152-FZ check

A claim does not only come from a stock agency

Fines for mishandling personal data arrive faster and hurt more than image claims: an inspector only has to open your site and look for a consent checkbox next to the contact form. We look at the site the same way and back every finding with the article of the law and the size of the fine.

  • No install
  • First check is free
  • Full report by email
What the free check looks atFrom the outside, the way an inspector or a stock agency lawyer would — by the code of the pages, the scripts and the image files themselves.
  • Transfers abroadCounters, Google Fonts, reCAPTCHA, chats and pixels — with the owner and jurisdiction of every service.
  • Forms and consentWhether every form has a consent checkbox, whether it is pre-ticked, whether it links to the policy and where the submission goes.
  • Documents on the sitePolicy, consent text, cookie notice and the mandatory sections inside the policy.
  • Connection securityHTTPS on every page and cookies set before the visitor agrees.
  • Rights to imagesPictures from the pages we walk: the filename, the rights holder in the metadata and a stock agency watermark on the shot itself.
Up to eight pages plus external scripts. Usually 20–40 seconds.
How the check works

What is visible from outside in half a minute

The scanner walks the site the way an inspector would — no install and no admin access.

01

Walking the pages

Home, policy, consent text, contacts, checkout, sign-in and registration — up to eight pages, including the site’s own subdomains.

02

Reading the scripts

We download external scripts and Google Tag Manager containers and look for counters, pixels and widgets by their call signatures.

03

Parsing forms and documents

Consent checkboxes, links to the policy, where the submission goes; mandatory policy sections, the cookie notice, cookies before consent and HTTPS.

04

Scoring

Every finding gets a risk level, the article of the law and the range of the fine. Part is shown right away, the full report goes to your email.

What cannot be seen from outside

  • What appears after a visitor’s actions: pop-up forms, checkout steps, the account area
  • Whether the regulator was notified, where the database lives and who is responsible — the plugin asks about that
  • Images, fonts and texts — the plugin checks those from inside the site
What a mistake costs

What a mistake costs and what exactly we check

Four groups of checks. Three run from the outside for free; the fourth the plugin covers with questions that code cannot answer.

up to ₽700kprocessing data without consent, up to ₽1.5m on repeat
up to ₽300kno processing notification filed with the regulator
up to ₽6mthe database of Russian citizens sits abroad
up to ₽15ma data breach, a share of annual revenue on repeat

Cross-border transfers

We open your pages the way a visitor sees them and catch every outbound connection. Twenty-six services in the dictionary, from Google Fonts and reCAPTCHA to Hotjar and Mailchimp, each with its owner and jurisdiction.

  • What exactly the service receives
  • A Russian replacement for it
  • Where on the site it was found

Forms and consent

We parse every form on the site no matter which plugin built it: is there a consent checkbox, is it pre-ticked, does its label link to the policy, is the newsletter opt-in kept separate.

  • Enquiries, comments, checkout
  • A checkbox that starts unticked
  • Marketing consent as its own tick

Documents on the site

We check that the policy is published rather than left as a draft, that the footer links to it, and that the text carries all ten required sections, from processing purposes to how consent is withdrawn.

  • Policy, consent text, cookie notice
  • Which sections are missing
  • Whether foreign recipients are named

Storage and the regulator

What code cannot answer we ask outright: was the notification filed, where does the database live, is a responsible person appointed, is there a breach procedure. Answering "not sure" never turns into a violation.

  • Notification to Roskomnadzor
  • Database kept inside Russia
  • 24 hours to report a breach
The audit is free. Only host names and form traits leave your server; we never see the contents of enquiries or your database. From the findings we can assemble a policy, a consent text and a cookie notice under your own details, and that part is included in a plan. The score is technical and is not legal advice.
Free and without install

Check your own site

No install, no sign-up. The full report with fixes goes to your email.