Last updated · 10 categories · 34
claims · 20 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
34Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
Jurisdiction brief
Lead Signal
NAIH exercised binding corrective powers under GDPR Article 58(2)(d) and Privacy Act Section 56(1) against a foundation for an Article 26(1) joint-controller infringement. The decision found that the joint-controller cooperation agreement failed to satisfy Article 26(1). The dispute involved cross-border children's video recordings from a Slovak primary school.
Other Developments
NAIH is Hungary's national data protection supervisory authority. Hungary's regime rests on the GDPR plus Act CXII of 2011, as amended, effective 26 July 2018. NAIH fined a company HUF 10 million on 17 May 2024 for unlawful processing. In the 2020 Forbes decision, NAIH required a documented interest-assessment and objection-handling. The Budapest Tribunal reviewed that decision on petition. NAIH also approves Binding Corporate Rules under GDPR Article 47(1). The EDPB's Opinion 07/2022 recorded no concerns on a Controller BCR NAIH led. NAIH declined jurisdiction over an unsubscribe complaint, referring it to NMHH. NAIH fined an employer over IT-monitoring policy failures. NAIH reported 744 breach notifications received by 30 November 2019. NAIH is reported to have fined a bank a record HUF 250 million over AI voice-analysis practices. A claimed sectoral DPO mandate in telecoms and banking is now contested by counter-evidence. Hungary's most recent notable development is a national AI Law enacted around November 2025.
Cross-Monitor Connections
The reported bank fine's AI voice-analysis processing may carry financial-crime data-sharing significance tracked by financial-integrity and world-payments. Hungary's new AI Law and the EU AI Act's biometric risk-tiering are better tracked by the artificial-intelligence monitor.
Outlook
NAIH's enforcement record this cycle centres on the Article 26 joint-controller infringement finding. Whether Hungary imposes any sector-specific DPO mandate beyond GDPR Article 37(1) remains an open, contested question. Hungary's new AI Law and any NAIH role under the AI Act remain the clearest open question at this monitor's boundary with artificial-intelligence coverage.
trust tier: ai_unverified
Regulatory Status
NAIH is Hungary's national data protection supervisory authority, operating under a dual GDPR and amended Privacy Act legal basis. This cycle's lead development is a binding NAIH corrective order against a foundation for an Article 26(1) joint-controller infringement. Its most recent quantified enforcement outcome is a HUF 10 million fine issued 17 May 2024. NAIH also approves Binding Corporate Rules for cross-border transfers under GDPR Article 47(1). A claimed sectoral DPO mandate in telecoms and banking is contested by multiple independent legal-guide sources. Hungary is reported to have enacted a national AI Law around November 2025, with substantive detail and any NAIH AI Act role unverified.
Outlook
Across the ten-module spine, Hungary shows active enforcement and stable cross-border transfer competence, with the AI Law and DPO-mandate questions the main open items for the next cycle.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
Strong T1/T2 confirmation of regulator identity, statutory basis and scope; only registration/filing nuance relies on secondary commentary.
Primary frameworkRegulation (EU) 2016/679 (GDPR); Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information, as amended by Act XXXVIII of 2018
Traffic-light rationale — GreenStrong T1/T2 confirmation of regulator identity, statutory basis and scope; only registration/filing nuance relies on secondary commentary.
Sub-modules (5)
Regulator And AuthorityGreen
NAIH is the confirmed national DPA.
Claims: CLM-HU-a1b2c3d4
Act And InstrumentsGreen
GDPR plus the amended Privacy Act form the dual instrument base.
Claims: CLM-HU-b2c3d4e5
Material ScopeGreen
Privacy Act supplements GDPR material scope on deceased persons' data and NAIH procedure.
Claims: CLM-HU-c3d4e5f6
Territorial ScopeAmber
GDPR Art 3 territorial scope applies; Weltimmo v NAIH is a leading CJEU 'establishment' authority.
Claims: CLM-HU-d4e5f6a7
Regulator Registration And FilingGreen
DPO contact details must be communicated to NAIH per Art 37(7); no separate national controller-registration regime.
Claims: CLM-HU-e5f6a7b8
Category narrative81 words
Hungary is an EU Member State applying the GDPR directly, supplemented by the national Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (the 'Privacy Act'), as amended by Act XXXVIII of 2018 to harmonise with the GDPR. The Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH) is the single national supervisory authority. Material and territorial scope track GDPR Arts 2-3, with the Privacy Act filling gaps outside GDPR's material scope (e.g. NAIH procedure, rights of deceased persons).
No periodic updates recorded against this sub-brief.
Sources and claims (5)
ConfirmedEDPB — <cite index="3-1">Hungarian National Authority for Data Protection and Freedom of Information · Budapest Falk Miksa utca 9-11 1055 Hungary · http://www.naih.hu/</cite> is the national supervisory authority for data protection in Hungary.
ConfirmedDataGuidance (OneTrust) — Hungary's data protection legal base is the GDPR together with <cite index="14-1">the Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information amended by Act XXXVIII of 2018, with effect of 26 July 2018, to ensure harmonisation with the GDPR</cite>.
ConfirmedDataGuidance (OneTrust) — Beyond GDPR, the Privacy Act sets additional rules such as <cite index="5-2">rights concerning the data of the deceased</cite> and NAIH's procedural competences.
ProbableEDPB — EDPB territorial-scope guidance cites <cite index="58-3">Weltimmo v NAIH (C-230/14)</cite> among the leading CJEU rulings interpreting the 'establishment' concept determining GDPR applicability to Hungary-linked processing.
ConfirmedDataGuidance (OneTrust) — NAIH guidance confirms that, per <cite index="9-7">Article 37(7) of the GDPR: "The controller or the processor shall publish the contact details of the data protection officer and communicate them to the supervisory authority"</cite>, controllers/processors must notify NAIH of DPO contact details under the GDPR itself, not a separate Hungarian filing regime.
GDPR Art 6 lawful bases and Art 9 special-category rules apply directly. The amended Privacy Act layers additional constraints on legal-obligation/public-interest processing and confirms no domestic derogation on the age required for valid consent. Pseudonymisation/anonymisation carries no confirmed Hungary-specific safe harbour beyond the GDPR baseline.
No periodic updates recorded against this sub-brief.
Sources and claims (3)
ConfirmedDataGuidance (OneTrust) — Under the amended Privacy Act, where processing rests on legal obligation or public-interest/official-authority grounds, <cite index="14-3">organisations can rely only on laws and municipality decrees, and must periodically review the purposes of the processing</cite>.
ProbableDataGuidance (OneTrust) — Legal commentary confirms <cite index="14-5">the Act does not provide for any derogations on the age for valid consent</cite> in Hungary.
ConfirmedIAPP — <cite index="33-3">Since 2018, the EU General Data Protection Regulation has governed the processing of biometric data as a form of personal data and, when used to uniquely identify individuals, as "special category data"</cite>, a rule applying directly in Hungary as an EU Member State.
Access, rectification/erasure, restriction/objection are all evidenced through NAIH enforcement practice. Portability carries no HU-specific derogation identified. Response-deadline obligations follow the GDPR's own one-month standard applied directly.
No periodic updates recorded against this sub-brief.
Sources and claims (4)
ProbableEDPS — Under <cite index="19-1">the relevant provisions (52-61.§) of Act CXII of 2011 on Informational Self-Determination and Freedom of Information ("Privacy Act")</cite>, data subjects may escalate unsatisfactory access responses to the Hungarian NAIH.
ConfirmedDataGuidance (OneTrust) — In a May 2024 decision, NAIH found a company had <cite index="27-4">failed to delete illegally processed data and did not provide necessary information to the applicant</cite> and ordered erasure.
ConfirmedEDPB — NAIH's Forbes decision held that a publisher must carry out a proper interest assessment and address data subjects' objections, since it <cite index="29-1">failed to carry out an individual interest assessment, the result of which would have demonstrated that data processing was justified</cite>.
ConfirmedEUR-Lex — The GDPR's directly applicable one-month response deadline (Art 12(3)) governs controller responses to data-subject requests in Hungary.
NAIH's own Art 97 questionnaire response confirms an operative breach-notification regime.
Claims: CLM-HU-d6e7f8a9
Retention And DisposalAmber
NAIH enforcement orders erasure/restriction pending resolution of legal challenges.
Claims: CLM-HU-e7f8a9b0
Category narrative52 words
Accountability, joint-controller and breach-notification duties are well evidenced via NAIH's Art 26 enforcement decision and its Art 97 self-report citing breach-notification volumes. DPO duties are shaped by both GDPR Art 37 and Hungarian sectoral practice. ROPA and security-measures sub-modules rely on the unadorned GDPR baseline with no HU-specific finding in this pass.
No periodic updates recorded against this sub-brief.
Sources and claims (5)
ConfirmedEDPB — NAIH's decision on a foundation's processing found <cite index="4-9">there was no arrangement between the Foundation and the School within the meaning of Article 26(1) of the GDPR, with regard to joint processing and their respective responsibilities</cite>, reflecting active accountability enforcement.
ProbableIAPP — Hungarian practice commentary states <cite index="52-1">Appointment of a DPO is mandatory in certain industries only, such as telecommunications providers and financial organisations</cite>, alongside the GDPR Art 37(7) notification duty to NAIH.
ConfirmedEDPB — NAIH ordered a foundation to remedy its breach after finding that <cite index="4-10">the cooperation agreement between them did not address the issues required by this provision</cite> of Art 26(1) GDPR.
ConfirmedEDPB — NAIH reported that <cite index="6-5">The Hungarian SA received 744 personal data breach notification by 30th November 2019</cite>, confirming an operative breach-notification pipeline under GDPR Arts 33-34.
ConfirmedDataGuidance (OneTrust) — NAIH's 2024 decision ordered that <cite index="27-5">the company was ordered to erase the data and restrict access until legal challenges are resolved</cite>.
Traffic-light rationale — AmberBCR/SCC mechanism confirmed; adequacy sub-modules are not applicable at MS level; TIA and localisation unresolved.
Sub-modules (6)
Transfer MechanismsGreen
NAIH exercises Art 47 BCR-approval powers as part of the Chapter V mechanism set.
Claims: CLM-HU-f8a9b0c1
Adequacy ReceivedRed
Not applicable at Member-State level; EU Commission adequacy decisions apply uniformly.
Absence provenance: not recorded. Searched: Hungary national adequacy decision received EU Commission.
Adequacy GrantedRed
Not applicable at Member-State level.
Absence provenance: not recorded. Searched: Hungary national adequacy decision granted third country.
Sccs And BcrsGreen
NAIH approved Controller BCRs as BCR-lead authority with EDPB Opinion 07/2022 concurrence.
Claims: CLM-HU-a9b0c1d2
Transfer Impact AssessmentRed
No HU-specific TIA guidance identified beyond general EDPB/Schrems II standard.
Absence provenance: not recorded. Searched: Hungary NAIH transfer impact assessment Schrems II guidance.
Data LocalisationRed
No general HU data-localisation mandate identified; sector-specific law-enforcement data rules addressed under sectoral_watch/state_surveillance_carveouts.
Absence provenance: not recorded. Searched: Hungary data localisation requirement personal data GDPR.
Category narrative56 words
Chapter V transfer mechanisms apply via GDPR directly; NAIH has approved Binding Corporate Rules as a BCR-lead authority. As adequacy decisions are made centrally by the European Commission for all EU Member States, Hungary does not receive or grant bespoke national adequacy determinations. No HU-specific transfer-impact-assessment guidance or general data-localisation mandate was identified in this pass.
No periodic updates recorded against this sub-brief.
Sources and claims (2)
ConfirmedNAIH / EDPB — <cite index="55-2">Having regard to Article 47(1) of the EU General Data Protection Regulation 2016/679 (GDPR), the National Authority for Data Protection and Freedom of Information shall approve Binding Corporate Rules</cite> as a recognised Chapter V transfer mechanism.
ConfirmedNAIH / EDPB — NAIH acted as BCR Lead authority and <cite index="55-5">the EDPB provided its opinion 07/2022 in accordance with Article 64(1)(f)</cite>, finding no concerns regarding the Controller BCR.
A record NAIH fine against a bank was identified by headline only; full decision content not retrievable in this pass.
Absence provenance: not recorded. Searched: NAIH fine bank Hungary 2020 GDPR financial sector.
Claims: CLM-HU-b0c1d2e3
Health Sector OverlayRed
No HU-specific health-sector overlay finding.
Absence provenance: not recorded. Searched: Hungary health sector data protection overlay NAIH.
Telecoms And EprivacyGreen
NMHH, not NAIH, holds competence over certain e-commerce/unsubscribe complaints.
Claims: CLM-HU-c1d2e3f4
Employment DataGreen
NAIH enforcement on employer IT/monitoring policy deficiencies.
Claims: CLM-HU-d2e3f4a5
Credit And ScoringRed
No HU-specific credit-scoring finding.
Absence provenance: not recorded. Searched: Hungary credit scoring data protection NAIH.
EducationAmber
Cross-border education-adjacent case on children's video recordings.
Claims: CLM-HU-e3f4a5b6
InsuranceRed
No HU-specific insurance-sector finding.
Absence provenance: not recorded. Searched: Hungary insurance sector data protection NAIH overlay.
Category narrative68 words
Telecoms/e-commerce direct-marketing complaints are carved out to the media regulator NMHH rather than NAIH. Employment-data processing has generated concrete NAIH enforcement on IT-monitoring policies. Education-adjacent processing of children's data has been the subject of an Art 26 cross-border case. Financial-sector enforcement (a record fine against a bank) was identified only by headline, not verified in full; health, credit-scoring and insurance sub-modules carry no HU-specific finding in this pass.
No periodic updates recorded against this sub-brief.
Sources and claims (4)
UncertainDataGuidance (OneTrust) — NAIH is reported to have issued a record HUF 250 million fine against a bank ('NAIH fines Budapest Bank record HUF 250M'), indicating an active financial-sector enforcement overlay, though full decision detail was not retrievable in this pass.
ConfirmedEDPB — NAIH held that <cite index="10-8">Pursuant to Section 16/B of Act CVIII of 2001 concerning electronic commercial services... the investigation... is within the powers of the Nemzeti Média- és Hírközlési Hatóság (NMHH...)</cite>, not NAIH, for certain newsletter/unsubscribe complaints.
ConfirmedIAPP — NAIH fined an employer after finding IT-policy deficiencies, requiring that <cite index="48-16">employees must also be informed of the privacy aspects of the monitoring; e.g., purpose of data processing, the data controller, data retention periods, data privacy rights and remedies</cite>.
ConfirmedEDPB — NAIH examined joint-controller responsibility for <cite index="4-5">recordings feature children performing and singing specifically from a Slovak Primary School</cite> published by a Hungarian-linked foundation.
Absence provenance: not recorded. Searched: Hungary dark patterns data protection NAIH.
Opt Out SignalsRed
No HU-specific opt-out-signal finding.
Absence provenance: not recorded. Searched: Hungary Global Privacy Control opt-out signal NAIH.
Clean Rooms And DcrRed
No HU-specific clean-room/DCR finding.
Absence provenance: not recorded. Searched: Hungary data clean room GDPR NAIH.
Cross Context AdvertisingRed
Not applicable in the GDPR model in the manner of US state 'sale/share' concepts; no HU-specific finding.
Absence provenance: not recorded. Searched: Hungary cross-context advertising GDPR equivalent.
Direct MarketingGreen
NMHH holds competence over certain direct-marketing/unsubscribe complaints under Act CVIII of 2001.
Claims: CLM-HU-f4a5b6c7
Category narrative40 words
Direct-marketing enforcement carve-outs to NMHH under Act CVIII of 2001 are confirmed. Cookie/tracker consent, dark-pattern prohibitions, opt-out signals, clean-room rules and cross-context advertising (a US-state-law concept largely inapplicable under the GDPR model) carry no HU-specific finding in this research pass.
No periodic updates recorded against this sub-brief.
Sources and claims (1)
ConfirmedEDPB — NAIH declined jurisdiction over an unsubscribe/newsletter complaint, noting that <cite index="10-7">as with respect to the unsubscribe itself it has no jurisdiction according to the rules of Hungarian law</cite>, referring the matter to NMHH under Act CVIII of 2001.
ADM, biometric and surveillance-carveout sub-modules evidenced; AI risk-assessment detail and profiling/genetic sub-modules remain unresolved or uncertain.
Primary frameworkGDPR Art 22; GDPR Art 9 (biometrics); EU AI Act; Hungarian AI Law (2025); national security/law-enforcement acts
Traffic-light rationale — AmberADM, biometric and surveillance-carveout sub-modules evidenced; AI risk-assessment detail and profiling/genetic sub-modules remain unresolved or uncertain.
Sub-modules (6)
Profiling RestrictionsRed
No HU-specific profiling-restriction finding beyond GDPR Art 22 baseline.
GDPR Art 22 ADM transparency rules apply directly.
Claims: CLM-HU-a5b6c7d8
Ai Risk AssessmentsAmber
Hungary enacted a national AI Law in late 2025; detailed provisions unverified in this pass.
Absence provenance: not recorded. Searched: Hungary AI Law 2025 NAIH designated authority AI Act.
Claims: CLM-HU-b6c7d8e9
Biometric RegimeGreen
EU-wide GDPR/AI Act biometric special-category regime applies directly in Hungary.
Claims: CLM-HU-c7d8e9f0
Genetic DataRed
No HU-specific genetic-data finding beyond GDPR Art 9 baseline.
Absence provenance: not recorded. Searched: Hungary genetic data protection NAIH guidance.
State Surveillance CarveoutsAmber
Sectoral security-sector acts (Police, Prison Service, Prosecution) carve out data processing from GDPR's material scope.
Claims: CLM-HU-d8e9f0a1
Category narrative62 words
GDPR Art 22 ADM rules and the EU-wide biometric special-category regime apply directly. Hungary enacted a national AI Law in November 2025, though its detailed risk-assessment provisions could not be verified from sources retrieved in this pass. Law-enforcement/security-sector data carve-outs (Police, Prison Service, Prosecution Acts) sit outside GDPR's material scope. Profiling-restriction and genetic-data sub-modules have no HU-specific finding beyond the GDPR baseline.
No periodic updates recorded against this sub-brief.
Sources and claims (4)
ConfirmedEUR-Lex — GDPR Art 22, in force since 25 May 2018, directly governs automated-decision-making transparency and the right to human intervention in Hungary as an EU Member State.
UncertainDataGuidance (OneTrust) — Hungary's government enacted a national AI Law ('Hungary: Government enacts AI Law') in approximately November 2025, though the specific scope of its AI risk-assessment obligations could not be confirmed from retrievable source text in this pass.
ConfirmedIAPP — <cite index="33-4">the EU AI Act introduces a new layer of regulation that targets four types of biometrics and classifies them by risk — ranging from prohibited to high risk and limited risk</cite>, applying directly in Hungary alongside the GDPR biometric special-category rule.
ProbableEUR-Lex — Hungary's law-enforcement/security-sector data processing is separately governed by instruments including <cite index="13-3">Act on Police (Act XXXIV of 1994)... Act on the Hungarian Prison Service Organisation (Act CVII of 1995)</cite> and the Prosecution Service Act, sitting outside GDPR's material scope.
Absence provenance: not recorded. Searched: Hungary minors profiling ban data protection NAIH.
Education SettingsAmber
NAIH's Art 26 decision engaged children's data in an education-adjacent, cross-border context.
Claims: CLM-HU-f0a1b2c3
Dependent AdultsRed
No HU-specific dependent-adults finding.
Absence provenance: not recorded. Searched: Hungary dependent adults elderly data protection NAIH.
Category narrative48 words
No domestic derogation from the GDPR's general consent-age rules was identified, though the specific Art 8 digital-minor-consent threshold for Hungary was not separately confirmed. An education-adjacent case involving children's video recordings evidences NAIH's practical engagement with minors' data. Minor-profiling-ban, dedicated parental-consent-mechanism and dependent-adults sub-modules carry no HU-specific finding.
No periodic updates recorded against this sub-brief.
Sources and claims (2)
ProbableDataGuidance (OneTrust) — Legal commentary confirms <cite index="14-5">the Act does not provide for any derogations on the age for valid consent</cite>, though the precise Art 8 digital-minors threshold for Hungary was not separately confirmed.
ConfirmedEDPB — NAIH's decision addressed processing of <cite index="4-5">recordings feature children performing and singing specifically from a Slovak Primary School</cite> in a cross-border, education-adjacent joint-controller dispute.
Strong evidence on powers, enforcement activity, and private redress; funding/capacity and collective-redress sub-modules unresolved; recent-developments window carries only an uncertain, borderline-dated item.
Primary frameworkGDPR Arts 58, 77-84; Act CXII of 2011 §56
Traffic-light rationale — AmberStrong evidence on powers, enforcement activity, and private redress; funding/capacity and collective-redress sub-modules unresolved; recent-developments window carries only an uncertain, borderline-dated item.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
NAIH exercises binding corrective powers under GDPR Art 58 and Privacy Act §56(1).
Claims: CLM-HU-a1b2c3e4
Enforcement Activity IndexGreen
A confirmed 2024 HUF 10 million GDPR fine evidences ongoing enforcement activity.
Claims: CLM-HU-b2c3e4f5
Regulator Funding And CapacityRed
No HU-specific funding/headcount finding.
Absence provenance: not recorded. Searched: NAIH budget headcount capacity Hungary data protection authority.
Collective Redress And Class ActionsRed
No HU-specific collective-redress mechanism finding.
Absence provenance: not recorded. Searched: Hungary collective redress class action data protection GDPR.
Private Right Of ActionGreen
Judicial review of NAIH decisions before the Budapest Tribunal is confirmed via the Forbes case.
Claims: CLM-HU-c3e4f5a6
Recent Developments 180DAmber
The most recent notable Hungarian development identified is the national AI Law (~Nov 2025), just outside the strict 180-day window from the 2026-08-05 run date; detailed content unverified.
Absence provenance: not recorded. Searched: Hungary data protection recent developments 2026, NAIH enforcement 2026.
Claims: CLM-HU-d4f5a6b7
Category narrative78 words
NAIH exercises GDPR Art 58 corrective powers, including binding compliance orders under Privacy Act §56(1). Enforcement activity is well documented (e.g. a HUF 10 million fine in May 2024). Private judicial review of NAIH decisions before the Budapest Tribunal is confirmed. Regulator funding/capacity and collective-redress mechanisms carry no HU-specific finding in this pass; the most recent notable development (a national AI Law) dates to approximately November 2025, just outside the strict 180-day look-back window from this run's date.
No periodic updates recorded against this sub-brief.
Sources and claims (4)
ConfirmedEDPB — NAIH exercised its corrective powers by giving notice to a foundation, <cite index="4-11">Based on Article 58(2)(d) of the GDPR and Section 56(1) of the Privacy Act the Hungarian Supervisory Authority (SA) gave notice to the Foundation ordering it to meet the requirements for joint controllers</cite>.
ConfirmedDataGuidance (OneTrust) — <cite index="27-6">On May 17, 2024, the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) issued decision No. NAIH/3977-4/2023</cite>, fining a company HUF 10 million for GDPR violations.
ConfirmedEDPB — Parties may seek judicial review of NAIH decisions, as shown where <cite index="29-11">A petition for review was submitted to the Fővárosi Törvényszék (Budapest Tribunal) by the Publisher against decision NAIH/2020/838/2</cite>.
UncertainDataGuidance (OneTrust) — Hungary's government enacted a national AI Law ('Hungary: Government enacts AI Law') dated on or around November 2025, the most recent notable HU development identified, though detailed provisions and precise commencement remain unverified.
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Hungary
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 34 claim(s), 41 source(s) in the cumulative register.