Personal data information system: how to classify a PDIS, choose a security level, and comply with GDPR

How to classify ISPDn, choose a UZ-1 to UZ-4 security level, and protect personal data under GDPR to avoid turnover-based fines.

  • What is a personal data system
  • What data counts as personal
  • Duties of a PDIS operator
  • PDIS security levels: how to determine them without mistakes

A personal data protection system is an information system (ISPDn) containing customer and employee data plus the organizational and technical measures that protect it from leaks. To comply with GDPR, the operator classifies the data, chooses a security level for the system from UZ-4 to UZ-1 under Government Decree No. 1119, and takes the required measures for that level from FSTEC Order No. 21. The rest of the article explains how to classify a system as ISPDn, how much protection at each level costs, and what fines apply for classification errors.

What is a personal data system

Any organization that stores data on employees, clients or partners is a personal data operator. Personal Data Information System (PDIS) - is a company's automated system that handles personal information. It covers CRM, databases, HR software and any other tool that collects, stores or processes personal information. Put simply, if your business uses computers and software to handle customer or employee data, you have a PDIS.

What data counts as personal: 4 categories by sensitivity level

Types of PDIS

Cross-functional

They process data on different categories of people - for example, clients, employees and partners. Large companies build them to optimize business processes and cut costs. For instance, a bank may use a single platform to score borrowers and calculate salaries.

Functional

They handle specific tasks in individual company departments. These are CRM platforms for the sales team, HR systems in the HR department, or marketing platforms for analytics.

Accounting and management systems

They automate internal processes - track working hours, calculate vacation and sick leave, manage access to premises.

Information and reference

They provide information to a limited group of users. For example, a counterparty verification system in the legal department or a loyalty database in a retail chain.

Duties of a PDIS operator

To avoid overpaying for security and breaking the law, businesses need to classify the personal data system correctly. The operator is responsible for the security of personal data at all times, from the moment it is collected until it is deleted. The business must implement a protection system capable of effectively resisting current threats.

The specific requirements for building such a system are set by Federal Law No. GDPR and Government Decree No. 1119. Law GDPR sets the basic rules: what is allowed, what is not, and who is responsible for it. Decree No. 1119 it shows which security measures should be used and in what situation. It is what establishes 4 protection levels (UZ) for the system, depending on what data you process and how many clients or employees you have.

What to do in practice: 1. Determine the protection level (PL) - exactly what data you store (standard or sensitive). This determines which protection tools you will need. 2. Choose licensed information protection tools (IPT) - FSTEC and FSB approve the list of permitted software and hardware solutions. You cannot use any tools you like - they must be approved by the regulators.

3. Assemble a package of internal documents - a data processing policy, staff regulations and a process register so you pass inspection without questions. 4. Notify Roskomnadzor - as soon as you start collecting personal data, you must notify the supervisory authority. 5. Sign proper contracts with contractors - if you outsource data handling (for example, to the cloud), the contract must require the contractor to protect the data exactly as you do.

Compliance with these requirements is monitored by: - Roskomnadzor - checks how you collect data and respond to citizens' requests. - FSTEC - assesses how you have organized technical information protection. - FSB - oversees the use of encryption (cryptography). The law requires businesses not merely to have documents, but to maintain active, continuousinformation protection.

If you choose the wrong data category or miss the requirements, you risk a fine of up to 20 million rubles.

Discuss your challenge with an architect

PDIS security levels: how to determine them without mistakes

Choosing the right protection level determines how much you will spend on security systems and which measures you will implement. A mistake leads to two risks: you will overpay for unnecessary protection or leave the data vulnerable, which can lead to leaks and fines.

How the ISPDn security level is determined

PDIS: How to Choose a Protection Level Under GDPR Three factors - the personal data category, the number of data subjects, and the current threat type - determine one of four security levels under Government Decree No. 1119: from UZ-4 with basic measures to UZ-1 with maximum protection and certification. How the security level is determined Government Decree No. 1119 - three inputs, one level out FACTORS Data category special · biometric · other · publicly available Number of data subjects more or fewer than 100,000 people Current threat type 1st (OS/DBMS) · 2nd (application software) · 3rd (people) SECURITY LEVEL UZ-1 · maximum protection, DLP, encryption, certification UZ-2 · firewall, antivirus, access control UZ-3 · password policy, access rights, logs UZ-4 · internal policy and data subject consent Special and biometric data raise the level regardless of the number of records.
The data category, number of data subjects, and threat type under Government Decree No. 1119 determine the UZ-1 to UZ-4 security level, and therefore the measures required and the costs.

