152-FZ audit: what it includes, how long it takes and what happens if you postpone it
152-FZ applies to any company processing personal data in Russia — customers, employees, site users. Since 2025, data leaks carry turnover-based fines. Here is what an audit and full compliance actually consist of.
Who must comply
Practically everyone: a website form, a customer base in a CRM or HR records already make a company a personal data operator. Special triggers — medical and biometric data, minors' data, sharing data with contractors and cross-border transfers — each carry additional requirements.
What inaction costs
- ◇Turnover-based fines for leaks: up to 3% of revenue for a repeat leak (20–500 million ₽); fixed fines up to 15 million ₽ for a first large leak.
- ◇Fines for procedural violations: missing regulator notification, missing consents, unpublished policy.
- ◇Regulator inspections — scheduled and complaint-driven (an unhappy customer or ex-employee is the most common source).
- ◇Blocking partner requirements: enterprise customers increasingly require proven compliance before signing.
What compliance consists of
- ◇Assessment: what personal data exists, where it lives, who has access, which contractors receive it. Output — a systems map and a gap list.
- ◇Categorization and protection levels per government decree No. 1119.
- ◇A formal threat model using the FSTEC methodology — the basis for choosing technical measures.
- ◇The document set: processing policy, purpose-specific consents, processor agreements, orders, logs, incident response procedure.
- ◇Organizational steps: regulator notification (including cross-border transfers), an appointed responsible person, staff training.
How long it takes
An express assessment takes about 2 weeks: a personal data processing map, a compliance checklist and a prioritized remediation plan. Full turnkey compliance takes 4–6 weeks: assessment, threat model, the complete document set and inspection readiness.
Common mistakes we find
- ◇One catch-all consent instead of purpose-specific consents — it fails at inspection.
- ◇Forgotten processors: cloud hosting, SaaS services and outsourced accounting handle your data without agreements.
- ◇Cross-border transfers without regulator notification — mail services, foreign clouds and analytics.
- ◇A policy copied from a competitor that does not match real processes — worse at inspection than no policy.
- ◇Documents without technical measures: the whole company shares one password to the customer database.
FAQ
In 2 weeks: a personal data processing map, a 152-FZ compliance checklist and a prioritized remediation plan. The price is fixed before work starts.
Get a quote in 24 hours