Legal and technical compliance

Secure your website from Roskomnadzor fines of up to 700,000 – 1,500,000 ₽ and blocking

Any website that has a callback form, an e-commerce cart, a quiz, a registration, or even a Yandex Metrica counter is, by law, a personal data operator. Roskomnadzor and the prosecutor's office continuously monitor commercial websites using automated parsers.

C September 1, 2025 harsh amendments came into effect (Federal Law No. 156-FZ and No. 420-FZ): consent to the processing of personal data is now it is prohibited to combine with a public offer, user agreement, or marketing mailing. Under Art. 13.11 of the Code of Administrative Offenses of the Russian Federation, fines for bundled or default-checked checkboxes range from 300,000 to 700,000 ₽ (Part 2), and in case of a repeated violation — from 1,000,000 to 1,500,000 ₽ (Part 2.1).

We take on the full cycle: from legal expertise and drafting customized policies to coding smart cookie banners, segmenting forms, and setting up a consent recording system in the database.

For medical clinics: Additional strict requirements from the Ministry of Health (Order No. 118n and new rules No. 659) apply to clinics, dental offices, and cosmetology centers. Go to medical compliance →

  • Audit of all site forms, carts, quizzes, and pop-ups for 152-FZ compliance
  • Separate unchecked checkboxes for Personal Data processing and marketing mailings
  • Smart Cookie banner: blocking Yandex Metrica and advertising pixels until consent
  • Individual document package: Personal Data Processing Policy, consent texts, and Cookie Policy
  • Software logging of consent evidence (IP, time, User-Agent) in a database or CRM

up to 1.5 million

Fine for repeated violations of data collection and bundled consents (Part 2.1 of Art. 13.11 of the Code of Administrative Offenses of the Russian Federation)

up to 6–18 million

Fine for non-localization of databases on servers in the Russian Federation (Parts 8 and 9 of Art. 13.11 of the Code of Administrative Offenses of the Russian Federation)

156-FZ

New law: mandatory separate checkboxes without pre-filled ticks

2026

Support guarantee: elimination of remarks and legal protocol for Roskomnadzor inspections

Why is a link in the footer no longer sufficient?

Inspecting authorities evaluate not just the presence of 'Privacy Policy' text at the bottom of the site, but the data collection mechanic: whether checkboxes are checked automatically, whether an electronic consent log is saved, whether cookies are transmitted to third-party services before user consent, and whether database servers are localized in Russia.

152-FZ express check

Assess your website's fine risks in 60 seconds

Check the elements implemented on your site. The interactive calculator will calculate the risk level and potential fines from supervisory authorities.

152-FZ key requirements checklist:

Critical audit risk
Potential fines: from 300,000 to 1,500,000 ₽

The site is vulnerable to automatic checks by Roskomnadzor under Art. 13.11 of the Code of Administrative Offenses of the Russian Federation.

Compliance Anatomy

6 key risk areas on a commercial website

Where businesses most often make critical violations and how we fix them.

Federal Law No. 156-FZ (from 01.09.2025)

Ban on 'bundled' consent

You cannot combine consent for personal data with a user agreement, offer contract, and marketing newsletters into one general statement.

Solution: we move consent to a separate unchecked checkbox, and consent for advertising to a second separate item.

Federal Law No. 152-FZ, Art. 6, 9

Cookies and trackers

Analytics counters (Yandex Metrica, Google Analytics, VK Pixel) collect IP and digital fingerprints of users, which constitutes the collection of Personal Data.

Solution: we implement a Cookie banner with a technical delay in executing external trackers until consent is given.

Federal Law No. 152-FZ, Art. 9 p. 1

Proof of consent

In case of an inspection, the burden of proving consent lies with the operator. If a visitor checked a box, but the fact is not recorded anywhere — there is no consent.

Solution: the script logs the date, time, IP address, User-Agent, and consent text hash into the database upon form submission.

Federal Law No. 152-FZ, Art. 18 Part 5

Database localization in the Russian Federation

Initial collection and storage of personal data of Russian Federation citizens must occur on servers physically located within Russia.

Solution: server environment audit, migration of databases to Russian clouds, and disabling foreign collector widgets.

Federal Law No. 152-FZ, Art. 22

Notification to Roskomnadzor

Since September 2022, almost all companies are required to be in the Register of Personal Data Operators of Roskomnadzor before starting to collect applications.

Solution: we prepare a legally flawless electronic notification in the form required by Roskomnadzor and support its registration.

Roskomnadzor Order No. 179

Destruction of data by act

Upon reaching the collection goal or withdrawal of consent, data must be irrevocably destroyed with the creation of a formalized act and log export.

Solution: storage regulations and data destruction certificate templates for your internal documentation.

Stages of work

How does making a website 152-FZ compliant work?

Clear regulations from audit of leaks to script implementation and filing documents with Roskomnadzor.

01

Legal and technical audit

We inspect all data input points on the site: lead forms, contact forms, subscriptions, authorization, checkout, online chats, and external scripts.

02

Development of documents

We compose an individual Personal Data Processing Policy, texts of consents for processing and advertising, a Cookie usage policy, and data destruction regulations.

03

Cookie banner installation

We implement an adaptive pop-up notification that blocks the initialization of analytics trackers until user consent is obtained.

04

Re-coding website forms

We separate checkboxes on the site: consent for Personal Data separately, advertising separately. We remove default checks and bind clickable links to the policy.

05

Consent logging setup

We connect a software module for consent recording: when a request is sent, the date, time, IP, and document version are recorded in the DB/CRM.

