As of May 30, 2025, amendments introduced by Law No. 420-FZ of 30.11.2024 apply to Article 13.11 of the Administrative Offenses Code. The fine for a breach depends on the number of affected data subjects, and a repeat violation turns the fine into a turnover-based penalty: 1% to 3% of annual revenue, but not less than RUB 20 million and not more than RUB 500 million (Part 15 of Article 13.11). Unlawful transfer of biometric personal data costs a legal entity from RUB 15 million to RUB 20 million (Part 17 of Article 13.11).
For business, this changes not the budget line, but the owner of the task. While the fine was fixed and moderate, the risk was handled legally - with documents and procedures. A revenue-based fine is tied to turnover, so it cannot be reserved for in advance, which means the question shifts to those responsible for architecture: where the data is physically stored, who has access to it, and what remains in the log if access falls into the wrong hands.
The deadlines reinforce the same shift. Roskomnadzor must be notified of an incident within 24 hours, and the results of the internal investigation must be reported within 72 hours. Reconstructing within a day what exactly was lost is only possible from a preconfigured log. If there is no log, the company gets a second violation on top of the first, this time for silence.