Consent Setup for Personal Data Processing in 1C-Bitrix
A consent form for personal data processing is not just a checkbox. We've encountered projects where the lack of proper consent led to site blocking by Roskomnadzor. Fines under Article 13.11 of the Administrative Code reach 75,000 rubles for officials and up to 300,000 for legal entities. Consent must be documented, tied to a specific user and form, and be revocable while preserving history. Bitrix provides the UserConsent module for this, introduced in the D7 core. With over 7 years of experience implementing 1C-Bitrix and 50+ full-cycle projects, we guarantee compliance with 152-FZ and 54-FZ. Even a single feedback form without consent can trigger an unscheduled inspection. A detailed audit of all data collection points is the first step toward compliance.
How the Built-in UserConsent Mechanism Works
Since D7 core, Bitrix includes the \Bitrix\Main\UserConsent\Consent class and related tables. The main ones:
-
b_user_consent — records of user consents
-
b_user_consent_text — consent texts with versioning
Consent is created via the add() or addByContext() method:
$result = \Bitrix\Main\UserConsent\Consent::addByContext(
'feedback_form', // Context ID (form name)
[
'USER_ID' => $userId, // or 0 for anonymous
'USER_IP' => $_SERVER['REMOTE_ADDR'],
],
[
'AGREEMENT_ID' => 1, // ID of the agreement text from b_user_consent_text
'URL' => \Bitrix\Main\Application::getInstance()->getContext()->getRequest()->getRequestUri(),
]
);
The AGREEMENT_ID field points to a specific version of the consent text. This is important: if you update your privacy policy, old consents remain linked to the old version — proving exactly what text the user agreed to.
Configuring Consent Texts via Admin Panel
Consent texts are managed in /bitrix/admin/ through the main module. Each text has an ID, title, and versioned content. When updating the privacy policy, a new version is created — old consents remain valid, and new users see the latest text.
For each form on the site, a separate 'context' (string identifier) is created: registration, checkout, callback_form, newsletter. This allows tracking which entry point collected the consent.
Integration with Forms and Web Forms
Registration form. The bitrix:main.register component supports a built-in consent checkbox — set USE_AGREEMENT = Y in component parameters, and pass the agreement text ID via AGREEMENT_ID. Data is recorded automatically on successful registration.
Web Forms module (form). For feedback forms, add a field of type AGREEMENT in the form builder (/bitrix/admin/form_edit.php). On submission, Bitrix automatically records the consent in b_user_consent linked to the form result (b_form_result).
Custom forms. For manual POST handling (e.g., AJAX form with Fetch API), call Consent::add() in your PHP handler before saving form data. Without this, consent is never recorded, even if the checkbox appears on the page.
Handling Consent Revocation
Users must be able to revoke consent. In the personal account (/personal/), add a consent management page. List a user's consents:
$consents = \Bitrix\Main\UserConsent\ConsentTable::getList([
'filter' => ['USER_ID' => $USER->GetID()],
'order' => ['DATE_CREATE' => 'DESC']
]);
Revocation is not deletion; it creates a new record with IS_ACCEPTED = N. The history is preserved: the user gave consent, later revoked — dates are recorded. This is legally critical.
After revocation, you must decide what to do with already collected data. There is no automatic deletion — it's an organizational process requiring technical support.
Why the Built-in UserConsent Module Beats Custom Implementation
Custom solutions often ignore text versioning and context binding. UserConsent ensures legal compliance three times faster to implement and eliminates the risk of site blocking. Moreover, the module automatically logs IP, URL, and user ID — satisfying regulatory requirements. On a recent e-commerce project with 15 forms, we implemented UserConsent in 3 days, reducing compliance risk to zero.
How to Check Consent Before Processing Data
At critical points (before sending email newsletters, before transferring data to CRM), check for active consent:
$hasConsent = \Bitrix\Main\UserConsent\Consent::isAccepted(
'newsletter',
['USER_ID' => $userId]
);
if (!$hasConsent) {
// do not process data
}
This prevents situations where a user revoked consent but the system continues sending emails due to accumulated queues in the b_subscribe_subscription table.
