// 152-FZ · website · law
What a website must have under 152-FZ and what a mistake costs
Which documents a website that collects personal data needs: policy, separate consent, cookies, operator details. And what happens if they are missing.
in short / answer
If a website collects personal data (a request form, a subscription, a chat, a visitor counter), its owner is an operator under Federal Law No. 152-FZ (Russia’s personal data law). The operator needs a published data processing policy, a separate consent to processing (from September 1, 2025, as a separate document), an honest description of cookies and counters, and details of who the operator is. A notification to Roskomnadzor (Russia’s data protection regulator) is filed before processing begins. Fines fall under Article 13.11 of the Russian Code of Administrative Offences (KoAP RF): their amount depends on the type of violation and on who the violator is, so current amounts should be checked against the current wording of the article.
Almost every small business website has a “Leave a request” form or a “Call me back” button. With it, the owner gets obligations under the personal data law, Federal Law No. 152-FZ (Russia’s personal data law). They are often remembered only when an inspection or a complaint arrives. Let us go through what a website must have, which mistakes are the most common, and why we do not give the “cost” of a mistake as a single figure.
This is an overview, not legal advice. The requirements depend on what data a particular website collects and what is done with it next. Before publishing the documents, have a lawyer check them.
When does a website process personal data?
Personal data is any information that relates, directly or indirectly, to a specific person. On a website it is usually:
- a name, phone number and email from a request or callback form;
- correspondence in the website chat;
- an address for a mailing list or subscription;
- data collected by visitor counters and advertising pixels: cookies, IP address, device identifiers.
If at least one of these is present, the website owner becomes a personal data operator, and the requirements of 152-FZ apply. It does not matter whether it is a company or a sole proprietor.
Which documents must a website have?
The set depends on the website, but for a website with a request form the basic kit is this.
- Personal data processing policy. An operator that collects data online must publish a document on its processing policy and ensure free access to it (Art. 18.1, part 2 of 152-FZ). The policy describes who the operator is, what data is collected and why, on what basis, how long it is stored, to whom it is transferred, how it is protected, and how a person can exercise their rights.
- Consent to personal data processing. Consent must be specific, informed, conscious and unambiguous (Art. 9 of 152-FZ). From September 1, 2025, it must be drawn up separately from other documents: a line such as “by clicking the button, you agree to the policy” inside the form, or a clause in a user agreement, does not meet this. The form should have a checkbox with a link to the consent text, and it must not be pre-checked.
- Cookie policy and cookie notice. If the website has visitor counters or advertising pixels, the visitor must be told which cookies are set, why, and how to refuse them. This is usually done with a separate document and a banner on the first visit.
- Operator details. A visitor must understand who processes their data: the name, or the full name of the entrepreneur, INN (taxpayer ID), OGRN or OGRNIP (sole proprietor registration number), and contacts for inquiries. If the website sells something to consumers, the consumer protection law (Art. 9) also separately requires details about the seller.
There is one obligation that is not visible on the website: before processing begins, the operator files a notification with Roskomnadzor (Russia’s data protection regulator) (Art. 22 of 152-FZ). Whether it has been filed can be checked in the open register of operators on the Roskomnadzor website.
Which mistakes are the most common?
The same problems come up again and again on small business websites.
- A link to nowhere. Under the form it says “consent to personal data processing”, but the link leads to an empty page or to
#. - Consent hidden inside the policy. There is no separate document, only the phrase “by submitting the form, you agree”.
- A pre-checked box. Such consent is hard to call conscious and unambiguous.
- A template without adaptation. The policy still has someone else’s details, placeholders in square brackets instead of the full name and INN, or it describes data the website does not collect. Meanwhile, the real services, such as a counter or a chat widget, are not mentioned.
- A counter is installed, but there is no information about it. Metrica or a pixel is running, but the documents say nothing about it, and there is no banner either.
- It is unclear who the operator is. The footer has only a logo and a phone number, without INN and OGRN.
What does a mistake cost?
Liability for violations in the area of personal data is set by Article 13.11 of the Russian Code of Administrative Offences (KoAP RF). It has several parts. For example, processing without consent where consent is required, or with a consent that lacks the necessary information (part 2), is punished separately, and so is failing to publish the processing policy (part 3). There are also offences for data leaks and for storing Russians’ data in databases outside Russia.
We deliberately do not name a single amount “per document”. The size of the fine depends on the part of the article, on who the violator is (an individual, an official, an entrepreneur or a legal entity), and on whether the violation is repeated. In 2025, amendments came into force that changed the fines under this article. Current amounts should be checked against the current wording of Article 13.11 of KoAP RF on the date of the inspection, not against figures from other people’s articles.
Besides the fine, there are other consequences: an order from Roskomnadzor to remedy the violations, client complaints, and, for lawyers and other companies that sell trust, questions about reputation.
How can you check your website in ten minutes?
- Open every form on the website. Next to it there should be a link to the policy and a separate, not pre-checked consent checkbox with a link to its text.
- Follow these links. The documents should open, not lead to an empty page.
- Compare the text with what the website actually does: which fields the forms have, which counters, chats and services are connected.
- Look at the footer: is there the name or full name of the entrepreneur, INN, OGRN or OGRNIP, and contacts.
- If a visitor counter is installed, check whether there is a cookie notice and whether cookies are described in the documents.
- Find yourself in the Roskomnadzor register of operators.
If the answer to any item is “no”, that is your list of fixes.
How is this handled on our website?
tacticgu.ru currently has no forms, registration or visitor counters. The savings calculator works right in the browser and sends nothing. So the website sets no cookies for visitors, and no banner is needed. The documents are nevertheless published: the personal data processing policy, a separate consent, the cookie policy and legal information with the sole proprietor’s details. When a request form or a counter appears, the documents will be updated, and the form will get a consent checkbox.
If you would like us to look at your website and draw up a list of what to fix, message us on Telegram.
author / CTO, Tactic Guru
Chief technology officer. Builds AI-based systems.