🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
HU · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 20 sources retrieved model claude-sonnet-5 ·

Hungary

HU schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 34 claims · 20 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
34Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Lead Signal

NAIH exercised binding corrective powers under GDPR Article 58(2)(d) and Privacy Act Section 56(1) against a foundation for an Article 26(1) joint-controller infringement. The decision found that the joint-controller cooperation agreement failed to satisfy Article 26(1). The dispute involved cross-border children's video recordings from a Slovak primary school.

Other Developments

NAIH is Hungary's national data protection supervisory authority. Hungary's regime rests on the GDPR plus Act CXII of 2011, as amended, effective 26 July 2018. NAIH fined a company HUF 10 million on 17 May 2024 for unlawful processing. In the 2020 Forbes decision, NAIH required a documented interest-assessment and objection-handling. The Budapest Tribunal reviewed that decision on petition. NAIH also approves Binding Corporate Rules under GDPR Article 47(1). The EDPB's Opinion 07/2022 recorded no concerns on a Controller BCR NAIH led. NAIH declined jurisdiction over an unsubscribe complaint, referring it to NMHH. NAIH fined an employer over IT-monitoring policy failures. NAIH reported 744 breach notifications received by 30 November 2019. NAIH is reported to have fined a bank a record HUF 250 million over AI voice-analysis practices. A claimed sectoral DPO mandate in telecoms and banking is now contested by counter-evidence. Hungary's most recent notable development is a national AI Law enacted around November 2025.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Strong T1/T2 confirmation of regulator identity, statutory basis and scope; only registration/filing nuance relies on secondary commentary.

Primary frameworkRegulation (EU) 2016/679 (GDPR); Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information, as amended by Act XXXVIII of 2018
Traffic-light rationale — GreenStrong T1/T2 confirmation of regulator identity, statutory basis and scope; only registration/filing nuance relies on secondary commentary.

Sub-modules (5)

Regulator And AuthorityGreen

NAIH is the confirmed national DPA.

Claims: CLM-HU-a1b2c3d4

Act And InstrumentsGreen

GDPR plus the amended Privacy Act form the dual instrument base.

Claims: CLM-HU-b2c3d4e5

Material ScopeGreen

Privacy Act supplements GDPR material scope on deceased persons' data and NAIH procedure.

Claims: CLM-HU-c3d4e5f6

Territorial ScopeAmber

GDPR Art 3 territorial scope applies; Weltimmo v NAIH is a leading CJEU 'establishment' authority.

Claims: CLM-HU-d4e5f6a7

Regulator Registration And FilingGreen

DPO contact details must be communicated to NAIH per Art 37(7); no separate national controller-registration regime.

Claims: CLM-HU-e5f6a7b8

Category narrative81 words

Hungary is an EU Member State applying the GDPR directly, supplemented by the national Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (the 'Privacy Act'), as amended by Act XXXVIII of 2018 to harmonise with the GDPR. The Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH) is the single national supervisory authority. Material and territorial scope track GDPR Arts 2-3, with the Privacy Act filling gaps outside GDPR's material scope (e.g. NAIH procedure, rights of deceased persons).

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ConfirmedEDPB<cite index="3-1">Hungarian National Authority for Data Protection and Freedom of Information · Budapest Falk Miksa utca 9-11 1055 Hungary · http://www.naih.hu/</cite> is the national supervisory authority for data protection in Hungary.
  2. ConfirmedDataGuidance (OneTrust)Hungary's data protection legal base is the GDPR together with <cite index="14-1">the Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information amended by Act XXXVIII of 2018, with effect of 26 July 2018, to ensure harmonisation with the GDPR</cite>.
  3. ConfirmedDataGuidance (OneTrust)Beyond GDPR, the Privacy Act sets additional rules such as <cite index="5-2">rights concerning the data of the deceased</cite> and NAIH's procedural competences.
  4. ProbableEDPBEDPB territorial-scope guidance cites <cite index="58-3">Weltimmo v NAIH (C-230/14)</cite> among the leading CJEU rulings interpreting the 'establishment' concept determining GDPR applicability to Hungary-linked processing.
  5. ConfirmedDataGuidance (OneTrust)NAIH guidance confirms that, per <cite index="9-7">Article 37(7) of the GDPR: "The controller or the processor shall publish the contact details of the data protection officer and communicate them to the supervisory authority"</cite>, controllers/processors must notify NAIH of DPO contact details under the GDPR itself, not a separate Hungarian filing regime.

