In short: On 15 July 2026 Russia's Ministry of Digital Development (Mintsifry) confirmed it is drafting a single register of personal-data consents on the Gosuslugi portal. Citizens would see, in one place, every company allowed to process their data and revoke any permission with a click, while operators would be required to report each consent and withdrawal to the state system. There are 2.6 million registered data operators, and the plan is welcomed for transparency but criticised for cost and for concentrating so much sensitive information in one target.
What happened
On 15 July 2026, Russian media including Forbes, Computerra and SecurityLab reported that the Ministry of Digital Development has returned to an idea it floated before: a unified consent-management service on the state portal Gosuslugi. It is being prepared as amendments to the personal-data law (152-FZ) and forms part of the third package of anti-fraud measures. The final text is not ready — the ministry is gathering input from industry and other agencies, and no launch date has been set.
The direction of travel is already visible, though. Since March 2026, Russians have started receiving notifications inviting them to review the consents they have given — a preparatory step ahead of the full service. If you have ever ticked "I agree to the processing of my personal data," this initiative is about giving you a way to see and undo those agreements. Our note on the fall in Russian data-leak postings covers the wider backdrop of tighter data rules.
How the single consent registry would work
The core idea is a single dashboard. Instead of each consent living only in the archives of the company that collected it, a citizen would see a full list of active permissions on Gosuslugi and be able to withdraw the ones they no longer want. To make that possible, data operators — companies, government bodies and sole traders alike — would be obliged to send information about every consent and every withdrawal to the portal, synchronised through the state identity system (ESIA).
A second change tightens the rules on asking in the first place. Businesses would be allowed to request consent only in cases directly provided for by law or an international treaty, rather than collecting it at their own discretion as many do today. On paper that shifts the balance toward the individual: fewer blanket "agree to everything" boxes, and a real off-switch when you change your mind.
What it means for your data
For an ordinary user the upside is genuine transparency. Right now almost no one can list the dozens of services holding a valid consent to process their data; a single register with one-click revocation would turn a scattered, invisible mess into something you can actually audit. With 2,639,808 operators recorded in the Roskomnadzor register, that is a lot of hidden relationships to surface.
The flip side is concentration of risk. Critics — including the Big Data Association, which calls the plan overly broad and costly — warn that pulling everyone's consent map into one system creates a single point of failure. A breach there would not leak one database but the web of links between citizens and the organisations that hold their data. It is a reminder that convenience and centralisation always carry a security trade-off, and that your own habits still matter regardless of what the state builds.
How to protect your personal data now
Review the consents you have already given. If you receive a Gosuslugi notification about checking your permissions, use it — and in the meantime, be sparing with new "agree to data processing" boxes on sites and apps that do not truly need them.
Minimise what you hand over. The less personal data spread across operators, the smaller your exposure if any one of them is breached. Give only what a service genuinely requires, and prefer providers with a clear privacy posture.
Use a password manager and two-factor authentication. Since Gosuslugi itself becomes an ever more valuable target, protect that account in particular with a unique password and 2FA, so a single leaked credential cannot open your whole profile.
Encrypt your connection on untrusted networks. A registry of consents does not protect the traffic you send day to day. On public or shared Wi-Fi a VPN routes your connection through an encrypted tunnel, so others on the same network cannot intercept the logins and forms you submit to portals, banking or mail. LiMP VPN is a no-logs service for iOS and Android — see the features and plans.
When will the service actually launch?
No date has been set. As of mid-July 2026 the amendments are still a draft, with the ministry collecting feedback from industry and agencies before any public consultation. Expect debate over cost and security before anything goes live — but the preparatory notifications already reaching citizens suggest the groundwork is under way.
Sources
This report is based on reporting by Forbes.ru, Computerra and SecurityLab, 15 July 2026.
