🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
HU v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 1 failing20 sources retrieved model claude-sonnet-5 · 2026-08-05

Hungary

HU schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 34 claims · 26 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
34Claimsbaseline..claims[]
4Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 21 September 2026

Lead Signal

NAIH's enforcement posture intensified materially this cycle. The Hungarian data protection authority fined Mediaworks Hungary Zrt HUF 50 million (approximately EUR 125,000) for intentional unlawful processing of personal and special-category political-opinion data, linked from Mediaworks' news portals to an unauthorised interactive map of political sympathisers, in breach of GDPR Articles 6(1) and 9(1). This is a High-confidence finding, though the exact NAIH decision reference and date were not located this cycle. Alongside the fine, NAIH recorded a substantial volume of enforcement activity generally: 539 CCTV-related investigative proceedings, 133 formal applications, and 15 ex-officio enforcement actions, plus ex-officio inspections of 21 webshops that found recurring privacy-notice deficiencies.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Strong T1/T2 confirmation of regulator identity, statutory basis and scope; only registration/filing nuance relies on secondary commentary.

Primary frameworkRegulation (EU) 2016/679 (GDPR); Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information, as amended by Act XXXVIII of 2018
Traffic-light rationale — GreenStrong T1/T2 confirmation of regulator identity, statutory basis and scope; only registration/filing nuance relies on secondary commentary.

Sub-modules (5)

Regulator And AuthorityGreen

NAIH is the confirmed national DPA.

Claims (1):

  • <cite index="3-1">Hungarian National Authority for Data Protection and Freedom of Information · Budapest Falk Miksa utca 9-11 1055 Hungary · http://www.naih.hu/</cite> is the national supervisory authority for data protection in Hungary.

Act And InstrumentsGreen

GDPR plus the amended Privacy Act form the dual instrument base.

Claims (1):

  • Hungary's data protection legal base is the GDPR together with <cite index="14-1">the Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information amended by Act XXXVIII of 2018, with effect of 26 July 2018, to ensure harmonisation with the GDPR</cite>.

Material ScopeGreen

Privacy Act supplements GDPR material scope on deceased persons' data and NAIH procedure.

Claims (1):

  • Beyond GDPR, the Privacy Act sets additional rules such as <cite index="5-2">rights concerning the data of the deceased</cite> and NAIH's procedural competences.

Territorial ScopeAmber

GDPR Art 3 territorial scope applies; Weltimmo v NAIH is a leading CJEU 'establishment' authority.

Claims (1):

  • EDPB territorial-scope guidance cites <cite index="58-3">Weltimmo v NAIH (C-230/14)</cite> among the leading CJEU rulings interpreting the 'establishment' concept determining GDPR applicability to Hungary-linked processing.

Regulator Registration And FilingGreen

DPO contact details must be communicated to NAIH per Art 37(7); no separate national controller-registration regime.

Claims (1):

  • NAIH guidance confirms that, per <cite index="9-7">Article 37(7) of the GDPR: "The controller or the processor shall publish the contact details of the data protection officer and communicate them to the supervisory authority"</cite>, controllers/processors must notify NAIH of DPO contact details under the GDPR itself, not a separate Hungarian filing regime.
Category narrative81 words

Hungary is an EU Member State applying the GDPR directly, supplemented by the national Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (the 'Privacy Act'), as amended by Act XXXVIII of 2018 to harmonise with the GDPR. The Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH) is the single national supervisory authority. Material and territorial scope track GDPR Arts 2-3, with the Privacy Act filling gaps outside GDPR's material scope (e.g. NAIH procedure, rights of deceased persons).

no periodic updates on record for this sub-brief

Sources and claims (5)
  1. ConfirmedEDPB — <cite index="3-1">Hungarian National Authority for Data Protection and Freedom of Information · Budapest Falk Miksa utca 9-11 1055 Hungary · http://www.naih.hu/</cite> is the national supervisory authority for data protection in Hungary.observed
  2. ConfirmedDataGuidance (OneTrust) — Hungary's data protection legal base is the GDPR together with <cite index="14-1">the Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information amended by Act XXXVIII of 2018, with effect of 26 July 2018, to ensure harmonisation with the GDPR</cite>.observed
  3. ConfirmedDataGuidance (OneTrust) — Beyond GDPR, the Privacy Act sets additional rules such as <cite index="5-2">rights concerning the data of the deceased</cite> and NAIH's procedural competences.observed
  4. ProbableEDPB — EDPB territorial-scope guidance cites <cite index="58-3">Weltimmo v NAIH (C-230/14)</cite> among the leading CJEU rulings interpreting the 'establishment' concept determining GDPR applicability to Hungary-linked processing.observed
  5. ConfirmedDataGuidance (OneTrust) — NAIH guidance confirms that, per <cite index="9-7">Article 37(7) of the GDPR: "The controller or the processor shall publish the contact details of the data protection officer and communicate them to the supervisory authority"</cite>, controllers/processors must notify NAIH of DPO contact details under the GDPR itself, not a separate Hungarian filing regime.observed

#

Lawful bases and consent well evidenced; pseudonymisation/anonymisation sub-module has no HU-specific finding.

Primary frameworkGDPR Arts 6, 7, 9; Act CXII of 2011 (amended)
Supervisory authorityNAIH
Traffic-light rationale — AmberLawful bases and consent well evidenced; pseudonymisation/anonymisation sub-module has no HU-specific finding.

Sub-modules (4)

Lawful BasesGreen

Privacy Act constrains legal-obligation/public-interest processing to statute/decree bases with periodic review.

Claims (1):

  • Under the amended Privacy Act, where processing rests on legal obligation or public-interest/official-authority grounds, <cite index="14-3">organisations can rely only on laws and municipality decrees, and must periodically review the purposes of the processing</cite>.

Special CategoriesGreen

Biometric data used for unique identification is Art 9 special-category data.

Claims (1):

  • <cite index="33-3">Since 2018, the EU General Data Protection Regulation has governed the processing of biometric data as a form of personal data and, when used to uniquely identify individuals, as "special category data"</cite>, a rule applying directly in Hungary as an EU Member State.

Pseudonymisation And AnonymisationRed

No Hungary-specific pseudonymisation/anonymisation safe-harbour identified in this research pass.

Absence provenance: unavailable. Searched: Hungary pseudonymisation anonymisation GDPR NAIH guidance.

Category narrative45 words

GDPR Art 6 lawful bases and Art 9 special-category rules apply directly. The amended Privacy Act layers additional constraints on legal-obligation/public-interest processing and confirms no domestic derogation on the age required for valid consent. Pseudonymisation/anonymisation carries no confirmed Hungary-specific safe harbour beyond the GDPR baseline.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. ConfirmedDataGuidance (OneTrust) — Under the amended Privacy Act, where processing rests on legal obligation or public-interest/official-authority grounds, <cite index="14-3">organisations can rely only on laws and municipality decrees, and must periodically review the purposes of the processing</cite>.observed
  2. ProbableDataGuidance (OneTrust) — Legal commentary confirms <cite index="14-5">the Act does not provide for any derogations on the age for valid consent</cite> in Hungary.observed
  3. ConfirmedIAPP — <cite index="33-3">Since 2018, the EU General Data Protection Regulation has governed the processing of biometric data as a form of personal data and, when used to uniquely identify individuals, as "special category data"</cite>, a rule applying directly in Hungary as an EU Member State.observed

#

Strong enforcement evidence for most rights; portability sub-module unresolved.

Primary frameworkGDPR Arts 12-22; Act CXII of 2011 §§52-61
Supervisory authorityNAIH
Traffic-light rationale — AmberStrong enforcement evidence for most rights; portability sub-module unresolved.

Sub-modules (5)

Access RightAmber

Right of access is exercisable via controllers with NAIH recourse where responses (e.g. SIRENE) are unsatisfactory.

Claims (1):

  • Under <cite index="19-1">the relevant provisions (52-61.§) of Act CXII of 2011 on Informational Self-Determination and Freedom of Information ("Privacy Act")</cite>, data subjects may escalate unsatisfactory access responses to the Hungarian NAIH.

Rectification And ErasureGreen

NAIH has ordered erasure of unlawfully processed data in enforcement decisions.

Claims (1):

  • In a May 2024 decision, NAIH found a company had <cite index="27-4">failed to delete illegally processed data and did not provide necessary information to the applicant</cite> and ordered erasure.

Restriction And ObjectionGreen

NAIH enforcement (Forbes case) required documented balancing tests and honouring of objections.

Claims (1):

  • NAIH's Forbes decision held that a publisher must carry out a proper interest assessment and address data subjects' objections, since it <cite index="29-1">failed to carry out an individual interest assessment, the result of which would have demonstrated that data processing was justified</cite>.

Data PortabilityRed

No HU-specific portability finding beyond GDPR Art 20 baseline.

Absence provenance: unavailable. Searched: Hungary NAIH data portability GDPR Article 20 guidance.

Deadlines And Response WindowsAmber

GDPR's one-month statutory response window applies directly.

Claims (1):

  • The GDPR's directly applicable one-month response deadline (Art 12(3)) governs controller responses to data-subject requests in Hungary.
Category narrative26 words

Access, rectification/erasure, restriction/objection are all evidenced through NAIH enforcement practice. Portability carries no HU-specific derogation identified. Response-deadline obligations follow the GDPR's own one-month standard applied directly.

no periodic updates on record for this sub-brief

Sources and claims (4)
  1. ProbableEDPS — Under <cite index="19-1">the relevant provisions (52-61.§) of Act CXII of 2011 on Informational Self-Determination and Freedom of Information ("Privacy Act")</cite>, data subjects may escalate unsatisfactory access responses to the Hungarian NAIH.observed
  2. ConfirmedDataGuidance (OneTrust) — In a May 2024 decision, NAIH found a company had <cite index="27-4">failed to delete illegally processed data and did not provide necessary information to the applicant</cite> and ordered erasure.observed
  3. ConfirmedEDPB — NAIH's Forbes decision held that a publisher must carry out a proper interest assessment and address data subjects' objections, since it <cite index="29-1">failed to carry out an individual interest assessment, the result of which would have demonstrated that data processing was justified</cite>.observed
  4. ConfirmedEUR-Lex — The GDPR's directly applicable one-month response deadline (Art 12(3)) governs controller responses to data-subject requests in Hungary.observed

#

Breach notification and joint-controller duties strongly evidenced; ROPA/security-measures sub-modules unresolved at HU-specific level.

Primary frameworkGDPR Arts 5, 24-32, 33-34, 35, 37-39; Act CXII of 2011 §56
Supervisory authorityNAIH
Traffic-light rationale — AmberBreach notification and joint-controller duties strongly evidenced; ROPA/security-measures sub-modules unresolved at HU-specific level.

Sub-modules (7)

Accountability And DpiaGreen

NAIH's Art 26 decision demonstrates active accountability enforcement.

Claims (1):

  • NAIH's decision on a foundation's processing found <cite index="4-9">there was no arrangement between the Foundation and the School within the meaning of Article 26(1) of the GDPR, with regard to joint processing and their respective responsibilities</cite>, reflecting active accountability enforcement.

Dpo RequirementsAmber

DPO contact-notification duty under Art 37(7); sectoral commentary suggests mandatory DPO practice in telecoms/finance.

Claims (1):

  • Hungarian practice commentary states <cite index="52-1">Appointment of a DPO is mandatory in certain industries only, such as telecommunications providers and financial organisations</cite>, alongside the GDPR Art 37(7) notification duty to NAIH.

Ropa RequirementsRed

No HU-specific ROPA finding beyond GDPR Art 30 baseline.

Absence provenance: unavailable. Searched: Hungary NAIH records of processing activities ROPA guidance.

Joint Controller ArrangementsGreen

NAIH found an Art 26(1) infringement for absence of a proper joint-controller arrangement.

Claims (1):

  • NAIH ordered a foundation to remedy its breach after finding that <cite index="4-10">the cooperation agreement between them did not address the issues required by this provision</cite> of Art 26(1) GDPR.

Security MeasuresRed

No HU-specific security-measures finding beyond GDPR Art 32 baseline.

Absence provenance: unavailable. Searched: Hungary NAIH technical organisational security measures GDPR guidance.

Breach NotificationGreen

NAIH's own Art 97 questionnaire response confirms an operative breach-notification regime.

Claims (1):

  • NAIH reported that <cite index="6-5">The Hungarian SA received 744 personal data breach notification by 30th November 2019</cite>, confirming an operative breach-notification pipeline under GDPR Arts 33-34.

Retention And DisposalAmber

NAIH enforcement orders erasure/restriction pending resolution of legal challenges.

Claims (1):

  • NAIH's 2024 decision ordered that <cite index="27-5">the company was ordered to erase the data and restrict access until legal challenges are resolved</cite>.
Category narrative52 words

Accountability, joint-controller and breach-notification duties are well evidenced via NAIH's Art 26 enforcement decision and its Art 97 self-report citing breach-notification volumes. DPO duties are shaped by both GDPR Art 37 and Hungarian sectoral practice. ROPA and security-measures sub-modules rely on the unadorned GDPR baseline with no HU-specific finding in this pass.

no periodic updates on record for this sub-brief

Sources and claims (5)
  1. ConfirmedEDPB — NAIH's decision on a foundation's processing found <cite index="4-9">there was no arrangement between the Foundation and the School within the meaning of Article 26(1) of the GDPR, with regard to joint processing and their respective responsibilities</cite>, reflecting active accountability enforcement.observed
  2. ProbableIAPP — Hungarian practice commentary states <cite index="52-1">Appointment of a DPO is mandatory in certain industries only, such as telecommunications providers and financial organisations</cite>, alongside the GDPR Art 37(7) notification duty to NAIH.observed
  3. ConfirmedEDPB — NAIH ordered a foundation to remedy its breach after finding that <cite index="4-10">the cooperation agreement between them did not address the issues required by this provision</cite> of Art 26(1) GDPR.observed
  4. ConfirmedEDPB — NAIH reported that <cite index="6-5">The Hungarian SA received 744 personal data breach notification by 30th November 2019</cite>, confirming an operative breach-notification pipeline under GDPR Arts 33-34.observed
  5. ConfirmedDataGuidance (OneTrust) — NAIH's 2024 decision ordered that <cite index="27-5">the company was ordered to erase the data and restrict access until legal challenges are resolved</cite>.observed

#

BCR/SCC mechanism confirmed; adequacy sub-modules are not applicable at MS level; TIA and localisation unresolved.

Primary frameworkGDPR Chapter V (Arts 44-49)
Supervisory authorityNAIH
Traffic-light rationale — AmberBCR/SCC mechanism confirmed; adequacy sub-modules are not applicable at MS level; TIA and localisation unresolved.

Sub-modules (6)

Transfer MechanismsGreen

NAIH exercises Art 47 BCR-approval powers as part of the Chapter V mechanism set.

Claims (1):

  • <cite index="55-2">Having regard to Article 47(1) of the EU General Data Protection Regulation 2016/679 (GDPR), the National Authority for Data Protection and Freedom of Information shall approve Binding Corporate Rules</cite> as a recognised Chapter V transfer mechanism.

Adequacy ReceivedRed

Not applicable at Member-State level; EU Commission adequacy decisions apply uniformly.

Absence provenance: unavailable. Searched: Hungary national adequacy decision received EU Commission.

Adequacy GrantedRed

Not applicable at Member-State level.

Absence provenance: unavailable. Searched: Hungary national adequacy decision granted third country.

Sccs And BcrsGreen

NAIH approved Controller BCRs as BCR-lead authority with EDPB Opinion 07/2022 concurrence.

Claims (1):

  • NAIH acted as BCR Lead authority and <cite index="55-5">the EDPB provided its opinion 07/2022 in accordance with Article 64(1)(f)</cite>, finding no concerns regarding the Controller BCR.

Transfer Impact AssessmentRed

No HU-specific TIA guidance identified beyond general EDPB/Schrems II standard.

Absence provenance: unavailable. Searched: Hungary NAIH transfer impact assessment Schrems II guidance.

Data LocalisationRed

No general HU data-localisation mandate identified; sector-specific law-enforcement data rules addressed under sectoral_watch/state_surveillance_carveouts.

Absence provenance: unavailable. Searched: Hungary data localisation requirement personal data GDPR.

Category narrative56 words

Chapter V transfer mechanisms apply via GDPR directly; NAIH has approved Binding Corporate Rules as a BCR-lead authority. As adequacy decisions are made centrally by the European Commission for all EU Member States, Hungary does not receive or grant bespoke national adequacy determinations. No HU-specific transfer-impact-assessment guidance or general data-localisation mandate was identified in this pass.

Periodic update · new data 2026-09-21

Cross-Border & Adequacy

The European Union has adopted Regulation (EU) 2025/2518, which lays down additional procedural rules for the enforcement of the GDPR in cross-border cases, and which becomes applicable from April 2027. This is a High-confidence finding, and its regulatory stage is enacted-but-not-yet-effective: the regulation exists as adopted EU law but does not yet govern how data protection authorities, including NAIH, cooperate on cross-border enforcement matters. Once applicable, the regulation will introduce additional procedural rules shaping how NAIH cooperates with other EU data protection authorities on cases involving controllers or processors operating across multiple member states.

No other cross-border or adequacy development was identified for Hungary this cycle beyond this EU-level procedural instrument; this brief does not extend to Hungary-specific adequacy decisions or transfer-mechanism developments, none of which were located in the sources reached this cycle.

Outlook

Because Regulation (EU) 2025/2518 does not become applicable until April 2027, no immediate operational change to NAIH's cross-border cooperation practice is expected before that date. The item to watch over the intervening period is whether NAIH or the European Data Protection Board issues implementing guidance ahead of the April 2027 application date.

Sources and claims (2)
  1. ConfirmedNAIH / EDPB — <cite index="55-2">Having regard to Article 47(1) of the EU General Data Protection Regulation 2016/679 (GDPR), the National Authority for Data Protection and Freedom of Information shall approve Binding Corporate Rules</cite> as a recognised Chapter V transfer mechanism.observed
  2. ConfirmedNAIH / EDPB — NAIH acted as BCR Lead authority and <cite index="55-5">the EDPB provided its opinion 07/2022 in accordance with Article 64(1)(f)</cite>, finding no concerns regarding the Controller BCR.observed

#

Meaningful telecoms/employment/education evidence; financial-sector detail unverified; health/credit/insurance unresolved.

Primary frameworkGDPR plus sectoral instruments (Act CVIII of 2001 on electronic commerce; labour-law/IT-policy practice)
Supervisory authorityNAIH
Traffic-light rationale — AmberMeaningful telecoms/employment/education evidence; financial-sector detail unverified; health/credit/insurance unresolved.

Sub-modules (7)

Financial Sector OverlayAmber

A record NAIH fine against a bank was identified by headline only; full decision content not retrievable in this pass.

Absence provenance: unavailable. Searched: NAIH fine bank Hungary 2020 GDPR financial sector.

Claims (1):

  • NAIH is reported to have issued a record HUF 250 million fine against a bank ('NAIH fines Budapest Bank record HUF 250M'), indicating an active financial-sector enforcement overlay, though full decision detail was not retrievable in this pass.

Health Sector OverlayRed

No HU-specific health-sector overlay finding.

Absence provenance: unavailable. Searched: Hungary health sector data protection overlay NAIH.

Telecoms And EprivacyGreen

NMHH, not NAIH, holds competence over certain e-commerce/unsubscribe complaints.

Claims (1):

  • NAIH held that <cite index="10-8">Pursuant to Section 16/B of Act CVIII of 2001 concerning electronic commercial services... the investigation... is within the powers of the Nemzeti Média- és Hírközlési Hatóság (NMHH...)</cite>, not NAIH, for certain newsletter/unsubscribe complaints.

Employment DataGreen

NAIH enforcement on employer IT/monitoring policy deficiencies.

Claims (1):

  • NAIH fined an employer after finding IT-policy deficiencies, requiring that <cite index="48-16">employees must also be informed of the privacy aspects of the monitoring; e.g., purpose of data processing, the data controller, data retention periods, data privacy rights and remedies</cite>.

Credit And ScoringRed

No HU-specific credit-scoring finding.

Absence provenance: unavailable. Searched: Hungary credit scoring data protection NAIH.

EducationAmber

Cross-border education-adjacent case on children's video recordings.

Claims (1):

  • NAIH examined joint-controller responsibility for <cite index="4-5">recordings feature children performing and singing specifically from a Slovak Primary School</cite> published by a Hungarian-linked foundation.

InsuranceRed

No HU-specific insurance-sector finding.

Absence provenance: unavailable. Searched: Hungary insurance sector data protection NAIH overlay.

Category narrative68 words

Telecoms/e-commerce direct-marketing complaints are carved out to the media regulator NMHH rather than NAIH. Employment-data processing has generated concrete NAIH enforcement on IT-monitoring policies. Education-adjacent processing of children's data has been the subject of an Art 26 cross-border case. Financial-sector enforcement (a record fine against a bank) was identified only by headline, not verified in full; health, credit-scoring and insurance sub-modules carry no HU-specific finding in this pass.

Periodic update · new data 2026-09-21

Sectoral Watch

NAIH's principal sectoral signal this cycle is a thematic review of artificial-intelligence deployment in Hungary's banking sector. The review examined training-data sourcing, model-accuracy validation, pseudonymisation and anonymisation practices, and controls against unauthorised or ungoverned ('shadow') AI use within banking institutions, and NAIH has signalled that further large-scale sectoral reviews are planned during 2026. This is a High-confidence finding for the review itself, though whether the signalled additional 2026 reviews beyond banking have actually commenced was not confirmed this cycle.

Reading this development through a sectoral-watch lens rather than the algorithmic-governance lens applied elsewhere in this cycle's coverage, the material point is NAIH's choice of the banking sector as its opening thematic focus: banking is both a systemically important sector and one in which AI deployment for credit decisioning, fraud detection and customer-risk scoring is already widespread.

Outlook

The item to watch is which sector NAIH selects for its next signalled thematic review during 2026, and whether the banking-sector review's specific findings are published in a form that gives other sectors advance notice of NAIH's supervisory expectations before their own turn comes.

Sources and claims (4)
  1. UncertainDataGuidance (OneTrust) — NAIH is reported to have issued a record HUF 250 million fine against a bank ('NAIH fines Budapest Bank record HUF 250M'), indicating an active financial-sector enforcement overlay, though full decision detail was not retrievable in this pass.observed
  2. ConfirmedEDPB — NAIH held that <cite index="10-8">Pursuant to Section 16/B of Act CVIII of 2001 concerning electronic commercial services... the investigation... is within the powers of the Nemzeti Média- és Hírközlési Hatóság (NMHH...)</cite>, not NAIH, for certain newsletter/unsubscribe complaints.observed
  3. ConfirmedIAPP — NAIH fined an employer after finding IT-policy deficiencies, requiring that <cite index="48-16">employees must also be informed of the privacy aspects of the monitoring; e.g., purpose of data processing, the data controller, data retention periods, data privacy rights and remedies</cite>.observed
  4. ConfirmedEDPB — NAIH examined joint-controller responsibility for <cite index="4-5">recordings feature children performing and singing specifically from a Slovak Primary School</cite> published by a Hungarian-linked foundation.observed

#

Only direct_marketing sub-module has confirmed evidence; the remaining five sub-modules are unresolved gaps.

Primary frameworkePrivacy Directive as implemented via Act CVIII of 2001 on electronic commerce; GDPR
Supervisory authorityNAIH
Traffic-light rationale — RedOnly direct_marketing sub-module has confirmed evidence; the remaining five sub-modules are unresolved gaps.

Sub-modules (6)

Cookies And TrackersRed

No HU-specific cookie-consent guidance identified in this pass.

Absence provenance: unavailable. Searched: Hungary cookie consent ePrivacy NAIH guidance.

Dark PatternsRed

No HU-specific dark-pattern finding.

Absence provenance: unavailable. Searched: Hungary dark patterns data protection NAIH.

Opt Out SignalsRed

No HU-specific opt-out-signal finding.

Absence provenance: unavailable. Searched: Hungary Global Privacy Control opt-out signal NAIH.

Clean Rooms And DcrRed

No HU-specific clean-room/DCR finding.

Absence provenance: unavailable. Searched: Hungary data clean room GDPR NAIH.

Cross Context AdvertisingRed

Not applicable in the GDPR model in the manner of US state 'sale/share' concepts; no HU-specific finding.

Absence provenance: unavailable. Searched: Hungary cross-context advertising GDPR equivalent.

Direct MarketingGreen

NMHH holds competence over certain direct-marketing/unsubscribe complaints under Act CVIII of 2001.

Claims (1):

  • NAIH declined jurisdiction over an unsubscribe/newsletter complaint, noting that <cite index="10-7">as with respect to the unsubscribe itself it has no jurisdiction according to the rules of Hungarian law</cite>, referring the matter to NMHH under Act CVIII of 2001.
Category narrative40 words

Direct-marketing enforcement carve-outs to NMHH under Act CVIII of 2001 are confirmed. Cookie/tracker consent, dark-pattern prohibitions, opt-out signals, clean-room rules and cross-context advertising (a US-state-law concept largely inapplicable under the GDPR model) carry no HU-specific finding in this research pass.

Periodic update · new data 2026-09-21

AdTech & Commercial Privacy

NAIH conducted ex-officio inspections of 21 webshops this cycle and found recurring privacy-notice deficiencies across them. This is part of a broader enforcement-activity picture that also included 539 CCTV-related investigative proceedings, 133 formal applications and 15 ex-officio enforcement actions, though the webshop inspections are the specific finding most relevant to commercial and adtech-adjacent privacy practice: privacy notices are the primary transparency mechanism through which e-commerce operators disclose their data-processing and, where applicable, adtech and cookie-related practices to consumers. No dedicated cookie-consent-specific or adtech-platform-specific enforcement action distinct from the general privacy-notice finding was confirmed this cycle, and this brief does not infer one beyond what the source material supports.

This is an Assessed-confidence, partial-cycle finding: the fact of the inspection programme and its headline finding are confirmed, but the precise legal basis for the inspections, the specific privacy-notice deficiencies identified, and any resulting sanctions or corrective orders were not established from the sources reached this cycle.

Outlook

The item to watch is whether NAIH's webshop inspection programme is followed by a published enforcement decision or a broader sectoral report on e-commerce privacy-notice compliance, which would clarify both the legal basis for the inspections and the practical scope of the deficiencies found.

Sources and claims (1)
  1. ConfirmedEDPB — NAIH declined jurisdiction over an unsubscribe/newsletter complaint, noting that <cite index="10-7">as with respect to the unsubscribe itself it has no jurisdiction according to the rules of Hungarian law</cite>, referring the matter to NMHH under Act CVIII of 2001.observed

#

ADM, biometric and surveillance-carveout sub-modules evidenced; AI risk-assessment detail and profiling/genetic sub-modules remain unresolved or uncertain.

Primary frameworkGDPR Art 22; GDPR Art 9 (biometrics); EU AI Act; Hungarian AI Law (2025); national security/law-enforcement acts
Supervisory authorityNAIH
Traffic-light rationale — AmberADM, biometric and surveillance-carveout sub-modules evidenced; AI risk-assessment detail and profiling/genetic sub-modules remain unresolved or uncertain.

Sub-modules (6)

Profiling RestrictionsRed

No HU-specific profiling-restriction finding beyond GDPR Art 22 baseline.

Absence provenance: unavailable. Searched: Hungary NAIH profiling restrictions Article 22 guidance.

Automated Decision Making TransparencyGreen

GDPR Art 22 ADM transparency rules apply directly.

Claims (1):

  • GDPR Art 22, in force since 25 May 2018, directly governs automated-decision-making transparency and the right to human intervention in Hungary as an EU Member State.

Ai Risk AssessmentsAmber

Hungary enacted a national AI Law in late 2025; detailed provisions unverified in this pass.

Absence provenance: unavailable. Searched: Hungary AI Law 2025 NAIH designated authority AI Act.

Claims (1):

  • Hungary's government enacted a national AI Law ('Hungary: Government enacts AI Law') in approximately November 2025, though the specific scope of its AI risk-assessment obligations could not be confirmed from retrievable source text in this pass.

Biometric RegimeGreen

EU-wide GDPR/AI Act biometric special-category regime applies directly in Hungary.

Claims (1):

  • <cite index="33-4">the EU AI Act introduces a new layer of regulation that targets four types of biometrics and classifies them by risk — ranging from prohibited to high risk and limited risk</cite>, applying directly in Hungary alongside the GDPR biometric special-category rule.

Genetic DataRed

No HU-specific genetic-data finding beyond GDPR Art 9 baseline.

Absence provenance: unavailable. Searched: Hungary genetic data protection NAIH guidance.

State Surveillance CarveoutsAmber

Sectoral security-sector acts (Police, Prison Service, Prosecution) carve out data processing from GDPR's material scope.

Claims (1):

  • Hungary's law-enforcement/security-sector data processing is separately governed by instruments including <cite index="13-3">Act on Police (Act XXXIV of 1994)... Act on the Hungarian Prison Service Organisation (Act CVII of 1995)</cite> and the Prosecution Service Act, sitting outside GDPR's material scope.
Category narrative62 words

GDPR Art 22 ADM rules and the EU-wide biometric special-category regime apply directly. Hungary enacted a national AI Law in November 2025, though its detailed risk-assessment provisions could not be verified from sources retrieved in this pass. Law-enforcement/security-sector data carve-outs (Police, Prison Service, Prosecution Acts) sit outside GDPR's material scope. Profiling-restriction and genetic-data sub-modules have no HU-specific finding beyond the GDPR baseline.

Periodic update · new data 2026-09-21

Algorithmic, Biometric & Surveillance Governance

NAIH's thematic review of AI deployment in Hungary's banking sector is this cycle's principal algorithmic-governance development. The review's four stated focus areas — training-data sourcing, model-accuracy validation, pseudonymisation and anonymisation practices, and controls against shadow-AI use — collectively describe a supervisory programme aimed at the full lifecycle of AI-system data governance within banking institutions. This is a High-confidence finding, and the interpreter has escalated this module's trajectory rating to escalating this cycle, reflecting the materiality of an active, named thematic supervisory programme rather than a general policy statement.

NAIH has also signalled further large-scale sectoral AI reviews during 2026, though whether these have commenced beyond banking was not confirmed this cycle; this brief treats the signal as a forward-looking indicator of NAIH's supervisory trajectory rather than a confirmed multi-sector rollout.

Outlook

The item to watch is the substantive outcome of the banking-sector review — whether it results in published findings, guidance, or enforcement action — and whether NAIH's signalled further reviews materialise in a specific additional sector during 2026, which would be the clearest indicator that algorithmic governance has become a standing NAIH supervisory priority rather than a single-sector initiative.

Sources and claims (4)
  1. ConfirmedEUR-Lex — GDPR Art 22, in force since 25 May 2018, directly governs automated-decision-making transparency and the right to human intervention in Hungary as an EU Member State.observed
  2. UncertainDataGuidance (OneTrust) — Hungary's government enacted a national AI Law ('Hungary: Government enacts AI Law') in approximately November 2025, though the specific scope of its AI risk-assessment obligations could not be confirmed from retrievable source text in this pass.observed
  3. ConfirmedIAPP — <cite index="33-4">the EU AI Act introduces a new layer of regulation that targets four types of biometrics and classifies them by risk — ranging from prohibited to high risk and limited risk</cite>, applying directly in Hungary alongside the GDPR biometric special-category rule.observed
  4. ProbableEUR-Lex — Hungary's law-enforcement/security-sector data processing is separately governed by instruments including <cite index="13-3">Act on Police (Act XXXIV of 1994)... Act on the Hungarian Prison Service Organisation (Act CVII of 1995)</cite> and the Prosecution Service Act, sitting outside GDPR's material scope.observed

#

Partial evidence on age/consent and one concrete education-adjacent enforcement matter; three sub-modules unresolved.

Primary frameworkGDPR Art 8; Act CXII of 2011 (amended)
Supervisory authorityNAIH
Traffic-light rationale — AmberPartial evidence on age/consent and one concrete education-adjacent enforcement matter; three sub-modules unresolved.

Sub-modules (5)

Age VerificationAmber

No domestic derogation on age for valid consent identified; specific Art 8 minors' threshold for HU unconfirmed.

Claims (1):

  • Legal commentary confirms <cite index="14-5">the Act does not provide for any derogations on the age for valid consent</cite>, though the precise Art 8 digital-minors threshold for Hungary was not separately confirmed.

Minor Profiling BansRed

No HU-specific minor-profiling-ban finding.

Absence provenance: unavailable. Searched: Hungary minors profiling ban data protection NAIH.

Education SettingsAmber

NAIH's Art 26 decision engaged children's data in an education-adjacent, cross-border context.

Claims (1):

  • NAIH's decision addressed processing of <cite index="4-5">recordings feature children performing and singing specifically from a Slovak Primary School</cite> in a cross-border, education-adjacent joint-controller dispute.

Dependent AdultsRed

No HU-specific dependent-adults finding.

Absence provenance: unavailable. Searched: Hungary dependent adults elderly data protection NAIH.

Category narrative48 words

No domestic derogation from the GDPR's general consent-age rules was identified, though the specific Art 8 digital-minor-consent threshold for Hungary was not separately confirmed. An education-adjacent case involving children's video recordings evidences NAIH's practical engagement with minors' data. Minor-profiling-ban, dedicated parental-consent-mechanism and dependent-adults sub-modules carry no HU-specific finding.

no periodic updates on record for this sub-brief

Sources and claims (2)
  1. ProbableDataGuidance (OneTrust) — Legal commentary confirms <cite index="14-5">the Act does not provide for any derogations on the age for valid consent</cite>, though the precise Art 8 digital-minors threshold for Hungary was not separately confirmed.observed
  2. ConfirmedEDPB — NAIH's decision addressed processing of <cite index="4-5">recordings feature children performing and singing specifically from a Slovak Primary School</cite> in a cross-border, education-adjacent joint-controller dispute.observed

#

Strong evidence on powers, enforcement activity, and private redress; funding/capacity and collective-redress sub-modules unresolved; recent-developments window carries only an uncertain, borderline-dated item.

Primary frameworkGDPR Arts 58, 77-84; Act CXII of 2011 §56
Supervisory authorityNAIH
Traffic-light rationale — AmberStrong evidence on powers, enforcement activity, and private redress; funding/capacity and collective-redress sub-modules unresolved; recent-developments window carries only an uncertain, borderline-dated item.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

NAIH exercises binding corrective powers under GDPR Art 58 and Privacy Act §56(1).

Claims (1):

  • NAIH exercised its corrective powers by giving notice to a foundation, <cite index="4-11">Based on Article 58(2)(d) of the GDPR and Section 56(1) of the Privacy Act the Hungarian Supervisory Authority (SA) gave notice to the Foundation ordering it to meet the requirements for joint controllers</cite>.

Enforcement Activity IndexGreen

A confirmed 2024 HUF 10 million GDPR fine evidences ongoing enforcement activity.

Claims (1):

  • <cite index="27-6">On May 17, 2024, the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) issued decision No. NAIH/3977-4/2023</cite>, fining a company HUF 10 million for GDPR violations.

Regulator Funding And CapacityRed

No HU-specific funding/headcount finding.

Absence provenance: unavailable. Searched: NAIH budget headcount capacity Hungary data protection authority.

Collective Redress And Class ActionsRed

No HU-specific collective-redress mechanism finding.

Absence provenance: unavailable. Searched: Hungary collective redress class action data protection GDPR.

Private Right Of ActionGreen

Judicial review of NAIH decisions before the Budapest Tribunal is confirmed via the Forbes case.

Claims (1):

  • Parties may seek judicial review of NAIH decisions, as shown where <cite index="29-11">A petition for review was submitted to the Fővárosi Törvényszék (Budapest Tribunal) by the Publisher against decision NAIH/2020/838/2</cite>.

