Data Protection and Privacy 2025

HUNGARY Law and Practice Contributed by: Adam Liber and Tamás Bereczki, PROVARIS Varga & Partners

such data transfer is ancillary to the asset trans - fer itself. In addition, the merging of databases between the target and the acquirer in a transac - tion may require a DPIA. 5. International Considerations 5.1 Restrictions on International Data Transfers In Hungary, international data transfers of per - sonal data are primarily regulated under the GDPR. The GDPR imposes specific restrictions and requirements on the transfer of personal data outside the European Economic Area (EEA) to ensure that the level of data protection afforded within the EEA is not undermined. When using adequacy measures, such as standard contrac - tual clauses (SCCs) or binding corporate rules (BCRs), organisations are required to conduct a Transfer Impact Assessment (TIA) to evaluate the level of data protection in the recipient coun - try, especially considering the recent Schrems II judgment of the CJEU. This assessment should consider the laws and practices of the third country, particularly those that may impact the effectiveness of the chosen transfer mechanism. Regarding the mechanisms or derogations that apply to international data transfers, the key restrictions and requirements are outlined below: • Adequacy Decisions: Personal data can be freely transferred to countries outside the EEA that have been deemed by decision of the European Commission to provide an ade - quate level of data protection. These adequa - cy decisions are based on a comprehensive assessment of the data protection framework and practices in the non-EEA country. • Appropriate Safeguards: In the absence of an adequacy decision, transfers are permitted

if appropriate safeguards are in place. These safeguards may include tools such as SCCs, BCRs, or specific conditions met under Arti - cle 46 of the GDPR. • Derogations: The GDPR also allows for data transfers in certain specific situations under Article 49, such as when the data subject has explicitly consented to the proposed transfer after being informed of the possible risks, or for the performance of a contract between the data subject and the data controller, or for important reasons of public interest. Data controllers are required to document these assessments and decisions as part of their accountability obligations under the GDPR. They may also need to consult with or obtain authori - sation from the NAIH in certain cases. 5.2 Government Notifications and Approvals Transfers of personal data within the EEA and to adequate countries are generally permitted and no government notifications or approvals are required. Under the GDPR, certain adequacy measures (such as approval of ad-hoc contrac - tual clauses) will require authorisation from the NAIH or the derogation under the “compelling legitimate interests” legal basis of Article 49(1) (2) of the GDPR requires notification of the data transfer. The Genetic Data Act requires data exporters to notify the Chief Public Health Officer of Hun - gary in connection with the international trans - fer of genetic data and genetic samples for the purpose of human genetic research or human genetic testing, and the relevant notification must also indicate a reference to the appropri - ate adequacy safeguards provided by the data exporter and the data importer.

175 CHAMBERS.COM

Powered by