Why “I have nothing to hide” no longer works
The phrase “I have nothing to hide” historically arose as an answer to the question of whether privacy is necessary. In modern Russia, it is often used in the opposite direction as well: “if you are not breaking the law, why should you be afraid of registries, checks, SORM, biometrics?” This article is a calm breakdown of why the reasoning “nothing to hide → this does not affect me” does not describe reality.
This is not about moral categories. It is about four practical factors: mass data leaks from large services, errors in state registries, the retroactive effect of new rules on old publications, and the fact that personal data about a person is not stored by that person. Each of these factors operates independently of behavior.
Below is a point-by-point breakdown, without moralizing and without emotional judgments. The goal is to give the reader a tool for assessing their own risks.
In short
- Personal data leaks in Russia are a mass phenomenon: banks, operators, marketplaces, state databases.
- Registries contain errors: a match in full name and date of birth with a listed person is a common situation.
- Rules change retrospectively: a 2015 publication can become a 2025 case.
- Your personal data does not belong to you — you have no right to recall a leaked database.
- “Nothing to hide” is not protection from errors, not protection from leaks, and not protection from changes in the law.
- Basic hygiene reduces risk much more effectively than confidence in your own non-involvement.
Four factors that do not depend on behavior
The argument “I have nothing to hide” assumes that risk is limited to the consequences of one’s own actions. In practice, a significant share of risks is created by external processes — technical failures, bureaucratic errors, changes in legislation, and the structure of the personal data market.
Leaks happen to everyone
Client databases of Russian banks, telecom operators, delivery services, and marketplaces regularly appear in the public domain. According to TASS, more than 130 major leaks were recorded in Russia in 2024. This does not depend on how the user behaves online: the data is stored in systems to which the user has no access.
Errors in registries
Federal registries contain entries with incomplete data — without a patronymic, or with an inaccurate date of birth. As a result, when checked by full name, people with the same surname receive a “match” in the wanted list or the debtor list. Correcting the error is a lengthy procedure, during which restrictions are applied automatically.
Retrospective criminalization
Legally, new provisions of the Criminal Code and the Code of Administrative Offenses on political offenses are applied to actions committed before their adoption, insofar as the original action was already an offense. In practice, this means that archived publications, comments, and reposts from previous years regularly become grounds for cases today.
Data does not belong to the user
A bank card, SNILS, passport data, search history, geolocation — all of this is stored in systems managed either by a commercial operator or by a state structure. The user has no technical ability to recall the data, delete a copy from a leaked database, or prohibit a state agency from exchanging data between departments.
What this means in practice
| Situation | How “nothing to hide” helps | What actually works |
|---|---|---|
| Leak of a major bank’s client database | It does not — the data is already in the public domain | SMS block, credit history monitoring |
| A namesake on the Ministry of Internal Affairs wanted list | It does not — the full-name match is automatic | Checking Wanted Radar and the Ministry of Internal Affairs registry, carrying documents with you |
| An old comment from 2015 | It does not — the rule is applied retrospectively | Knowing the limitation periods for the specific article |
| Leak of a phone number | It does not — the number is already in fraudster databases | Two-factor authentication without SMS, a PIN in the operator account |
| A state database with telecom operator biometrics | It does not — the data has been submitted automatically | The right to opt out of the Unified Biometric System (ЕБС) by written application |
| A query in the summons registry | It does not — inclusion is automatic | Checking the status in the Gosuslugi (Госуслуги) personal account |
How to check right now
The fastest way to start is to check yourself against two types of public databases. Wanted Radar shows data from the Russian Ministry of Internal Affairs wanted registry (source: Mediazona); searching by full name and date of birth takes a few seconds. This does not cover everything, but it gives a first reference point.
At the same time, it is useful to understand whether your contact details have appeared in public leaks. There is a separate article about checking leaks, as well as a general breakdown of how mass database leaks in Russia work.
Check full name in the Ministry of Internal Affairs wanted registry
Warning signs vs false alarms
A match by full name and date of birth in an open database is not a verdict, but a reason to check the details (passport data, region, patronymic). Most such matches are resolved by comparing additional fields. A real signal is an official document: a summons, a protocol, a ruling, or a request from an agency.
A leak of contact details is also not a verdict. After a leak, the risk of targeted phishing and fraud calls increases, but this is a manageable risk: passwords can be changed, two-factor authentication can be enabled, and credit monitoring can be connected. Panic about a leak is counterproductive; doing nothing is too.
What to do next
- Check yourself and your relatives in Wanted Radar and official state registries.
- Understand that leaks happen not because of user behavior, but because of how storage systems are built.
- Enable two-factor authentication wherever possible, and do not use SMS as the only factor.
- Know the limitation periods under Criminal Code articles that may affect archived publications.
- If there is a registry match by full name, immediately request clarification through the agency’s official channel.
- Understand the difference between the right to refuse biometrics and the fact that an operator collects data.
- A detailed overview of the current state of digital freedoms in Russia is in the Freedom House Freedom on the Net 2025 report and in the IPHR report on digital authoritarianism.
Conclusion
The argument “I have nothing to hide” does not describe the part of risk that does not depend on user behavior. Leaks, registry errors, changes in legislation, and the fact that data is stored in other people’s systems affect both those who carefully monitor their online reputation and those who ignore the issue entirely.
A calm position is to know which registries you appear in, what data about you is publicly available, and what steps can be taken to reduce risk. Wanted Radar helps answer the first question — searching the Russian Ministry of Internal Affairs wanted registry.