06

Registration with Roskomnadzor

We help draft and send an electronic notification to Roskomnadzor to enter your company into the official Register of personal data operators.

Compliance stack

Technological protection modules

Reliable software solutions that integrate with any CMS (Bitrix, WordPress, Tilda, custom frameworks).

Smart Cookie Consent

Adaptive lightweight JS-module. Manages cookies, blocks advertising pixels and counters until consent, and saves the selection status in LocalStorage.

Audit Logger (DB / CRM)

Server-side script for logging electronic consents. It records an evidentiary base (IP, date, text of consent) every time a form is submitted.

Forms with 156-FZ validation

Adaptive form layout with separate empty checkboxes, frontend validation, and a ban on form submission without explicit consent.

Prices

Tariffs for making a site compliant with 152-FZ

Engagement models: from free express audit to comprehensive legal and technical turnkey implementation.

Capabilities and scope of work Express Audit Initial check of 10 key risk points 0 ₽ Duration: 24 hours Check for free Popular choice Detailed audit + Technical requirements Full audit, legal document package, and TS for the programmer 15 000 ₽ Duration: 2-3 working days Order for 15 000 ₽ Turnkey implementation Audit + documents + we implement all changes on the site ourselves 45 000 ₽ Duration: 5 working days Order for 45 000 ₽
Checking all site forms, cart, and pop-ups Up to 3 main forms All site forms and quizzes All site forms and quizzes
Checking the mechanism for Cookie collection and analytics operation Express check Full technical audit Full technical audit
Individual document kit (Policy, Consent, Cookies) Ready-made custom texts Ready-made custom texts
Step-by-step TS for a developer on re-layout of forms Detailed technical specification with code Performed by our programmers
Programming a Cookie banner with tracker blocking Implementation guide Installation and debugging on the site
Separating checkboxes (Personal Data separate, advertising separate) Implementation guide Full re-layout of all forms
Consent logging setup (IP, time, revision) Implementation scheme Programming in database / CRM
Preparation of notification for the Roskomnadzor operator register Consultation Template and instructions Full form completion for Roskomnadzor
FAQ

FAQ about the 152-FZ law for websites

Don't know if your website is subject to Roskomnadzor sanctions? Leave a request — we will conduct a free express analysis of your forms and counters.

  • Why are bundled consents prohibited starting September 1, 2025 (Federal Law No. 156-FZ)?

    Federal Law No. 156-FZ introduced significant changes to Art. 9 of Law No. 152-FZ. Now, consent to the processing of personal data must be specific, objective, informed, conscious, and unambiguous. It is prohibited to include consent to Personal Data in the text of a public offer or user agreement. It is also prohibited to combine in one checkbox the consent for data processing for order fulfillment and consent for receiving marketing mailings. Each action requires a separate unchecked checkbox.
  • What is the fine for lacking a policy or a separate checkbox?

    Liability is regulated by Art. 13.11 of the Administrative Code of the Russian Federation (taking into account the tightening of rules under Federal Law No. 420-FZ). For the absence of a personal data processing policy, the fine is up to 60,000 ₽ (Part 3 of Art. 13.11). For data collection without proper consent (including bundled checkboxes under 156-FZ or auto-checked boxes), the fine for legal entities ranges from 150,000 to 300,000 ₽ (Part 1 of Art. 13.11), and in cases where written consent is required by law — from 300,000 to 700,000 ₽ (Part 2 of Art. 13.11, for repeat offenses — from 1,000,000 to 1,500,000 ₽ under Part 2.1). Please note that the 50% discount on fines under Art. 13.11 has been abolished.
  • Is it mandatory to submit a notification to Roskomnadzor?

    Yes, in the vast majority of cases. Since September 1, 2022, exemptions from the obligation to file a notification with Roskomnadzor have been almost completely eliminated. If you collect customer names, phone numbers, or emails via your website, process orders, or hire employees, the company is obligated to send a notification of the commencement of personal data processing to the regional office of Roskomnadzor before processing begins.
  • Are cookies and analytics counters considered personal data?

    Yes. According to Art. 3 of the 152-FZ law and clarifications from Roskomnadzor, the combination of cookie data, IP address, geolocation, and ClientID of web analytics systems allows for the indirect identification of an individual. If a site collects cookies without informing the user and without prior consent, Roskomnadzor qualifies this as unlawful processing of personal data under Part 1 of Art. 13.11 of the Administrative Code of the Russian Federation.
  • What does the requirement for database localization mean (Part 5, Art. 18)?

    When collecting personal data of citizens of the Russian Federation, the operator is obliged to ensure the recording, systematization, accumulation, and storage of data using databases located in the Russian Federation. If the site or its database (CRM system, application form) is hosted on foreign servers without primary recording in the Russian Federation, the fine for legal entities ranges from 1 000 000 to 6 000 000 ₽, and for repeat violations — up to 18 000 000 ₽.
  • How does the service for standard websites differ from medical ones?

    For medical organizations (clinics, dental offices, cosmetology centers), specific industry regulations apply: Decree of the Government of the Russian Federation No. 659 dated 30.05.2026 and Order of the Ministry of Health of the Russian Federation No. 118n dated 13.03.2025. They require the placement of information about doctors with accreditation, a license with a QR code, a price list, and data on supervisory authorities. We have a separate specialized compliance service for medical websites.
Business and website protection

Bring the site into compliance with 152-FZ without unnecessary bureaucracy

Leave a request — we will conduct a free express audit of your website, check forms and analytics counters, calculate the cost, and put your site in full order in 3–5 days.

Order implementation (45 000 ₽)