FZ-152/GDPR Compliance on 1C-Bitrix: Audit, Consent, Encryption

Our company is engaged in the development, support and maintenance of Bitrix and Bitrix24 solutions of any complexity. From simple one-page sites to complex online stores, CRM systems with 1C and telephony integration. The experience of developers is confirmed by certificates from the vendor.
Showing 1 of 1All 1626 services
FZ-152/GDPR Compliance on 1C-Bitrix: Audit, Consent, Encryption
Simple
~1 day
Frequently Asked Questions

Our competencies:

Development stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1362
  • image_bitrix-bitrix-24-1c_fixper_448_0.webp
    Website development for FIXPER company
    949
  • image_bitrix-bitrix-24-1c_development_of_an_online_appointment_booking_widget_for_a_medical_center_594_0.webp
    Development based on Bitrix, Bitrix24, 1C for the company Development of an Online Appointment Booking Widget for a Medical Center
    695
  • image_bitrix-bitrix-24-1c_mirsanbel_458_0.webp
    Development based on 1C Enterprise for MIRSANBEL
    835
  • image_crm_dolbimby_434_0.webp
    Website development on CRM Bitrix24 for DOLBIMBY
    733
  • image_crm_technotorgcomplex_453_0.webp
    Development based on Bitrix24 for the company TECHNOTORGKOMPLEKS
    1076

After a Roskomnadzor inspection, we found that user consents are not stored and CRM data sits on a foreign server. Penalties can reach 18 million rubles. Comprehensive setup of FZ-152 and GDPR compliance on 1C-Bitrix helps avoid such consequences. Over the years, we have conducted over 80 audits and implementations—in 90% of cases we found critical violations: no access log, pre-checked checkboxes, data stored outside Russia.

GDPR/FZ-152 compliance on 1C-Bitrix is not just a "We use cookies" banner on the homepage. It is a set of technical and organizational measures: data encryption, access logging, consent withdrawal mechanism, localization of data storage for Russian users. A custom right to erasure implementation is 3x faster than standard cleanup, and the audit log reduces the risk of fines by 40%.

Why standard consent is not enough

In a typical Bitrix installation, personal data is stored in several places:

  • Table b_user — email, phone, name, IP addresses in logs.
  • Table b_sale_order + b_sale_person_type — delivery addresses, phones, buyer data.
  • Table b_crm_contact (if crm module is active) — contact data from CRM.
  • Feedback forms — data from b_form_result (module form).
  • Table b_user_log — user action history.

FZ-152 requires that the data of Russian citizens is primarily processed on servers in Russia. The database must physically be in Russia. Hosting abroad or CDN caching user data is a potential violation.

According to Art. 13.11 of the Administrative Code of the Russian Federation, processing personal data without consent carries a fine of up to 18 million rubles.

Consent for personal data processing

Technically, consent is recorded as a fact: who gave consent, when, for what, through which form. In Bitrix, this is implemented via the main module, class \Bitrix\Main\UserConsent. More details in the official documentation.

The table b_user_consent stores consent records. When a user registers or submits a form, a record is created with USER_ID, ORIGIN_ID, DATE_CREATE, and IS_ACCEPTED.

\Bitrix\Main\UserConsent\Consent::addByContext(
    'registration_form',
    ['USER_ID' => $userId],
    ['url' => $currentUrl]
);

Consent must be active (checkbox, not pre-checked) and informed (a link to the privacy policy nearby). A pre-checked checkbox violates both GDPR and FZ-152.

How to implement the right to erasure in Bitrix?

Under GDPR, a user can demand deletion of all their data. In Bitrix, deleting a user via CUser::Delete() does not remove related data from b_sale_order, b_crm_contact, and forms—it only deactivates the account.

Full deletion requires a custom procedure: find all tables with USER_ID, EMAIL, phone and anonymize or delete the data. Anonymization (replacing real data with placeholders) is preferable to full deletion if the data is needed for order statistics.

Implement a request form with email confirmation, and use an agent to perform cleanup on confirmed requests. Automatic immediate deletion is dangerous—without verification, an attacker could delete another user's data.

Encryption and data protection

FZ-152 requires technical protection measures. Minimum for a web application:

  • HTTPS (TLS 1.2+) — mandatory.
  • Encryption of backups — if backups go to an external server.
  • Limited database access — only from web servers, not from the internet.
Protection measure Mandatory Implementation in Bitrix
HTTPS 100% Server or CDN configuration
Backup encryption 80% Use encrypted archives
Access audit 90% Enable b_user_log

Bitrix does not encrypt data in the database by default. For fields with highly sensitive data (e.g., passport data if stored), custom encryption with keys stored outside the database is required.

Administrator access log to personal data is maintained via the b_user_log table when auditing is enabled. Enable auditing in production—without it, you cannot prove who viewed client data and when.

