Data Protection and Privacy 2025

HUNGARY Law and Practice Contributed by: Adam Liber and Tamás Bereczki, PROVARIS Varga & Partners

NAIH’s position on the importance of GDPR compliance in AI applications, especially in automated decision-making and profiling. In this instance, the bank employed AI tech - nology for applying sentiment analysis on every incoming phone call, which the NAIH found disproportionate in terms of the risks posed to data subjects’ fundamental rights. The NAIH highlighted that the bank did not provide any information about the application of this technology and therefore data subjects were deprived of their respective data subject rights. This decision highlights the NAIH’s stringent stance on ensuring that AI and ML applications, especially those involving auto - mated decision-making and profiling, comply with GDPR principles. It also underscores the necessity for data controllers to conduct thorough data protection impact assessments and balancing test assessments when imple - menting AI solutions. • Cookies Use and Dark Patterns: The NAIH fined a leading Hungarian media service pro - vider approximately EUR25,000 for failing to comply with lawful, fair, and transparent data processing in cookie management, based on the Interactive Advertising Bureau (IAB) Europe’s Transparency and Consent Frame - work. The NAIH found that cookie usage and assigning identifiers constitute personal data processing. The controller must clearly define, describe, and justify processing purposes and legal bases, ensuring cookie banners meet fairness and transparency standards. The authority criticised the provider’s lengthy, confusing banner text, the complex process for selecting data transfer partners, and the misleading presentation of consent and legiti - mate interest. The NAIH highlighted the need for easy consent withdrawal, critiquing the design where the “Reject All” option was less accessible than “Accept All Cookies”. The

decision aligns with the Belgian Data Protec - tion Authority’s ruling against IAB Europe’s framework. • Digi Case: In another instance, the NAIH fined an electronic communications service provider, Digi Távközlési és Szolgáltató Kft., EUR250,000 due to a personal data breach resulting from a known website vulnerability. The NAIH’s investigation revealed that the service provider had failed to address this vulnerability for years, neglecting its own internal security policies. The authority cited several aggravating factors, including the prolonged existence of the vulnerability and the large number of affected data subjects. The service provider appealed the decision, leading to a referral to the Court of Justice of the European Union (CJEU) for a preliminary ruling on the interpretation of GDPR principles related to purpose and storage limitation. In October 2022, the CJEU clarified that further processing of personal data for carrying out tests and correcting errors must be compat - ible with the original collection purposes and that data should not be retained longer than necessary. Subsequently, the NAIH reas - sessed the case and, in June 2023, reduced the fine to approximately EUR208,000. 1.5 AI Regulation The Hungarian government has adopted Reso - lution No 1301/2024 (IX. 30.) on the implemen - tation of the European Parliament and Council Regulation (2024/1689/EU) on artificial intelli - gence in Hungary. The resolution provides that the domestic implementation of the AI Act shall be overseen by a specialised organisation estab - lished by law under the supervision of the Minis - ter for the National Economy. This responsibility was not assigned to the NAIH. This organisa - tion ensures a one-stop shop for administrative procedures, performs market surveillance tasks,

168 CHAMBERS.COM

Powered by