To avoid overpaying for security and breaking the law, businesses need to classify the personal data system correctly. The operator is responsible for the security of personal data at all times, from the moment it is collected until it is deleted. The business must implement a protection system capable of effectively resisting current threats.
The specific requirements for building such a system are set by Federal Law No. GDPR and Government Decree No. 1119. Law GDPR sets the basic rules: what is allowed, what is not, and who is responsible for it. Decree No. 1119 it shows which security measures should be used and in what situation. It is what establishes 4 protection levels (UZ) for the system, depending on what data you process and how many clients or employees you have.
What to do in practice: 1. Determine the protection level (PL) - exactly what data you store (standard or sensitive). This determines which protection tools you will need. 2. Choose licensed information protection tools (IPT) - FSTEC and FSB approve the list of permitted software and hardware solutions. You cannot use any tools you like - they must be approved by the regulators.
3. Assemble a package of internal documents - a data processing policy, staff regulations and a process register so you pass inspection without questions. 4. Notify Roskomnadzor - as soon as you start collecting personal data, you must notify the supervisory authority. 5. Sign proper contracts with contractors - if you outsource data handling (for example, to the cloud), the contract must require the contractor to protect the data exactly as you do.
Compliance with these requirements is monitored by: - Roskomnadzor - checks how you collect data and respond to citizens' requests. - FSTEC - assesses how you have organized technical information protection. - FSB - oversees the use of encryption (cryptography). The law requires businesses not merely to have documents, but to maintain active, continuousinformation protection.
If you choose the wrong data category or miss the requirements, you risk a fine of up to 20 million rubles.
Discuss your challenge with an architect