- Job title
- Front office accounting
- Sector
- IT services
- Organization type
- 20-person company
- Joined
- Sep 2024
- Message
- 27
We run a small online bakery and gift shop based in Saint Petersburg. Through our site, we take orders and collect names, phone numbers, emails, and delivery addresses for our newsletter. We handle around 250 deliveries a month on average, and we've accumulated records for about 3,000 registered customers in our system.
Last week, our local accounting consultant told us our website is in serious violation of Russia's 152-ФЗ personal data protection law. Our server was hosted with a provider in Germany our site just has a contact form without any checkboxes, and we never posted a privacy notice.
We want to sort the system out quickly before facing fines or getting the site blocked. What are the basic requirements this law imposes on small businesses? Where should we start, and what are the most common mistakes small websites make?