{
 "jurisdiction_id": "HU",
 "jurisdiction": "Hungary",
 "url": "https://dataprotection.gi/jurisdictions/hungary/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 34,
  "sub_modules": 57,
  "source_register": 41
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/hungary/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Strong T1/T2 confirmation of regulator identity, statutory basis and scope; only registration/filing nuance relies on secondary commentary.",
   "claims": [
    {
     "statement": "<cite index=\"3-1\">Hungarian National Authority for Data Protection and Freedom of Information · Budapest Falk Miksa utca 9-11 1055 Hungary · http://www.naih.hu/</cite> is the national supervisory authority for data protection in Hungary.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/contact/contact-dpas_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Hungary's data protection legal base is the GDPR together with <cite index=\"14-1\">the Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information amended by Act XXXVIII of 2018, with effect of 26 July 2018, to ensure harmonisation with the GDPR</cite>.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance (OneTrust)",
     "source_url": "https://www.dataguidance.com/news/hungary-gdpr-implementation-law-comes-effect",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Beyond GDPR, the Privacy Act sets additional rules such as <cite index=\"5-2\">rights concerning the data of the deceased</cite> and NAIH's procedural competences.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance (OneTrust)",
     "source_url": "https://www.dataguidance.com/notes/hungary-data-transfers",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "EDPB territorial-scope guidance cites <cite index=\"58-3\">Weltimmo v NAIH (C-230/14)</cite> among the leading CJEU rulings interpreting the 'establishment' concept determining GDPR applicability to Hungary-linked processing.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/documents/files/file1/edpb_guidelines_3_2018_territorial_scope_after_public_consultation_en_1.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "NAIH guidance confirms that, per <cite index=\"9-7\">Article 37(7) of the GDPR: \"The controller or the processor shall publish the contact details of the data protection officer and communicate them to the supervisory authority\"</cite>, controllers/processors must notify NAIH of DPO contact details under the GDPR itself, not a separate Hungarian filing regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance (OneTrust)",
     "source_url": "https://www.dataguidance.com/opinion/europe-register-or-not-register-dpo-contact-0",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/hungary/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Lawful bases and consent well evidenced; pseudonymisation/anonymisation sub-module has no HU-specific finding.",
   "claims": [
    {
     "statement": "Under the amended Privacy Act, where processing rests on legal obligation or public-interest/official-authority grounds, <cite index=\"14-3\">organisations can rely only on laws and municipality decrees, and must periodically review the purposes of the processing</cite>.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance (OneTrust)",
     "source_url": "https://www.dataguidance.com/news/hungary-gdpr-implementation-law-comes-effect",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Legal commentary confirms <cite index=\"14-5\">the Act does not provide for any derogations on the age for valid consent</cite> in Hungary.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance (OneTrust)",
     "source_url": "https://www.dataguidance.com/news/hungary-gdpr-implementation-law-comes-effect",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"33-3\">Since 2018, the EU General Data Protection Regulation has governed the processing of biometric data as a form of personal data and, when used to uniquely identify individuals, as \"special category data\"</cite>, a rule applying directly in Hungary as an EU Member State.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/biometrics-in-the-eu-navigating-the-gdpr-ai-act",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/hungary/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Strong enforcement evidence for most rights; portability sub-module unresolved.",
   "claims": [
    {
     "statement": "Under <cite index=\"19-1\">the relevant provisions (52-61.§) of Act CXII of 2011 on Informational Self-Determination and Freedom of Information (\"Privacy Act\")</cite>, data subjects may escalate unsatisfactory access responses to the Hungarian NAIH.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EDPS",
     "source_url": "https://www.edps.europa.eu/system/files/2022-04/2022_04_sis_ii_guide_of_access_update_2022_en_0.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In a May 2024 decision, NAIH found a company had <cite index=\"27-4\">failed to delete illegally processed data and did not provide necessary information to the applicant</cite> and ordered erasure.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance (OneTrust)",
     "source_url": "https://www.dataguidance.com/news/hungary-naih-fines-company-huf-10m-unlawful-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "NAIH's Forbes decision held that a publisher must carry out a proper interest assessment and address data subjects' objections, since it <cite index=\"29-1\">failed to carry out an individual interest assessment, the result of which would have demonstrated that data processing was justified</cite>.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2020/hungarian-dpa-fines-forbes_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The GDPR's directly applicable one-month response deadline (Art 12(3)) governs controller responses to data-subject requests in Hungary.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/hungary/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Breach notification and joint-controller duties strongly evidenced; ROPA/security-measures sub-modules unresolved at HU-specific level.",
   "claims": [
    {
     "statement": "NAIH's decision on a foundation's processing found <cite index=\"4-9\">there was no arrangement between the Foundation and the School within the meaning of Article 26(1) of the GDPR, with regard to joint processing and their respective responsibilities</cite>, reflecting active accountability enforcement.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/news/2024/final-decision-hungarian-supervisory-authority-about-infringement-article-26-gdpr_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Hungarian practice commentary states <cite index=\"52-1\">Appointment of a DPO is mandatory in certain industries only, such as telecommunications providers and financial organisations</cite>, alongside the GDPR Art 37(7) notification duty to NAIH.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/gdpr-conundrums-the-data-protection-officer-requirement",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "NAIH ordered a foundation to remedy its breach after finding that <cite index=\"4-10\">the cooperation agreement between them did not address the issues required by this provision</cite> of Art 26(1) GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/news/2024/final-decision-hungarian-supervisory-authority-about-infringement-article-26-gdpr_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "NAIH reported that <cite index=\"6-5\">The Hungarian SA received 744 personal data breach notification by 30th November 2019</cite>, confirming an operative breach-notification pipeline under GDPR Arts 33-34.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://edpb.europa.eu/sites/edpb/files/hu_sa_gdpr_art_97questionnaire.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "NAIH's 2024 decision ordered that <cite index=\"27-5\">the company was ordered to erase the data and restrict access until legal challenges are resolved</cite>.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance (OneTrust)",
     "source_url": "https://www.dataguidance.com/news/hungary-naih-fines-company-huf-10m-unlawful-data",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/hungary/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "BCR/SCC mechanism confirmed; adequacy sub-modules are not applicable at MS level; TIA and localisation unresolved.",
   "claims": [
    {
     "statement": "<cite index=\"55-2\">Having regard to Article 47(1) of the EU General Data Protection Regulation 2016/679 (GDPR), the National Authority for Data Protection and Freedom of Information shall approve Binding Corporate Rules</cite> as a recognised Chapter V transfer mechanism.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "NAIH / EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/2022-10/naih-5180-2-2022_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "NAIH acted as BCR Lead authority and <cite index=\"55-5\">the EDPB provided its opinion 07/2022 in accordance with Article 64(1)(f)</cite>, finding no concerns regarding the Controller BCR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "NAIH / EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/2022-10/naih-5180-2-2022_en.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/hungary/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Meaningful telecoms/employment/education evidence; financial-sector detail unverified; health/credit/insurance unresolved.",
   "claims": [
    {
     "statement": "NAIH is reported to have issued a record HUF 250 million fine against a bank ('NAIH fines Budapest Bank record HUF 250M'), indicating an active financial-sector enforcement overlay, though full decision detail was not retrievable in this pass.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance (OneTrust)",
     "source_url": "https://www.dataguidance.com/news/hungary-naih-fines-budapest-bank-record-huf-250m-fine",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "NAIH held that <cite index=\"10-8\">Pursuant to Section 16/B of Act CVIII of 2001 concerning electronic commercial services... the investigation... is within the powers of the Nemzeti Média- és Hírközlési Hatóság (NMHH...)</cite>, not NAIH, for certain newsletter/unsubscribe complaints.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/news/2023/hungarian-sas-procedure-handling-unsubscribe-newsletter_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "NAIH fined an employer after finding IT-policy deficiencies, requiring that <cite index=\"48-16\">employees must also be informed of the privacy aspects of the monitoring; e.g., purpose of data processing, the data controller, data retention periods, data privacy rights and remedies</cite>.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/hungary-hungarian-dpa-suggests-refinements-in-it-policies/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "NAIH examined joint-controller responsibility for <cite index=\"4-5\">recordings feature children performing and singing specifically from a Slovak Primary School</cite> published by a Hungarian-linked foundation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/news/2024/final-decision-hungarian-supervisory-authority-about-infringement-article-26-gdpr_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "red",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/hungary/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Only direct_marketing sub-module has confirmed evidence; the remaining five sub-modules are unresolved gaps.",
   "claims": [
    {
     "statement": "NAIH declined jurisdiction over an unsubscribe/newsletter complaint, noting that <cite index=\"10-7\">as with respect to the unsubscribe itself it has no jurisdiction according to the rules of Hungarian law</cite>, referring the matter to NMHH under Act CVIII of 2001.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/news/2023/hungarian-sas-procedure-handling-unsubscribe-newsletter_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/hungary/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "ADM, biometric and surveillance-carveout sub-modules evidenced; AI risk-assessment detail and profiling/genetic sub-modules remain unresolved or uncertain.",
   "claims": [
    {
     "statement": "GDPR Art 22, in force since 25 May 2018, directly governs automated-decision-making transparency and the right to human intervention in Hungary as an EU Member State.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Hungary's government enacted a national AI Law ('Hungary: Government enacts AI Law') in approximately November 2025, though the specific scope of its AI risk-assessment obligations could not be confirmed from retrievable source text in this pass.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance (OneTrust)",
     "source_url": "https://www.dataguidance.com/news/hungary-government-enacts-ai-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"33-4\">the EU AI Act introduces a new layer of regulation that targets four types of biometrics and classifies them by risk — ranging from prohibited to high risk and limited risk</cite>, applying directly in Hungary alongside the GDPR biometric special-category rule.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/biometrics-in-the-eu-navigating-the-gdpr-ai-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Hungary's law-enforcement/security-sector data processing is separately governed by instruments including <cite index=\"13-3\">Act on Police (Act XXXIV of 1994)... Act on the Hungarian Prison Service Organisation (Act CVII of 1995)</cite> and the Prosecution Service Act, sitting outside GDPR's material scope.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:52012SC0075",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/hungary/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Partial evidence on age/consent and one concrete education-adjacent enforcement matter; three sub-modules unresolved.",
   "claims": [
    {
     "statement": "Legal commentary confirms <cite index=\"14-5\">the Act does not provide for any derogations on the age for valid consent</cite>, though the precise Art 8 digital-minors threshold for Hungary was not separately confirmed.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance (OneTrust)",
     "source_url": "https://www.dataguidance.com/news/hungary-gdpr-implementation-law-comes-effect",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "NAIH's decision addressed processing of <cite index=\"4-5\">recordings feature children performing and singing specifically from a Slovak Primary School</cite> in a cross-border, education-adjacent joint-controller dispute.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/news/2024/final-decision-hungarian-supervisory-authority-about-infringement-article-26-gdpr_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/hungary/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Strong evidence on powers, enforcement activity, and private redress; funding/capacity and collective-redress sub-modules unresolved; recent-developments window carries only an uncertain, borderline-dated item.",
   "claims": [
    {
     "statement": "NAIH exercised its corrective powers by giving notice to a foundation, <cite index=\"4-11\">Based on Article 58(2)(d) of the GDPR and Section 56(1) of the Privacy Act the Hungarian Supervisory Authority (SA) gave notice to the Foundation ordering it to meet the requirements for joint controllers</cite>.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/news/2024/final-decision-hungarian-supervisory-authority-about-infringement-article-26-gdpr_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "<cite index=\"27-6\">On May 17, 2024, the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) issued decision No. NAIH/3977-4/2023</cite>, fining a company HUF 10 million for GDPR violations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance (OneTrust)",
     "source_url": "https://www.dataguidance.com/news/hungary-naih-fines-company-huf-10m-unlawful-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Parties may seek judicial review of NAIH decisions, as shown where <cite index=\"29-11\">A petition for review was submitted to the Fővárosi Törvényszék (Budapest Tribunal) by the Publisher against decision NAIH/2020/838/2</cite>.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2020/hungarian-dpa-fines-forbes_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Hungary's government enacted a national AI Law ('Hungary: Government enacts AI Law') dated on or around November 2025, the most recent notable HU development identified, though detailed provisions and precise commencement remain unverified.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance (OneTrust)",
     "source_url": "https://www.dataguidance.com/news/hungary-government-enacts-ai-law",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}