Personal data information system: how to classify a PDIS, choose a security level, and comply with GDPR

How to classify ISPDn, choose a UZ-1 to UZ-4 security level, and protect personal data under GDPR to avoid turnover-based fines.

  • What is a personal data system
  • What data counts as personal
  • Duties of a PDIS operator
  • PDIS security levels: how to determine them without mistakes

A personal data protection system is an information system (ISPDn) containing customer and employee data plus the organizational and technical measures that protect it from leaks. To comply with GDPR, the operator classifies the data, chooses a security level for the system from UZ-4 to UZ-1 under Government Decree No. 1119, and takes the required measures for that level from FSTEC Order No. 21. The rest of the article explains how to classify a system as ISPDn, how much protection at each level costs, and what fines apply for classification errors.

What is a personal data system

Any organization that stores data on employees, clients or partners is a personal data operator. Personal Data Information System (PDIS) - is a company's automated system that handles personal information. It covers CRM, databases, HR software and any other tool that collects, stores or processes personal information. Put simply, if your business uses computers and software to handle customer or employee data, you have a PDIS.

What data counts as personal: 4 categories by sensitivity level

Types of PDIS

Cross-functional

They process data on different categories of people - for example, clients, employees and partners. Large companies build them to optimize business processes and cut costs. For instance, a bank may use a single platform to score borrowers and calculate salaries.

Functional

They handle specific tasks in individual company departments. These are CRM platforms for the sales team, HR systems in the HR department, or marketing platforms for analytics.

Accounting and management systems

They automate internal processes - track working hours, calculate vacation and sick leave, manage access to premises.

Information and reference

They provide information to a limited group of users. For example, a counterparty verification system in the legal department or a loyalty database in a retail chain.

Duties of a PDIS operator

To avoid overpaying for security and breaking the law, a business must classify its personal data system correctly. The operator is responsible for personal data security at all times — from the moment data is collected until it is deleted. The business must implement protection system, capable of effectively countering current threats.

Specific requirements for building such a system are set by _GDPR and Government Decree No. 1119._ Law GDPR sets the basic rules: what is allowed, what is not, and who is responsible for it. Decree No. 1119 indicates which security measures to use and in what situation. It is what establishes _4 protection levels (PL)_ for the system, depending on which data you process and how many clients or employees you have.

What to do in practice: 1. Determine the protection level (PL) - exactly what data you store (standard or sensitive). This determines which protection tools you will need. 2. Choose licensed information protection tools (IPT) - FSTEC and FSB approve the list of permitted software and hardware solutions. You cannot use any tools you like - they must be approved by the regulators.

3. Assemble a package of internal documents - a data processing policy, staff regulations and a process register so you pass inspection without questions. 4. Notify Roskomnadzor - as soon as you start collecting personal data, you must notify the supervisory authority. 5. Sign proper contracts with contractors - if you outsource data handling (for example, to the cloud), the contract must require the contractor to protect the data exactly as you do.

Compliance with these requirements is monitored by: - Roskomnadzor - checks how you collect data and respond to citizens' requests. - FSTEC - assesses how you have organized technical information protection. - FSB - oversees the use of encryption (cryptography). The law requires businesses not merely to have documents, but to maintain active, continuousinformation protection.

Get the data category wrong or overlook requirements - and you risk a fine of up to 15 million rubles.

Discuss your challenge with an architect

PDIS security levels: how to determine them without mistakes

Choosing the right protection level determines how much you spend on security systems and which measures you implement. A mistake leads _to two risks:_ you overpay for unnecessary protection or leave data vulnerable, which risks leaks and fines.

