01 / THE QUESTION
A contact form is already a data flow
A name, email, phone number, message and analytics identifiers may relate to a person. A website owner should know why each item is collected, where it travels and who can access it.
For projects aimed at Russian users, Federal Law No. 152-FZ applies to personal-data processing. The exact duties depend on the operator, processing grounds and services used. This article is a practical starting point, not a legal opinion for a particular business.
02 / BEFORE LAUNCH
Review the whole path of an enquiry
Map fields, analytics, inboxes, CRM, hosting and third parties. Define purposes and lawful grounds. Publish an accessible processing policy. When relying on consent, make it specific and separate from other documents. Check whether the operator must notify Roskomnadzor before processing, where Russian citizens’ data is first recorded and stored, and how access, retention, deletion and incident response work. A checkbox alone does not solve the entire task.
Read my processing policy, consent text and cookie policy as examples of site documents, then adapt your own documents to your actual data flows.
03 / RESPONSIBILITY
The owner remains responsible
A developer can build the form and consent interface; the operator determines purposes and grounds and remains responsible for compliance. Article 13.11 of the Russian Administrative Offences Code provides fines for particular violations, including failure to publish a required policy or notify the authority when required. Check the applicable provision and current amount for your legal status.
Sources: Federal Law No. 152-FZ · Administrative Offences Code, Article 13.11. Reviewed 29 September 2026.
