Skip to content

152-FZ for a sole proprietor

Key idea:

A sole proprietor is a full-fledged personal-data operator: a website with a request form already means processing customers' data. The mandatory minimum is a Roskomnadzor notification before processing starts, a published policy, and consent at every form. Key detail: under the note to Art. 13.11 of the Administrative Code, a sole proprietor is fined as a legal entity — up to ₽300k under part 1, not a token individual fine.

Check your site →

Why a sole proprietor is an operator

152-FZ does not distinguish big and small operators: an operator is anyone who defines the purposes and scope of personal-data processing. A sole proprietor with a landing page and a "Leave your phone" form fits the definition entirely. The personal-and-family-needs exemption does not cover commercial lead collection.

  • RKN notification — filed before processing starts; since September 2022 the exemptions are minimal and a site with forms does not qualify
  • Processing policy — a public document on the site
  • Consent at forms — a checkbox or an explicit wording at the button

Fines: a sole proprietor pays as a legal entity

A common mistake is expecting an individual-level fine. The note to Art. 13.11 explicitly equates persons doing business without forming a legal entity to legal entities. So processing without consent (part 1) is up to ₽300k, a missing policy (part 3) has its own range, and database-localisation violations (part 8) reach ₽6M.

A one-evening minimal plan

  1. Publish the policy and the consent text (two pages: /privacy and /consent)
  2. Add a consent checkbox with a policy link to every form
  3. File the notification via the Roskomnadzor portal
  4. Check the site with the compliance scanner: it finds forms without consent, missing documents and foreign trackers — across several pages at once

Related

Cookies Before ConsentWhat is written without permission
Consent BannerIs there an equal Reject option
PII FormsConsent and policy at the form
Projections152-FZ and GDPR grades

Why teams trust us

A–F
grade + 152-FZ/GDPR
3
browser sessions per page
PDF
integrity-signed report
Free
scan without signup

How it works

1

Enter your site URL

2

The scanner opens pages in a browser

3

Get a grade and a fix list

Why check your site for privacy compliance?

Regulators fine sites for processing personal data without consent — and a site starts processing earlier than it seems: analytics, pixels and widgets write cookies the moment the page loads. The scanner shows the auditor's view: what leaves for third parties before consent, whether the banner works, and whether forms collect data correctly.

Real Browser

Three sessions per page: no action, banner accepted, banner rejected.

Trackers and Jurisdiction

Service catalogue: who receives visitor data and in which country.

Policy at Collection Point

The policy link and consent element are checked next to the form, not in the footer.

Signed PDF

Report with an HMAC integrity stamp — hand it to your lawyer or contractor.

Who uses this

Business

preparing for an audit

Lawyers

technical facts for an opinion

Web Studios

client site handover

DevOps

consent regression monitoring

Common Mistakes

Loading analytics before consentA counter in writes cookies before any banner. This is exactly what an audit records.
Banner without a Reject buttonConsent is voluntary only when refusing is as easy as agreeing.
Policy only in the footerThe visitor must see who receives their data at the moment of submission — next to the form itself.
Checking once and forgettingA new widget or tag manager quietly adds trackers. Only a re-check catches the regression.

Best Practices

Delay trackers until consentInitialise analytics from the CMP accept callback, not on page load.
Offer an equal RejectAccept and Reject buttons — same size, same level.
Consent checkbox at every formUnchecked by default, with the processing policy linked right there.
Turn on monitoringA standing watch alerts you when the grade drops — before an auditor notices.

Monitor compliance automatically

Scheduled re-checks with an alert when pre-consent trackers appear on your site.

Sign up free

Learn more

Frequently Asked Questions

I only sell via marketplaces and phone, no website. Am I an operator?

If you record customers (name, phone) in a spreadsheet or CRM — yes, you process personal data. The notification and internal documents are needed; the website is secondary.

Is the RKN notification paid?

No, filing is free. It is submitted through the Roskomnadzor portal form and usually processed within 30 days.

Can I take a competitor's policy and swap the details?

The skeleton — yes; the substance — no: purposes, data scope and third parties (CRM, counters, telephony) are unique to each business. A policy with someone else's facts asserts falsehoods on your behalf.

Try the live tool that powered this guide

Free plan — 10 monitors, checks every 5 min, no card required. Upgrade for 1-minute interval and multi-region monitoring.