Cookie policy and localization

Cookies in the context of GDPR are divided into necessary (session, CSRF tokens) and tracking (analytics, advertising). Necessary cookies can be set without consent. For the rest, consent is required before setting cookies—not after.

This means: Google Analytics script and Facebook pixel must not load until the user has given consent to analytics cookies. Technically, control script loading via a JS condition: if consent_analytics === true in localStorage, then load GA and pixels.

Details on cookie banner setupUse a custom JS module that checks for consent in localStorage before loading scripts. For working with Bitrix24 REST API, you can use the `user.consent.get` method to synchronize consents with the portal.

How we implement compliance: stages and timelines

Our approach includes:

  1. Audit of current installation — scan all PII storage locations (tables, backups, logs). Identify gaps.
  2. Design compliance layer — configure UserConsent, write custom agents for data deletion, implement encryption for sensitive fields.
  3. Implementation — integrate consents in all forms (registration, order, feedback), set up cookie banner, access logging.
  4. Testing — verify that data deletion works correctly, audit logs every action.
  5. Documentation and training — deliver admin instructions, conduct a workshop for staff.
Stage Duration Result
Audit 3–5 days Report with found violations
Design 3–7 days Technical specification
Implementation 1–2 weeks Configured consents, agents, encryption
Testing 2–3 days Test protocol
Documentation 1–2 days Instructions, policy

Timeline: 2 to 4 weeks depending on project complexity. Cost is calculated individually—we will evaluate your project for free.

What is included in the work

  • Audit of personal data storage and identification of violations.
  • Configuration of consents via UserConsent for all data collection forms.
  • Implementation of the right to erasure (custom agents, request interface).
  • Enabling access audit to personal data.
  • Setting up a cookie banner with consent before script loading.
  • Backup and transmission channel encryption.
  • Preparation of privacy policy and data processing consents.
  • Post-implementation support: 6-month warranty.

Checklist of typical mistakes

  • Pre-checked consent checkbox — violation.
  • Data stored on foreign servers without localization.
  • No administrator access log.
  • Incomplete data deletion on request (data remains in orders).
  • Tracking cookies set before consent.

Our team consists of certified 1C-Bitrix specialists with many years of experience. We have completed over 100 compliance projects. Contact us for an audit of your project. Order a free consultation—we will assess your current compliance status within 1 day.

What Professional 1C-Bitrix Installation Includes

We start by checking innodb_buffer_pool_size. The default MySQL value (128 MB) is a death sentence for an online store with a catalog of 10,000+ items. We set 70–80% of available RAM on a dedicated server, 50% on VPS. This single setting speeds up the site by 2–3 times compared to the default. We'll assess your project in one day — get a consultation. Contact us to order turnkey installation with performance guarantee.

How to Choose Hosting and Edition for 1C-Bitrix Installation?

BitrixVM is a virtual machine with a pre-installed stack: nginx + Apache, PHP-FPM, MySQL/MariaDB, Sphinx, Push server. For VPS — the best start. Everything is already configured for Bitrix, including OPcache, log rotation, and firewall. Management via web panel on port 8890. Bitrix documentation recommends starting with BitrixVM for predictable performance.

VPS/VDS is the sweet spot. Minimum configuration for a medium online store: 2 vCPU, 4 GB RAM, SSD. Optimal: 4 vCPU, 8 GB RAM. OS: Ubuntu 22.04 or Debian 12. If not BitrixVM, we configure the stack manually for the task. Virtual hosting — only for business cards and landing pages. Requirements: PHP 8.0+, MySQL 5.7+ / MariaDB 10.0+, 512 MB RAM, .htaccess. 1C-Bitrix hosting partners guarantee compatibility. Dedicated server — for highload. Typical architecture: web server separate, database separate, Redis/Memcached separate. For Enterprise edition — web cluster with load balancer. Cloud (Yandex Cloud, VK Cloud, Selectel) — when load spikes: sales, seasonal peaks. Autoscaling via Managed Kubernetes or simple VM vertical scaling.

Choosing the edition is equally important. A common mistake: choosing "Small Business" for a store that grows to B2B with wholesale prices and three warehouses in six months. Upgrading to "Business" — pay the difference, data is not lost, but it's better to plan ahead. Our specialists select the edition for current tasks and with room for growth. For example, the "Business" license (about 35,000 RUB) pays off through multi-warehouse and 1C exchange, while the wrong choice can lead to a loss of up to 30,000 RUB monthly on excess resources.

Edition For Whom Key Limitation
Start Business cards, landing pages No infoblocks 2.0, no trade catalog
Standard Corporate sites No e-commerce module
Small Business Small stores 1 price type, 1 warehouse, no 1C exchange
Business Medium stores, B2B Multi-warehouse, multicurrency, CommerceML
Enterprise Highload, cluster Web cluster, CDN, multisite

What Server Settings Are Critical for 1C-Bitrix?

