The volume of personal data leaks in Russia continues to grow. To improve information storage security, the Analytical Center under the Government proposed exempting data centers (DPCs) from liability for compromising personal data, Izvestia reports.

This refers to commercial data centers that provide clients only with infrastructure services — equipment placement, power supply, and server cooling — but do not have access to the information itself. However, in current practice, such DPCs can be held liable for leaks, with fines potentially reaching 500 million rubles for the first violation and 3% of annual revenue for a repeat offense.

According to the authors of the document, exempting DPCs from liability will force those who actually collect and use citizens' data to approach its protection more carefully. Information owners will no longer be able to shift the blame to infrastructure providers.

The Ministry of Digital Development, Communications and Mass Media agreed that a DPC that does not have access to data and does not determine the purposes of its processing cannot act as its operator. Experts link the proposal to a change in the nature of attacks: attackers are increasingly stealing entire databases, which they use to train neural networks. The volume of compromised records in 2026 increased to 70%.

The initiative will reduce the regulatory burden on data centers and concentrate responsibility directly on data operators. Businesses and government agencies will be forced to more thoroughly search for real sources of leaks, rather than shifting the blame to third-party companies.

Read more on the topic: