Data Protection and Privacy 2025

HUNGARY Law and Practice Contributed by: Adam Liber and Tamás Bereczki, PROVARIS Varga & Partners

voice recordings and it establishes the right to bring civil law claims if this right is violated. Section 11 of the Act generally protects the privacy of communications. 1.2 Regulators The NAIH, Hungary’s chief data protection authority, serves as the independent overseer of the country’s data protection rights. Its core role is to ensure the lawful and secure processing of personal data by enforcing data protection laws. The NAIH’s responsibilities include setting and implementing regulations and guidelines, and compelling organisations to maintain stringent data security standards. It conducts investiga - tions and audits to verify compliance with data protection laws, focusing on organisations’ data security measures. Additionally, the NAIH regu - lates data breach notifications, ensuring timely reporting of breaches and implementation of risk mitigation strategies. The authority also educates and advises data controllers on best practices for data protection and security. The NAIH has the power to enforce penalties and legal actions against entities that breach data security and privacy regulations. 1.3 Enforcement Proceedings and Fines Enforcement Environment in Hungarian Data Protection Law In the realm of data protection in Hungary, the enforcement environment encompasses various types of sanctions to ensure compliance with data protection regulations. These sanctions are designed to address different aspects of non- compliance and are critical in maintaining the integrity of data protection practices. The key types of sanctions include: • Administrative Fines: These are the primary sanction under the GDPR framework. In cases of non-compliance, organisations may

face substantial fines, which can amount to up to EUR20 million or 4% of their annual global turnover, whichever is higher. These severe financial penalties underline the impor - tance the EU places on data protection. The fine that may be imposed on a state budget authority is capped at a maximum of HUF20 million (approximately EUR52,000). • Civil Law Sanctions: Hungarian law enables individuals to initiate private legal actions against data controllers and processors for breaches of data protection rules. This right empowers data subjects to seek redress directly, including pecuniary (financial) and non-pecuniary (such as emotional distress) damages. • Criminal Sanctions: In more severe instances, where the abuse of personal data is driven by financial gain or causes significant harm to individuals, criminal penalties can be imposed by Hungarian criminal courts. Data Protection Procedures of the NAIH The NAIH in Hungary conducts two main types of procedures in data protection cases: inves - tigation procedures and administrative proce - dures for data protection. • Investigation Procedure: This can be initi - ated by complaints from data subjects, third parties, data controllers/processors, or by the NAIH itself. Its purpose is to gather evidence and ascertain if there has been a breach of data protection laws. If no breach is found, the case is closed. However, if unlawful data processing is identified, the NAIH may instruct the data controller to rectify it within 30 days. Failure to comply or severe breaches can lead to an administrative procedure. • Administrative Procedure: This serves as the primary enforcement mechanism, enabling the NAIH to impose fines or other corrective

166 CHAMBERS.COM

Powered by