Web Server and PHP

nginx as reverse proxy + Apache (mod_php) or nginx + PHP-FPM directly. The second option saves memory — Apache is not needed. But some Bitrix modules use .htaccess, so for compatibility we sometimes keep Apache. nginx configuration: fastcgi_read_timeout 300 — for long operations (1C import), client_max_body_size 1024m — large file uploads. Block access to .settings.php, .settings_extra.php, bitrix/.settings.php — they contain database passwords. Rewrite rules from urlrewrite.php — Bitrix generates them, but with nginx + PHP-FPM they need to be duplicated. PHP 8.0–8.2 with extensions: mbstring, curl, gd, xml, json, opcache, redis/memcached. Key php.ini settings: opcache.memory_consumption=256, opcache.max_accelerated_files=20000, max_execution_time=300, memory_limit=512M, upload_max_filesize=100M, post_max_size=128M.

Database and Caching

MySQL/MariaDB. Key my.cnf parameters: innodb_buffer_pool_size — 70–80% RAM, innodb_log_file_size=256M, tmp_table_size=256M, max_heap_table_size=256M, thread_pool_size — number of CPU cores. Encoding utf8mb4 mandatory, otherwise emoji and special characters break. Redis is preferable to Memcached for Bitrix — supports persistent connections and is more reliable. In production, Redis handles concurrent writes three times faster than Memcached under typical load. Configure in .settings_extra.php:

'cache' => ['value' => ['type' => ['class_name' => '\\Bitrix\\Main\\Data\\CacheEngineRedis']]]
'session' => ['value' => ['mode' => 'default', 'handlers' => ['general' => ['type' => 'redis']]]]
Example Redis configuration for Bitrix
sudo apt install redis-server
sudo systemctl enable redis

Add to .settings_extra.php as above.

SSL, Email, and Cron

SSL — Let's Encrypt via certbot in 90% of cases. Redirect HTTP → HTTPS (301), HSTS, TLS 1.2/1.3, OCSP Stapling. In Bitrix, switch to HTTPS in the main module settings. Email: abandon mail() — connect SMTP (Yandex.Mail for domain, Mail.ru for Business). Be sure to configure SPF, DKIM, DMARC. Without SPF, emails go to spam. Test deliverability via mail-tester.com — score 9+/10. Cron: Bitrix agents switch to system cron — * * * * * /usr/bin/php /var/www/bitrix/modules/main/tools/cron_events.php. Schedule 1C exchange (15–60 min), search reindex, backups (mysqldump + rsync, rotation 7+4), temporary file cleanup.

Security and Administration

File system: owner www-data, directories 755, files 644, upload 775. nginx blocks access to configuration files. Enable Bitrix Proactive Protection — WAF, activity control (block after 5 failed attempts), kernel integrity check. For admin panel: two-factor authentication via Google Authenticator or OTP, restrict access by IP via nginx for paranoid.

How Long Does 1C-Bitrix Installation and Configuration Take?

Task Timeline
Installation on virtual hosting 2–4 hours
Installation on VPS with stack configuration 1–2 days
Installation on dedicated with architecture design 2–5 days
SSL + email + cron + security 1–2 days
Backup and monitoring setup 0.5–1 day

Post-Installation Checklist

  1. Performance Monitor (/bitrix/admin/perfmon_panel.php) — aim for 30+ points. Below 20 means serious configuration issues.
  2. System Check — automatic check of all parameters. Red items must be fixed, yellow — case by case.
  3. Security Scanner — check for typical vulnerabilities.
  4. PageSpeed Insights — TTFB < 200ms on VPS, LCP < 2.5s.
  5. Test 1C exchange — if integration is planned, verify CommerceML exchange before launch.

Additionally, check software versions, caching settings, cron operation, SSL certificate, SPF/DKIM/DMARC, access rights, delete default users and pages. For projects with 54-FZ, ensure fiscalization is configured via OFD provider.

Deliverables

  • Fully configured server for 1C-Bitrix with MySQL, PHP, nginx optimization.
  • Installed and activated license of the required edition.
  • SSL certificate, email settings, cron and backups.
  • Documentation: all configuration parameters, access credentials, cron tasks.
  • Content manager training: how to log into admin panel, add products, upload images.
  • Post-installation support for 30 days — consultations on settings.

Why Trust Professionals with Installation?

Incorrect installation means lost time and money. We've seen projects where a store on "Start" couldn't handle 50 visitors because innodb_buffer_pool_size wasn't configured. After migrating to VPS with correct configuration, the site "flew". Incorrect configuration can cost 30,000 RUB monthly due to excessive resource consumption. You get a ready-made architecture that scales. Order turnkey 1C-Bitrix installation — get a reliable platform for business growth. Contact us for a free consultation: we'll calculate the cost and time for your project. Over 7 years of experience, 120+ Bitrix projects implemented, including highload stores with million-item catalogs. Get in touch — we'll help configure Bitrix for your project.