: a turnover fine of 1 to 3% of annual revenue for a repeated breach. For biometric data leaks the ceiling reaches 500 million rubles. Wagner stated plainly that no protocols had been issued under this provision. The official explanation: no repeated breaches have been detected in this period.
The statement was made in public and reported by Vedomosti and Interfax, two of Russia's most authoritative business publications. It has nonetheless prompted scepticism among cybersecurity professionals.
What a turnover fine is and why it was introduced
Before the 2024–2025 reform, liability for Russian data operators was negligible. Maximum penalties amounted to a few hundred thousand rubles — a figure large companies simply absorbed as an operating cost. The resulting incentive structure was inverted: paying a fine after a breach was cheaper than investing in protection before one.
The reform was designed to break that logic. When 1–3% of a major Russian bank's or retailer's annual revenue translates to hundreds of millions or billions of rubles, the business case for robust data security becomes self-evident. The introduction of turnover fines was therefore widely described as a structural shift in Russia's regulatory approach, not a cosmetic legislative fix.
A structural shift on paper, however, is not the same thing as enforcement in practice.
Why the absence of fines raises legitimate questions
The claim that no repeated breaches occurred is difficult to accept at face value given the documented incident record for 2025–2026. Russian cybersecurity publications and Tier-1 media reported compromises affecting banking ecosystems, healthcare platforms, logistics operators, and marketplaces throughout this period. None resulted in a turnover fine.
Information security professionals cite several structural reasons why the mechanism has not been activated:
- A narrow definition of “repeated.” The law requires that a company has already received a fine for a comparable violation before the repeat provision can trigger. This means a first case must be fully concluded before the repeat clock starts — and administrative proceedings in Russia routinely span many months.
- Attribution complexity. Proving that a breach occurred within the company itself — rather than at a contractor, sub-processor, or third-party partner — is legally demanding.
- Undisclosed incidents. A significant share of breaches never become the subject of a formal investigation: data surfaces in dark-web markets without a confirmed source and without complaints from affected individuals.
Wagner characterised the outcome as a success, noting that expert concerns about “terrible financial consequences for business” had not materialised. That is accurate — but it is an observation about an enforcement mechanism that has not yet fired, not evidence that Russian user data is in safe hands.
For a broader picture of the current threat landscape, see our security coverage in the LiMP VPN blog.
What this means for your personal data
The practical takeaway is straightforward: data you share with services is still protected primarily by each company's own technical culture and internal priorities — not by the credible threat of a catastrophic fine. Turnover sanctions exist as a deterrent on paper, but there is no precedent to make that deterrent real in a risk manager's calculations.
This is not a permanent state. As the first cases under the basic statute reach conclusion and companies accumulate a formal violation history, the conditions for triggering turnover fines will gradually fall into place. But that remains a prospect, not a present reality.
For ordinary users, the implication is clear: you cannot fully outsource responsibility for your data to a regulator. Government enforcement operates at a systemic level — slowly, and through precedent. Personal data hygiene operates at an individual level — quickly, and under your own control.
Practical steps you can take right now
While turnover fine enforcement develops, you can meaningfully reduce your personal exposure with a handful of concrete actions:
- Minimise your footprint. Complete only mandatory fields when registering. Do not grant permissions a service does not need for its core function. Less stored data means less potential exposure when a breach occurs.
- Compartmentalise registrations. A dedicated email address and a secondary phone number for non-critical services prevent the compromise of one account from reaching your primary identity.
- Monitor for breaches. Services such as HaveIBeenPwned.com notify you when your email appears in known breach datasets. Early alerts give you time to rotate credentials before damage escalates.
- Enable two-factor authentication everywhere possible. A stolen password is nearly useless to an attacker who also needs a one-time code from a device you physically hold.
- Encrypt your traffic on public networks. If your data has already been exposed in a third-party breach, there is no reason to add the risk of traffic interception on an open Wi-Fi connection. A VPN encrypts everything your device sends and receives, making it opaque to eavesdroppers. See how this works on our LiMP VPN features page.
Plans from 69 ₽/month with a verified no-logs policy: LiMP VPN pricing.
