What problem does it solve?
Russian operators are required by Article 18.1 of Federal Law 152-FZ to publish a personal data processing policy, but these policies frequently fall out of sync with actual business practices, creating compliance gaps that risk regulatory fines from Roskomnadzor.
Core Features & Use Cases
- Dual operation modes: Run a full sweep of recent data processing outputs (privacy impact assessments, data processing agreements, use case triages, DSAR responses) to identify drift, or run a direct check for a specific planned new business activity.
- Structured gap classification: Categorize identified gaps by severity (critical violations, internal inconsistencies, improvement opportunities) with clear risk labels tied to 152-FZ requirements.
- Actionable drift reports: Generate formatted reports with specific recommended policy updates, compliance action items, and timelines for DPO review and policy publication.
Common use cases include quarterly compliance audits, pre-launch validation of new initiatives like AI-powered candidate screening, and ad-hoc checks when teams propose changes to data processing workflows.
Quick Start
Use the policy-monitor skill to run a full sweep of your recent data processing outputs to identify gaps between your published personal data policy and actual business practices, or check if a planned new activity like AI-powered candidate screening requires policy updates.