Skip to the content
08Security

AI compliance

Fines for personal data, unlabelled advertising and cookies are handed out for formalities that can be closed in a week. We check your website, app and AI services against 152-FZ (Russia’s personal-data law) and the ad-labelling rules, and give you a checklist rather than a retelling of the statute.

What is included

Scope of work
point by point.

  • Inventory: which personal data you collect
  • Forms reviewed: consent, checkboxes, wording, storage
  • Privacy policy written around your actual processes
  • Consent to data processing and consent to marketing, collected separately
  • Check of the filing with Роскомнадзор (the data-protection regulator)
  • Database localisation on Russian territory
  • A cookie banner that actually blocks the trackers
  • Ad labelling and reporting to ERIR (the state advertising register)
  • AI usage rules and disclosure to users
  • GDPR, if you have customers in the EU
  • Report with priorities and an estimate of the fine at stake
Who it fits

Situations
where this pays for itself.

An inspection before the inspection

A review of the site and the processes before a request from the regulator arrives.

Checklist of 40+ items

Starting marketing emails and ads

We collect consent in a form that can actually be produced as evidence, and set up creative reporting.

Consent with proof for every contact

You have adopted AI—now what

We work out which data goes to the model, what has to be disclosed to users and what goes into the policy.

A 3-page AI usage policy

Customers in the EU

A GDPR review: lawful basis, data subject rights, cross-border transfer.

Data flow map

How we do it

Four steps
from brief to handover.

  1. 01

    Inventory

    We build the map: which data, from where, where it is stored, who has access, how long it lives.

  2. 02

    Gap against the requirements

    We compare with 152-FZ, the advertising law and your own commitments. Every gap comes with the size of the fine.

  3. 03

    Documents and fixes

    We prepare the policy, the consent forms and the wording, and fix the forms and the cookie banner in the code.

  4. 04

    Checking the result

    We run the checklist again and hand it over to you, so you can repeat the check yourselves.

Technology

What we
build it with.

152-FZGDPRERIRORDРоскомнадзорCookie ConsentЯндекс.Метрика
Timeline and cost

Three tiers.
The exact estimate follows the brief.

Start

from ₽90,000

5–10 working days

  • One website
  • Audit of forms and consent
  • Privacy policy and personal-data consent
  • Cookie banner set up
  • Report with priorities
Business

from ₽250,000

10–25 working days

  • Website, app and CRM
  • Map of personal data flows
  • Ad labelling and ERIR reporting
  • AI usage policy
  • A 2-hour session for the team
Enterprise

on request

25–60 working days

  • Several legal entities and systems
  • GDPR and cross-border transfer
  • Internal policies and named responsible officers
  • Preparation for a regulator inspection
  • A year of support

Prices are the lower bound. What pushes an estimate up is set out on the pricing page

Questions

About this
service.

01Do we really have to notify Роскомнадзор?

If you collect a name, a phone number or an email through a form on your site, you are a personal-data operator and the filing is mandatory. It is submitted once through the regulator’s website, costs nothing and takes about an hour. The fine for not doing it is up to ₽300,000 for a legal entity.

02What is wrong with the usual “I agree to the policy” checkbox?

Usually two things. First, consent to data processing and consent to marketing are different things in law—one checkbox cannot collect both. Second, the checkbox must not be ticked in advance. Both mistakes appear on almost every site and both are easy to fix.

03We send data to a foreign AI service. Is that a breach?

It is a cross-border transfer, and it needs its own lawful basis and a filing. The simple route is to anonymise the data before sending it: models almost never need real names and phone numbers. We show you where that can be done without losing quality.

04Are you lawyers?

No, and we do not pretend to be. We are engineers: we check how things work technically, prepare documents from tested templates and fix the code. The documents are worth showing to a lawyer before you publish them—we say so plainly in the handover letter.

Get an estimate:
AI compliance

The brief takes 5–7 minutes. In working hours we reply within two hours, and the estimate is free.