Data Protection and Privacy 2025

HUNGARY Law and Practice Contributed by: Adam Liber and Tamás Bereczki, PROVARIS Varga & Partners

parency, data minimisation, and purpose limi - tation. These principles take precedence over other data-related regulations to ensure the fundamental rights of individuals are upheld. The Information Act complements the GDPR by addressing specific national concerns, includ - ing data processing for purposes of law enforce - ment, national security, and defence, which may fall outside the direct scope of the GDPR. Cer - tain sectors, such as healthcare and finance, are subject to additional data protection obligations under Hungarian law. For instance, the Health Data Act governs the processing of health- related personal data, implementing a com - prehensive regulatory framework for entities in the healthcare sector. These sectoral laws often impose more stringent requirements to address the unique nature of data processing activities within these fields. 3.3 Rights and Obligations Under Applicable Data Regulation IoT providers and data processors in Hungary must ensure lawful data processing based on legal grounds such as consent, contractual necessity, or legal obligations. Transparency is required through clear privacy notices, and data subjects’ rights (access, deletion, correction, etc) must be respected. Strong technical and organisational measures, such as encryption, are necessary to protect data security. High-risk processing requires a DPIA, and data breaches must be reported to the NAIH within 72 hours. Data processing agreements are mandatory for third-party processors, and a Data Protection Officer (DPO) must be appointed for large-scale or sensitive data processing. 3.4 Regulators and Enforcement The NAIH oversees compliance with data pro - tection laws, including the GDPR and the Infor - mation Act. Other regulatory bodies, such as

the Hungarian Competition Authority (GVH), the National Media and Infocommunications Author - ity (NMHH), may also play roles in enforcing data protection and cybersecurity regulations within their respective sectors. The Supervisory Authority for Regulated Activities (SZTFH) and the Special Service for National Security (NBSZ) also play a pivotal role in enforcing cybersecurity regulations, particularly concerning the imple - mentation of the NIS2 Directive. Established to oversee compliance with cybersecurity stand - ards, the SZTFH and NBSZ ensure that organi - sations adhere to national and EU-level cyber - security requirements. The use of cookies in Hungary is primarily gov - erned by the ePrivacy Directive as implemented through the E-Commerce Act (Act CVIII of 2001 on Electronic Commerce and Information Soci - ety Services) and complemented by the GDPR for personal data processing. Hungarian regula - tions require that cookies be categorised based on their purpose, with explicit user consent nec - essary for all non-essential cookies. Essential cookies, such as those facilitating communica - tion or strictly required for the provision of ser - vices explicitly requested by users, are exempt from the consent requirement. However, even in these cases, transparency is mandatory, requir - ing clear notice to users about the cookies in use, their functions, and the scope of data pro - cessing. 4. Sectoral Issues 4.1 Use of Cookies Consent for cookies must be voluntary, informed, and obtained through a clear affirmative action by the user. Practices such as pre-ticked check - boxes or ambiguous consent mechanisms are considered non-compliant under both the GDPR

171 CHAMBERS.COM

Powered by