The absence of a policy entails administrative liability. Angelina Balakina, head of practice at the Orlova\Ermolenko law firm, noted that liability may be tightened this year: "Since 2017, the legislator has been constantly tightening liability for violations in the field of personal data protection; this topic has become sensitive cameroon whatsapp number database for citizens and the state over the past few years. One of the latest innovations was the amendments to Article 13.11 of the Code of Administrative Offenses of the Russian Federation in terms of increasing fines for the lack of consent to the processing of personal data or non-compliance with the requirements of the law. Also, in January 2024, the State Duma adopted in the first reading a bill (No. 502104-8), significantly increasing liability for violations in the event of a leak of personal data. Otherwise, liability remains the same. Thus, failure to fulfill the obligation to post a privacy policy on the website entails the imposition of an administrative fine on officials in the amount of 6-12 thousand rubles, on individual entrepreneurs - from 10 thousand to 20 thousand rubles, on legal entities - 30-60 thousand rubles."
data is primarily fraught with fines. The maximum fine is for storing personal data outside the territory of the Russian Federation. It is already measured in millions of rubles. And for SMEs, this is a fairly common violation, since, due to ignorance, personal data is stored in foreign cloud services. And this is a significant violation. But soon, businesses will bear even more responsibility for the leakage of personal data: the introduction of turnover fines is expected, which operate with fundamentally different figures. Also, the responsibility itself will increase to criminal. In especially serious cases, the fine can be up to half a billion rubles, and even up to 10 years in prison," reminds Alexey Parfentyev.
"The fine may seem small, but the absence of a policy on the site may lead to additional questions when the site is checked by representatives of Roskomnadzor, since the absence of a policy in this case, most often, will not be the only violation. Thus, it is important for operators to monitor compliance with the requirements not only for the policy, but also for all aspects of processing personal data using their site, such as, for example, placing a cookie banner, correct design of collection forms, etc.," warns Nikita Volodin.
"The practice of ignoring the requirements for processing personal
-
- Posts: 553
- Joined: Thu Jan 02, 2025 7:17 am