The State Duma has passed a law introducing significant fines for website and application owners who use foreign services for user login or violate rules governing recommendation algorithms. For a first offense, companies face fines of up to 700,000 rubles, and for repeated violations – up to 1.4 million rubles.
The requirement to authorize users exclusively through Russian tools was introduced back in December 2023 under Federal Law No. 149. However, until recently, there was no enforcement mechanism for violations. Now that the amendments to the Administrative Code have been adopted, ignoring these requirements has become prohibitively expensive.
What Fines Businesses Face
Using foreign login systems is now covered under Article 13.55 of the Administrative Code. The fines are as follows:
Individuals – from 10,000 to 20,000 rubles; for repeat offenses – up to 40,000 rubles.
Officials (managers and other responsible staff) – from 30,000 to 50,000 rubles; for repeat offenses – up to 100,000 rubles.
Legal entities (companies, organizations) – from 500,000 to 700,000 rubles. For a repeated violation, the fine increases to 1.4 million rubles.
These fines apply to resource owners, not to regular users simply accessing websites.
New Rules for Recommendation Algorithms
At the same time, new requirements have been introduced for those who use recommendation technologies – when a website or application uses algorithms to suggest content, products, or services based on user behavior.
The new rules prohibit:
using algorithms that in any way violate the rights of individuals or organizations;
applying such technologies without notifying users;
failing to publish a clear document describing how the algorithms work;
ignoring Roskomnadzor's orders to stop using recommendation systems.
The fines for violations in this area are identical to those for improper authorization. Companies face up to 700,000 rubles for a first violation and up to 1.4 million for repeat offenses.
What You Need to Do Now
To avoid significant fines and issues with regulatory authorities, you should review your systems and bring them into compliance as soon as possible. Here's a minimum checklist:
Review all login methods currently used on your website, mobile app, or user portal. If you're using foreign services – they must be replaced.
Implement at least one approved Russian login option – such as phone number verification via SMS, the Gosuslugi portal (ESIA), or Russian ID systems like VK ID, Yandex ID, or Sber ID.
Update your legal documents – the user agreement and privacy policy must align with the new requirements.
If you use recommendation algorithms – ensure you have clear user notifications, published rules of operation, and information about the resource owner.
How We Can Help
Acsour offers a service to review authorization systems and ensure compliance with the law on recommendation algorithms. We help you navigate the new regulations and avoid fines.
What we do:
Conduct a comprehensive audit of your websites, applications, and information systems for compliance with legal requirements.
Verify the presence and correctness of all required documents and notifications.
Provide clear recommendations for remediating violations and assist with implementation.
We have many years of experience working with companies of all sizes across various industries. We understand that it's not just about identifying a problem – it's about offering a practical solution that can be implemented quickly.
These new fines represent a serious risk for businesses that have overlooked legal requirements or delayed compliance. The penalties can be comparable to the annual budget for website development and support, especially for smaller companies.
Reviewing and adjusting your authorization and recommendation algorithm systems to meet legal standards is an investment in the stability of your business in an environment of constantly evolving legislation.