Data Protection and Privacy 2025

HUNGARY Law and Practice Contributed by: Adam Liber and Tamás Bereczki, PROVARIS Varga & Partners

of personality rights under the Civil Code. The consequences of unauthorised data process - ing under the Information Act differ from those under the Civil Code, and claims for grievance awards for data processing violations must pri - marily rely on the Information Act’s framework. The Curia (the Supreme Court), in decisions Pfv. IV.20.927/2020/7 and Pfv.IV.21.084/2020/4, also confirmed that not all data protection breaches result in violations of personality rights. The Civil Code and Information Act protect personality differently, with separate legal standards and scopes of protection. The New Civil Code Advisory Board has opined that the occurrence of non-pecuniary harm is a prerequisite for awarding a grievance award. Therefore, even if an infringement is established, the claim for a grievance award may be denied if no actual harm is demonstrated. Article 82 of the GDPR establishes that any person who suffers material or non-material damage as a result of an infringement of the GDPR has the right to receive compensation from the controller or processor responsible for the damage. The provision aims to protect individuals’ data rights and ensure accountability for GDPR violations. The Curia, in decision Pfv.20003/2024/13, pro - vided clarity on the interpretation of GDPR Article 82 in Hungary. It ruled that the mere occurrence of a GDPR violation does not automatically enti - tle a data subject to compensation. Claimants must demonstrate actual damage – whether material or non-material – and establish a direct causal link between the infringement and the harm suffered. The judicial practice underscores the nuanced relationship between the Civil Code grievance awards and the GDPR compensation mechanism. Under the Civil Code, the presump - tion of harm simplifies the claimant’s burden in personality rights cases, but judicial scrutiny

still considers the specific circumstances of the case. In contrast, Article 82 of the GDPR requires proof of actual damage and a causal link, focus - ing on the material or non-material harm caused by data protection violations. 2.3 Collective Redress Mechanisms From June 2023, it is possible to file class actions for GDPR infringements. These class actions allow competent authorities and rep - resentative organisations to represent a broad consumer base adversely affected by unlawful data protection practices, seeking civil law rem - edies in court. Aligning with GDPR guidelines, the Information Act clarifies that in legal dis - putes, the burden of proof to demonstrate com - pliance with data protection regulations rests on the data controller or processor who is the defendant. The courts can award both damages and injunctive relief. 3. Data Regulation on IoT Providers, Data Holders and Data Processing Services 3.1 Objectives and Scope of Data Regulation Hungary does not have specific regulations gov - erning IoT. Instead, sector-specific laws estab - lish general information security and cyberse - curity requirements in high-risk industries where IoT is widely used. The NAIH issued guidance on smart energy metres in 2019. The data protection impact assessment (DPIA) blacklist mandates a DPIA for public utilities using smart metres. 3.2 Interaction of Data Regulation and Data Protection The GDPR establishes stringent standards for the processing of personal data, emphasising principles such as lawfulness, fairness, trans -

170 CHAMBERS.COM

Powered by