Stages of Turnkey Consent Configuration
| Stage |
Description |
Duration (working days) |
| Analysis |
Audit of current forms and data flows, identification of PD collection points |
1–3 |
| Design |
Development of consent scheme, contexts, policy texts |
1–2 |
| Implementation |
UserConsent module setup, integration with forms, personal account enhancement |
3–7 |
| Testing |
Verification of recording, revocation, checking, and legal validity |
1–2 |
| Documentation |
Handover of instructions, access, and support process description |
1 |
Cost is calculated individually after analyzing the scope of forms and modifications. Contact us for a free project estimate. We work with a 12-month warranty and 1C-Bitrix certificates.
Comparison: Custom Implementation vs UserConsent
| Parameter |
Custom Implementation |
UserConsent |
| Text versioning |
Missing or custom-built |
Built-in, linked to record |
| User binding |
Must be written manually |
Automatic by ID or IP |
| Logging IP, URL, date |
Often omitted |
Recorded in tables |
| Revocation with history |
Needs implementation |
Ready mechanism |
| Legal validity |
Questionable |
Compliant with 152-FZ |
Our Process: Step by Step
- Audit all data collection points on the site (forms, cart, personal account).
- Create contexts for each form in the UserConsent module.
- Connect consent to existing components via parameters or rewrite.
- Set up a consent revocation page and handling logic for withdrawal.
- Test scenarios: registration, form submission, revocation, consent check.
Ensure your site is protected from fines. Get a consultation right now — contact us for a project cost estimate.
What Professional 1C-Bitrix Installation Includes
We start by checking innodb_buffer_pool_size. The default MySQL value (128 MB) is a death sentence for an online store with a catalog of 10,000+ items. We set 70–80% of available RAM on a dedicated server, 50% on VPS. This single setting speeds up the site by 2–3 times compared to the default. We'll assess your project in one day — get a consultation. Contact us to order turnkey installation with performance guarantee.
How to Choose Hosting and Edition for 1C-Bitrix Installation?
BitrixVM is a virtual machine with a pre-installed stack: nginx + Apache, PHP-FPM, MySQL/MariaDB, Sphinx, Push server. For VPS — the best start. Everything is already configured for Bitrix, including OPcache, log rotation, and firewall. Management via web panel on port 8890. Bitrix documentation recommends starting with BitrixVM for predictable performance.
VPS/VDS is the sweet spot. Minimum configuration for a medium online store: 2 vCPU, 4 GB RAM, SSD. Optimal: 4 vCPU, 8 GB RAM. OS: Ubuntu 22.04 or Debian 12. If not BitrixVM, we configure the stack manually for the task. Virtual hosting — only for business cards and landing pages. Requirements: PHP 8.0+, MySQL 5.7+ / MariaDB 10.0+, 512 MB RAM, .htaccess. 1C-Bitrix hosting partners guarantee compatibility. Dedicated server — for highload. Typical architecture: web server separate, database separate, Redis/Memcached separate. For Enterprise edition — web cluster with load balancer. Cloud (Yandex Cloud, VK Cloud, Selectel) — when load spikes: sales, seasonal peaks. Autoscaling via Managed Kubernetes or simple VM vertical scaling.
Choosing the edition is equally important. A common mistake: choosing "Small Business" for a store that grows to B2B with wholesale prices and three warehouses in six months. Upgrading to "Business" — pay the difference, data is not lost, but it's better to plan ahead. Our specialists select the edition for current tasks and with room for growth. For example, the "Business" license (about 35,000 RUB) pays off through multi-warehouse and 1C exchange, while the wrong choice can lead to a loss of up to 30,000 RUB monthly on excess resources.
| Edition |
For Whom |
Key Limitation |
| Start |
Business cards, landing pages |
No infoblocks 2.0, no trade catalog |
| Standard |
Corporate sites |
No e-commerce module |
| Small Business |
Small stores |
1 price type, 1 warehouse, no 1C exchange |
| Business |
Medium stores, B2B |
Multi-warehouse, multicurrency, CommerceML |
| Enterprise |
Highload, cluster |
Web cluster, CDN, multisite |
What Server Settings Are Critical for 1C-Bitrix?
Web Server and PHP
nginx as reverse proxy + Apache (mod_php) or nginx + PHP-FPM directly. The second option saves memory — Apache is not needed. But some Bitrix modules use .htaccess, so for compatibility we sometimes keep Apache. nginx configuration: fastcgi_read_timeout 300 — for long operations (1C import), client_max_body_size 1024m — large file uploads. Block access to .settings.php, .settings_extra.php, bitrix/.settings.php — they contain database passwords. Rewrite rules from urlrewrite.php — Bitrix generates them, but with nginx + PHP-FPM they need to be duplicated. PHP 8.0–8.2 with extensions: mbstring, curl, gd, xml, json, opcache, redis/memcached. Key php.ini settings: opcache.memory_consumption=256, opcache.max_accelerated_files=20000, max_execution_time=300, memory_limit=512M, upload_max_filesize=100M, post_max_size=128M.
