Separate Personal Data Consent in Russia: Checklist for Sites and CRM
Since September 1, 2025, consent to personal data processing under 152-FZ can't be bundled into terms or contracts. What to change in forms, chatbots and CRM.
Published: 2025-09-03
Since September 1, 2025, Russian law requires consent to personal data processing to be drawn up separately from anything else the person signs or confirms. It can no longer sit inside a public offer, a contract or website terms of use. For businesses this is mostly an interface task: website forms, chatbots and the CRM are easiest to rework so that consent is a distinct action by the customer and is stored in the system.
What changed on September 1
Federal Law No. 156-FZ of June 24, 2025 (Article 5) added one sentence to Part 1 of Article 9 of 152-FZ, Russia's personal data law: consent must be drawn up separately from any other information or documents that the data subject confirms or signs. Under Part 2 of Article 7 of 156-FZ, the rule took effect on September 1, 2025.
What did not change:
- Consent still has to be specific, substantive, informed, conscious and unambiguous (Part 1, Article 9 of 152-FZ).
- The burden of proving that consent was obtained lies with the operator, i.e. the company (Part 3, Article 9).
- Consent is not always the legal basis. Processing needed to perform a contract with the customer, or to conclude one at the customer's request, is a separate ground (Clause 5, Part 1, Article 6).
- Marketing calls and messages require prior consent, and in a dispute the company must prove it was obtained (Part 1, Article 15).
- Consent to make data publicly available already had to be separate from other consents (Part 1, Article 10.1).
What follows is what this means for forms, bots and the CRM. These are development recommendations, not legal advice: have a lawyer sign off on consent texts and legal bases.
Website forms
The most common pattern on Russian websites is a single checkbox under the form: "I accept the offer, the privacy policy and consent to the processing of my personal data." Here consent is confirmed in one action together with the offer and the policy, while Part 1 of Article 9 now requires it to be drawn up separately from any other information or documents the person confirms.
What to change in forms:
- A standalone consent text on its own page, with a version number and date. The personal data policy is a different document with its own link.
- A separate checkbox for consent, linking to that text. If you need the offer accepted, give it its own checkbox.
- No pre-ticked boxes. The person ticks the box themselves, so the log records their own action. It is the simplest way to show that consent is conscious and unambiguous, as Part 1 of Article 9 requires.
- Marketing separately. Consent to newsletters is a third, optional checkbox; the form submits without it.
Audit every collection point, not just the main form: quizzes, calculators, pop-ups, mobile app sign-up, landing pages built by contractors.
CRM: proving consent
The company has to prove that consent was obtained (Part 3, Article 9). So in practice a checkbox on the website is not much on its own: you need a record in the system. The consent data we recommend storing:
| What to store | Why |
|---|---|
| Customer and contact | Link consent to the CRM record |
| Consent type | Processing, marketing, publication are separate |
| Text version | Prove which wording the person agreed to |
| Date and time | Show when consent was obtained |
| Channel | Website, chat, messenger, bot, app, offline |
| Technical evidence | Form page, phone confirmed by one-time code |
| Withdrawal: date, channel | Stop processing and remove from mailing lists |
Good practice is an append-only log. If a manager can edit a consent date after the fact, the log is weak evidence.
Check integrations separately. Forms often push leads to the CRM via webhook or email, and the consent flag gets lost on the way: the name and phone arrive, the consent mark does not. That is an integration fix, not a website copy fix. The fewer hand-offs between systems, the fewer places where the flag can get lost. For service chains, we brought online booking and the customer base into one system in our own product, Aphorio. If you are rebuilding your customer records anyway, it is easiest to design the consent log in from the start — this is how we approach CRM projects.
AI chatbots and website chat
A booking bot collects personal data right inside the conversation. In our AI booking bot project for a spa salon chain, the bot picks a service and time slot and creates a booking in the CRM, which requires a name and phone number. Where consent is the legal basis for processing, it makes sense to place the consent step before the bot asks for the phone number, not after.
How it works in a dialogue:
- The bot answers questions about services and prices without collecting any data.
- Before booking, it shows a short message with a link to the consent text and an "I agree" button.
- Only then does it ask for the name and phone and pass them to the CRM together with the consent record, text version and conversation ID.
- If the customer declines, the bot offers another route: call the front desk or book in person.
We tackled this in our own product, DialIQ: its website chat can show the privacy policy and consent text, record that consent was given, and ask for a name and phone number confirmed with a one-time code. The consent wording and legal basis remain the company's responsibility; the service records that the person accepted them.
If the bot runs on an external language model, conversation data goes to one more processor. Discuss with a lawyer how to reflect that in your documents.
Liability
Fines for personal data violations are set by Article 13.11 of Russia's Code of Administrative Offences (KoAP). For legal entities, among others:
- Part 1 — processing in cases not provided for by law, or incompatible with the purposes of collection: RUB 150,000–300,000 (as amended by 420-FZ, in force since May 30, 2025);
- Part 2 — processing without written consent where it is mandatory, or with consent missing required details: RUB 300,000–700,000 (as amended by 589-FZ);
- Part 2.1 — repeat violation of Part 2: RUB 1–1.5 million.
Also keep in mind that a CRM with a customer base is a personal data store. 420-FZ introduced fines for data leaks: RUB 3–15 million for companies depending on the number of people affected (Parts 12–14), and for a repeat leak 1% to 3% of revenue, but no less than RUB 20 million and no more than RUB 500 million (Part 15).
What this means for business
The change affects anyone collecting leads online in Russia: service businesses with online booking, clinics, schools, online stores, B2B companies with website forms. For most, this is not a system rebuild but an update to forms, CRM fields and integrations. It is harder where data comes in through many channels and lands in different systems — there, an inventory comes first.
Checklist
- List every point where you collect personal data: forms, quizzes, chats, messenger bots, the app, paper forms.
- For each one, decide the legal basis: a contract with the customer or consent.
- Publish a standalone consent text with a version and date on a permanent page.
- Remove consent wording from the offer, contracts and terms of use.
- Add a separate, unticked consent checkbox to forms, plus an optional one for marketing.
- Set up a consent log in the CRM: type, version, date, channel, withdrawal.
- Verify that the consent record reaches the CRM from every form and bot.
- Build consent into the chatbot flow before it asks for a phone number.
- Define the withdrawal process: where customers write and how it updates the CRM and mailing lists.
- Update paper forms: consent goes on a separate sheet, not as a clause in the contract.
Sources
- Federal Law No. 156-FZ of 24.06.2025 — Official legal information portal of Russia (in Russian)
- Federal Law No. 266-FZ of 14.07.2022 — Official legal information portal of Russia, current wording of Part 1, Article 9 of 152-FZ on consent requirements (in Russian)
- Federal Law No. 519-FZ of 30.12.2020 — Official legal information portal of Russia, Article 10.1 of 152-FZ (in Russian)
- Article 9 of 152-FZ: consent of the data subject — ConsultantPlus (in Russian)
- Article 6 of 152-FZ: conditions for processing personal data — ConsultantPlus (in Russian)
- Article 15 of 152-FZ: processing for marketing purposes — ConsultantPlus (in Russian)
- Federal Law No. 589-FZ of 12.12.2023 amending the Code of Administrative Offences — Official legal information portal of Russia (in Russian)
- Federal Law No. 420-FZ of 30.11.2024 amending the Code of Administrative Offences — Official legal information portal of Russia (in Russian)