How the ISPDn security level is determined

PDIS: How to Choose a Protection Level Under GDPR Three factors - the personal data category, the number of data subjects, and the current threat type - determine one of four security levels under Government Decree No. 1119: from UZ-4 with basic measures to UZ-1 with maximum protection and certification. How the security level is determined Government Decree No. 1119 - three inputs, one level out FACTORS Data category special · biometric · other · publicly available Number of data subjects more or fewer than 100,000 people Current threat type 1st (OS/DBMS) · 2nd (application software) · 3rd (people) SECURITY LEVEL UZ-1 · maximum protection, DLP, encryption, certification UZ-2 · firewall, antivirus, access control UZ-3 · password policy, access rights, logs UZ-4 · internal policy and data subject consent Special and biometric data raise the level regardless of the number of records.
The data category, number of data subjects, and threat type under Government Decree No. 1119 determine the UZ-1 to UZ-4 security level, and therefore the measures required and the costs.

To understand how to protect the system, you need to consider 4 key aspects

The legislation divides threats into three categories

How the protection level affects business risks and costs

SLThreat typeWhat to doPractical business benefits
SL-1Type 1 threats (OS and DBMS vulnerabilities)Deploy the maximum set of protection tools, including data leak prevention (DLP) systems and strong encryption. Obtain a compliance certificate.Pass Roskomnadzor and FSTEC inspections with confidence. Build greater trust with major partners.
SL-2Type 2 threats (application software vulnerabilities)Install a firewall, antivirus protection and access control software.You effectively protect the most vulnerable data while minimizing reputational risks.
SL-3Type 3 threats (human factor, insiders)Implement a password policy, segregate employee access rights, and maintain activity logs.You comply with the law at minimal cost, focusing on basic but reliable protection.
SL-4Type 3 threats in limited formAdopt an internal data processing policy and obtain consent from data subjects.Run marketing legally without overspending on complex security systems.

Let's look at an example. A plant with 5,000 employees processes passport data and medical clearance certificates for work admission, and uses an access control system with fingerprint identification. - _What data is involved_ - other (passports), special (medical certificates), and biometric (fingerprints). - _Protection level_ - the presence of biometric and special data automatically requires PL-2 for these systems. - _Threat type_ - a system storing passports and medical certificates is characterized by type 2 threats (vulnerabilities in HR software), while a fingerprint system faces type 1 threats (attacks on the server's operating system).

Protection and PDIS organization requirements

Once you have determined the PL, you can start designing the protection system. Specific requirements for personal data protection are set by _FSTEC Order No. 21._ Organizational measures - are the basis on which you will be checked in the event of a complaint or audit. They require developing and approving mandatory documents that govern how data is handled, access rights, incident response procedures and employees' individual responsibility.

You need to prepare

Technical protection measures include the following tools

Companies that have deployed secure PDIS not only avoid fines but also demonstrate their reliability to clients and partners.

Step-by-step PDIS protection plan: from audit to system certification

Companies that have deployed secure PDIS not only avoid fines but also gain a real competitive advantage by demonstrating their reliability to clients and partners. Follow the plan — a clear step-by-step algorithm will help minimize costs and build your security system consistently and soundly. ###

Step 1: Audit and classify the system

Compile a complete register of all processes and storage locations for personal data. Record where and how you process data: in CRM, HR departments, accounting. Precisely define the data categories - standard (full name, phone numbers) or special (health status). Based on this information, classify the PDIS by security levels. ###

Step 2: Prepare organizational and administrative documentation

You need to create a package of internal policies that will serve as the foundation for all processes (described above). Such documents prove to the auditing authority that you run an orderly operation, not chaos. ###

Step 3: Deploy technical protection measures

Once you have determined the protection level, select and deploy certified information security tools. A contractor can help you - system integrator, which will select certified information security tools matching the protection level, test and deploy solutions in pilot zones before a full-scale rollout. The contractor will also configure integration of the security tools with your IT infrastructure and develop technical documentation for the protection system. ###

Step 4: Train staff and certify the system

Train your team: run briefings on using protective mechanisms and following procedures. Put all developed documents into effect and obtain a _compliance certificate_ (issued for 3 years and serving as strong proof of your good faith).

