Russian law gives you 24 hours to tell the regulator about a data breach — and the clock starts when you discover it, not when you finish investigating.
An initial notification to Roskomnadzor describing what happened and what you have done about it. The clock runs from discovery.
A follow-up report with the results of your investigation — causes, scope and the measures taken.
Most foreign companies discover Russia's breach notification regime at the worst possible moment: the day something has already gone wrong. By then the clock has started, and it is a short one.
The obligation applies to any operator of personal data — which, if you employ anyone in Russia or serve Russian customers, includes you. It is not limited to technology companies or to large databases, and there is no threshold below which an incident stops being reportable.
Russian law sets two separate reporting steps, and missing either is its own violation.
Within 24 hours of discovering the incident: an initial notification to Roskomnadzor describing what happened and what has been done about it
Within 72 hours: a follow-up notification setting out the results of your internal investigation — causes, scope, and the measures taken to contain it
The 24 hours run from discovery, not from the breach itself. In practice that means the clock often starts when a support engineer notices something odd on a Friday evening, and the notification is due before Monday. Companies that have not thought about this in advance lose most of the first day deciding who is allowed to make the decision.
The definition is broader than a hacked database. It covers unlawful or accidental transfer, disclosure, distribution of or access to personal data where the rights of the individuals concerned are affected.
That reaches situations foreign teams do not always think of as incidents: an employee spreadsheet emailed to the wrong recipient, a misconfigured storage bucket, a departing employee taking client contacts, a vendor with access to your data suffering their own breach. If personal data of people in Russia has ended up somewhere it should not be, the question is whether to notify, not whether it qualifies as an attack.
There is a practical argument for prompt notification beyond simple compliance, and Russian court practice illustrates it.
Pick what applies — we will tell you what has to go out today:
In a 2026 case, a company whose employee and applicant records were stolen by attackers faced proceedings that could have carried a substantial fine. It received a warning instead. The court took into account that the company had notified within 24 hours, that it was a first offence, and that no harm to life, health or property had resulted.
The pattern is worth understanding: the notification itself is not an admission that attracts punishment. Late or absent notification, on the other hand, is a separate violation on top of whatever else happened — and it removes the mitigation that early reporting provides.
The 24-hour window is too short to design a process inside. What makes the difference is what exists beforehand.
A named person authorised to decide that a notification goes out — without waiting for group headquarters in another time zone
The Roskomnadzor notification route already tested, not researched during the incident
A basic incident log so the 72-hour investigation report has something to draw on
Clarity on which systems hold personal data of people in Russia, and who your processors are
A translation path: the notification goes to a Russian regulator in Russian, and improvised translation costs hours you do not have
The last point catches out more foreign groups than any technical failing. A well-run security team can contain an incident quickly and still miss the deadline because nobody could produce a Russian-language filing in time.
A breach affecting Russian personal data rarely stays a Russian problem. If the same incident touches EU or UK data subjects, parallel notification duties run on their own timetables — and those regimes ask questions about what you told other regulators.
Coordinating the two is a drafting exercise as much as a legal one: statements made quickly to one authority are read later by another. It is worth having someone look at the Russian filing who understands what else is being said elsewhere.
If you process personal data of individuals in Russia, the law treats you as an operator regardless of where you are incorporated. Enforcement against a foreign company without local presence is a separate practical question, but the obligation exists — and it becomes very real if you have a Russian subsidiary, employees or a local partner through which the regulator can act.
Being the operator is about whose data it is and who determines the purposes of processing, not about whose servers failed. If a processor you engaged suffers the incident, the notification duty generally still sits with you — which is why processor contracts should require immediate notice to you, on a timescale that leaves you room inside the 24 hours.
This is the most common reason companies miss the deadline — waiting for certainty that will not arrive in a day. The initial notification is meant to describe what is known at the time; the 72-hour report is where the investigated picture goes. Reporting on incomplete information is the intended design, not a failure of it.
The evidence points the other way. Prompt notification is treated as mitigation, and court practice shows fines replaced with warnings where a company reported within 24 hours, had no prior violations and no harm resulted. Failing to notify is a distinct violation that adds to the original one.
Knowing the deadline is one thing; making it at two in the morning with headquarters asleep in another time zone is another. What decides the outcome is what exists before the incident — an authorised decision-maker, a tested filing route, and someone who can write to a Russian regulator in Russian at short notice.
If an incident is live right now, the clock started at discovery — tell us what you know and we will file on what you have.
Practical support for international business in Russia.