+7 499 460-63-47 RU

EMPLOYMENT LAW FOR EMPLOYERS / 05

Personal data compliance

Almost every company processes the personal data of customers and employees, and in recent years the requirements have tightened, as have the fines. We work out how data is collected, stored and transferred, and put the documents and processes in order.

Call: +7 (499) 460-63-47
For whom
Companies and entrepreneurs
Format
Moscow and remotely across Russia

What is happening

An online shop collects customers' phone numbers and addresses through its website, runs web analytics and a CRM, and has a privacy policy downloaded from the internet five years ago. Nobody has ever notified Roskomnadzor, the data protection regulator.

There has been a breach: an export of the customer database has turned up in the public domain or left with a former employee. The company needs to know what it must do and by when, without making matters worse.

The company uses foreign cloud services and passes employee data to its foreign parent. Management is unsure whether the data localisation and cross-border transfer requirements have been met.

What the law says

  • An operator must have a legal basis for processing each category of data, publish its processing policy and take organisational and technical protective measures (Articles 18.1 and 19 of the Personal Data Law).
  • Before processing begins, the operator as a rule notifies Roskomnadzor, and gives separate notice of its intention to transfer data across borders (Articles 22 and 12 of the Personal Data Law).
  • When data of Russian citizens is collected, its recording, systematisation, accumulation and storage must use databases located in Russia (Article 18 of the Personal Data Law).
  • The operator must notify Roskomnadzor of an unlawful transfer of data within 24 hours, and of the results of its internal investigation within 72 hours (Article 21 of the Personal Data Law).
  • Liability is set by Article 13.11 of the Code of Administrative Offences; data breaches attract increased fines that depend on the number of individuals affected, and repeat breaches attract fines calculated on turnover.
  • Consent, where required, must be specific, informed, conscious and unambiguous, and separate consent is needed to make data publicly available (Articles 9 and 10.1 of the Personal Data Law).

What we do

  • We audit what data is collected, where it comes from, where it is stored, who receives it and on what basis it is processed.
  • We map the processes and list the information systems in which personal data is processed.
  • We draft the documents: the processing policy, internal regulations, consent forms, instructions to processors and orders appointing the person responsible.
  • We prepare and file notifications with Roskomnadzor, including on cross-border transfers.
  • We review the wording and forms on the website and in the app, and contracts with contractors and service providers.
  • In an incident, we help organise the first hours, prepare the notifications and handle dealings with Roskomnadzor.
  • We defend the company and its officers in administrative offence proceedings.

What we will need from you

  • A list of processes in which data is collected: website, app, CRM, HR, building access, video surveillance.
  • The current policy, consent forms and internal documents on personal data.
  • A list of the information systems and services where data is held, with the location of the servers.
  • Contracts with providers who have access to the data: hosting, mailing services, call centre, outsourced accounting.
  • Details of notifications already filed with Roskomnadzor, and of past inspections and incidents.

HOW THE WORK IS BUILT

How the work is built

Interviews

We go through the business processes and systems with the responsible staff and IT.

1–2 meetings

Audit

We map the data and list the gaps with an assessment of risk.

1–3 weeks

Documents

We prepare the set of documents and notifications and agree them with you.

1–2 weeks

Support

We help implement the changes and advise on new processes and incidents.

as required

QUESTIONS

Frequent questions

We are a small company. Do we also have to notify Roskomnadzor?

Most likely yes: the exemptions from notification are narrow. We check whether your processing falls under any of them and, if not, prepare the notification.

Is a consent tick box on the website enough?

No, not unless it is backed by proper consent wording, a policy and a clear purpose. Moreover, many operations need no consent at all but a different legal basis, and using consent in its place is a mistake.

What should we do in the first hours after a breach?

Record what happened, stop further disclosure, establish what data is affected and prepare the initial notification to Roskomnadzor within 24 hours. Call us straight away: time runs from the moment the incident is detected.

NEXT STEP

Let us discuss your situation

The consultation is free of charge when an engagement agreement is signed: on it we say what has to be done and by when.

Call: +7 (499) 460-63-47