#

Lawful bases and consent well evidenced; pseudonymisation/anonymisation sub-module has no HU-specific finding.

Primary frameworkGDPR Arts 6, 7, 9; Act CXII of 2011 (amended)
Supervisory authorityNAIH
Traffic-light rationale — AmberLawful bases and consent well evidenced; pseudonymisation/anonymisation sub-module has no HU-specific finding.

Sub-modules (4)

Lawful BasesGreen

Privacy Act constrains legal-obligation/public-interest processing to statute/decree bases with periodic review.

Claims: CLM-HU-f6a7b8c9

Special CategoriesGreen

Biometric data used for unique identification is Art 9 special-category data.

Claims: CLM-HU-b8c9d0e1

Pseudonymisation And AnonymisationRed

No Hungary-specific pseudonymisation/anonymisation safe-harbour identified in this research pass.

Absence provenance: not recorded. Searched: Hungary pseudonymisation anonymisation GDPR NAIH guidance.

Category narrative45 words

GDPR Art 6 lawful bases and Art 9 special-category rules apply directly. The amended Privacy Act layers additional constraints on legal-obligation/public-interest processing and confirms no domestic derogation on the age required for valid consent. Pseudonymisation/anonymisation carries no confirmed Hungary-specific safe harbour beyond the GDPR baseline.

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedDataGuidance (OneTrust)Under the amended Privacy Act, where processing rests on legal obligation or public-interest/official-authority grounds, <cite index="14-3">organisations can rely only on laws and municipality decrees, and must periodically review the purposes of the processing</cite>.
  2. ProbableDataGuidance (OneTrust)Legal commentary confirms <cite index="14-5">the Act does not provide for any derogations on the age for valid consent</cite> in Hungary.
  3. ConfirmedIAPP<cite index="33-3">Since 2018, the EU General Data Protection Regulation has governed the processing of biometric data as a form of personal data and, when used to uniquely identify individuals, as "special category data"</cite>, a rule applying directly in Hungary as an EU Member State.

#

Strong enforcement evidence for most rights; portability sub-module unresolved.

Primary frameworkGDPR Arts 12-22; Act CXII of 2011 §§52-61
Supervisory authorityNAIH
Traffic-light rationale — AmberStrong enforcement evidence for most rights; portability sub-module unresolved.

Sub-modules (5)

Access RightAmber

Right of access is exercisable via controllers with NAIH recourse where responses (e.g. SIRENE) are unsatisfactory.

Claims: CLM-HU-c9d0e1f2

Rectification And ErasureGreen

NAIH has ordered erasure of unlawfully processed data in enforcement decisions.

Claims: CLM-HU-d0e1f2a3

Restriction And ObjectionGreen

NAIH enforcement (Forbes case) required documented balancing tests and honouring of objections.

Claims: CLM-HU-e1f2a3b4

Data PortabilityRed

No HU-specific portability finding beyond GDPR Art 20 baseline.

Absence provenance: not recorded. Searched: Hungary NAIH data portability GDPR Article 20 guidance.

Deadlines And Response WindowsAmber

GDPR's one-month statutory response window applies directly.