To understand how to protect the system, you need to consider 4 key aspects

The legislation divides threats into three categories

How the protection level affects business risks and costs

SLThreat typeWhat to doPractical business benefits
SL-1Type 1 threats (OS and DBMS vulnerabilities)Deploy the maximum set of protection tools, including data leak prevention (DLP) systems and strong encryption. Obtain a compliance certificate.Pass Roskomnadzor and FSTEC inspections with confidence. Build greater trust with major partners.
SL-2Type 2 threats (application software vulnerabilities)Install a firewall, antivirus protection and access control software.You effectively protect the most vulnerable data while minimizing reputational risks.
SL-3Type 3 threats (human factor, insiders)Implement a password policy, segregate employee access rights, and maintain activity logs.You comply with the law at minimal cost, focusing on basic but reliable protection.
SL-4Type 3 threats in limited formAdopt an internal data processing policy and obtain consent from data subjects.Run marketing legally without overspending on complex security systems.

Let's look at an example. A plant with 5,000 employees processes passport data, medical certificates for work clearance, and uses an access control system with fingerprint identification. - What data exists - other (passports), special (medical certificates), and biometric (fingerprints). - Protection level - the presence of biometric and special data automatically requires UZ-2 for these systems. - Threat type - for a system storing passports and medical certificates, threat type 2 is typical (vulnerabilities in HR software), while for a fingerprint system, threat type 1 applies (attacks on the server operating system).

Protection and PDIS organization requirements

After you have determined the UZ, you can start designing the protection system. The specific requirements for protecting personal data are set by FSTEC Order No. 21. Organizational measures - are the basis on which you will be checked in the event of a complaint or audit. They require developing and approving mandatory documents that govern how data is handled, access rights, incident response procedures and employees' individual responsibility.

You need to prepare

Technical protection measures include the following tools

Companies that have deployed secure PDIS not only avoid fines but also demonstrate their reliability to clients and partners.

Step-by-step PDIS protection plan: from audit to system certification

Companies that have deployed secure PDIS not only avoid fines but also gain a real competitive advantage by demonstrating their reliability to clients and partners. Follow the plan — a clear step-by-step algorithm will help minimize costs and build your security system consistently and soundly. ###

Step 1: Audit and classify the system

Compile a complete register of all processes and storage locations for personal data. Record where and how you process data: in CRM, HR departments, accounting. Precisely define the data categories - standard (full name, phone numbers) or special (health status). Based on this information, classify the PDIS by security levels. ###

Step 2: Prepare organizational and administrative documentation

You need to create a package of internal policies that will serve as the foundation for all processes (described above). Such documents prove to the auditing authority that you run an orderly operation, not chaos. ###

Step 3: Deploy technical protection measures

Once you have determined the protection level, choose and implement certified security tools. The contractor selects the security tools for the specific UZ, tests them in a pilot environment before full-scale launch, configures integration of the protection tools with your IT infrastructure, and prepares the technical documentation for the protection system. It is important to understand the boundary of responsibility here. The security vendor is responsible for its product, not for ensuring that the personal data system as a whole complies with the chosen protection level - under GDPR, that responsibility lies with the operator, meaning you.

That is why a contractor is chosen not by the length of the license price list, but by whether they are ready to work from the business process outward: where the personal data actually resides, which events are unacceptable for the company, and how control is embedded into the work of departments. KT.Team does Bringing a personal data processing system into GDPR compliance in this logic, first map the processes and unacceptable events, then define the measures for the required UZ, and then embed control into daily operations and support. ###

Step 4: Train staff and certify the system

Train the team: conduct briefings on how to use protective mechanisms and follow procedures. Put all developed documents into effect and obtain certificate of conformity (issued for 3 years and serves as strong proof of your good faith).

