152-FZ audit: what it includes, how long it takes and what happens if you postpone it

2026-09-03

152-FZ applies to any company processing personal data in Russia — customers, employees, site users. Since 2025, data leaks carry turnover-based fines. Here is what an audit and full compliance actually consist of.

Who must comply

Practically everyone: a website form, a customer base in a CRM or HR records already make a company a personal data operator. Special triggers — medical and biometric data, minors' data, sharing data with contractors and cross-border transfers — each carry additional requirements.

What inaction costs

  • Turnover-based fines for leaks: up to 3% of revenue for a repeat leak (20–500 million ₽); fixed fines up to 15 million ₽ for a first large leak.
  • Fines for procedural violations: missing regulator notification, missing consents, unpublished policy.
  • Regulator inspections — scheduled and complaint-driven (an unhappy customer or ex-employee is the most common source).
  • Blocking partner requirements: enterprise customers increasingly require proven compliance before signing.

What compliance consists of

  • Assessment: what personal data exists, where it lives, who has access, which contractors receive it. Output — a systems map and a gap list.
  • Categorization and protection levels per government decree No. 1119.
  • A formal threat model using the FSTEC methodology — the basis for choosing technical measures.
  • The document set: processing policy, purpose-specific consents, processor agreements, orders, logs, incident response procedure.
  • Organizational steps: regulator notification (including cross-border transfers), an appointed responsible person, staff training.

How long it takes

An express assessment takes about 2 weeks: a personal data processing map, a compliance checklist and a prioritized remediation plan. Full turnkey compliance takes 4–6 weeks: assessment, threat model, the complete document set and inspection readiness.

Common mistakes we find

  • One catch-all consent instead of purpose-specific consents — it fails at inspection.
  • Forgotten processors: cloud hosting, SaaS services and outsourced accounting handle your data without agreements.
  • Cross-border transfers without regulator notification — mail services, foreign clouds and analytics.
  • A policy copied from a competitor that does not match real processes — worse at inspection than no policy.
  • Documents without technical measures: the whole company shares one password to the customer database.

FAQ

We are a small company — does this really apply to us?
Yes. Operator obligations do not depend on size: a website form and a customer base already make you an operator. Only the scope differs — small companies usually fit the express format.
Can we do documents only, without the technical part?
Documents formally cover part of the requirements, but at a leak or inspection the mismatch between paper and real processes works against you. We always start by assessing how data is actually processed.
How much does it cost?
It depends on the number of systems and processes involving personal data. Send the details through the form — a fixed-price quote within 24 hours.
Start with an express assessment

In 2 weeks: a personal data processing map, a 152-FZ compliance checklist and a prioritized remediation plan. The price is fixed before work starts.

Get a quote in 24 hours