Claims: CLM-HU-f2a3b4c5

Category narrative26 words

Access, rectification/erasure, restriction/objection are all evidenced through NAIH enforcement practice. Portability carries no HU-specific derogation identified. Response-deadline obligations follow the GDPR's own one-month standard applied directly.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ProbableEDPSUnder <cite index="19-1">the relevant provisions (52-61.§) of Act CXII of 2011 on Informational Self-Determination and Freedom of Information ("Privacy Act")</cite>, data subjects may escalate unsatisfactory access responses to the Hungarian NAIH.
  2. ConfirmedDataGuidance (OneTrust)In a May 2024 decision, NAIH found a company had <cite index="27-4">failed to delete illegally processed data and did not provide necessary information to the applicant</cite> and ordered erasure.
  3. ConfirmedEDPBNAIH's Forbes decision held that a publisher must carry out a proper interest assessment and address data subjects' objections, since it <cite index="29-1">failed to carry out an individual interest assessment, the result of which would have demonstrated that data processing was justified</cite>.
  4. ConfirmedEUR-LexThe GDPR's directly applicable one-month response deadline (Art 12(3)) governs controller responses to data-subject requests in Hungary.

#

Breach notification and joint-controller duties strongly evidenced; ROPA/security-measures sub-modules unresolved at HU-specific level.

Primary frameworkGDPR Arts 5, 24-32, 33-34, 35, 37-39; Act CXII of 2011 §56
Supervisory authorityNAIH
Traffic-light rationale — AmberBreach notification and joint-controller duties strongly evidenced; ROPA/security-measures sub-modules unresolved at HU-specific level.

Sub-modules (7)

Accountability And DpiaGreen

NAIH's Art 26 decision demonstrates active accountability enforcement.

Claims: CLM-HU-a3b4c5d6

Dpo RequirementsAmber

DPO contact-notification duty under Art 37(7); sectoral commentary suggests mandatory DPO practice in telecoms/finance.

Claims: CLM-HU-b4c5d6e7

Ropa RequirementsRed

No HU-specific ROPA finding beyond GDPR Art 30 baseline.

Absence provenance: not recorded. Searched: Hungary NAIH records of processing activities ROPA guidance.

Joint Controller ArrangementsGreen

NAIH found an Art 26(1) infringement for absence of a proper joint-controller arrangement.

Claims: CLM-HU-c5d6e7f8

Security MeasuresRed

No HU-specific security-measures finding beyond GDPR Art 32 baseline.

Absence provenance: not recorded. Searched: Hungary NAIH technical organisational security measures GDPR guidance.

Breach NotificationGreen

NAIH's own Art 97 questionnaire response confirms an operative breach-notification regime.

Claims: CLM-HU-d6e7f8a9

Retention And DisposalAmber

NAIH enforcement orders erasure/restriction pending resolution of legal challenges.

Claims: CLM-HU-e7f8a9b0

Category narrative52 words

Accountability, joint-controller and breach-notification duties are well evidenced via NAIH's Art 26 enforcement decision and its Art 97 self-report citing breach-notification volumes. DPO duties are shaped by both GDPR Art 37 and Hungarian sectoral practice. ROPA and security-measures sub-modules rely on the unadorned GDPR baseline with no HU-specific finding in this pass.

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ConfirmedEDPBNAIH's decision on a foundation's processing found <cite index="4-9">there was no arrangement between the Foundation and the School within the meaning of Article 26(1) of the GDPR, with regard to joint processing and their respective responsibilities</cite>, reflecting active accountability enforcement.
  2. ProbableIAPPHungarian practice commentary states <cite index="52-1">Appointment of a DPO is mandatory in certain industries only, such as telecommunications providers and financial organisations</cite>, alongside the GDPR Art 37(7) notification duty to NAIH.
  3. ConfirmedEDPBNAIH ordered a foundation to remedy its breach after finding that <cite index="4-10">the cooperation agreement between them did not address the issues required by this provision</cite> of Art 26(1) GDPR.
  4. ConfirmedEDPBNAIH reported that <cite index="6-5">The Hungarian SA received 744 personal data breach notification by 30th November 2019</cite>, confirming an operative breach-notification pipeline under GDPR Arts 33-34.
  5. ConfirmedDataGuidance (OneTrust)NAIH's 2024 decision ordered that <cite index="27-5">the company was ordered to erase the data and restrict access until legal challenges are resolved</cite>.

#

BCR/SCC mechanism confirmed; adequacy sub-modules are not applicable at MS level; TIA and localisation unresolved.