Database and Caching
MySQL/MariaDB. Key my.cnf parameters: innodb_buffer_pool_size — 70–80% RAM, innodb_log_file_size=256M, tmp_table_size=256M, max_heap_table_size=256M, thread_pool_size — number of CPU cores. Encoding utf8mb4 mandatory, otherwise emoji and special characters break. Redis is preferable to Memcached for Bitrix — supports persistent connections and is more reliable. In production, Redis handles concurrent writes three times faster than Memcached under typical load. Configure in .settings_extra.php:
'cache' => ['value' => ['type' => ['class_name' => '\\Bitrix\\Main\\Data\\CacheEngineRedis']]]
'session' => ['value' => ['mode' => 'default', 'handlers' => ['general' => ['type' => 'redis']]]]
Example Redis configuration for Bitrix
sudo apt install redis-server
sudo systemctl enable redis
Add to .settings_extra.php as above.
SSL, Email, and Cron
SSL — Let's Encrypt via certbot in 90% of cases. Redirect HTTP → HTTPS (301), HSTS, TLS 1.2/1.3, OCSP Stapling. In Bitrix, switch to HTTPS in the main module settings. Email: abandon mail() — connect SMTP (Yandex.Mail for domain, Mail.ru for Business). Be sure to configure SPF, DKIM, DMARC. Without SPF, emails go to spam. Test deliverability via mail-tester.com — score 9+/10. Cron: Bitrix agents switch to system cron — * * * * * /usr/bin/php /var/www/bitrix/modules/main/tools/cron_events.php. Schedule 1C exchange (15–60 min), search reindex, backups (mysqldump + rsync, rotation 7+4), temporary file cleanup.
Security and Administration
File system: owner www-data, directories 755, files 644, upload 775. nginx blocks access to configuration files. Enable Bitrix Proactive Protection — WAF, activity control (block after 5 failed attempts), kernel integrity check. For admin panel: two-factor authentication via Google Authenticator or OTP, restrict access by IP via nginx for paranoid.
How Long Does 1C-Bitrix Installation and Configuration Take?
| Task |
Timeline |
| Installation on virtual hosting |
2–4 hours |
| Installation on VPS with stack configuration |
1–2 days |
| Installation on dedicated with architecture design |
2–5 days |
| SSL + email + cron + security |
1–2 days |
| Backup and monitoring setup |
0.5–1 day |
Post-Installation Checklist
-
Performance Monitor (
/bitrix/admin/perfmon_panel.php) — aim for 30+ points. Below 20 means serious configuration issues.
- System Check — automatic check of all parameters. Red items must be fixed, yellow — case by case.
- Security Scanner — check for typical vulnerabilities.
- PageSpeed Insights — TTFB < 200ms on VPS, LCP < 2.5s.
- Test 1C exchange — if integration is planned, verify CommerceML exchange before launch.
Additionally, check software versions, caching settings, cron operation, SSL certificate, SPF/DKIM/DMARC, access rights, delete default users and pages. For projects with 54-FZ, ensure fiscalization is configured via OFD provider.
Deliverables
- Fully configured server for 1C-Bitrix with MySQL, PHP, nginx optimization.
- Installed and activated license of the required edition.
- SSL certificate, email settings, cron and backups.
- Documentation: all configuration parameters, access credentials, cron tasks.
- Content manager training: how to log into admin panel, add products, upload images.
- Post-installation support for 30 days — consultations on settings.
Why Trust Professionals with Installation?
Incorrect installation means lost time and money. We've seen projects where a store on "Start" couldn't handle 50 visitors because innodb_buffer_pool_size wasn't configured. After migrating to VPS with correct configuration, the site "flew". Incorrect configuration can cost 30,000 RUB monthly due to excessive resource consumption. You get a ready-made architecture that scales. Order turnkey 1C-Bitrix installation — get a reliable platform for business growth. Contact us for a free consultation: we'll calculate the cost and time for your project. Over 7 years of experience, 120+ Bitrix projects implemented, including highload stores with million-item catalogs. Get in touch — we'll help configure Bitrix for your project.