Legal and compliance requirements for the site: 152-FZ, GDPR, CCPA

17.06.20254 min read
Sergey Martynov
Legal Advisor for IT and data complianceSergey Martynov

⚖️ A modern website is not just code. It is a legal entity in the digital space. Violations in the field of data collection and storage can cost companies millions of rubles in fines and loss of customer trust.

Why comply with legal regulations on the site at all?

According to Cisco Data Privacy Benchmark Study (2025), Companies that comply with data protection requirements gain a competitive advantage.

Some 86% of international respondents recognized the positive impact of privacy laws on their business. While compliance requires costs (developing consent modules, hiring a DPO), 96% of organizations report that the return on investment in privacy outweighs the cost.

A site that collects applications, e-mails, phone numbers, cookies or uses Yandex Metrica - already processes personal data. Violation can lead to:

  • fines from Roskomnadzor (up to 500,000 ₽ for each case)
  • blocking a website in the Russian Federation
  • claims from users and “consumer terrorism”
  • international sanctions when working with residents of the EEA (EU) or the USA

📌 NBM-IT specialists implement a comprehensive compliance site audit, including adaptation to 152-FZ, GDPR and CCPA. We don’t just write “papers” - we technically implement consent collection processes into the architecture of your project.

Free SEO audit of your website

Leave a request and our specialists will find areas of search traffic growth.


🇷🇺 152-FZ (Russia): basic and hidden requirements

Federal Law No. 152-FZ “On Personal Data” is the alpha and omega for sites in RuNet. Changes in recent years have tightened control over companies that collect data in reserve.

What is considered personal data? Any information directly or indirectly related to an individual:

  • Name, phone, email, IP address, MAC address of the device.
  • Geolocation and behavior data (Yandex Metrics session identifiers).
  • Files (resume, photo) uploaded through feedback forms.

Mandatory checklist for the site under 152-FZ:

  1. PD processing policy: A link to it should be accessible from any page of the site (usually in the footer). The document must be specific, and not downloaded from a 2015 generator.
  2. Explicit Consent: The checkbox in the feedback form should not be checked by default (Pre-ticked box is a direct violation). The user must click on it themselves.
  3. Goal setting: If a person left an email to receive a price list, you you have no right enter his database for weekly marketing mailings without separate consent.
  4. Database localization: The primary collection and storage of data of citizens of the Russian Federation must take place on servers physically located on the territory of Russia (Article 18, Part 5).

🇪🇺 GDPR (European Union): the gold standard for privacy

GDPR (General Data Protection Regulation) applies to all sites that interact with EU citizens or residents, even if the company is physically located in Russia, Kazakhstan or the UAE. It is enough that you offer goods/services in euros or have a version of the site in the language of an EU country.

Key differences between GDPR and 152-FZ:

  • Cookie banners without compromise: Functionality for selecting cookie categories is required (strictly necessary, marketing, analytical). The “Refuse All” button should be as prominent as the “Accept All” button. The option “By continuing to use the site, you agree...” is invalid under the GDPR (ECJ decision in the Planet49 case).
  • Right to be forgotten: The site should have a mechanism that allows the user to request complete deletion of their profile and purchase history with one click.
  • Export data: The obligation to provide the user with an archive of his data in machine-readable format (JSON/CSV) upon request.

💬 Fines for violating the GDPR can reach €20 million or 4% of the company’s global annual turnover. Meta was fined €1.2 billion for illegal cross-border data transfers.


🇺🇸 CCPA (USA, California): focus on commercialization

California Consumer Privacy Act (CCPA) regulates websites serving California residents. The law even applies to foreign companies if their revenue exceeds $25 million or they process the data of 50,000+ state residents.

The main requirement of the CCPA - option «Do Not Sell My Personal Information» (Do not sell my personal information). If your site shares data with advertising networks (such as Facebook Pixel or Google Ads for retargeting), this is classified as a “sale of data” under California law, even if no money physically changes hands.

The site is required to provide the user with a transparent link (often in the footer), clicking on which instantly disables the transfer of his data to advertising trackers.


How to automate Compliance at the code level?

Legal validation requires technical tools (Consent Management Platform - CMP). Modern methods of implementing compliance:

  • Google Consent Mode v2: Allows Google tags (Analytics, Ads) to adapt their behavior based on the user's consent status from the Cookie banner. If the user refuses cookies, anonymous pings are sent (Cookieless pings).
  • Audit Logs: Your database should store a consent log: user_id, ip_address, timestamp, consent_version_hash. This is the only way you can prove to Roskomnadzor or the EU court that a specific person really checked the box.
  • Base protection: Encryption of PII (Personally Identifiable Information) data at the SQL level (for example, email hashing or phone tokenization).

Free project cost estimate

Answer 4 questions and we will send you a range of prices to suit your needs.

1. What type of corporate website do you need?


Summary

Compliance is more than text in the footer of a website. This is an architectural requirement. Ignoring 152-FZ, GDPR or CCPA can jeopardize not only the budget, but also the existence of the digital product.

Do you need integration of the 152-FZ consent module, setting up Google Consent Mode or data logging audit? NBM-IT Development Team adapts your website to the most stringent international legal standards.

Useful on the topic

Leave your contacts - we will call you back, sort out the problem and offer the best way. We have more than 350 projects behind us, each of which we launched with an individual approach. We guarantee expert advice during business hours.