EN

Hey, pay up: the State Duma introduced fines of up to 700,000 ₽ for authorization through foreign services

· · The Ateo Digital editorial team

Hey, pay up: the State Duma introduced fines of up to 700,000 ₽ for authorization through foreign services

The State Duma passed in the second and third readings a bill that introduces administrative fines of up to 700 thousand roubles for Russian websites for authorizing users through foreign services — including Google, Apple ID, GitHub, Discord, Microsoft Account, and foreign email. The amendments are being made to the Code of Administrative Offences; the initiator is deputy Anton Gorelkin.

The law effectively closes the Runet to the familiar “Login with Google”. To register on a Russian website, you will have to provide a Russian phone number, sign in through Gosuslugi (госуслуги) / ESIA, the Unified Biometric System, or use an “information system owned by a citizen of the Russian Federation or a Russian legal entity” — that is, VK ID, Yandex ID, Sber ID, and similar systems.

We explain what this means for users and website owners: which scenarios break, which alternatives remain, and why this law will make the internet in Russia even more tied to Gosuslugi.

In brief

  • The State Duma passed a law on fines of up to 700 thousand ₽ for legal entities for authorizing users through foreign services.
  • Authorization is allowed only through: a Russian number, Gosuslugi / ESIA, the Unified Biometric System, or systems of Russian legal entities (VK ID / Yandex ID / Sber ID).
  • Banned: Google OAuth, Apple ID, GitHub, Discord, Microsoft Account, and any foreign email.
  • Individuals are fined 10–20 thousand, officials — 30–50 thousand, legal entities — 500–700 thousand ₽. For repeat violations — up to 1.4 million.
  • Separate fines apply for recommendation algorithms without informing users (also up to 700 thousand ₽).
  • Telecom operators face fines of up to 5 million ₽ for disclosing methods of operational-search activities; for repeat violations — 1–3% of annual revenue, but not less than 10 million.
  • The law still has to be signed by the president — this usually takes 1–2 weeks.

What falls under the law

Formally, the law concerns “owners of internet resources” that provide access to information. In practice, this is any website, including:

  • online stores (Ozon, Wildberries, local shop systems)
  • forums, topic communities, and Q&A sites
  • media outlets with registration for comments
  • SaaS services, education platforms, freelance exchanges
  • any website that has “Sign in with X”

What is allowed as a login method

  • Russian phone number — SMS code or call from a Russian telecom operator number.
  • Gosuslugi / ESIA — Unified Identification and Authentication System.
  • Unified Biometric System — separate infrastructure with biometrics.
  • VK ID, Yandex ID, Sber ID, MAX account and similar SSO systems whose operator is a Russian legal entity.

What is banned

  • Login through Google / Apple / Microsoft / GitHub / Discord / Twitter / Facebook
  • Registration by email at gmail.com, outlook.com, icloud.com, protonmail.com, and any foreign email service
  • Magic-link authentication to a foreign email address

What users will notice

ScenarioTodayAfter the law takes effect
Registration on a new Russian service You can use “Login with Google” Only Gosuslugi / Russian number / VK ID
Already registered through Gmail You log in as usual The site must ask you to link a Russian number; otherwise the account is blocked
Your only email is at gmail.com You receive emails from the site The site may stop sending important notifications to a foreign email address
No Russian number (relocated user) Registration by email Registration is unavailable without Gosuslugi or the Unified Biometric System
The site uses a recommendation feed Without explicit notification It must show a policy on how the algorithms work + an email for contact

How to check which services have already broken

Many platforms will change authorization gradually. If you previously logged in through Google and today the site suddenly requires an SMS code, this is already an effect of the law (or early compliance with it). If the site does not open at all, check whether this is blocking on the operator’s side using availability diagnostics.

Freedom Checker regularly checks the availability of Russian and foreign services through MTS, MegaFon, Beeline, Tele2, Rostelecom — so you can distinguish “the site is alive, but the Google button is gone” from “the whole site does not open on my operator”.

Check availability through Freedom Checker

Is this blocking or new regulation?

This law is not blocking Google / Apple / GitHub. They continue to work as services, their websites remain in your browser, and you can use them directly. What changes is that Russian websites no longer have the right to use them as a login method for their users.

Analogies:

  • Google was not banned — Russian websites were banned from using “Login with Google” as the standard login method.
  • Gmail was not disabled — but a Russian site cannot send legally important mandatory notifications to it.
  • Apple ID works on your iPhone — it is just that Wildberries will no longer be allowed to let you register through it.

In other words, the boundary between “the service is available” and “the service is integrated into the Russian web” is becoming stricter.

Additional provisions of the law

Recommendation algorithms

A separate block of fines concerns sites that use recommendation technologies (any “you may like” feed, a marketplace alg-feed, music auto-play, etc.). Requirements:

  • inform users that recommendations are being used
  • publish a document with the “rules for applying” the technologies
  • provide an email for legally important messages
  • not violate the “rights and interests of citizens and organizations” when collecting data about preferences

For a violation — the same 500–700 thousand ₽ for legal entities; for a repeat violation — up to 1.4 million.

Telecom operators and operational-search activities

Operators receive fines for violating rules on interaction with law enforcement during operational-search measures and for disclosing methods used to conduct them. The base fine is 3–5 million ₽; for a repeat violation — 1–3% of the operator’s annual revenue, but not less than 10 million.

This affects the user indirectly: an operator will be even more restrained in any public comments about exactly how SORM works and what data is transmitted. This does not expand the powers of law enforcement, but it raises the cost of any leak of information about methods on their side.

What users should do

  • Link a Russian number to accounts on the main Russian services — it will become the universal recovery key.
  • Create a Gosuslugi account if you do not have one yet — it is becoming de facto mandatory for most new registrations.
  • Do not tie critical services only to Gmail / iCloud — a Russian site may require an email change at any time.
  • If you are registering as a relocated user — keep in mind that without a Russian number, access to Russian services will narrow sharply; keep an active SIM from Russia if you plan to use marketplaces / Gosuslugi.
  • Remember that the law will not take effect immediately — usually there is a transition period (90–180 days from the moment of signing).

Conclusion

The law on fines for authorization through foreign services is another step toward making the Runet a self-sufficient system with mandatory tying of users to Gosuslugi or Russian SSO. This is not blocking foreign services, but it is a blow to UX: the familiar “Login with Google” button will disappear from most Russian websites in the coming months.

For users, the main thing is to have a working Russian number and a Gosuslugi account. Without them, by the end of the year it will be difficult to register anywhere in the Runet. For website owners, it means urgently auditing the auth infrastructure and removing foreign OAuth before Roskomnadzor starts issuing fines.

Check service availability now