Primary frameworkGDPR Chapter V (Arts 44-49)
Supervisory authorityNAIH
Traffic-light rationale — AmberBCR/SCC mechanism confirmed; adequacy sub-modules are not applicable at MS level; TIA and localisation unresolved.

Sub-modules (6)

Transfer MechanismsGreen

NAIH exercises Art 47 BCR-approval powers as part of the Chapter V mechanism set.

Claims: CLM-HU-f8a9b0c1

Adequacy ReceivedRed

Not applicable at Member-State level; EU Commission adequacy decisions apply uniformly.

Absence provenance: not recorded. Searched: Hungary national adequacy decision received EU Commission.

Adequacy GrantedRed

Not applicable at Member-State level.

Absence provenance: not recorded. Searched: Hungary national adequacy decision granted third country.

Sccs And BcrsGreen

NAIH approved Controller BCRs as BCR-lead authority with EDPB Opinion 07/2022 concurrence.

Claims: CLM-HU-a9b0c1d2

Transfer Impact AssessmentRed

No HU-specific TIA guidance identified beyond general EDPB/Schrems II standard.

Absence provenance: not recorded. Searched: Hungary NAIH transfer impact assessment Schrems II guidance.

Data LocalisationRed

No general HU data-localisation mandate identified; sector-specific law-enforcement data rules addressed under sectoral_watch/state_surveillance_carveouts.

Absence provenance: not recorded. Searched: Hungary data localisation requirement personal data GDPR.

Category narrative56 words

Chapter V transfer mechanisms apply via GDPR directly; NAIH has approved Binding Corporate Rules as a BCR-lead authority. As adequacy decisions are made centrally by the European Commission for all EU Member States, Hungary does not receive or grant bespoke national adequacy determinations. No HU-specific transfer-impact-assessment guidance or general data-localisation mandate was identified in this pass.

No periodic updates recorded against this sub-brief.

Sources and claims (2)
  1. ConfirmedNAIH / EDPB<cite index="55-2">Having regard to Article 47(1) of the EU General Data Protection Regulation 2016/679 (GDPR), the National Authority for Data Protection and Freedom of Information shall approve Binding Corporate Rules</cite> as a recognised Chapter V transfer mechanism.
  2. ConfirmedNAIH / EDPBNAIH acted as BCR Lead authority and <cite index="55-5">the EDPB provided its opinion 07/2022 in accordance with Article 64(1)(f)</cite>, finding no concerns regarding the Controller BCR.

#

Meaningful telecoms/employment/education evidence; financial-sector detail unverified; health/credit/insurance unresolved.

Primary frameworkGDPR plus sectoral instruments (Act CVIII of 2001 on electronic commerce; labour-law/IT-policy practice)
Supervisory authorityNAIH
Traffic-light rationale — AmberMeaningful telecoms/employment/education evidence; financial-sector detail unverified; health/credit/insurance unresolved.

Sub-modules (7)

Financial Sector OverlayAmber

A record NAIH fine against a bank was identified by headline only; full decision content not retrievable in this pass.

Absence provenance: not recorded. Searched: NAIH fine bank Hungary 2020 GDPR financial sector.

Claims: CLM-HU-b0c1d2e3

Health Sector OverlayRed

No HU-specific health-sector overlay finding.

Absence provenance: not recorded. Searched: Hungary health sector data protection overlay NAIH.

Telecoms And EprivacyGreen

NMHH, not NAIH, holds competence over certain e-commerce/unsubscribe complaints.

Claims: CLM-HU-c1d2e3f4

Employment DataGreen

NAIH enforcement on employer IT/monitoring policy deficiencies.

Claims: CLM-HU-d2e3f4a5

Credit And ScoringRed

No HU-specific credit-scoring finding.

Absence provenance: not recorded. Searched: Hungary credit scoring data protection NAIH.

EducationAmber

Cross-border education-adjacent case on children's video recordings.

Claims: CLM-HU-e3f4a5b6

InsuranceRed

No HU-specific insurance-sector finding.

Absence provenance: not recorded. Searched: Hungary insurance sector data protection NAIH overlay.

