Russia's Cyber Sovereignty Fractures Global Digital Rules

Russia's Cyber Sovereignty Fractures Global Digital Rules

As of May 2026, only Qatar, Azerbaijan, and Vietnam have ratified the Hanoi Convention, with 74 signatories in total, including Tajikistan and Colombia. A state-centric vision of cyber sovereignty asserts that state borders extend over cyberspace, granting states the right to control their domestic internet spaces, as detailed by the Harvard International Review and the University of Chicago Journal of International Law. Lawfare reports that through United Nations processes like the Open-Ended Working Group (OEWG) and the 2024 UN Cybercrime Convention, also known as the Hanoi Convention, Russia has embedded principles such as the "inadmissibility of unsubstantiated attributions." Lawfare explains that this provision is designed to diminish the importance of state attribution in cyber accountability, effectively creating a high bar behind which state-supported activities can hide.

US and Western States Shun Hanoi Convention

Major powers like the United States have disengaged, and Western-aligned states, which hold the majority of global electronic evidence, have not joined, Lawfare observes. Lawfare documented that while the UN General Assembly adopted the Hanoi Convention in December 2024 and it opened for signature in October 2025, its final text largely mirrors the Western-backed Budapest Convention rather than adopting Moscow's full authoritarian narrative. Despite Russia's procedural dominance in UN cyber diplomacy, this has not translated into a durable structural shift of enforcement power to intergovernmental bodies, leading to persistent accountability vacuums, Lawfare determined.

Russia and China Fill Western Capacity Vacuum

Lawfare points out that the non-participation of Western-aligned states means data required for cybercrime investigations will be inaccessible under the UN treaty framework for many nations. Lawfare asserts that the lack of universal participation in Russia-backed treaties, particularly the Hanoi Convention, is actively fragmenting the digital governance architecture, with Russia and China filling this vacuum. This entrenches competing jurisdictional silos; the Budapest Convention potentially remains the only practical option for international cooperation among its signatories, while Russia's state-centric track operates separately, Lawfare warns.

Russia's Data Localization Fines Reach RUB 500 Million

Effective May 30, 2025, new regulations impose fines up to RUB 500,000,000 (or 1% to 3% of aggregate revenue) for actions causing a data leak, as detailed by the Digital Watch Observatory. Russia’s dual strategy imposes significant and escalating compliance costs and penalty regimes on multinational tech firms. Domestically, Federal Law No. 242-FZ requires data localization, forcing companies to rent local server space, a requirement highlighted by the Atlantic Council and the Brookings Institution. Hunton Andrews Kurth documented that penalties for localization violations have increased from initial fines of RUB 6,000,000 (approximately $100,000 USD) to up to 20% of a company's Russian turnover for repeated offenses. In jurisdictions that have ratified the Hanoi Convention, firms face a state-centric compliance environment characterized by broad language and weak human rights safeguards, according to the Harvard International Review and the RAND Corporation. The University of Chicago Journal of International Law and NATO CCDCOE note that the Convention requires signatory states to establish liability for legal persons involved in cybercrimes, subject to "effective, proportionate and dissuasive criminal or non-criminal sanctions."

The Bifurcated Internet

Accountability mechanisms are now split: within state borders, national sovereignty dictates strict data and content controls, while internationally, the principle of "inadmissibility of unsubstantiated attributions" provides a shield against external scrutiny for state-sponsored cyber activities. Russia's procedural victory in the global cyber norms contest has solidified a bifurcated international digital governance system. This dual approach challenges the multi-stakeholder model of internet governance, empowering intergovernmental bodies and authoritarian states to exert greater control over information flows and digital infrastructure. The long-term implication is a less open, more balkanized internet, where geopolitical alignments increasingly determine digital rights and responsibilities, leaving multinational tech firms to navigate a complex and often contradictory regulatory environment.


Download the full research report (PDF)