International tax, legal & operational advisory · Moscow · Dubai
EN中文TR Telegram Client login
taxwell.
Your situation
Expertise +
Tax & compliance

CIT, VAT and withholding tax — filed right, and defended when the FTS asks.

  • CIT 25%
  • Treaties suspended
  • Audit defence
Full service →
Company registration

LLC, branch or representative office — registered and operational.

  • LLC in 3–5 days
  • Operational in 6–8 wks
  • 100% foreign-owned
Full service →
Transfer pricing

TP documentation, benchmarking and FTS audit defence.

  • Local file
  • Benchmarking
  • TP notification
Full service →
Legal & corporate

Corporate, commercial and regulatory legal support.

  • Contracts
  • Regulatory
  • Disputes
Full service →
VAT compliance

Russian VAT for foreign companies — registration, returns and digital services.

  • VAT 22%
  • Digital services
  • Reverse charge
Full service →
Payroll & HR

Monthly payroll, NDFL and contributions — run properly, reported in English.

  • +30% employer cost
  • HQS exempt
  • Paid twice monthly
Full service →
Employment law

Contracts, dismissals, inspections and labour disputes.

  • Not at-will
  • Documentary compliance
  • Dismissal procedure
Full service →
NDFL agent duties

Foreign employers paying for work done through Russian systems.

  • In force since 2025
  • Register before first payment
  • Five-band scale
Full service →
Accounting (RAS)

RAS bookkeeping, statutory reporting and the numbers head office can use.

  • Dividends = RAS profit
  • 1C statutory
  • IFRS recon
Full service →
Immigration · HQS

HQS work permits and mobility for foreign executives.

  • HQS permits
  • Work visas
  • Registration
Full service →
Customs

Classification, customs value and clearance for foreign importers.

  • Duty 5–15%
  • Import VAT 22%
  • Related-party value
Full service →
Personal data · 152-FZ

Roskomnadzor registration, localisation and the 24-hour breach rule.

  • Register or be fined
  • Localisation architecture
  • 24h incident rule
Full service →
Exit & liquidation

Winding down, selling or restructuring a Russian entity.

  • Sub-Commission approval
  • Tax audit on liquidation
  • Getting the cash out
Full service →
Russian real estate

Buying, holding, letting and selling property — individuals and companies.

  • Property tax annually
  • Exempt after holding period
  • Currency control on exit
Full service →
For individuals personal tax · residency · CFC
Customers Book a call
Insights / Market entry & registration
Market entry · 6 min

Reporting a personal data breach in Russia: the 24-hour rule

Russian law gives you 24 hours to tell the regulator about a data breach — and the clock starts when you discover it, not when you finish investigating.

TW
TaxWell & Partners
Tax & legal advisers · reviewed for 2026 rules
Updated July 20266 min read
Within 24 hours

An initial notification to Roskomnadzor describing what happened and what you have done about it. The clock runs from discovery.

Within 72 hours

A follow-up report with the results of your investigation — causes, scope and the measures taken.

Most foreign companies discover Russia's breach notification regime at the worst possible moment: the day something has already gone wrong. By then the clock has started, and it is a short one.

The obligation applies to any operator of personal data — which, if you employ anyone in Russia or serve Russian customers, includes you. It is not limited to technology companies or to large databases, and there is no threshold below which an incident stops being reportable.

01

The two deadlines

Russian law sets two separate reporting steps, and missing either is its own violation.

Within 24 hours of discovering the incident: an initial notification to Roskomnadzor describing what happened and what has been done about it

Within 72 hours: a follow-up notification setting out the results of your internal investigation — causes, scope, and the measures taken to contain it

The 24 hours run from discovery, not from the breach itself. In practice that means the clock often starts when a support engineer notices something odd on a Friday evening, and the notification is due before Monday. Companies that have not thought about this in advance lose most of the first day deciding who is allowed to make the decision.

02

What counts as a breach

The definition is broader than a hacked database. It covers unlawful or accidental transfer, disclosure, distribution of or access to personal data where the rights of the individuals concerned are affected.

That reaches situations foreign teams do not always think of as incidents: an employee spreadsheet emailed to the wrong recipient, a misconfigured storage bucket, a departing employee taking client contacts, a vendor with access to your data suffering their own breach. If personal data of people in Russia has ended up somewhere it should not be, the question is whether to notify, not whether it qualifies as an attack.

03

Why the first 24 hours matter more than they look

There is a practical argument for prompt notification beyond simple compliance, and Russian court practice illustrates it.

Incident happening now?

