Back to the blog

Personal data on a website: how to comply with 152-FZ and avoid a fine

A feedback form without consent to data processing is already a violation. What a site must have under 152-FZ: a policy, consents, a Roskomnadzor notification, a cookie banner.

July 1, 2026
9 min read
69 views
MOLOTILO

MOLOTILO DIGITAL

Personal data on a website: how to comply with 152-FZ and avoid a fine

Why this concerns every site with a form

A name and phone number in a “Request a call” form are personal data. If you collect them, you are a personal-data operator with all the obligations under 152-FZ (Russia’s personal data law). Fines have risen noticeably and keep tightening: for missing consent — up to ₽300k for a legal entity (repeat — up to ₽500k), for leaks — millions, and since 2025 there are turnover-based fines for repeat leaks. Roskomnadzor checks sites, including automatically, so “we are small, no one will notice” no longer works.

Disclaimer: we are developers, not lawyers; this article is a guide — for complex cases you need a data-protection lawyer.

The minimum set for a site

1. A personal data processing policy

A separate page: what data you collect, why, how you store and protect it, whom you share it with, how to delete it. A link — in the footer of every page. A template from the internet is better than nothing, but adapt it: the purposes listed in the policy must match reality.

2. Consent in every form

  • A “I consent to the processing of personal data” checkbox with a link to the policy — on every form: request, callback, comments, subscription.
  • The checkbox is not pre-ticked — this is a direct requirement.
  • Without the tick the form does not submit.
  • Consent to marketing — a separate checkbox, not bundled with the request.

3. Roskomnadzor notification

An operator must notify Roskomnadzor about the start of personal data processing before it begins — via a form on the agency’s site. There are almost no exceptions left. It is free, done once, and non-submission is fined.

4. A cookie banner

Analytics and pixels collect identifiers that practice treats as personal data. Put up a “We use cookies” banner with a link to the policy. Requirements are tightening toward explicit consent — build in an “accept/decline” option.

5. Storing data in Russia

Databases with Russians’ personal data must be primarily stored on servers in Russia. The practical conclusion: the hosting and database are Russian; foreign form and CRM services are a legal risk.

Technical measures (asked about during a check and after a leak)

  • HTTPS across the whole site — submitting forms in the clear is already a “failure to take protective measures”.
  • Access to requests — by role, not “the admin password in a shared chat”.
  • CMS and plugin updates — most small-business leaks happen through leaky plugins.
  • A designated person responsible for data processing (by order) and a couple of internal documents — they are the first thing requested.
  • A leak now must be reported to Roskomnadzor within 24 hours — have a plan for this.

Common misconceptions

  • “We just have a phone form, that’s not personal data” — phone + name = personal data.
  • “We’re a sole trader, the law is for the big ones” — the law is for all operators, including sole traders and the self-employed with a site.
  • “We added a checkbox — done, we can sleep easy” — consent is only one item; a policy, the Roskomnadzor notification and data protection are also mandatory.

A checklist for today

  1. A personal data policy on the site, a link in the footer.
  2. Consent checkboxes in all forms (not pre-ticked).
  3. The Roskomnadzor notification submitted.
  4. A cookie banner in place.
  5. HTTPS, an updated CMS, role-based access.
  6. Hosting in Russia.

Takeaway

Bringing a site into compliance with 152-FZ is a day’s work; a fine is hundreds of thousands and your reputation. We will check your site and implement everything technical: forms, policy, banner, HTTPS — write to us.

Enjoyed the article?

Subscribe to our blog so you don’t miss new posts