Digital Surveillance in Russia

Open Sources

This system has three tiers. The first is state infrastructure for direct access. The second is ecosystem platforms that collect data commercially but are required to hand it over on request. The third is technical intermediaries that provide the infrastructure for the first two. Together, they form a closed loop from which data never leaves — it only accumulates.

Tier One — State Infrastructure

This is the foundation of the system. Not commercial players, not advertising brokers — but a legally established, direct state access to any and all data of any user within Russian territory. No court order presented to the operator. No notification to the data subject. No right to challenge it.

SORM — the System for Operational-Investigative Activities

Created in 1995, built on the foundation of the Soviet KGB. Over thirty years, it grew from a phone-tapping system into a total interception infrastructure covering all of the country’s digital traffic. It exists in four generations.

— SORM-1 (1995) — Telephony

Interception of telephone calls. The first generation, still operating alongside the newer versions.

SORM-2 (1998) — Internet Traffic

A server that connects to an operator’s network and receives a copy of all traffic passing through it. Controlled from a console at the regional FSB office over a separate secure channel. The operator doesn’t see what exactly is being intercepted — it only provides access to the infrastructure.

SORM-3 (2014) — Big Data

Integration with data-storage systems. Retention of user communications data for up to 3 years. Cross-referencing of data from different sources — telephony, internet, finance, location — within a single system.

SORM-86 (2018) — Messengers and Apps

Extension to mobile apps, messengers, and data-transmission services. Mandatory installation for all “organizers of information dissemination” (ORI — a legal category covering platforms enabling user communication).

As of 2026, SORM must be installed by all telecom operators, all ORIs, hosting providers, and — as of March 2026 — freight forwarders. Banks were required to install SORM starting in October 2025. Insurance companies — in 2024. The expansion proceeds methodically: every year, another industry gets connected to the FSB’s single control console.

The Yarovaya Law (2016) — Mandatory Retention

The law required all telecom operators and ORIs to retain the content of users’ correspondence, calls, and other communications. The initial retention period was 6 months. In November 2025, a law was passed extending it to 3 years. The Big Data Association — bringing together Sberbank, Yandex, and VK — publicly stated that companies’ costs would grow by more than a multiple. This did not stop the law’s passage.

Roskomnadzor — Regulator and Instrument

Formally — the regulator for telecommunications and media. In fact — the executive body enforcing FSB requirements on the digital space. It maintains the ORI register, which as of late 2025 includes 413 Russian and foreign services. Inclusion in the register automatically creates the obligation to hand over data on FSB request. Since July 2024, it has had the power to add services to the register forcibly.

The ORI Register — 413 Entities Under Direct Control

An “organizer of information dissemination” is any service where users can communicate with each other. The register includes: every major Russian platform, messengers, banking apps, dating services, news aggregators, marketplaces. Inclusion creates three obligations: store user data on servers within Russia, hand it over on FSB request within 24 hours, and install equipment allowing remote access for the security services.

Tier Two — Ecosystem Platforms

These are commercial companies that collect data for business purposes — but operate under mandatory cooperation with the state. Unlike their European counterparts, they cannot refuse to provide data — refusal means a block or criminal prosecution of leadership. This is where the primary bulk of data on citizens’ everyday lives is concentrated.

Yandex — Russia’s Google, with Obligations to the FSB

Yandex is Russia’s largest technology ecosystem. In terms of the breadth of user data it holds, it’s comparable to Google in Europe: search queries, email, maps with routes, ride-hailing with location data, delivery with addresses, music preferences, viewing history on Kinopoisk, smart-home data, voice commands to its Alice assistant.

The 2019 Precedent

The FSB requested from Yandex the session keys for Yandex.Mail and Yandex.Disk — that is, the ability to decrypt in real time all data transmitted between Yandex and a specific user, including logins and passwords. Yandex refused. The FSB went to court. The outcome showed that, within Russian jurisdiction, a tech company’s refusal to the security services is a temporary state of affairs — not a matter of principle.

