DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Unprecedented increase in liability for personal data leaks in the Russian Federation to take effect in May 2025

Posted on December 4, 2024 by Dissent Doe

Advant Beiten writes:

A law increasing administrative liability for personal data leaks was signed on 30 November 2024 (No. 420-FZ) (the “Law“). The Law will enter into force on 30 May 2025.

A new article of the Criminal Code of the Russian Federation also enters into force on 11 December 2024. It establishes liability for the illegal use and/or transfer, collection and/or storage of information on computers that contains personal data.

MAIN PARAMETERS OF THE ONSET OF THE NEW ADMINISTRATIVE LIABILITY FOR LEAKS:

  • Applicable not only in instances when personal data entered the public domain illegally, but also when they were transferred illegally to a limited number of persons;
  • Applicable only for the actions (inaction) of the data controller which led to the illegal transfer of the personal data. Consequently, liability is not established for the accidental transfer of personal data. At the same time, however, it is sometimes difficult to establish whether the transfer was illegal or accidental. For example, in instances when personal data were sent by mistake to another e-mail address, instead of the intended recipient;
  • Fines are differentiated depending on the amount of the “leaked” data and on the specific data categories that were transferred illegally, as well as on whether respective fines had been imposed previously;
  • As a general rule, administrative liability is not imposed on the general directors and other officials of private companies for personal data leaks (however, see the note *** in the table below);
  • We present in the table below the specific sizes of the fines for companies, depending on the actual circumstances and respective explanations:

See the chart and get additional information at Lexology.

Category: LegislationNon-U.S.Of Note

Post navigation

← Failure to terminate access can be costly. Very costly.
Trump FBI Pick Kash Patel’s Emails Accessed By Iranian Hackers: Report →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • AT&T gets preliminary approval for $177 million data breach settlement
  • Aflac notifies SEC of breach suspected to be work of Scattered Spider
  • Former JBLM soldier pleads guilty to attempting to share military secrets with China
  • No, the 16 billion credentials leak is not a new data breach — a wake-up call about fake news (Updated)
  • Tonga’s health system hit by cyberattack (1)
  • Russia Expert Falls Prey to Elite Hackers Disguised as US Officials
  • Proposed class action settlement in In re Netgain Technology litigation
  • Qilin Offers “Call a lawyer” Button For Affiliates Attempting To Extort Ransoms From Victims Who Won’t Pay
  • Ireland’s Data Protection Commission publishes 2024 Annual Report
  • The headlines suggested Freedman Healthcare suffered a ransomware attack that affected patient data. The reality was quite different.

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • The Markup caught 4 more states sharing personal health data with Big Tech
  • Privacy in the Big Sky State: Montana’s Consumer Privacy Law Gets Amended
  • UK Passes Data Use and Access Regulation Bill
  • Officials defend Liberal bill that would force hospitals, banks, hotels to hand over data
  • US Judge Invalidates Biden Rule Protecting Privacy for Abortions
  • DOJ’s Data Security Program: Key Compliance Considerations for Impacted Entities
  • 23andMe fined £2.31 million for failing to protect UK users’ genetic data

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.