Category narrative68 words

Telecoms/e-commerce direct-marketing complaints are carved out to the media regulator NMHH rather than NAIH. Employment-data processing has generated concrete NAIH enforcement on IT-monitoring policies. Education-adjacent processing of children's data has been the subject of an Art 26 cross-border case. Financial-sector enforcement (a record fine against a bank) was identified only by headline, not verified in full; health, credit-scoring and insurance sub-modules carry no HU-specific finding in this pass.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. UncertainDataGuidance (OneTrust)NAIH is reported to have issued a record HUF 250 million fine against a bank ('NAIH fines Budapest Bank record HUF 250M'), indicating an active financial-sector enforcement overlay, though full decision detail was not retrievable in this pass.
  2. ConfirmedEDPBNAIH held that <cite index="10-8">Pursuant to Section 16/B of Act CVIII of 2001 concerning electronic commercial services... the investigation... is within the powers of the Nemzeti Média- és Hírközlési Hatóság (NMHH...)</cite>, not NAIH, for certain newsletter/unsubscribe complaints.
  3. ConfirmedIAPPNAIH fined an employer after finding IT-policy deficiencies, requiring that <cite index="48-16">employees must also be informed of the privacy aspects of the monitoring; e.g., purpose of data processing, the data controller, data retention periods, data privacy rights and remedies</cite>.
  4. ConfirmedEDPBNAIH examined joint-controller responsibility for <cite index="4-5">recordings feature children performing and singing specifically from a Slovak Primary School</cite> published by a Hungarian-linked foundation.

#

Only direct_marketing sub-module has confirmed evidence; the remaining five sub-modules are unresolved gaps.

Primary frameworkePrivacy Directive as implemented via Act CVIII of 2001 on electronic commerce; GDPR
Supervisory authorityNAIH
Traffic-light rationale — RedOnly direct_marketing sub-module has confirmed evidence; the remaining five sub-modules are unresolved gaps.

Sub-modules (6)

Cookies And TrackersRed

No HU-specific cookie-consent guidance identified in this pass.

Absence provenance: not recorded. Searched: Hungary cookie consent ePrivacy NAIH guidance.

Dark PatternsRed

No HU-specific dark-pattern finding.

Absence provenance: not recorded. Searched: Hungary dark patterns data protection NAIH.

Opt Out SignalsRed

No HU-specific opt-out-signal finding.

Absence provenance: not recorded. Searched: Hungary Global Privacy Control opt-out signal NAIH.

Clean Rooms And DcrRed

No HU-specific clean-room/DCR finding.

Absence provenance: not recorded. Searched: Hungary data clean room GDPR NAIH.

Cross Context AdvertisingRed

Not applicable in the GDPR model in the manner of US state 'sale/share' concepts; no HU-specific finding.

Absence provenance: not recorded. Searched: Hungary cross-context advertising GDPR equivalent.

Direct MarketingGreen

NMHH holds competence over certain direct-marketing/unsubscribe complaints under Act CVIII of 2001.

Claims: CLM-HU-f4a5b6c7

Category narrative40 words

Direct-marketing enforcement carve-outs to NMHH under Act CVIII of 2001 are confirmed. Cookie/tracker consent, dark-pattern prohibitions, opt-out signals, clean-room rules and cross-context advertising (a US-state-law concept largely inapplicable under the GDPR model) carry no HU-specific finding in this research pass.

No periodic updates recorded against this sub-brief.

Sources and claims (1)
  1. ConfirmedEDPBNAIH declined jurisdiction over an unsubscribe/newsletter complaint, noting that <cite index="10-7">as with respect to the unsubscribe itself it has no jurisdiction according to the rules of Hungarian law</cite>, referring the matter to NMHH under Act CVIII of 2001.

#

ADM, biometric and surveillance-carveout sub-modules evidenced; AI risk-assessment detail and profiling/genetic sub-modules remain unresolved or uncertain.

Primary frameworkGDPR Art 22; GDPR Art 9 (biometrics); EU AI Act; Hungarian AI Law (2025); national security/law-enforcement acts
Supervisory authorityNAIH
Traffic-light rationale — AmberADM, biometric and surveillance-carveout sub-modules evidenced; AI risk-assessment detail and profiling/genetic sub-modules remain unresolved or uncertain.

