Until 2025 Russian data penalties were a documentary irritation. Since 30 May they reach a percentage of annual revenue, which changes who inside the company cares about the answer.
Turnover-based fines for repeat leaks, a separate penalty for never notifying the regulator, and higher penalties for special categories and biometrics.
Get on the register, have a processing policy that reflects reality, and know where Russian personal data physically sits.
Until 2025, Russian personal data enforcement was something most foreign companies could treat as a documentary irritation. Fines were fixed, modest, and rarely changed anyone's behaviour.
Amendments in force from 30 May 2025 changed the arithmetic. The headline is turnover-based fines for leaks, but the more significant shift for a well-run company is the number of separate violations now capable of attracting their own penalty.
Three things matter for a foreign business operating in Russia.
Leaks moved to a graded scale, with penalties set by the volume of data affected — and for repeat incidents at larger companies, turnover-based fines reaching up to 3% of annual revenue
Failing to notify the regulator of an intention to process personal data became its own violation, carrying 100,000–300,000 roubles for a legal entity
Failing to report a leak within the deadline carries 1–3 million roubles in its own right, separately from whatever caused the incident
Special categories of data — health, religion, nationality, criminal record — and biometric data attract higher penalties than ordinary personal data
For a group with meaningful Russian revenue, the theoretical maximum on a serious repeat leak is now a number that appears on a board agenda rather than in a compliance report.
In our experience the expensive findings are rarely the dramatic ones. They cluster in three places.
The missing notification. Many foreign companies process Russian employee data for years without ever having told Roskomnadzor they were doing so. Since 2025 that omission is separately punishable, and it is trivially easy for a regulator to establish — either you are on the register or you are not.
The absent policy document. The law expects an operator to have an internal policy on processing personal data. Its absence carries penalties across every category of respondent, and it is the first document asked for in any interaction with the regulator.
The late breach notification. Covered separately, but worth repeating here: missing the 24-hour deadline is a violation in its own right, stacked on top of whatever caused the incident.
Most gaps fall into three places — pick the one that sounds familiar:
A fixed fine is a cost of doing business. A percentage of revenue is a different category of risk, and it changes who inside a company cares about the answer.
The practical consequence for foreign groups is that Russian data compliance has moved from a local administrative matter to something a parent company's risk function will ask about. That shift is worth getting ahead of: the documentation that satisfies a Russian inspection is also what a group audit will want to see.
Most of what helps is unglamorous and cheap relative to the penalties.
Being on the Roskomnadzor register, and keeping the entry accurate as processing changes
An internal processing policy that exists, is in Russian, and reflects what you actually do
Documented consents where consent is the basis you rely on
Knowing where Russian personal data physically sits, including with processors
A tested breach notification route with someone authorised to use it
None of this requires a large programme. What it requires is that the documents exist before anyone asks for them — which is the recurring theme of Russian compliance generally, and the reason most findings are documentary rather than substantive.
Penalty ranges in this area have moved repeatedly, and the graded structure means a headline figure rarely describes any particular company's exposure. Anyone planning around specific amounts should have them confirmed against the current text rather than relying on a summary — including this one.
The obligations apply to operators processing personal data of individuals in Russia. Whether a penalty can practically be enforced against an entity with no Russian presence is a different question from whether the violation exists — and groups with a Russian subsidiary, branch or employees have a very direct exposure through those.
Registering is generally better than continuing not to, and the omission is easier to address before it is found than after. The sequencing matters though — the register entry describes what you process, so it is worth being clear about your actual data flows before filing rather than discovering discrepancies later.
Yes. Employment records are personal data, and an employer is an operator. Foreign companies that assume the regime is about consumer-facing businesses are among the more commonly caught, precisely because they never considered themselves in scope.
Not automatically. Court practice shows outcomes varying with the operator's conduct — prompt notification, absence of prior violations and absence of demonstrated harm have all supported warnings rather than fines. What is consistent is that doing nothing, or notifying late, removes those arguments.
The penalties are only alarming if the basics are missing — and for most foreign companies one or two of them are. Being on the register, having a policy that reflects reality, and knowing where Russian data actually sits closes most of the exposure at modest cost.
Penalty ranges in this area moved repeatedly through 2025 — anything you plan around should be confirmed against the current text.
Practical support for international business in Russia.