Financial risks

For personal data leaks, legal entities face higher fines, and repeated violations now trigger turnover-based sanctions - a percentage of annual company revenue rather than a fixed amount (amendments to the Administrative Offenses Code under 420-FZ). The law also introduced criminal liability for illegal trafficking in personal data (Article 272.1 of the Criminal Code of the CIS) - a mistake in ISPDn protection can now cost tens of millions of rubles and lead to criminal charges.

Direct impact on business metrics

Reduced operating profit

Fines of 1–3% of revenue can "swallow" a significant part of a mid-sized business's quarterly profit.

Blocked growth

Funds earmarked for marketing, procurement, or upgrades will have to be redirected to paying penalties.

Loss of investment appeal

A company with a "violator" reputation and the risk of suspended operations becomes less attractive to investors and partners.

Penalties for legal entities for personal data breaches

ViolationFine
Data compromise affecting 1,000-10,000 people3-5 million rubles
Disclosure of data on 10,000-100,000 individuals5-10 million rubles
Violation involving the processing of over 100,000 records10-15 million rubles
Disclosure of special categories of data (health status, beliefs)10-15 million rubles
Compromise of biometric data15-20 million rubles
Repeat violation of protection requirementsTurnover-based fine of 1-3% of annual revenue (floor: 20-25 million rubles; ceiling: 500 million rubles)

What ISPDn protection looks like in practice: a scenario and the consequences of insufficient protection

### Scenario: upgrading ISPDn protection in an insurance company to UZ-2

The insurance company processes special categories of data - health information about clients under voluntary medical insurance policies, which are special personal data for a large number of data subjects, so the system must comply with _UZ-2._

The correct workflow starts with IT infrastructure audit, which identifies risk areas and then enables comprehensive protection: - a DLP system is configured to prevent leaks; - data transfer channels between branches are encrypted; - access to medical information is restricted between insurance agents, medical institutions, and accounting.

After connecting incident monitoring systems response to threats drops from hours to minutes - the incident is visible as soon as it occurs, not afterward.

What UZ-2-aligned protection gives the business

Legal consequences of weak data protection at a microfinance organization

The reverse scenario - how weak security system and identification leads to direct financial and reputational losses. A microfinance organization was sued by a citizen who claimed he had not signed a loan agreement and had not consented to the processing of his personal data: the agreement was issued remotely through the website using an SMS code sent to someone else's number, and the company had no reliable customer identification system.

By court order, the company was required to delete the claimant's data and stop processing it - the weakness in protection directly translated into legal and reputational costs.

FAQ

FAQ

What is a personal data system (PDIS)?

An ISPDn is any software or database where you store and process customer, employee, or partner data: CRM, HR systems, and even Excel sheets with phone numbers and email addresses. A personal data protection system is the ISPDn together with the organizational documents and technical measures that protect it from leaks.

Which companies need to protect personal data?

Everyone. If you store data on employees, clients, or counterparties, you are a personal data operator. This applies even to small companies with a client base in Excel.

How do you choose the ISPDn security level?

The UZ-1 to UZ-4 security level is set by Government Decree No. 1119 based on three factors: the data category, the number of data subjects, and the current threat type. Special and biometric data automatically raise the level regardless of the number of records. Both the protection measures and the costs depend on the level.

Is registering a PDIS mandatory?

It is not the system itself that is registered, but the fact of processing confidential information: the law requires notifying Roskomnadzor before starting to work with personal data. The list of exemptions has been significantly reduced since 2025, so check the current grounds for each specific case.

What happens if you don't protect your personal data system?

Businesses face fines from 3 to 20 million rubles, and repeated leaks can trigger turnover-based penalties of 1-3% of revenue. Illegal data trafficking now carries criminal liability (Article 272.1 of the Criminal Code of the CIS). Beyond money, you lose customers, partners, and reputation.

{{cta}}

Discuss the article: Personal data system: how…

Send via: