RUEN
Home/Materials/BCM and data protection
Cybersecurity and continuity

Business continuity and data protection: 152-FZ and leak fines

A data leak is not only reputation but also legal risk and fines. We break down the link between continuity and data protection, the requirements of 152-FZ and how to reduce the risk with simple measures.

Updated: June 28, 2026 · Author: Evgeny Telenkov · ≈ 6 min read

Why data is a continuity matter

The loss or leak of data can stop processes (nothing to work with) and carry legal consequences. So data protection is part of both cybersecurity and business continuity. The target for acceptable data loss (RPO) is set in the BIA and covered by backups (DRP).

What 152-FZ requires

Russia's Federal Law 152-FZ "On Personal Data" obliges operators to protect personal data, restrict access, respond to incidents and, in some cases, notify the regulator. Violations and leaks carry liability, and legislation is moving toward tougher rules and turnover-based fines (tied to revenue). This shifts the risk from "technical" to "money and owner liability".

Important: the exact amounts and wording of fines change — check the current edition of the law or with a lawyer before making decisions.

Basic risk-reduction measures

  • Minimisation: store only the data you need and restrict access.
  • Backups, including isolated copies.
  • An incident and breach response plan (see "cyberattack response").
  • Staff training and basic cyber hygiene.

FAQ

What are the fines for a personal data leak?

Liability under 152-FZ is tightening, and turnover-based fines (tied to revenue) are being discussed and introduced. Specific amounts depend on the current edition of the law — check the law in force or with a lawyer.

How are data protection and business continuity linked?

Data loss stops processes and carries legal risk. Continuity sets the acceptable data loss (RPO) and ensures recovery from backups.

Is your team ready for the first hour of a crisis

Plans are tested by scenarios, not by reading. The assessment shows the gaps, the corporate format works them through with your team on your processes.

Evgeny Telenkov
Evgeny Telenkov
Director, business continuity practice · PhD in Economics · Academic Director & Chief Examiner
Risk Manager of the Year in Russia 2020 (RusRisk). Built business continuity from scratch at Nornickel, more than 20 plans; led risk functions at Beeline, Rosneft and EY. Chief risk officer of a 20 billion dollar petrochemical megaproject. Deputy chair of Rosstandart technical committee 010 "Risk management", co-author of six national standards. Author of the ERGP and SAFE programmes.