Why this concerns every site with a form
A name and phone number in a “Request a call” form are personal data. If you collect them, you are a personal-data operator with all the obligations under 152-FZ (Russia’s personal data law). Fines have risen noticeably and keep tightening: for missing consent — up to ₽300k for a legal entity (repeat — up to ₽500k), for leaks — millions, and since 2025 there are turnover-based fines for repeat leaks. Roskomnadzor checks sites, including automatically, so “we are small, no one will notice” no longer works.
Disclaimer: we are developers, not lawyers; this article is a guide — for complex cases you need a data-protection lawyer.
The minimum set for a site
1. A personal data processing policy
A separate page: what data you collect, why, how you store and protect it, whom you share it with, how to delete it. A link — in the footer of every page. A template from the internet is better than nothing, but adapt it: the purposes listed in the policy must match reality.
2. Consent in every form
- A “I consent to the processing of personal data” checkbox with a link to the policy — on every form: request, callback, comments, subscription.
- The checkbox is not pre-ticked — this is a direct requirement.
- Without the tick the form does not submit.
- Consent to marketing — a separate checkbox, not bundled with the request.
3. Roskomnadzor notification
An operator must notify Roskomnadzor about the start of personal data processing before it begins — via a form on the agency’s site. There are almost no exceptions left. It is free, done once, and non-submission is fined.
4. A cookie banner
Analytics and pixels collect identifiers that practice treats as personal data. Put up a “We use cookies” banner with a link to the policy. Requirements are tightening toward explicit consent — build in an “accept/decline” option.
5. Storing data in Russia
Databases with Russians’ personal data must be primarily stored on servers in Russia. The practical conclusion: the hosting and database are Russian; foreign form and CRM services are a legal risk.
Technical measures (asked about during a check and after a leak)
- HTTPS across the whole site — submitting forms in the clear is already a “failure to take protective measures”.
- Access to requests — by role, not “the admin password in a shared chat”.
- CMS and plugin updates — most small-business leaks happen through leaky plugins.
- A designated person responsible for data processing (by order) and a couple of internal documents — they are the first thing requested.
- A leak now must be reported to Roskomnadzor within 24 hours — have a plan for this.
Common misconceptions
- “We just have a phone form, that’s not personal data” — phone + name = personal data.
- “We’re a sole trader, the law is for the big ones” — the law is for all operators, including sole traders and the self-employed with a site.
- “We added a checkbox — done, we can sleep easy” — consent is only one item; a policy, the Roskomnadzor notification and data protection are also mandatory.
A checklist for today
- A personal data policy on the site, a link in the footer.
- Consent checkboxes in all forms (not pre-ticked).
- The Roskomnadzor notification submitted.
- A cookie banner in place.
- HTTPS, an updated CMS, role-based access.
- Hosting in Russia.
Takeaway
Bringing a site into compliance with 152-FZ is a day’s work; a fine is hundreds of thousands and your reputation. We will check your site and implement everything technical: forms, policy, banner, HTTPS — write to us.



