Data Protection and Privacy 2025

HUNGARY Law and Practice Contributed by: Adam Liber and Tamás Bereczki, PROVARIS Varga & Partners

if the limitation is proportional to the objective pursued. • Surveillance and Monitoring Restrictions: Monitoring of employees is permissible only in relation to work-related activities. The methods used must respect human dignity (no harassment, intimidation, or disturbance), be limited in time and space, and conducted only by authorised personnel. Personal life and private correspondence shall be exclud - ed from such monitoring. • Transparency and Information Duty: The employer must inform the employees in advance about the nature, conditions, and expected duration of any limitations on their privacy rights. Employers must provide writ - ten notification about data processing activi - ties and the use of technical monitoring tools. • Processing of Documents: The employer can only ask for the presentation of documents (identification cards, certificates, diplomas, etc) from the employee, but copying is restricted unless legally permitted. • Biometric Access Control Measures: Bio - metric identification measures can be used to prevent unauthorised access to sensitive information or assets, considering the poten - tial serious or irreversible consequences. • Processing of Criminal Data: Employers may process criminal personal data of job appli - cants and employees for vetting purposes, particularly to protect financial interests, safe - guard information protected by law, or in rela - tion to the handling of hazardous materials. • Prohibition of Private Use of Company IT Equipment: The Labour Code restricts private use of company IT equipment, unless explic - itly agreed otherwise between employer and employee. • Consultation Requirement: Consultation with the works council is required for implement - ing any measures and internal regulations

affecting large number of employees; this information obligation covers the processing and protection of personal data of employees as well as the use of technical measures used for employee monitoring. Employee Whistle-Blowing The Hungarian Act No XXV of 2023, known as the Complaints Act, aligns with the EU Directive 2019/1937 to govern employee whistle-blowing. It requires employers with 50 or more employees, including certain sectors like financial services, banks, and airlines, to implement an internal whistle-blowing system. The Act covers a wide range of reportable issues, such as illegal activi - ties or suspected illegalities, and includes the ambiguous category of “other abuses”, which it does not specifically define. While anony - mous reporting is allowed, investigations for such reports are not legally mandated. The Act sets procedural deadlines, obliging employers to acknowledge reports within seven days and complete investigations within three months. It also restricts smaller employers, those with 50 to 249 employees, from forming joint internal whistle-blowing systems with other employers. 4.4 Transfer of Personal Data in Asset Deals In Hungary, there is a limited amount of specific case law directly addressing due diligence pro - cesses. Data protection-related due diligence in corporate transactions requires strict compli - ance with the GDPR and local legislation. This process includes verifying the lawful processing of personal data, closely examining data han - dling practices, especially for sensitive informa - tion, and ensuring compliance with data sub - jects’ rights. Under NAIH case law, legitimate interest is generally accepted as a legal basis for the transfer or disclosure of client personal data in asset transfer transactions, provided that

174 CHAMBERS.COM

Powered by