Financial risks

For personal data leaks, legal entities face increased fines, and for repeated violations there are turnover-based penalties - a percentage of the company's annual revenue, not a fixed amount (amendments to the Administrative Offenses Code under Federal Law No. 420-FZ). The law also introduced criminal liability for unlawful trafficking in personal data (Article 272.1 of the Criminal Code of the CIS) - the risk of a personal data system security mistake is now measured in tens of millions of rubles and a criminal charge.

Direct impact on business metrics

Reduced operating profit

Fines of 1–3% of revenue can "swallow" a significant part of a mid-sized business's quarterly profit.

Blocked growth

Funds earmarked for marketing, procurement, or upgrades will have to be redirected to paying penalties.

Loss of investment appeal

A company with a "violator" reputation and the risk of suspended operations becomes less attractive to investors and partners.

Penalties for legal entities for personal data breaches

ViolationFine
Data compromise affecting 1,000-10,000 people3-5 million rubles
Disclosure of data on 10,000-100,000 individuals5-10 million rubles
Violation involving the processing of over 100,000 records10-15 million rubles
Disclosure of special categories of data (health status, beliefs)10-15 million rubles
Compromise of biometric data15-20 million rubles
Repeat violation of protection requirementsA turnover-based fine of 1-3% of total revenue for the previous year, but not less than 20 million and not more than 500 million rubles (Part 15 of Article 13.11 of the Administrative Offenses Code of the CIS)

What ISPDn protection looks like in practice: a scenario and the consequences of insufficient protection

### Scenario: upgrading ISPDn protection in an insurance company to UZ-2

An insurance company processes special categories of data - health information about clients under voluntary medical insurance policies, which means special personal data for a large number of data subjects, so the system must comply with UZ-2.

The correct workflow starts with IT infrastructure audit, which identifies risk areas and then enables comprehensive protection: - a DLP system is configured to prevent leaks; - data transfer channels between branches are encrypted; - access to medical information is restricted between insurance agents, medical institutions, and accounting.

After connecting incident monitoring systems response to threats drops from hours to minutes - the incident is visible as soon as it occurs, not afterward.

What UZ-2-aligned protection gives the business

Legal consequences of weak data protection at a microfinance organization

The reverse scenario - how weak security system and identification leads to direct financial and reputational losses. A microfinance organization was sued by a citizen who claimed he had not signed a loan agreement and had not consented to the processing of his personal data: the agreement was issued remotely through the website using an SMS code sent to someone else's number, and the company had no reliable customer identification system.

By court order, the company was required to delete the claimant's data and stop processing it - the weakness in protection directly translated into legal and reputational costs.

FAQ

FAQ

What is a personal data system (PDIS)?

An ISPDn is any software or database where you store and process customer, employee, or partner data: CRM, HR systems, and even Excel sheets with phone numbers and email addresses. A personal data protection system is the ISPDn together with the organizational documents and technical measures that protect it from leaks.

Which companies need to protect personal data?

Everyone. If you store data on employees, clients, or counterparties, you are a personal data operator. This applies even to small companies with a client base in Excel.

How do you choose the ISPDn security level?

The UZ-1 to UZ-4 security level is set by Government Decree No. 1119 based on three factors: the data category, the number of data subjects, and the current threat type. Special and biometric data automatically raise the level regardless of the number of records. Both the protection measures and the costs depend on the level.

Is registering a PDIS mandatory?

It is not the system itself that is registered, but the fact of processing confidential information: the law requires notifying Roskomnadzor before starting to work with personal data. The list of exemptions has been significantly reduced since 2025, so check the current grounds for each specific case.

What happens if you don't protect your personal data system?

Businesses face fines from 3 to 20 million rubles, and repeated leaks can trigger turnover-based penalties of 1-3% of revenue. Illegal data trafficking now carries criminal liability (Article 272.1 of the Criminal Code of the CIS). Beyond money, you lose customers, partners, and reputation.

{{cta}}

Discuss the article: Personal data system: how…

Enter your email or phone number so we can get back to you.

Send via: