152-FZ on personal data: what your website must do
A contact form, a pop-up asking for a phone number, a newsletter sign-up, an online store cart — every one of these makes your website a personal data operator. Since 30 May 2025 the fines under Article 13.11 of the Code of Administrative Offences have grown several times over, and a repeat data leak now carries turnover-based penalties. Below is the practical minimum that closes 90% of the complaints inspectors raise.
Who counts as an operator, and why that means almost everyone
An operator is any party that organises the processing of personal data. Collecting a name and a phone number is enough. Neither the size of the business nor the absence of a CRM changes anything. If your site has even one form, you are an operator with all the obligations that follow. We run into this constantly during corporate website development: the client is certain that "we do not store anything", while in reality enquiries have been piling up in a manager's inbox for years.
Step 1. Notifying Roskomnadzor
Since September 2022 the exemptions from the duty to notify have effectively been removed — nearly every operator must file a notification, including those who process only their own employees' data. The notification is submitted through the Roskomnadzor portal and takes up to 30 days to review. Failing to file carries a fine of up to 300,000 roubles for a legal entity under Part 10 of Article 13.11. You can check whether your company is in the register for free on the regulator's site in about a minute.
Step 2. Processing policy and consents
- A personal data processing policy — a standalone document reachable by a direct link from every page that has a form. Not a PDF in the footer, but an HTML page.
- A separate consent to processing — a checkbox with no pre-ticked default. A pre-ticked box is treated by the regulator as no consent at all.
- A separate consent for marketing messages — it cannot be bundled into the general consent, these are two different legal grounds.
- A consent to cross-border transfer, if you use foreign analytics or mailing services.
- An order appointing the person responsible for organising processing — an internal document, but the first one requested during an inspection.
Step 3. Localising databases
Part 5 of Article 18 of 152-FZ requires that the initial collection of Russian citizens' data happen in databases located in Russia. In practice this means your site hosting and CRM server must sit in a Russian data centre. A foreign service is acceptable only as a secondary copy. This is what most often pushes businesses to move their CRM systems onto local infrastructure. The register of violators and site blocking are last-resort measures, but the precedents exist.
Step 4. Technical protection measures
The law demands "the adoption of necessary measures", and the specifics live in Government Decree No. 1119 on protection levels. For a typical site holding contact details this is level four: access segregation, logging, current updates, channel encryption. The bare minimum is a valid SSL certificate and an admin panel closed to indexing. A good reference point for technical threats is the OWASP Top 10, which lists the vulnerability classes through which data most often leaks.
What a mistake costs
- Processing without consent — up to 700,000 roubles for a first offence by a legal entity.
- An unpublished processing policy — up to 60,000 roubles.
- Failure to notify Roskomnadzor — up to 300,000 roubles.
- A leak affecting 1,000–10,000 data subjects — 3 to 5 million roubles.
- A repeat leak — a turnover-based fine of 1% to 3% of annual revenue, but no less than 20 million roubles.
What to do this week
Open your home page and check whether there is a link to the policy. Then check the Roskomnadzor register for your tax ID. Then check every form for pre-ticked boxes. These three actions take half an hour and remove the complaints that are cheapest for an inspector to raise. The current wording of the law is easiest to read on the official legal information portal — texts on third-party sites are often out of date. If you need an audit and full compliance work done for you, get in touch; it usually takes two weeks or more.
Need help with a project?
Let's discuss your task and propose a solution — from a website to SaaS and security.
Get in touch