New Fines for Using Foreign Authentication Methods on Russian Resources
Starting July 7, 2026, Russia will enforce strict penalties for owners of websites, apps, and information systems that allow users to log in via foreign platforms. The legislative ban on using services like Google OAuth, Apple ID, Microsoft Account, Discord, or foreign emails like Gmail or Yahoo has been in effect since December 2023, but no real punishments were established until now.
The new Federal Law No. 199-FZ amends the Code of Administrative Offenses (KoAP) by adding Article 13.55, which introduces hefty administrative fines for ignoring these rules. For a first-time violation, individual resource owners face a fine of 10,000 to 20,000 rubles, officials face 30,000 to 50,000 rubles, and legal entities face liability ranging from 500,000 to 700,000 rubles. In the case of a repeated offense, the amounts increase and can reach up to 1.4 million rubles for companies.
Notably, the law does not penalize ordinary citizens who use these login methods; the entire responsibility lies solely on the platform owners. To avoid massive fines from Roskomnadzor, Russian businesses must completely disable foreign login buttons and leave only legal domestic authentication options, such as Russian mobile phone numbers, the "Gosuslugi" portal (ESIA), the Unified Biometric System, or other IT services controlled by Russian citizens, including Yandex ID, Sber ID, or VK ID.
