#
Strong T1/T2 confirmation of regulator identity, statutory basis and scope; only registration/filing nuance relies on secondary commentary.
Sub-modules (5)
Regulator And AuthorityGreen
NAIH is the confirmed national DPA.
Claims (1):
- <cite index="3-1">Hungarian National Authority for Data Protection and Freedom of Information · Budapest Falk Miksa utca 9-11 1055 Hungary · http://www.naih.hu/</cite> is the national supervisory authority for data protection in Hungary.
Act And InstrumentsGreen
GDPR plus the amended Privacy Act form the dual instrument base.
Claims (1):
- Hungary's data protection legal base is the GDPR together with <cite index="14-1">the Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information amended by Act XXXVIII of 2018, with effect of 26 July 2018, to ensure harmonisation with the GDPR</cite>.
Material ScopeGreen
Privacy Act supplements GDPR material scope on deceased persons' data and NAIH procedure.
Claims (1):
- Beyond GDPR, the Privacy Act sets additional rules such as <cite index="5-2">rights concerning the data of the deceased</cite> and NAIH's procedural competences.
Territorial ScopeAmber
GDPR Art 3 territorial scope applies; Weltimmo v NAIH is a leading CJEU 'establishment' authority.
Claims (1):
- EDPB territorial-scope guidance cites <cite index="58-3">Weltimmo v NAIH (C-230/14)</cite> among the leading CJEU rulings interpreting the 'establishment' concept determining GDPR applicability to Hungary-linked processing.
Regulator Registration And FilingGreen
DPO contact details must be communicated to NAIH per Art 37(7); no separate national controller-registration regime.
Claims (1):
- NAIH guidance confirms that, per <cite index="9-7">Article 37(7) of the GDPR: "The controller or the processor shall publish the contact details of the data protection officer and communicate them to the supervisory authority"</cite>, controllers/processors must notify NAIH of DPO contact details under the GDPR itself, not a separate Hungarian filing regime.
no periodic updates on record for this sub-brief
Sources and claims (5)
- ConfirmedEDPB — <cite index="3-1">Hungarian National Authority for Data Protection and Freedom of Information · Budapest Falk Miksa utca 9-11 1055 Hungary · http://www.naih.hu/</cite> is the national supervisory authority for data protection in Hungary.observed
- ConfirmedDataGuidance (OneTrust) — Hungary's data protection legal base is the GDPR together with <cite index="14-1">the Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information amended by Act XXXVIII of 2018, with effect of 26 July 2018, to ensure harmonisation with the GDPR</cite>.observed
- ConfirmedDataGuidance (OneTrust) — Beyond GDPR, the Privacy Act sets additional rules such as <cite index="5-2">rights concerning the data of the deceased</cite> and NAIH's procedural competences.observed
- ProbableEDPB — EDPB territorial-scope guidance cites <cite index="58-3">Weltimmo v NAIH (C-230/14)</cite> among the leading CJEU rulings interpreting the 'establishment' concept determining GDPR applicability to Hungary-linked processing.observed
- ConfirmedDataGuidance (OneTrust) — NAIH guidance confirms that, per <cite index="9-7">Article 37(7) of the GDPR: "The controller or the processor shall publish the contact details of the data protection officer and communicate them to the supervisory authority"</cite>, controllers/processors must notify NAIH of DPO contact details under the GDPR itself, not a separate Hungarian filing regime.observed