Skip to content
RU

152-FZ on a Tilda website

Key idea:

Tilda ships every tool you need, but they are off by default. The plan: enable the consent checkbox in each form's settings, create a policy page and bind it to the checkbox, add a cookie banner, and audit where submissions go — a form integration with a foreign service means cross-border data transfer. The builder is not liable for your site: the operator is you, not the platform.

Check your site →

Forms: checkbox and policy

Every Tilda form has a consent block in its settings — it adds a checkbox with a document link. What matters:

  • Create the policy page (a regular page or /privacy) and point the checkbox to it
  • Do not enable "pre-checked" — a pre-ticked box is not an expression of will
  • Check every form block individually: the setting is per-form, not site-wide

Where submissions go

Tilda itself is a Russian service, but submissions are often forwarded: Google Sheets, Notion, foreign CRMs and mail services. Each receiver is a transfer; a foreign one is cross-border — with an RKN notification and a policy entry. Russian receivers (amoCRM, Bitrix24, mail on a Russian domain) remove the issue. The form's integration list is visible in its settings — walk through all of them.

Cookie banner and counters

Analytics and pixels on Tilda sites are usually wired through site settings and load immediately. Add a cookie-consent banner (Tilda has a ready block) and describe the counters in the policy. Then run the site through the compliance scanner — it checks forms, documents and counters, and shows what loads before consent, across several pages at once.

Related

Cookies Before ConsentWhat is written without permission
Consent BannerIs there an equal Reject option
PII FormsConsent and policy at the form
Projections152-FZ and GDPR grades

Why teams trust us

A–F
grade + 152-FZ/GDPR
3
browser sessions per page
PDF
integrity-signed report
Free
scan without signup

How it works

1

Enter your site URL

2

The scanner opens pages in a browser

3

Get a grade and a fix list

Why check your site for privacy compliance?

Regulators fine sites for processing personal data without consent — and a site starts processing earlier than it seems: analytics, pixels and widgets write cookies the moment the page loads. The scanner shows the auditor's view: what leaves for third parties before consent, whether the banner works, and whether forms collect data correctly.

Real Browser

Three sessions per page: no action, banner accepted, banner rejected.

Trackers and Jurisdiction

Service catalogue: who receives visitor data and in which country.

Policy at Collection Point

The policy link and consent element are checked next to the form, not in the footer.

Signed PDF

Report with an HMAC integrity stamp — hand it to your lawyer or contractor.

Who uses this

Business

preparing for an audit

Lawyers

technical facts for an opinion

Web Studios

client site handover

DevOps

consent regression monitoring

Common Mistakes

Loading analytics before consentA counter in writes cookies before any banner. This is exactly what an audit records.
Banner without a Reject buttonConsent is voluntary only when refusing is as easy as agreeing.
Policy only in the footerThe visitor must see who receives their data at the moment of submission — next to the form itself.
Checking once and forgettingA new widget or tag manager quietly adds trackers. Only a re-check catches the regression.

Best Practices

Delay trackers until consentInitialise analytics from the CMP accept callback, not on page load.
Offer an equal RejectAccept and Reject buttons — same size, same level.
Consent checkbox at every formUnchecked by default, with the processing policy linked right there.
Turn on monitoringA standing watch alerts you when the grade drops — before an auditor notices.

Monitor compliance automatically

Scheduled re-checks with an alert when pre-consent trackers appear on your site.

Sign up free

Learn more

Frequently Asked Questions

Tilda stores submissions itself — does that satisfy localisation?

Submissions in the Tilda dashboard are stored in Russia, so for that part — yes. But copies going to foreign integrations break localisation: trace the submission's full route.

Is the stock policy from Tilda templates good enough?

As a draft. Replace the operator, purposes, data scope and recipients with yours: the template knows nothing about your CRM, telephony or mailings.

Is a separate mailing checkbox needed in a Tilda form?

Yes, if the form subscribes to emails: consent to process a request and consent to advertising are different purposes; Tilda supports a second checkbox.

Try the live tool that powered this guide

Free plan — 10 monitors, checks every 5 min, no card required. Upgrade for 1-minute interval and multi-region monitoring.