Sub-modules (6)

Profiling RestrictionsRed

No HU-specific profiling-restriction finding beyond GDPR Art 22 baseline.

Absence provenance: not recorded. Searched: Hungary NAIH profiling restrictions Article 22 guidance.

Automated Decision Making TransparencyGreen

GDPR Art 22 ADM transparency rules apply directly.

Claims: CLM-HU-a5b6c7d8

Ai Risk AssessmentsAmber

Hungary enacted a national AI Law in late 2025; detailed provisions unverified in this pass.

Absence provenance: not recorded. Searched: Hungary AI Law 2025 NAIH designated authority AI Act.

Claims: CLM-HU-b6c7d8e9

Biometric RegimeGreen

EU-wide GDPR/AI Act biometric special-category regime applies directly in Hungary.

Claims: CLM-HU-c7d8e9f0

Genetic DataRed

No HU-specific genetic-data finding beyond GDPR Art 9 baseline.

Absence provenance: not recorded. Searched: Hungary genetic data protection NAIH guidance.

State Surveillance CarveoutsAmber

Sectoral security-sector acts (Police, Prison Service, Prosecution) carve out data processing from GDPR's material scope.

Claims: CLM-HU-d8e9f0a1

Category narrative62 words

GDPR Art 22 ADM rules and the EU-wide biometric special-category regime apply directly. Hungary enacted a national AI Law in November 2025, though its detailed risk-assessment provisions could not be verified from sources retrieved in this pass. Law-enforcement/security-sector data carve-outs (Police, Prison Service, Prosecution Acts) sit outside GDPR's material scope. Profiling-restriction and genetic-data sub-modules have no HU-specific finding beyond the GDPR baseline.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedEUR-LexGDPR Art 22, in force since 25 May 2018, directly governs automated-decision-making transparency and the right to human intervention in Hungary as an EU Member State.
  2. UncertainDataGuidance (OneTrust)Hungary's government enacted a national AI Law ('Hungary: Government enacts AI Law') in approximately November 2025, though the specific scope of its AI risk-assessment obligations could not be confirmed from retrievable source text in this pass.
  3. ConfirmedIAPP<cite index="33-4">the EU AI Act introduces a new layer of regulation that targets four types of biometrics and classifies them by risk — ranging from prohibited to high risk and limited risk</cite>, applying directly in Hungary alongside the GDPR biometric special-category rule.
  4. ProbableEUR-LexHungary's law-enforcement/security-sector data processing is separately governed by instruments including <cite index="13-3">Act on Police (Act XXXIV of 1994)... Act on the Hungarian Prison Service Organisation (Act CVII of 1995)</cite> and the Prosecution Service Act, sitting outside GDPR's material scope.

#

Partial evidence on age/consent and one concrete education-adjacent enforcement matter; three sub-modules unresolved.

Primary frameworkGDPR Art 8; Act CXII of 2011 (amended)
Supervisory authorityNAIH
Traffic-light rationale — AmberPartial evidence on age/consent and one concrete education-adjacent enforcement matter; three sub-modules unresolved.

Sub-modules (5)

Age VerificationAmber

No domestic derogation on age for valid consent identified; specific Art 8 minors' threshold for HU unconfirmed.

Claims: CLM-HU-e9f0a1b2

Minor Profiling BansRed

No HU-specific minor-profiling-ban finding.

Absence provenance: not recorded. Searched: Hungary minors profiling ban data protection NAIH.

Education SettingsAmber

NAIH's Art 26 decision engaged children's data in an education-adjacent, cross-border context.

Claims: CLM-HU-f0a1b2c3

Dependent AdultsRed

No HU-specific dependent-adults finding.

Absence provenance: not recorded. Searched: Hungary dependent adults elderly data protection NAIH.

