On August 14, 2026, the Federal Service for Supervision of Communications, Information Technology, and Mass Media (Roskomnadzor, hereinafter “RKN”) held an "Open Day" event on personal data — an annual event organized by the agency dedicated to providing up-to-date information on control and supervisory activities, analyzing typical violations by PD operators, updates to Law No. 152-FZ, and the work of the Center for Legal Assistance to Citizens in the Digital Environment, established under the Federal State Unitary Enterprise “Main Radio Frequency Center” (GRCC).
Statistics on the Results of Inspections for 2025–2026
The RKN conducted 9,397 inspections without interaction with the entities subject to inspection. As part of website monitoring, 159,111 inspections of internet resources were inspected, of which 135,953 revealed violations. The proportion of violations of personal data protection legislation among the inspected resources was 86%. The number of websites inspected doubled compared to the previous period.
The main sources of information on personal data protection violations:
-
reports from citizens;
-
monitoring (supervisory) activities (website inspections and analysis);
-
preventive measures.
The most common violations include: unlawful processing of personal data, excessive processing of personal data (data volume, processing periods), non-compliance of the document defining the personal data processing policy with legal requirements, actual activities, and the information in the personal data processing notice.
Data Breaches and Statistics for 2025–2026
In response to identified personal data breaches, 52 administrative investigations and 5 unscheduled inspections were conducted. The latter were carried out in where operator’s databases had been compromised but the operator had no confirmed the breach. Fines totaling 2.6 million rubles were imposed, 19 warnings were issued, and 40 administrative reports were drawn up under various provisions of Article 13.11 of the Code of the Russian Federation on Administrative Offenses No. 195-FZ dated December 30, 2001 (hereinafter referred to as the Code of Administrative Offenses of the Russian Federation) “Violation of the legislation of the Russian Federation in the field of personal data”—depending on the scale of the breach (involving 1,000 or more data subjects, as well as special categories of personal data).
M. E. Wagner, Deputy Head of the RKN, emphasized that the amount of fines imposed is not an indicator of the agency’s effectiveness; rather, the priority is to bring operators’ activities into compliance with legal requirements and to ensure respect for the rights of data subjects.
Preventive visits: violations were identified during 711 mandatory visits to 115 operators; 89 were ordered to rectify the violations within the specified timeframe. Operators also initiated 17 additional visits, following which they received recommendations.
Sources of information on violations: complaints from citizens, monitoring, and preventive measures. Most frequently, the RKN records the following violations: unlawful processing of personal data, excessive processing (in terms of data volume and processing duration), and discrepancies between the personal data processing policy and actual operations or the notification filed with the operator registry.
Amendment on Cross-Border Transfer of Personal Data (CBTPD)
Federal Law No. 265-FZ of July 26, 2026, “On Amending Article 12 of the Federal Law ‘On Personal Data’ and Certain Legislative Acts of the Russian Federation” (hereinafter, “Federal Law No. 265-FZ”) amended Article 12 of Federal Law No. 152-FZ, which governs the cross-border transfer of personal data (CBT)—that is, the transfer of personal data to the territory of a foreign state, to a foreign government authority, foreign individual, or foreign legal entity.
- The procedure for cross-border transfers remains unchanged; there is no requirement to resubmit notifications on such transfers;
-
The list of “adequate” foreign countries is now prepared based on international criteria (including the existence of an authorized body, national data protection legislation, and a system of sanctions) and approved by an order of the Federal Service for Supervision of Communications, Information Technology, and Mass Media (Roskomnadzor).
For reference: under the new version, the list of countries providing “adequate” protection of personal data includes states whose legal framework governing personal data and the measures applied to ensure compliance with the principles of personal data protection, confidentiality, and security correspond to the provisions of the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (ETS No. 108, Strasbourg, January 28, 1981)—regardless of whether the state is formally a party to it.
Case Studies from the Center for Legal Assistance to Citizens in the Digital Environment (GRChC)
Statistics on inquiries received by the Center for Legal Assistance to Citizens in the Digital Environment were presented, indicating that more than 70% of all inquiries are related to digital fraud (including the processing of personal data without the data subject’s knowledge or consent, as well as complaints about unsolicited mailings and advertising).
The Center’s recommendations: widespread errors in user identification by online platforms create opportunities for fraudsters to operate through remote services. The RKN proposes improving identity verification methods and implementing anti-fraud systems beyond the financial sector. It also recommends that businesses carefully vet their counterparties, avoid questionable projects, and strictly comply with data protection legislation.
Roskomnadzor's Answers to Practical Questions from Personal Data Operators
During the "Open Day", Roskomnadzor representatives provided detailed answers to the most pressing and complex questions faced by personal data operators. The questions covered nuances of applying Federal Law No. 152‑FZ, notification procedures, interaction with the regulator, risk assessment, and many other practical aspects.
We have compiled all these answers into a separate PDF file.
Download it to review Roskomnadzor's position on difficult situations — this will help you build robust compliance and avoid common mistakes.
***
This review was prepared by the lawyers of Lidings' Data Protection & Technology practice. If you have any questions regarding the application of personal data legislation or would like individual advice, we would be happy to assist.