Pick what applies — we will tell you what has to go out today:

We found a breach and have not notified yet →A vendor told us they were breached →We are not sure whether it qualifies →

In a 2026 case, a company whose employee and applicant records were stolen by attackers faced proceedings that could have carried a substantial fine. It received a warning instead. The court took into account that the company had notified within 24 hours, that it was a first offence, and that no harm to life, health or property had resulted.

The pattern is worth understanding: the notification itself is not an admission that attracts punishment. Late or absent notification, on the other hand, is a separate violation on top of whatever else happened — and it removes the mitigation that early reporting provides.

04

What a foreign company should have ready in advance

The 24-hour window is too short to design a process inside. What makes the difference is what exists beforehand.

A named person authorised to decide that a notification goes out — without waiting for group headquarters in another time zone

The Roskomnadzor notification route already tested, not researched during the incident

A basic incident log so the 72-hour investigation report has something to draw on

Clarity on which systems hold personal data of people in Russia, and who your processors are

A translation path: the notification goes to a Russian regulator in Russian, and improvised translation costs hours you do not have

The last point catches out more foreign groups than any technical failing. A well-run security team can contain an incident quickly and still miss the deadline because nobody could produce a Russian-language filing in time.

05

The relationship with your other obligations

A breach affecting Russian personal data rarely stays a Russian problem. If the same incident touches EU or UK data subjects, parallel notification duties run on their own timetables — and those regimes ask questions about what you told other regulators.

Coordinating the two is a drafting exercise as much as a legal one: statements made quickly to one authority are read later by another. It is worth having someone look at the Russian filing who understands what else is being said elsewhere.

Frequently asked questions
We are a foreign company with no Russian entity. Does this apply to us?

If you process personal data of individuals in Russia, the law treats you as an operator regardless of where you are incorporated. Enforcement against a foreign company without local presence is a separate practical question, but the obligation exists — and it becomes very real if you have a Russian subsidiary, employees or a local partner through which the regulator can act.

The breach happened at our vendor, not at us. Who notifies?

Being the operator is about whose data it is and who determines the purposes of processing, not about whose servers failed. If a processor you engaged suffers the incident, the notification duty generally still sits with you — which is why processor contracts should require immediate notice to you, on a timescale that leaves you room inside the 24 hours.

What if we are not sure yet whether personal data was actually taken?

This is the most common reason companies miss the deadline — waiting for certainty that will not arrive in a day. The initial notification is meant to describe what is known at the time; the 72-hour report is where the investigated picture goes. Reporting on incomplete information is the intended design, not a failure of it.

Does notifying make enforcement more likely?

The evidence points the other way. Prompt notification is treated as mitigation, and court practice shows fines replaced with warnings where a company reported within 24 hours, had no prior violations and no harm resulted. Failing to notify is a distinct violation that adds to the original one.

Related service: Company registration →
+ how we can help

Knowing the deadline is one thing; making it at two in the morning with headquarters asleep in another time zone is another. What decides the outcome is what exists before the incident — an authorised decision-maker, a tested filing route, and someone who can write to a Russian regulator in Russian at short notice.

Breach response, from hour one — We draft and file the 24-hour notification and the 72-hour investigation report, and handle the correspondence that follows.
Incident readiness — The decision authority, filing route and document templates put in place before you need them — usually a short exercise.
Processor contract review — Making sure your vendors have to tell you fast enough that your own 24 hours are still intact.

If an incident is live right now, the clock started at discovery — tell us what you know and we will file on what you have.

We have a live incident →Book a 30-min call
Or read how we handle Legal & corporate →
+ more in Market entry & registration
Market entry
Annual corporate obligations for a foreign-owned Russian company
Read
Market entry
When a Russian company can't just sign: major and interested-party transactions
Read
Market entry
Arbitration and dispute resolution in Russia for foreign companies
Read
Market entry
Changing the director and corporate changes in Russia: step-by-step
Read
Call WhatsApp Telegram Email
taxwell.

Practical support for international business in Russia.

Moscow · Dubai · St. Petersburg
Services
Tax & complianceVAT complianceTransfer pricingLegal & corporateAccounting (RAS)Payroll & HRImmigration · HQSCustomsCompany registration
Company
Expertise Customers Insights Tax rates 2026 Glossary Reporting calendar Cost of doing business Compare jurisdictions Buying a business About Contact
Market focus
China desk UAE Turkey Europe
Industries
IT & SaaS Trading & import/export Manufacturing E-commerce
Insights
3-NDFL tax return in Russia: complete guide for foreign individualsAccounting Outsourcing in Russia: PracticalAccounting in Russia: RAS rules and mandatory reporting for foreign companies All articles →
Contact
moscow@taxwellpartners.com
+7 (966) 976 96 27
WhatsApp Telegram LinkedIn
© 2026 TaxWell & Partners LLC · All rights reservedPrivacyTermsPersonal data