Category narrative48 words

No domestic derogation from the GDPR's general consent-age rules was identified, though the specific Art 8 digital-minor-consent threshold for Hungary was not separately confirmed. An education-adjacent case involving children's video recordings evidences NAIH's practical engagement with minors' data. Minor-profiling-ban, dedicated parental-consent-mechanism and dependent-adults sub-modules carry no HU-specific finding.

No periodic updates recorded against this sub-brief.

Sources and claims (2)
  1. ProbableDataGuidance (OneTrust)Legal commentary confirms <cite index="14-5">the Act does not provide for any derogations on the age for valid consent</cite>, though the precise Art 8 digital-minors threshold for Hungary was not separately confirmed.
  2. ConfirmedEDPBNAIH's decision addressed processing of <cite index="4-5">recordings feature children performing and singing specifically from a Slovak Primary School</cite> in a cross-border, education-adjacent joint-controller dispute.

#

Strong evidence on powers, enforcement activity, and private redress; funding/capacity and collective-redress sub-modules unresolved; recent-developments window carries only an uncertain, borderline-dated item.

Primary frameworkGDPR Arts 58, 77-84; Act CXII of 2011 §56
Supervisory authorityNAIH
Traffic-light rationale — AmberStrong evidence on powers, enforcement activity, and private redress; funding/capacity and collective-redress sub-modules unresolved; recent-developments window carries only an uncertain, borderline-dated item.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

NAIH exercises binding corrective powers under GDPR Art 58 and Privacy Act §56(1).

Claims: CLM-HU-a1b2c3e4

Enforcement Activity IndexGreen

A confirmed 2024 HUF 10 million GDPR fine evidences ongoing enforcement activity.

Claims: CLM-HU-b2c3e4f5

Regulator Funding And CapacityRed

No HU-specific funding/headcount finding.

Absence provenance: not recorded. Searched: NAIH budget headcount capacity Hungary data protection authority.

Collective Redress And Class ActionsRed

No HU-specific collective-redress mechanism finding.

Absence provenance: not recorded. Searched: Hungary collective redress class action data protection GDPR.

Private Right Of ActionGreen

Judicial review of NAIH decisions before the Budapest Tribunal is confirmed via the Forbes case.

Claims: CLM-HU-c3e4f5a6

Recent Developments 180DAmber

The most recent notable Hungarian development identified is the national AI Law (~Nov 2025), just outside the strict 180-day window from the 2026-08-05 run date; detailed content unverified.

Absence provenance: not recorded. Searched: Hungary data protection recent developments 2026, NAIH enforcement 2026.

Claims: CLM-HU-d4f5a6b7

Category narrative78 words

NAIH exercises GDPR Art 58 corrective powers, including binding compliance orders under Privacy Act §56(1). Enforcement activity is well documented (e.g. a HUF 10 million fine in May 2024). Private judicial review of NAIH decisions before the Budapest Tribunal is confirmed. Regulator funding/capacity and collective-redress mechanisms carry no HU-specific finding in this pass; the most recent notable development (a national AI Law) dates to approximately November 2025, just outside the strict 180-day look-back window from this run's date.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedEDPBNAIH exercised its corrective powers by giving notice to a foundation, <cite index="4-11">Based on Article 58(2)(d) of the GDPR and Section 56(1) of the Privacy Act the Hungarian Supervisory Authority (SA) gave notice to the Foundation ordering it to meet the requirements for joint controllers</cite>.
  2. ConfirmedDataGuidance (OneTrust)<cite index="27-6">On May 17, 2024, the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) issued decision No. NAIH/3977-4/2023</cite>, fining a company HUF 10 million for GDPR violations.
  3. ConfirmedEDPBParties may seek judicial review of NAIH decisions, as shown where <cite index="29-11">A petition for review was submitted to the Fővárosi Törvényszék (Budapest Tribunal) by the Publisher against decision NAIH/2020/838/2</cite>.
  4. UncertainDataGuidance (OneTrust)Hungary's government enacted a national AI Law ('Hungary: Government enacts AI Law') dated on or around November 2025, the most recent notable HU development identified, though detailed provisions and precise commencement remain unverified.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Hungary
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 34 claim(s), 41 source(s) in the cumulative register.