Russia’s 152-FZ for websites: policy, consent and Article 13.11 fines
What Russia’s personal data law asks of a site: policy, consent, the form checkbox, and the fines companies pay under Article 13.11.
Checked against sources: 30 September 2026

- ₽700KPart 2 maximum for a company
- ₽60Kmaximum for a missing policy
- 30.05.2025new rules took effect
What the law requires
- A personal data policy is published on the site and open to everyone without login (Article 18.1).
- Consent is specific, informed and conscious (Article 9): not “I agree to everything”, but tied to purposes.
- The form checkbox is not pre-ticked and the policy is linked nearby.
- The form is submitted over HTTPS and data never appears in the page URL.
Fines for legal entities under Article 13.11
From 30 May 2025 fines were added for not notifying Roskomnadzor about starting processing, up to ₽300,000. Always check the exact part and amount in the current text.
- Part 1, processing in cases the law does not allow: ₽150,000–300,000, ₽300,000–500,000 if repeated.
- Part 2, processing without consent in the required form: ₽300,000–700,000, ₽1–1.5M if repeated.
- Part 3, policy not published: ₽30,000–60,000.
- Part 4, a person was not given information about processing of their data: ₽40,000–80,000.
Where a site should start
Publish the policy in the footer of every page, add a separate consent with a policy link to each form, and make sure form submissions do not travel by unprotected mail. Awe Check shows exactly where the rules are broken and gives the fine range for each item.
Frequently asked
Do I need a policy for a business card site?
Yes, if there is a form or an analytics counter. Even a visitor’s IP address and cookie are treated as data by regulators, so a policy is needed almost always.
How does a company fine differ from a director’s?
Amounts under Article 13.11 are smaller for officials and individuals. The checker shows the amounts for legal entities.
