Skip to content
RU

How a Roskomnadzor inspection works

Key idea:

The typical scenario is not a scheduled visit but a reaction to a signal: a customer complaint, a breach report, media coverage, or discrepancies visible right on the website. An inspection starts with a document request: the policy, the notification, proof of consents, processor contracts, database-localisation details. The best preparation is a regular self-audit: most of an inspector's findings are visible to you too — earlier.

Check your site →

What triggers an inspection

  • A subject's complaint — an unhappy customer, an employee, a spam-mail recipient
  • An incident — a breach report (yours or a third party's) involving your data
  • Open sources — a site without a policy, forms without consent, foreign trackers are visible without any request
  • The agency's monitoring and materials from other authorities

Tellingly, much of the trigger list is what is visible from outside. The inspector starts where any auditor would: by opening the website.

What they request

  1. The processing policy and proof of its availability to subjects
  2. The RKN notification and the registry entry's currency
  3. Proof of consents: texts and the consent register (who, when, under which revision)
  4. Processor contracts — couriers, CRM, call centres
  5. Localisation: where the databases with Russians' data physically reside
  6. Internal documents: the responsible-person order, the access list, protection measures

A one-day preparation

Walk the inspector's path in advance: open your site as an outsider. The compliance scanner does the external half of that work in minutes — forms without consent, missing documents, trackers before the banner, a foreign server — and returns a report referencing the Administrative Code articles. Fixing findings before the request is cheaper than explaining them in the reply.

Related

Cookies Before ConsentWhat is written without permission
Consent BannerIs there an equal Reject option
PII FormsConsent and policy at the form
Projections152-FZ and GDPR grades

Why teams trust us

A–F
grade + 152-FZ/GDPR
3
browser sessions per page
PDF
integrity-signed report
Free
scan without signup

How it works

1

Enter your site URL

2

The scanner opens pages in a browser

3

Get a grade and a fix list

Why check your site for privacy compliance?

Regulators fine sites for processing personal data without consent — and a site starts processing earlier than it seems: analytics, pixels and widgets write cookies the moment the page loads. The scanner shows the auditor's view: what leaves for third parties before consent, whether the banner works, and whether forms collect data correctly.

Real Browser

Three sessions per page: no action, banner accepted, banner rejected.

Trackers and Jurisdiction

Service catalogue: who receives visitor data and in which country.

Policy at Collection Point

The policy link and consent element are checked next to the form, not in the footer.

Signed PDF

Report with an HMAC integrity stamp — hand it to your lawyer or contractor.

Who uses this

Business

preparing for an audit

Lawyers

technical facts for an opinion

Web Studios

client site handover

DevOps

consent regression monitoring

Common Mistakes

Loading analytics before consentA counter in writes cookies before any banner. This is exactly what an audit records.
Banner without a Reject buttonConsent is voluntary only when refusing is as easy as agreeing.
Policy only in the footerThe visitor must see who receives their data at the moment of submission — next to the form itself.
Checking once and forgettingA new widget or tag manager quietly adds trackers. Only a re-check catches the regression.

Best Practices

Delay trackers until consentInitialise analytics from the CMP accept callback, not on page load.
Offer an equal RejectAccept and Reject buttons — same size, same level.
Consent checkbox at every formUnchecked by default, with the processing policy linked right there.
Turn on monitoringA standing watch alerts you when the grade drops — before an auditor notices.

Monitor compliance automatically

Scheduled re-checks with an alert when pre-consent trackers appear on your site.

Sign up free

Learn more

Frequently Asked Questions

How long is the reply window for a document request?

The deadline is stated in the request itself — usually days, not weeks. That is why the consent register and processor contracts must exist before the request, not be assembled after it.

Are sites checked without an office visit?

Yes: documentary checks and compliance observation run remotely, and the website is a public source of evidence by itself.

How does a first inspection usually end?

With a remediation order carrying a deadline, plus a protocol on the identified offences. Ignoring the order is a separate offence, dearer than the original one.

Try the live tool that powered this guide

Free plan — 10 monitors, checks every 5 min, no card required. Upgrade for 1-minute interval and multi-region monitoring.