FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Advertising
  4. SberCRM

SberCRM

MarketingWebsite

Related services

<

<model-viewer>

<model-viewer> is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. <model-viewer> provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, <model-viewer> helps deliver the right message to the right audience at the right time.

Marketing

33Across

33Across is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. 33Across enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, 33Across empowers marketing teams to achieve measurable growth.

Marketing

7moor

7moor is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. 7moor enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, 7moor empowers marketing teams to achieve measurable growth.

Marketing

A-Frame

A-Frame is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. A-Frame integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, A-Frame helps organizations maintain robust websites that meet user expectations and technical requirements.

Marketing

Aarki

Aarki is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Aarki enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Aarki empowers marketing teams to achieve measurable growth.

Marketing
A

Acquia Campaign Factory

Acquia Campaign Factory is a marketing campaign management platform that helps businesses plan, execute, and measure multi-channel marketing campaigns. It provides tools for audience segmentation, content creation, automated workflows, and performance tracking across email, social, web, and mobile. Acquia Campaign Factory enables personalized messages at scale, real-time campaign optimization, and detailed ROI reports, driving more effective marketing operations and measurable business growth.

Marketing
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does SberCRM do?

SberCRM is a customer relationship management platform operated by Sber (PJSC Sberbank), the largest Russian banking group. It bundles lead management, marketing automation, web chat widgets and integrations with the wider Sber ecosystem. When deployed on a public website, the SberCRM widget sets cookies, captures form submissions and synchronises data with Sber servers in the Russian Federation. Because Russia has no GDPR adequacy decision and is currently subject to international sanctions, SberCRM is treated as a high risk vendor for European deployments.

What SberCRM is

SberCRM is the customer relationship management platform of the Sber group (PJSC Sberbank), the largest Russian bank. It is sold to small and mid sized Russian businesses as a bundle of CRM, marketing automation, lead capture, web chat and integration with other Sber services. The product is operated and hosted in the Russian Federation.

What data SberCRM collects

When the SberCRM widget is loaded on a website, it sets third party cookies (sber_session, sber_uid), captures the form fields submitted by visitors, the page URL, the referrer and an internal source identifier. The web push subscription token, when activated, is stored on Sber servers. The full lead profile is then available in the SberCRM back office for marketing and sales activation.

GDPR and ePrivacy implications

The SberCRM cookies fall under Article 5(3) ePrivacy and require prior consent. The lead capture and profile building activity falls under Article 6(1)(a) GDPR. Because data is transferred to the Russian Federation, an additional explicit consent is required under Article 49(1)(a) GDPR, with a clear warning that the transfer is to a country without adequacy.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Sanctions and operational risks

Sber and several of its subsidiaries are listed under EU, UK and US sanctions regimes. EU established controllers must verify they are not in breach of restrictive measures when contracting Sber group services. Standard Contractual Clauses are difficult to enforce against sanctioned counterparties, and Russian authorities have wide statutory access to data under Federal Law 152-FZ and the FSB framework.

Consent requirements

The SberCRM widget must be tag blocked until explicit, granular opt in consent is given. The consent message must clearly identify Sber as the operator, the Russian Federation as the destination and the absence of an adequacy decision. A clear refuse option must be available and the choice must be revocable at any time.

Practical compliance steps

For European deployments, run a sanctions screening on Sber and any sub processor, document a transfer impact assessment, prepare an Article 49(1)(a) consent flow, list SberCRM in the privacy and cookie policies with the Russian destination, restrict the widget to non sensitive use cases and seriously consider migrating to an EU based CRM (HubSpot EU, Salesforce Hyperforce EU, Pipedrive, Brevo, Bitrix24 hosted outside Russia) instead.

GDPR consent category

Marketing

Websites using SberCRM must obtain user consent under GDPR regulations.

Legal basisConsent (Art. 6(1)(a) GDPR + Art. 5(3) ePrivacy Directive) for the cookies set by the SberCRM widget and analytics, plus explicit consent under Article 49(1)(a) GDPR for the transfer to the Russian Federation. Legitimate interest is not admissible.
Risk levelhigh
Applicable regulationsGDPR, ePrivacy Directive, EU sanctions framework, Russian Federal Law 152-FZ on personal data, French CNIL guidelines, German TTDSG, Spanish LSSI, Italian Garante guidelines

DPIA considerations

A DPIA is required for any meaningful EU deployment of SberCRM, given the transfer to a non adequate country, the integration with the Sber advertising and identity stack, and the systematic capture of lead data. The DPIA must address the EU sanctions framework and the practical impossibility of enforcing Standard Contractual Clauses against a sanctioned counterparty.

