No repeated data leaks since Jan 2025, Roskomnadzor says
On May 30, 2025, new compositions of administrative violations came into force, as well as significantly higher fines for violations in the sphere of personal data turnover, including turnover fines for repeated data leaks.
Consensus
- Roskomnadzor has not detected any repeated personal data leaks since January 1, 2025.
- Since January 2025, 52 administrative investigations have been conducted by Roskomnadzor.
- 40 administrative violation protocols were issued by Roskomnadzor.
- A total of 2.6 million rubles in fines were imposed on companies.
- Roskomnadzor conducted 159,000 website checks and identified violations on 135,000 sites.
- The supervisory system for personal data violations detected violations in 90% of cases.
- The introduction of stricter penalties has motivated businesses to improve data protection.
Points of divergence
- No protocols were issued under Part 15 of Article 13.11 of the KоАП РФ, as the turnover-based fines mechanism was not applied. — interfax
- Five unplanned inspections were conducted because the operator did not confirm the data leak despite a compromised database. — interfax
- Roskomnadzor stated it uses its new powers very carefully and only in exceptional cases involving personal data leaks. — interfax
- The information campaign around the new law caused fear of ruinous fines, but these fears were proven to be unfounded. — interfax
Coverage (2 sources)
- RKN did not identify any repeated leak of personal data since the beginning of 2025 — Коммерсантъ
- RKN did not record repeated leaks of personal data since the beginning of 2025 — Интерфакс