Yandex’s international operations raise particular concern. The Yango service (the international name for Yandex.Taxi) operates in more than twenty countries, including Israel, Norway, Finland, Georgia, and Armenia. According to an investigation by Meduza, trip data for users in these countries was stored on servers in Russia — meaning potential FSB access to the data of foreign nationals without their knowledge, and without the knowledge of the governments of those countries.

VK — A Social Graph Under Direct Control

VKontakte is the largest Russian-language social network. It knows the same things about a user that Meta knows about a European user: social graph, private messages, interest groups, music preferences, political views inferred from subscriptions and likes, location via check-ins.

A Documented Case

According to investigative reports, VKontakte handed over users’ personal data to the FSB over a phone call — with no official request and no court order. Screenshots from VKontakte regularly turn up in criminal case files as evidence obtained by the security services.

Sberbank — A Financial Ecosystem as a Tool for a Total Profile

Sberbank has long since expanded beyond banking. Today, the Sber ecosystem includes: banking operations and transactions, food delivery (Samokat), medicine (SberHealth), streaming (Okko), cloud storage (SberDisk), a smart home (Salut), a voice assistant, insurance, investments. A person who uses the Sber ecosystem hands data about their finances, health, diet, entertainment, and home environment to a single entity, all at once. In October 2025, the FSB demanded that major banks install SORM — a system for remote access to the correspondence of banking-app users.

Tier Three — Technical Intermediaries

These are companies that provide the technical infrastructure for the first two tiers. They’re less publicly visible — but the system wouldn’t function without them. This is also where players sit that collect data at the intersection of the Russian and international internet.

SORM Equipment Manufacturers

SORM isn’t just a law. It’s physical equipment sitting in the server rooms of every Russian telecom operator. This equipment is manufactured and serviced by a handful of specialized Russian companies that work exclusively under FSB and FSTEC licensing. Without certification from these agencies, the equipment cannot be used. This creates a closed loop: the FSB sets the technical requirements, certifies the manufacturers, and receives data through their equipment.

Yandex.Metrica — the Russian Equivalent of Google Analytics

Installed on hundreds of thousands of Russian websites. Collects user behavioral data — pages visited, clicks, time on site, device, location. Unlike Google Analytics, the data is stored on servers within Russia and falls under the requirement to hand it over to the FSB. This means visiting any Russian site running Yandex.Metrica potentially adds an entry to a system accessible to the security services.

Mail.ru / VK Mail

The largest email provider in Russia. Tens of millions of users. Message content, attachments, contacts, communication history — all of it is stored on Russian servers and handed over on FSB request within 24 hours. For users in other countries who correspond with Russian mail.ru addresses, their data also enters this system.

GosLog — A New Tier Starting March 2026

As of March 1, 2026, all freight forwarders are required to register on the state platform GosLog and provide the FSB with round-the-clock remote access to their information systems. Data on routes, cargo, clients, counterparties — in real time. Architecturally, this is a complete replica of SORM applied to the logistics industry. Judging by the pace of expansion, medical institutions and educational platforms could be next in line.

Russia vs. Europe — Fundamental Differences

Russia’s data-collection system affects not only Russian citizens. It concerns everyone who has any communication with people in Russia: anyone who exchanges messages with them via VK or Mail.ru, uses Yandex services outside the country, takes trips via Yango in other countries, or works with Russian companies through their digital platforms.

The data generated in these communications isn’t protected by the GDPR — it’s stored on Russian servers and accessible to the FSB without the judicial oversight that a European legal system would recognize as valid.

The Key Difference from the AdTech Ecosystem

Advertising brokers use data to sell you a product. Russia’s state system uses data to make decisions about your life — whether to grant a visa, whether to allow entry, whether to open a criminal case. This is a fundamentally different level of consequence for the data subject.

The data-broker market in Europe is valued at $290 billion and is regulated by the GDPR, with the right to access data, the right to erasure, and the right to compensation. Russia’s system has no equivalent mechanism protecting the data subject — because the state, which would otherwise be the body responsible for protecting these rights, is itself the primary consumer of the data.

← All journal entries