Data Protection and Privacy 2025

HUNGARY Trends and Developments Contributed by: Adam Liber and Tamás Bereczki, PROVARIS Varga & Partners

therefore requires a different legal basis, such as the user’s consent. In 2024, the NAIH fined a bank approximate - ly EUR145,000 for deficiencies in the camera warning signs in the lobby of a branch office. The NAIH highlighted that camera warning signs must be detailed and placed at the entrance, with references to detailed privacy information, and that a simple pictogram is insufficient. Detailed notices must not be placed where access is limited outside business hours and should also be available online. A single data subject’s com - plaint led to an investigation of the transparency practices concerning all branches. The unlaw - ful practice persisted for one-and-a-half years, which was considered an aggravating factor, but the bank’s prompt correction of the issue was treated as a mitigating circumstance. A three- day delay in responding to the data subject’s request was noted but did not result in a fine. ePrivacy – Cookies Use, Notice and Consent Requirements In a landmark decision, the NAIH fined a major Hungarian media service provider approximate - ly EUR 25,000 for failing to comply with GDPR principles in its cookie management. This deci - sion marked the first time the NAIH imposed a fine for cookie management issues and made it public. The NAIH’s decision was based on several critical findings regarding cookie man - agement practices. The authority determined that cookies and cookie identifiers used on websites constitute the processing of person - al data. As a result, website operators, in their role as data controllers, bear the responsibil - ity for the modules they use on their websites, the third parties they share data with, and the legal basis they rely upon for data processing. This requires clear, transparent communication about the specific purposes and legal grounds

for data processing. A key issue identified by the NAIH was the design of the cookie banner. The NAIH found that the banner used by the ser - vice provider was overly complex and displayed too much information in a limited screen space. Furthermore, the process to reject all cookies was made more difficult than accepting them, with the “Reject All” option being less accessible than the “Accept All” option. The NAIH empha - sised that withdrawing consent should be as easy as giving it, a principle not upheld in this case. The NAIH also criticised the misuse of the term “legitimate interest” and the lack of clarity in communicating the processing purposes for cookies based on consent versus those based on legitimate interest. The data controller’s argu - ment that it had based its cookie management solution on the IAB Europe’s Transparency and Consent Framework was rejected by the NAIH. The NAIH referred to a Belgian DPA decision, which had found IAB Europe’s framework illegal, and applied the same reasoning to this case. This decision is a clear message to businesses about the importance of GDPR compliance in cookie management and the potential risks of relying solely on third-party solutions for com - pliance. It signals a stricter enforcement regime for cookie consent management, implying that businesses can no longer claim the widespread nature of such infringements as a defence. Data Subject Rights Management The NAIH places a strong emphasis on the management of data subject rights, particu - larly in ensuring timely responses to data sub - ject requests and the careful evaluation of data subject access rights. This focus is essential for ensuring that data subjects’ rights under the GDPR are respected and fulfilled. The NAIH con - firmed that data subjects may only have access to copies of their personal data, and the scope of such requests does not cover technical corre -

182 CHAMBERS.COM

Powered by