Liability scales from hygiene-level offences to catastrophic ones. Processing without consent — up to ₽300k for legal entities (Art. 13.11(1)), an unpublished policy — up to ₽60k (13.11(3)), collecting Russians' data without a database in Russia — up to ₽6M (13.11(8)), repeat — up to ₽18M (13.11(9)). Breaches are a separate block: fixed multi-million fines scaled by incident size, and a repeat breach triggers a turnover-based fine as a share of annual revenue. A sole proprietor is fined as a legal entity under this article.
Free online tool — compliance checker: instant results, no signup.
These are exactly the offences the compliance scanner tags in its report: each finding carries the article and its upper range, and the total sums distinct articles — the way a court would.
Since 2025 data breaches are priced separately and harshly: fixed fines for legal entities run into millions and grow with incident scale (thousands, tens of thousands, hundreds of thousands of subjects); leaking special categories or biometrics costs more; failing to report the incident to RKN is its own fine. A repeat breach moves the company into turnover-fine territory — a share of annual revenue with a multi-million floor. The economics are plain: prevention is orders of magnitude cheaper than the first incident.
Regulators fine sites for processing personal data without consent — and a site starts processing earlier than it seems: analytics, pixels and widgets write cookies the moment the page loads. The scanner shows the auditor's view: what leaves for third parties before consent, whether the banner works, and whether forms collect data correctly.
Three sessions per page: no action, banner accepted, banner rejected.
Service catalogue: who receives visitor data and in which country.
The policy link and consent element are checked next to the form, not in the footer.
Report with an HMAC integrity stamp — hand it to your lawyer or contractor.
preparing for an audit
technical facts for an opinion
client site handover
consent regression monitoring
Scheduled re-checks with an alert when pre-consent trackers appear on your site.
Sign up freePractice charges the offence, not the finding count: same-type violations are normally qualified under one article. Our report therefore sums distinct articles, not individual forms.
The Administrative Code allows half-rate fines for small enterprises under several offences and a warning for a first violation, but that is not a strategy to rely on.
Basic hygiene (policy, consents, notification) is a few hours of work. Part 1 alone runs to ₽300k, so the question answers itself.
Free plan — 10 monitors, checks every 5 min, no card required. Upgrade for 1-minute interval and multi-region monitoring.