// Engineering Log

Personal Data Protection: What Federal Law 152-FZ Requires of Small Businesses

Published on 2026-09-21

The Federal Law of July 27, 2006 No. 152-FZ “On Personal Data” establishes the rules by which companies and individual entrepreneurs collect, store, and use information about people. Over the past two years the law’s requirements have tightened noticeably, and fines have increased many times over, so even the smallest business should understand them.

What the law regulates

The law regulates the processing of personal data — any actions with them: collection, recording, storage, clarification, use, transfer, deletion. Its purpose is to protect a person’s rights when information about them is processed, including the right to privacy, and personal and family secrecy.

If you collect, store, or use information about people — surname, name, phone number, email, address, date of birth — you are obliged to comply with this law.

Who is considered an operator

An operator is the one who organizes the processing of personal data and determines why and how it is carried out. You are an operator if:

  • your website has a form where visitors leave their name, phone, or email;
  • you collect customer contacts for mailings or calls;
  • you have employees and keep personnel records;
  • you maintain a database of customers or individual suppliers, including in a CRM system.

The size of the business does not matter: an individual entrepreneur without employees who accepts applications via a website is also an operator.

What is considered personal data

Personal data is any information directly or indirectly relating to an identified or identifiable person. For example:

  • surname, given name, patronymic;
  • date and place of birth;
  • residential address;
  • phone number and email address;
  • passport details, INN, SNILS;
  • place of work and position;
  • IP address and identifiers from cookies — if in combination with other information they allow identifying the person.

Main requirements

  • Lawfulness. Processing must have a lawful basis: the person’s consent, a contract with them, or a legal requirement.
  • Consent. If consent is the basis, it must be specific, targeted, informed, conscious, and unambiguous. From September 1, 2025 consent must be executed separately from any other documents: it cannot be included in a contract, a user agreement, or a data processing policy. Consents obtained before that date do not need to be reissued.
  • Defined purpose. Data must be collected for a predefined purpose. You cannot collect it “just in case.”
  • Minimal volume. Only what is necessary for that purpose should be collected. Passport data is not needed for a mailing.
  • Accuracy. Data must be accurate and updated when necessary.
  • Limited retention period. Data is stored no longer than required by the processing purpose and is then destroyed or anonymized.
  • Protection. The operator must take legal, organizational, and technical measures against unauthorized access to data, their destruction, alteration, blocking, copying, and dissemination. This includes appointing a person responsible for organizing processing, approving a personal data processing policy and publishing it on the website, limiting employee access to data, and transmitting data via protected channels.
  • Localization. The collection, recording, systematization, accumulation, storage, clarification, and extraction of personal data of Russian citizens must be carried out using databases located in Russia. From July 1, 2025 primary entry of data into foreign databases is explicitly prohibited: for example, a form on a website must not send applications immediately to a foreign server or foreign service.
  • Breach notification. Upon discovering a breach, the operator must notify Roskomnadzor within 24 hours, and within 72 hours report the results of the internal investigation.

Liability

Fines are established by Article 13.11 of the Code of Administrative Offenses of the Russian Federation; from May 30, 2025 they have increased significantly. For organizations, in particular:

  • processing without a lawful basis, including without proper consent — from 300,000 to 700,000 rubles;
  • failure to submit a notification of the start of processing to Roskomnadzor — from 100,000 to 300,000 rubles;
  • failure to report a breach — from 1 to 3 million rubles;
  • violation of the localization requirement — from 1 to 6 million rubles, repeated — up to 18 million;
  • data breach — from 3 to 15 million rubles depending on the number of affected persons, and for special categories and biometric data — up to 20 million;
  • repeated breach — from 1 to 3% of annual revenue, but not less than 20 million and not more than 500 million rubles.

Since December 11, 2024 Article 272.1 of the Criminal Code has been in force: illegal use, transfer, collection, and storage of computer information containing personal data obtained illegally is a criminal offense.

In addition, by court decision a site that violates the rights of personal data subjects can be added to the register of violators and blocked.

Where to start

  1. Make a list of data. Determine what information about people you collect, where it is stored, who has access to it, and what it is needed for.
  2. Prepare documents. Approve a personal data processing policy and publish it on the website. It should indicate the purposes of processing, the composition of the data, retention periods, and protection measures.
  3. Make consent separate. The consent text on the site must be a separate document, and the consent checkbox in a form must not be pre-checked.
  4. Check where data is stored. Hosting, CRM, mailing services, and form services that receive data of Russian citizens must use databases in Russia.
  5. Notify Roskomnadzor. Since September 1, 2022 the scope of exceptions has narrowed, and most operators, including small companies and individual entrepreneurs, are required to notify Roskomnadzor of the start of processing. The notification is submitted on Roskomnadzor’s personal data portal pd.rkn.gov.ru.
  6. Protect the data. Use HTTPS on the site, strong passwords and two-factor authentication, limit access to data to only those employees who truly need it.

Compliance with Federal Law No. 152-FZ is the responsibility of every operator. Basic steps are not complicated and cost incomparably less than the fines.

I will set up a network or infrastructure for your needs

I will sort out the configuration, explain the principles, and make it work stably.

Написать в Telegram →

// Contact

Need help?

Get in touch with me and I'll help solve the problem

I reply within one business day (03:00-13:00 GMT)

Или оставьте заявку здесь:

Confirm that you are not a bot.

Write and get a quick reply