Sample consent text

This site uses SberCRM (Sber, PJSC Sberbank, Russia) for customer support and lead management. SberCRM sets cookies, captures the data you submit and transfers it to servers in the Russian Federation, which is not covered by an EU adequacy decision. Click Accept only if you understand and agree to this transfer. You can withdraw your consent at any time.

Technical details

Tracking methodJavaScript widget loaded from sbercrm.com (chat, lead capture, web push subscription), REST API for the CRM back office, optional first party tracking script that records form submissions, page views and visitor source. Synchronisation with Sber group ad and analytics platforms.
Server locationSberCRM is operated by Sber (PJSC Sberbank) and SberDevices. Production data centres are located in the Russian Federation, with replication to other Sber group regions including Moscow, Saint Petersburg and Ural.
Data transferred outside the EUPersonal data is transferred to the Russian Federation. Russia has no GDPR adequacy decision and is on the EDPB list of high risk jurisdictions. Sber group is also subject to international sanctions, which adds operational restrictions. Standard Contractual Clauses are difficult to enforce in practice and explicit consent under Article 49(1)(a) GDPR is required for occasional transfers.

Third-party domains contacted

sbercrm.comcdn.sbercrm.comapi.sbercrm.comsber.ru

Cookies placed

NameTypeDurationPurpose
sber_sessionsessionSessionSession cookie that maintains the SberCRM widget interaction during the visit.
sber_uidpersistent1 yearPersistent identifier that links visits and form submissions to a unique browser inside the Sber group ecosystem.
sber_chatpersistent6 monthsStores the open conversation thread of the SberCRM web chat so the visitor can resume it on a later visit.

SberCRM places tracking cookies for advertising — comply with GDPR using FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does SberCRM set?

The SberCRM widget sets third party cookies on its operator domains (sber_session, sber_uid, _ya_uid for Yandex integrations, sber_chat) used to identify a unique browser, persist the chat session and synchronise with Sber group analytics.

Do I need consent to use SberCRM?

Yes. The cookies fall under Article 5(3) ePrivacy and the lead capture under Article 6(1)(a) GDPR. In addition, an explicit consent under Article 49(1)(a) GDPR is required for the transfer to the Russian Federation, which has no adequacy decision.

What is the legal basis for SberCRM?

Consent for the cookies and the lead capture, plus explicit consent for the transfer to Russia. Legitimate interest is not admissible because the destination country is not adequate, the operator is sanctioned in several jurisdictions and the data flows feed the Sber advertising and identity stack.

Does SberCRM transfer data to the US or Russia?

Production data is transferred to the Russian Federation. Russia has no GDPR adequacy decision, no DPF equivalent, and Sber group is subject to EU, UK and US sanctions. Standard Contractual Clauses are difficult to enforce. Article 49(1)(a) explicit consent is therefore the only realistic legal basis for the transfer.

Do I need a DPIA for SberCRM?

Yes for any meaningful EU deployment. The combination of lead profiling, transfer to a non adequate country, sanctions exposure, persistent cookies and integration with Sber identity systems triggers the DPIA criteria of WP248 and the EDPB threshold guidance.

How do I implement SberCRM compliantly?

Run a sanctions screening on Sber and any sub processor first. If you proceed, tag block the widget until consent, prepare a clear Article 49(1)(a) consent message, document a transfer impact assessment, restrict the widget to non sensitive use cases, list SberCRM in the privacy and cookie policies and review the configuration regularly. In most cases a migration to an EU based CRM is recommended.

What are the alternatives to SberCRM?

EU based CRM alternatives include HubSpot EU, Salesforce Hyperforce EU, Pipedrive (Estonia), Brevo (France), Bitrix24 hosted outside Russia, Zoho EU and Odoo. These tools avoid the Russia transfer and the sanctions overlap, and several offer EU only data residency.

How do I update the cookie policy for SberCRM?

List SberCRM with the operator (Sber, PJSC Sberbank, Russia), the purpose (CRM, lead management, web chat), the cookies (sber_session, sber_uid, sber_chat) with their retention, the legal basis (consent and Article 49(1)(a) explicit consent), the transfer destination (Russian Federation) and the residual risks (sanctions, lack of adequacy).