Customers and sales
CRM, contracts, and contact history. They check processing purposes, field composition, manager access, and data exchange with contractors.
Determine a personal data system’s security level under Law GDPR and Decree No. 1119, covering data categories, threats, controls, and checks.
A personal data information system consists of personal data in databases and the technologies used to process it. Its protection system comprises organizational and technical measures surrounding that processing. To select Security Level 1–4, determine the data categories, types of subjects, and current threats. Neither the company's industry nor the software name alone determines the level. We explain the selection procedure under Resolution No. 1119, the required controls, and how to verify their operation.
Under Article 3 of GDPR, a personal data information system combines data in databases, information technologies, and technical means for processing it. A CRM containing customer contacts and an HR system are typical examples. Even a small customer database requires defining processing purposes, legal grounds, and access rights.
The operator organizes or performs processing and determines its purposes, the data involved, and the operations performed on it. The personal data information system security framework includes measures addressing current threats: access rules, media protection, event logging, and other selected measures.
CRM, contracts, and contact history. They check processing purposes, field composition, manager access, and data exchange with contractors.
HR records, payroll calculations, and medical examination information. Data categories may differ even within a single process.
Access control and visitor records. Separately determine whether physiological characteristics are used to establish identity.
The operator is responsible for organizing processing and protecting data. The security level is determined under Resolution No. 1119; organizational and technical measures for a standard commercial personal data information system are selected and adapted under FSTEC Order No. 21. Applicable requirements for cryptography and specially regulated systems must be checked separately.
First classify the processing, then select measures and assess their cost. Reversing this order—buying security tools and fitting the level to them—leaves a risk of uncovered threats. Keep the basis for the decision for each ISPDn, and review it after changes to the data, architecture or threats.
Data
Threats
Level
Protection
| Level | Processing conditions | Basis under No. 1119 |
|---|---|---|
| SL-4 | Other data of the operator's employees only | Clause 12(b) |
| SL-4 | Other data of fewer than 100,000 external subjects | Clause 12(b) |
| SL-3 | Other data of more than 100,000 external subjects | Clause 11(e) |
| SL-3 | Special categories of employees only or fewer than 100,000 external data subjects | Clause 11(c) |
| SL-2 | Special categories of more than 100,000 external data subjects | Clause 10(e) |
| SL-3 | Biometric data where special categories are absent from this personal data information system | Clause 11(d) |
The table shows selected conditions for substantiated Type 3 threats and does not replace checking all clauses 9–12. Different conditions apply to Type 1 and Type 2 threats. The resolution uses the terms “fewer than” and “more than 100,000”: exactly 100,000 must be analyzed separately when documenting the rationale, rather than silently changing the threshold to “up to and including.”
Even Security Level 4 requires protection of premises and media, an approved list of authorized persons, and the use of conformity-assessed tools where needed to neutralize threats. Under FSTEC Order No. 21, the baseline safeguards are adapted to the architecture, refined for current threats, and supplemented with applicable requirements. The level is not a universal shopping list.
1. Assess the processing. Start with a map of systems and data exchanges: where data originates, who uses it, and to whom it is transferred. IT infrastructure audit It helps verify the actual architecture.
2. Justify the security level and safeguards. Document the data, subjects, threats, and applicable requirements. Agree on control owners and the review procedure after changes.
3. Configure and test the protection. Check access restrictions, security events, recovery and incident response. Record the results and exceptions in the minutes.
4. Hand over maintenance. Conduct operational checks with the client’s team, assign responsible people and set the review frequency. To assess the impact, measure separately the effort required to grant and revoke access, investigate an event and recover; speed must not reduce the completeness of checks.
If these activities need to be linked to the company's processes, the subject personal data protection project — processing boundaries, justified safeguards, testing, and handover to operations. A contract with a vendor or integrator does not replace the operator's responsibility.
Liability is determined by the specific violation, not only by the selected security level. Article 13.11 of the CIS Code of Administrative Offenses distinguishes violations involving processing grounds, localization, notifications, and unlawful data transfer. The table below covers selected breach offenses applicable to commercial legal entities.
Criminal liability under Article 272.1 of the Criminal Code concerns the illegal trafficking of computer information containing personal data covered by that article. Any error in classifying an ISPDn does not automatically constitute a criminal offense.