Recent Developments 180DAmber

The most recent notable Hungarian development identified is the national AI Law (~Nov 2025), just outside the strict 180-day window from the 2026-08-05 run date; detailed content unverified.

Absence provenance: unavailable. Searched: Hungary data protection recent developments 2026, NAIH enforcement 2026.

Claims (1):

  • Hungary's government enacted a national AI Law ('Hungary: Government enacts AI Law') dated on or around November 2025, the most recent notable HU development identified, though detailed provisions and precise commencement remain unverified.
Category narrative78 words

NAIH exercises GDPR Art 58 corrective powers, including binding compliance orders under Privacy Act §56(1). Enforcement activity is well documented (e.g. a HUF 10 million fine in May 2024). Private judicial review of NAIH decisions before the Budapest Tribunal is confirmed. Regulator funding/capacity and collective-redress mechanisms carry no HU-specific finding in this pass; the most recent notable development (a national AI Law) dates to approximately November 2025, just outside the strict 180-day look-back window from this run's date.

Periodic update · new data 2026-09-21

Enforcement & Redress

NAIH's enforcement posture intensified materially this cycle. The authority fined Mediaworks Hungary Zrt HUF 50 million (approximately EUR 125,000) for intentional unlawful processing of personal and special-category political-opinion data, linked from Mediaworks' news portals to an unauthorised interactive map of political sympathisers, in breach of GDPR Articles 6(1) and 9(1). This is a High-confidence finding, though the exact NAIH decision reference and date were not located this cycle, a gap this brief flags rather than resolves by inference. The special-category nature of the data involved and the unauthorised interactive-map delivery mechanism together distinguish this case from routine security-incident enforcement.

Alongside the Mediaworks fine, NAIH recorded a substantial general enforcement-activity volume this cycle: 539 CCTV-related investigative proceedings, 133 formal applications, and 15 ex-officio enforcement actions, plus ex-officio inspections of 21 webshops that found recurring privacy-notice deficiencies. This is an Assessed-to-High-confidence composite finding sourced to a CMS GDPR Enforcement Tracker report, and it indicates NAIH sustained a high investigative tempo across CCTV and e-commerce sectors during the period, independent of the Mediaworks case specifically.

Outlook

The clearest open item is confirmation of the exact NAIH decision reference and date for the Mediaworks fine, which would allow future coverage to anchor to a primary regulatory source. A second item is whether the CCTV and webshop enforcement-volume figures represent a sustained elevated tempo or a single high-activity period, a question this brief cannot resolve without a prior-cycle baseline for comparison.

Sources and claims (4)
  1. ConfirmedEDPB — NAIH exercised its corrective powers by giving notice to a foundation, <cite index="4-11">Based on Article 58(2)(d) of the GDPR and Section 56(1) of the Privacy Act the Hungarian Supervisory Authority (SA) gave notice to the Foundation ordering it to meet the requirements for joint controllers</cite>.observed
  2. ConfirmedDataGuidance (OneTrust) — <cite index="27-6">On May 17, 2024, the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) issued decision No. NAIH/3977-4/2023</cite>, fining a company HUF 10 million for GDPR violations.observed
  3. ConfirmedEDPB — Parties may seek judicial review of NAIH decisions, as shown where <cite index="29-11">A petition for review was submitted to the Fővárosi Törvényszék (Budapest Tribunal) by the Publisher against decision NAIH/2020/838/2</cite>.observed
  4. UncertainDataGuidance (OneTrust) — Hungary's government enacted a national AI Law ('Hungary: Government enacts AI Law') dated on or around November 2025, the most recent notable HU development identified, though detailed provisions and precise commencement remain unverified.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

Blocking. 1 failing check(s).

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okFAIL
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct0.0
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Hungary
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 34 claim(s) (34 category placement(s)), 26 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Regulator identity, core instrument basis, GDPR Art 26 joint-controller enforcement, breach-notification volume, BCR approval, Forbes objection/erasure enforcement, and the 2024 HUF 10M fine are all grounded in T1/T2 primary or EDPB-published official sources. DPO, financial-sector, AI-Law and biometric-surveillance findings rely on T3/T4 secondary commentary (DataGuidance/IAPP) where full primary-source text was paywalled or inaccessible in this pass (financial_sector_overlay, ai_risk_assessments headline-only). Several sub-modules (pseudonymisation/anonymisation, ROPA, security_measures, data_portability, health/credit/insurance sectoral overlays, all adtech sub-modules except direct_marketing, minor_profiling_bans, dependent_adults, regulator_funding_and_capacity, collective_redress_and_class_actions) carry explicit absent_field_provenance with no HU-specific finding located.

Unresolved questions (5):

  • What is Hungary's confirmed Art 8 GDPR digital-minor age-of-consent threshold (13 vs 16)?
  • What are the full substantive provisions and commencement date of Hungary's 2025 national AI Law, and has NAIH or another body been designated as the AI Act market-surveillance authority?
  • What is the full decision text and legal basis of the reported record HUF 250M NAIH fine against a bank?
  • Does Hungary have any sector-specific data-localisation mandate (e.g. for gambling, tax, or health records) beyond the law-enforcement carve-outs identified?
  • What is NAIH's current budget and headcount relative to EU-DPA benchmarks?

Escalate to primary-source review: yes