Russia Russia foreign agents law platform regulation

Russia Closes Its 2023 Foreign-Login Loophole, Fining Sites Up to 700,000 Rubles for Letting Users Sign In With Google or Apple ID

Federal Law 199-FZ adds enforcement teeth to a 2023 ban on foreign logins, steering Russian users toward Gosuslugi, VK ID, and other state-linked identity systems.

Russia's Foreign-Login Fines, by the Numbers People of Internet Research · Russia 700K₽ Max fine, legal entities First-violation fine cap for platf… 1.4M₽ Repeat-violation fine cap Fine ceiling for organizations on … 3 years Gap before enforcement Time between the 2023 login ban an… 10-20K₽ Individual fine range Fines for individuals found respon… peopleofinternet.com
Russia's Foreign-Login Fines, by the N… People of Internet Research · Russia 700K₽ Max fine, legal entities 1.4M₽ Repeat-violation fine cap 3 years Gap before enforcement 10-20K₽ Individual fine range peopleofinternet.com

Key Takeaways

A Three-Year-Old Ban Finally Gets Teeth

On June 26, 2026, Vladimir Putin signed Federal Law No. 199-FZ, amending Russia's Code of Administrative Offenses to punish website operators that let Russian users authenticate through foreign services — Google, Apple ID, Microsoft accounts, GitHub, Discord, or any foreign email address used as a login identifier. The penalties are steep: 10,000–20,000 rubles for individuals, 30,000–50,000 rubles for company officials, and 500,000–700,000 rubles for legal entities on a first violation, rising to as much as 1.4 million rubles for organizations on repeat offenses (Meduza; ConsultantPlus, text of 199-FZ).

What makes this notable isn't the mandate itself — Russia banned foreign-service logins for domestic websites back in 2023 — but the fact that it took three years to attach a punishment to it. The State Duma passed the enforcement amendments on June 9, 2026, and Putin signed them seventeen days later, finally closing a loophole that let compliant-in-name-only platforms keep Google and Apple sign-in buttons live simply because nothing happened if they did (Meduza). Approved alternatives are narrow and specific: a Russian mobile number, the Gosuslugi state-services portal (ESIA), the Unified Biometric System, or a domestic identity provider such as VK ID, Yandex ID, or Sber ID (Lidings legal update).

The Case Regulators Will Make

To be fair to Moscow's stated rationale, there is a coherent policy argument buried in this law, and it deserves to be stated plainly before it's dismantled. Foreign identity providers are, in fact, outside the reach of Russian courts and data-protection orders — if Google refuses a Russian legal request for account data tied to a fraud or child-safety investigation, domestic law enforcement has no real recourse. Many jurisdictions, including EU member states under GDPR's data-localization-adjacent provisions, have grappled with similar sovereignty gaps in cross-border identity infrastructure. A government that wants enforceable jurisdiction over the platforms its citizens use every day has a legitimate interest in making sure the identity layer sits somewhere it can actually regulate. That is a real problem, and it is not a uniquely Russian one.

Why the Remedy Outweighs the Problem

But the fix Russia has chosen collapses a legitimate jurisdictional concern into something closer to a surveillance and market-consolidation program, and the mechanics make that hard to dispute. Every approved alternative funnels authentication through infrastructure the state already has privileged access to. Mobile carriers log the phone number, timestamp, and requesting service for every one-time password sent — data directly accessible through Russia's SORM lawful-intercept system. Gosuslugi, by design, records which third-party service a citizen accessed and when, inside the same government portal used for taxes, court filings, and military registration. The Unified Biometric System centralizes facial and voice templates in a state-run database (Riposte). None of that is a side effect — it's the architecture the law requires.

There's also a security regression the law's drafters don't seem to have priced in. Consolidating logins under a handful of Russian-owned identity providers with "very different security standards" than the international OAuth ecosystem means a breach at any one domestic provider — VK, Yandex, Sber — now compromises the login credentials for a much larger swath of Russian internet users than a single foreign provider breach would have (Riposte). Fragmenting a functioning, internationally audited authentication standard into siloed state-linked alternatives isn't a security upgrade; it's a security downgrade dressed as sovereignty.

Market Consolidation by Statute

The commercial effect is just as significant as the surveillance one. By statute, Russian platforms must now route identity through VK ID, Yandex ID, Sber ID, Gosuslugi, or mobile carriers — a closed list of state-aligned or state-adjacent providers with no international competitor able to enter. This is protectionism executed through the identity layer rather than tariffs, and it lands at a moment when Russia's war-driven economic growth is already cooling, with independent analysts warning that the wartime stimulus effect is running out of room (ERR News). Insulating a handful of domestic identity vendors from competition may serve short-term industrial policy, but it does so by making every Russian website marginally more expensive and legally riskier to operate — a tax on compliance that foreign-facing Russian tech companies, already isolated from Western app stores and cloud infrastructure, can least afford.

The Proportionality Test

Nothing in 199-FZ is retroactive — accounts created through foreign services before the rule took effect keep working, and end users face no fines at all; the liability sits entirely with platforms (Lidings). That narrower targeting is a genuine, if modest, mercy compared to blunter instruments Russia has used elsewhere, such as the 2025 law fining VPN providers and criminalizing deliberate searches for banned content (The Moscow Times). But proportionality has to be judged against the actual remedy chosen, not just the harm regulators cite. A government genuinely worried about extraterritorial identity providers evading its courts had options short of forcing every login through Gosuslugi and three state-linked vendors — audited data-sharing agreements, in-country data residency requirements for foreign providers, or graduated liability tied to actual noncooperation, rather than a blanket authentication mandate. Russia chose the version that maximizes state visibility and minimizes competitive choice. That's not proportionate regulation; it's identity policy built for control.

Sources & Citations

  1. Meduza: Duma sets fines for foreign-login noncompliance
  2. ConsultantPlus: Federal Law 199-FZ text
  3. Lidings: Fines for authorization via Google, Apple ID, foreign email
  4. The Moscow Times: Russia's internet restrictions explained
  5. Riposte: critical analysis of the login ban
  6. ERR News: Russia's war-driven economic boom losing steam