Skip to content

Fines for violating 152-FZ

Key idea:

Liability scales from hygiene-level offences to catastrophic ones. Processing without consent — up to ₽300k for legal entities (Art. 13.11(1)), an unpublished policy — up to ₽60k (13.11(3)), collecting Russians' data without a database in Russia — up to ₽6M (13.11(8)), repeat — up to ₽18M (13.11(9)). Breaches are a separate block: fixed multi-million fines scaled by incident size, and a repeat breach triggers a turnover-based fine as a share of annual revenue. A sole proprietor is fined as a legal entity under this article.

Check your site →

Offences a routine site audit finds

  • Part 1 — processing without consent or violating its terms: forms without a checkbox, pre-ticked boxes, trackers before consent — up to ₽300k
  • Part 3 — the policy not published or inaccessible: up to ₽60k
  • Part 8 — localisation: databases with Russians' data outside Russia — up to ₽6M; repeat (part 9) — up to ₽18M
  • Failure to file the RKN notification — a standalone offence, up to hundreds of thousands of roubles

These are exactly the offences the compliance scanner tags in its report: each finding carries the article and its upper range, and the total sums distinct articles — the way a court would.

Breaches: a different order of magnitude

Since 2025 data breaches are priced separately and harshly: fixed fines for legal entities run into millions and grow with incident scale (thousands, tens of thousands, hundreds of thousands of subjects); leaking special categories or biometrics costs more; failing to report the incident to RKN is its own fine. A repeat breach moves the company into turnover-fine territory — a share of annual revenue with a multi-million floor. The economics are plain: prevention is orders of magnitude cheaper than the first incident.

Setting priorities

  1. Close localisation (part 8) — the most expensive of the fixable items
  2. Sort out consent at forms (part 1) — the most common offence
  3. Publish the policy and file the notification — the cheapest items on the list
  4. Run the site through the scanner: the report sorts findings by severity and shows the total rouble exposure

Related

Cookies Before ConsentWhat is written without permission
Consent BannerIs there an equal Reject option
PII FormsConsent and policy at the form
Projections152-FZ and GDPR grades

Why teams trust us

A–F
grade + 152-FZ/GDPR
3
browser sessions per page
PDF
integrity-signed report
Free
scan without signup

How it works

1

Enter your site URL

2

The scanner opens pages in a browser

3

Get a grade and a fix list

Why check your site for privacy compliance?

Regulators fine sites for processing personal data without consent — and a site starts processing earlier than it seems: analytics, pixels and widgets write cookies the moment the page loads. The scanner shows the auditor's view: what leaves for third parties before consent, whether the banner works, and whether forms collect data correctly.

Real Browser

Three sessions per page: no action, banner accepted, banner rejected.

Trackers and Jurisdiction

Service catalogue: who receives visitor data and in which country.

Policy at Collection Point

The policy link and consent element are checked next to the form, not in the footer.

Signed PDF

Report with an HMAC integrity stamp — hand it to your lawyer or contractor.

Who uses this

Business

preparing for an audit

Lawyers

technical facts for an opinion

Web Studios

client site handover

DevOps

consent regression monitoring

Common Mistakes

Loading analytics before consentA counter in writes cookies before any banner. This is exactly what an audit records.
Banner without a Reject buttonConsent is voluntary only when refusing is as easy as agreeing.
Policy only in the footerThe visitor must see who receives their data at the moment of submission — next to the form itself.
Checking once and forgettingA new widget or tag manager quietly adds trackers. Only a re-check catches the regression.

Best Practices

Delay trackers until consentInitialise analytics from the CMP accept callback, not on page load.
Offer an equal RejectAccept and Reject buttons — same size, same level.
Consent checkbox at every formUnchecked by default, with the processing policy linked right there.
Turn on monitoringA standing watch alerts you when the grade drops — before an auditor notices.

Monitor compliance automatically

Scheduled re-checks with an alert when pre-consent trackers appear on your site.

Sign up free

Learn more

Frequently Asked Questions

Is every checkbox-less form fined separately?

Practice charges the offence, not the finding count: same-type violations are normally qualified under one article. Our report therefore sums distinct articles, not individual forms.

Any discounts for small business?

The Administrative Code allows half-rate fines for small enterprises under several offences and a warning for a first violation, but that is not a strategy to rely on.

Which is dearer: the fine or the cleanup?

Basic hygiene (policy, consents, notification) is a few hours of work. Part 1 alone runs to ₽300k, so the question answers itself.

Try the live tool that powered this guide

Free plan — 10 monitors, checks every 5 min, no card required. Upgrade for 1-minute interval and multi-region monitoring.