Compliance review (152-FZ / GDPR / CCPA)
We check the site against typical personal-data and privacy requirements: the cookie banner and consents, the privacy policy and consent to processing, what data you collect and where it goes, trackers and third-party scripts, the data-residency question (152-FZ) — and build a prioritized list of what to put in order. Honestly and upfront: we are not lawyers, this is an informational and technical review, not a legal opinion and not a guarantee of legal compliance — the final legal assessment is given by a lawyer.
Compliance review (152-FZ / GDPR / CCPA) — overview

A compliance review (152-FZ / GDPR / CCPA) is a one-time technical and substantive check of how your site handles personal data and privacy, against the typical requirements of Russia's 152-FZ and the foreign GDPR (EU) and CCPA (California): whether the privacy policy and consent to processing of personal data exist and are correct, how the cookie banner and consent collection (CMP) are built, what data is collected by forms and counters and where it is sent, which trackers and third-party scripts are in place (analytics, pixels, chats), the data-residency question (152-FZ requires that the personal data of Russian citizens be stored in databases on Russian territory), cross-border transfer, and consent/unsubscribe forms. The goal is to show the gaps and risks and to give a prioritized plan of what to put in order. Honestly and without evasion about the main point: we are not lawyers and not a licensed audit firm, and this service is an informational and technical review, NOT a legal opinion, not a certification and not a guarantee of compliance or protection from fines (Roskomnadzor, the FAS, EU regulators, etc.). We will point out where typical non-conformities and risks are visible from a technical and substantive standpoint, but the final legal assessment for your specific situation and jurisdiction must be given by a qualified lawyer or DPO — our report helps them. Laws and their enforcement change, the requirements of different countries differ and sometimes conflict — there is no universal "compliant with everything at once" (for example, a cookie banner sufficient for GDPR may not cover the 152-FZ requirement to store Russian citizens' data in Russia). The results cannot be complete or exhaustive: this is a limited, point-in-time check, while the legal and technical context constantly changes. And bluntly: within this service we do not make changes and do not prepare legal documents — this is diagnosis, and the implementation and the legal part are done by your lawyer. It is a snapshot in time. Access is needed: to the site, forms, counter settings and, where possible, information about where and how data is stored; without it the check will be based on what is visible from the outside. What you get: a report with the gaps and risks found, by priority (policy, consents, cookies, trackers, residency) and recommendations on what to put in order and in what order, and which questions to take to a lawyer; implementing the fixes and the legal documents are separate work. If you have a landing page with no forms or data collection, we will honestly say there is almost nothing to check. Picture this: instead of "it all seems legal" you learn that the cookie banner sets analytics cookies before consent, the policy lacks the required clauses, and form data goes to a foreign service with no note about cross-border transfer. The base price starts from 25,000 ₽; it depends on the site size and the number of jurisdictions.
Problems we solve
- You are not sure the site meets personal-data requirements.
- There is a cookie banner and a policy, but it is unclear if they are correct.
- You work with a foreign audience (EU, US) and fear violations.
- You received a request or complaint about personal data and want to check the site.
What's included in the Compliance review (152-FZ / GDPR / CCPA) service
- Privacy policy and consent to processing: presence and completeness
- Cookie banner and consent collection (CMP): correctness and the moment cookies are set
- Inventory: what data is collected by forms and counters
- Trackers and third-party scripts (analytics, pixels, chats) and where data goes
- Data residency (152-FZ) and cross-border transfer
- Consent and unsubscribe forms and handling of data-subject requests
- Differences and conflicts of 152-FZ / GDPR / CCPA requirements
- A prioritized report with gaps, risks and questions for a lawyer
What you get
- Clear understanding of where typical non-conformities and risks are visible
- Priorities: what to put in order first
- A list of questions to take to a lawyer (not instead of one)
- Understanding where it is technical and where a legal assessment is needed
How the work goes: steps
- We clarify the jurisdictions, audience and collect access (site, forms, counters, storage info)
- We check the policy, consents, cookies, trackers and data residency
- We prepare a prioritized report with risks and questions for a lawyer and review it with you
Why PDV Expert
- Fixed price and timeline — no surprises on the invoice.
- Report and recommendations in plain language — clear without a technical background.
- In touch at every step and answering questions about the result.
FAQ
Is this a legal opinion and a guarantee I will not be fined?
No. We are not lawyers, this is an informational and technical review, not a legal opinion, not a certification and not a guarantee of compliance or protection from fines. We show technical and substantive gaps and risks, while the final legal assessment is given by a lawyer or DPO for your situation.
Will you bring the site into compliance and prepare the documents?
The audit is diagnosis and a plan. Implementing the fixes (banner, settings, data migration) and the legal documents (policy, consents) are separate work: we can do the technical part, your lawyer the legal part. We honestly separate what is included.
Do you check Russian 152-FZ and GDPR and CCPA?
Yes, against the typical requirements of each, but these are different laws with different and sometimes conflicting requirements. "Compliant with everything at once" does not happen automatically — we will show the discrepancies and priorities for your markets.
About the provider
The «Compliance review (152-FZ / GDPR / CCPA)» service is provided by PDV Expert — a team specialising in «Diagnostics & monitoring». We work under contract and deliver a written report with recommendations.