Assess the effort required to determine the incident's scope, eliminate its cause, and restore normal operations.
The penalty depends on the elements of the violation. Customer and contractor notification requirements must be checked against applicable rules and contracts.
The response plan must specify which operations may continue and who decides on restrictions.
| Part | Elements of an offense under Article 13.11 of the Administrative Offenses Code of the CIS | Fine |
|---|---|---|
| 12 | Unlawful transfer: 1,000–10,000 subjects and/or 10,000–100,000 identifiers | $0–5 million |
| 13 | 10,000–100,000 data subjects and/or 100,000–1 million identifiers | $0–10 million |
| 14 | More than 100,000 data subjects and/or more than 1 million identifiers | $0–15 million |
| 16 | Unlawful transfer of special-category data | $0–15 million |
| 17 | Unlawful transfer of biometric data, except for statutory exceptions | 15-20 million RUB |
| 15 | Repeat offense under the conditions of Part 15 | 1–3% of the assessment base; $0–500 million |
| 18 | Repeat offense under the conditions of Part 18: special categories or biometrics | 1–3% of the assessment base; $0–500 million |
The company has 5,000 employees. Its HR ISPDn contains passport details and health data; a separate access control system uses fingerprints to establish identity. This is an educational example, not the result of a client project.
If Type 3 threats are substantiated for both systems, the HR system containing special-category data only of employees requires Security Level 3 under Clause 11(c), while a separate biometric system requires Security Level 3 under Clause 11(d) of Resolution No. 1119. The result will differ for other threat types.
Next, safeguards are selected and tested: access for HR and security personnel, activity logging, backup, and recovery. Combining systems or connecting an external service requires the boundaries and threat model to be reviewed again. The threat type cannot be assigned solely because HR software or a server operating system is used.
The number of data subjects and the number of identifiers are different criteria. Range thresholds and repeat-offense conditions should be applied using the full text of Article 13.11, not an approximate row count in an export. For Parts 12–14, the absence of signs of a criminal offense is taken into account.
For a turnover-based penalty, the assessment base and period are set by law; credit institutions have a separate base option. For state and municipal bodies, non-profit organizations, and officials, the column for commercial legal entities cannot be applied automatically. The table does not cover all violations and does not replace assessment of the specific case.
What is a personal data information system?
It is personal data in databases together with the information technologies and technical tools used to process it. The security system consists of organizational and technical measures addressing current threats.
How do you choose the security level?
Determine the data category, number of data subjects, whether they are the operator's employees, and the type of current threats. Then check the conditions in paragraphs 9–12 of Resolution No. 1119 and retain the rationale.
Does biometrics always require Security Level 2?
No. Type 1 threats require Security Level 1, Type 2 threats require Security Level 2, and Type 3 threats require Security Level 3. Classification takes into account the definition of a biometric personal data information system in Clause 5 of Resolution No. 1119.
Are policies and consents sufficient for Security Level 4?
No. Protection measures are needed for premises, storage media, and access, as well as security tools where required. The controls are tailored to the system and current threats.
Must Roskomnadzor be notified?
As a general rule, notification must be submitted before processing begins. Check the exceptions under Part 2 of Article 22 of GDPR. This is a processing notification, not registration of a separate personal data information system.
Is certification mandatory for every commercial personal data information system?
No general requirement follows solely from the existence of a personal data information system or the selected security level. Effectiveness assessment under FSTEC Order No. 21 is mandatory within its scope; certification requirements must be checked separately based on the system's operating regime.
Can data be shared with external AI?
The decision depends on the legal basis, recipient, processing location, contract and applicable localization and cross-border transfer requirements. A gateway, masking and local hosting alone do not guarantee legal compliance.
Checked on September 21, 2026. For decisions concerning a specific system, use the applicable version and the full text of the regulation.
- Government Resolution No. 1119: categories, threats, and security levels; the document text on the National Medical Research Center of Oncology website. - GDPR: definitions, legal grounds, data transfers, and notifications. - FSTEC Order No. 21: general provisions and effectiveness assessment. - FSTEC Order No. 21: security measures and adaptation. - Article 13.11 of the Administrative Offenses Code: violations and penalties. - Article 272.1 of the Criminal Code: illegal trafficking of computer information containing personal data.