Skip to content

How to file the Roskomnadzor notification

Key idea:

The personal-data processing notification is filed with Roskomnadzor before processing starts — via the agency's portal form (electronically with Gosuslugi identity confirmation, or on paper). Filing is free. The notification describes purposes, data and subject categories, legal bases, protection measures and the location of the databases. Once listed in the operator registry, changes must be reported with a follow-up notification.

Check your site →

Who must file

Since September 2022 virtually every operator files — legal entities, sole proprietors and individuals processing personal data: the old broad exemptions (employees-only, contract-only) were repealed. A website with a request form already qualifies. The remaining exemptions are narrow: state secrets, transport security, and purely manual processing without automation — a typical website fits none of them.

What the notification states

  • Operator name, address, tax ID
  • Processing purposes — per category (site requests, mailings, HR)
  • Categories of personal data and of subjects
  • Legal bases (consent, contract, statute)
  • The list of operations and processing methods
  • Protection measures, including encryption, and the person responsible for processing
  • Database location details — the localisation requirement of Art. 18(5)

The form is filled in on the Roskomnadzor portal; draft it from your policy — an honest policy nearly rewrites itself into the notification.

Deadlines, changes, self-check

File before processing starts; report changed details (a new purpose, a new CRM, a database move) with an additional notification. Ceasing processing is also reported. Verify your listing in the public operator registry. The technical side — forms, documents, counters, server localisation — is shown by the compliance scanner: its report is handy to reconcile against what the notification declares.

Related

Cookies Before ConsentWhat is written without permission
Consent BannerIs there an equal Reject option
PII FormsConsent and policy at the form
Projections152-FZ and GDPR grades

Why teams trust us

A–F
grade + 152-FZ/GDPR
3
browser sessions per page
PDF
integrity-signed report
Free
scan without signup

How it works

1

Enter your site URL

2

The scanner opens pages in a browser

3

Get a grade and a fix list

Why check your site for privacy compliance?

Regulators fine sites for processing personal data without consent — and a site starts processing earlier than it seems: analytics, pixels and widgets write cookies the moment the page loads. The scanner shows the auditor's view: what leaves for third parties before consent, whether the banner works, and whether forms collect data correctly.

Real Browser

Three sessions per page: no action, banner accepted, banner rejected.

Trackers and Jurisdiction

Service catalogue: who receives visitor data and in which country.

Policy at Collection Point

The policy link and consent element are checked next to the form, not in the footer.

Signed PDF

Report with an HMAC integrity stamp — hand it to your lawyer or contractor.

Who uses this

Business

preparing for an audit

Lawyers

technical facts for an opinion

Web Studios

client site handover

DevOps

consent regression monitoring

Common Mistakes

Loading analytics before consentA counter in writes cookies before any banner. This is exactly what an audit records.
Banner without a Reject buttonConsent is voluntary only when refusing is as easy as agreeing.
Policy only in the footerThe visitor must see who receives their data at the moment of submission — next to the form itself.
Checking once and forgettingA new widget or tag manager quietly adds trackers. Only a re-check catches the regression.

Best Practices

Delay trackers until consentInitialise analytics from the CMP accept callback, not on page load.
Offer an equal RejectAccept and Reject buttons — same size, same level.
Consent checkbox at every formUnchecked by default, with the processing policy linked right there.
Turn on monitoringA standing watch alerts you when the grade drops — before an auditor notices.

Monitor compliance automatically

Scheduled re-checks with an alert when pre-consent trackers appear on your site.

Sign up free

Learn more

Frequently Asked Questions

How long does review take?

Registry inclusion usually takes up to 30 days. Processing may start once the notification is filed — the law does not require waiting for the listing.

What happens for operating without a notification?

Failure to file is a standalone administrative offence with fines for legal entities reaching hundreds of thousands of roubles — and, worse, a marker inviting an unscheduled inspection of everything else.

Are this and the cross-border notification the same thing?

No, they are two separate filings: the base processing notification, and a dedicated cross-border transfer notification when data leaves Russia.

Try the live tool that powered this guide

Free plan — 10 monitors, checks every 5 min, no card required. Upgrade for 1-minute interval and multi-region monitoring.