Data Protection and Privacy 2025

HUNGARY Law and Practice Contributed by: Adam Liber and Tamás Bereczki, PROVARIS Varga & Partners

5.3 Data Localisation Requirements Data localisation and residency requirements in Hungary are governed by Act LXIX of 2024 on Hungary’s Cybersecurity. These requirements apply to administrative bodies, state-owned enterprises, and entities designated as essen - tial or important. Such organisations must con - duct a data classification process in accordance with Annex I of Government Decree 418/2024 (XII. 23.). Depending on their criticality, certain data classes may only be stored within the ter - ritory of the EU or specifically within Hungary. Furthermore, under Act XCI of 2021 on National Data Assets, more stringent rules have been established for the handling of state databas - es belonging to national data assets, including criminal records, land registry records, company registry records, and ID records. This law stipu - lates that data processing activities may only be performed within the territory of Hungary. 5.4 Blocking Statutes Article 48 GDPR provides that: “Any judgment of a court or tribunal and any decision of an admin - istrative authority of a third country requiring a controller or processor to transfer or disclose per - sonal data may only be recognized or enforceable in any manner if based on an international agree - ment, such as a mutual legal assistance treaty, in force between the requesting third country and the Union or a Member State, without prejudice to other grounds for transfer pursuant to this Chapter”. The request of a foreign government for access to personal data does not automatically establish a legal ground under the GDPR. When a foreign government requests access to personal data held by an organisation, the organisation must carefully assess the request considering its legal obligations. This assessment includes considering any applicable data protection laws, international treaties, and the legal basis for pro - cessing and transferring such data.

5.5 Recent Developments The NAIH emphasises concerns regarding data sovereignty and national security risks associated with the international transfer of personal data. This issue has been brought into focus due to political parties storing Hungarian citizens’ per - sonal data abroad without sufficient justification. NAIH president, Attila Péterfalvi, has publicly stated that the authority will continue to priori - tise investigations into improper data processing practices by political organisations to safeguard individuals’ rights. This stance emerged following complaints received by the NAIH during the 2022 election campaign, where 112 Hungarian voters reported the unauthorised use of their personal data. The investigation highlighted the complexi - ties of enforcing data protection standards when processing is carried out by third-country service providers. Transparency and accountability were found to be compromised due to convoluted contracting chains. The President underlined the risks of storing and processing large volumes of sensitive data, such as political opinions, in juris - dictions outside Hungary. He emphasised that such data should ideally be processed domesti - cally to ensure compliance with national and EU data protection laws. Moreover, the NAIH presi - dent warned that controllers cannot circumvent their responsibilities through contractual arrange - ments, stressing that accountability under the GDPR remains with the data controller regard - less of where processing occurs. He urged politi - cal parties and organisations to strictly adhere to data protection regulations, ensuring clear accountability and transparency in their practices. The NAIH’s position highlights the need for robust safeguards, local processing where possible, and a commitment to upholding GDPR principles to mitigate risks associated with international data transfers.

176 CHAMBERS.COM

Powered by