What you need to know about personal data to avoid paying a 300,000-ruble fine
Starting from July 1, 2017, the fine for violation of the law on personal data processing will increase to 75 thousand rubles.
1. What kind of law?
At the moment, article 13.11 of the code of administrative offences of the Russian Federation States that for violation of the procedure for collecting, storing, using or distributing information about citizens, the fine for legal entities is from 5 to 10 thousand rubles.
In February 2017, amendments were made to article 13.11, which will come into force on July 1, 2017, where various types of violations are described in more detail and the fine for legal entities is increased to 75 thousand rubles. And if there are several violations, then there will be several fines.
The essence of the law is that the site must publish a policy on the collection and processing of personal data, and request the consent of visitors when leaving data.
2. Do I process personal data?
Personal data refers to information that can be used to identify a person. Username and password do not fall under this criterion, since they can not identify a person. But any combination of personal data from the list below is subject to the definition of law 13.11 of the administrative Code :
last name first name and patronymic
date or place of birth
It turns out that all owners of sites that have personal accounts, subscription forms, registration or feedback and where you can buy something, place an ad, fill out a questionnaire are personal data operators. Even if the site only has a button for ordering a call or sending a message , this is also the processing of personal data.
3. What should I do?
4. Cases of punishment under law 13.11 of the administrative Code
In the Tambov region, the Prosecutor’s office fined a law firm for filling out a feedback form without the user’s consent to the processing of personal data. Resolution of the Tambov regional court no. 4A-288/2016
The Director of the management company was fined for giving the debtors ‘ data to lawyers in order to make statements of claim. He did not receive consent to the processing of personal data from the residents. The constitutional court did not help him. Determination of COP No. 100-O of 28.01.16 in the case of the Director of the criminal code
In Astrakhan, prosecutors fine site owners for alphabetical feedback forms. About fines in Astrakhan in the newspaper ” Volga»
In addition to fines in favor of the state for violating the rules for processing personal data, they can collect compensation for moral damage and try to bring criminal responsibility.