Hungary flag

Hungary

Hungary Data Privacy Laws: GDPR, NAIH Enforcement & Compliance Guide (2026)

By Recording Law Editorial TeamReviewed May 20, 202622 min read
Hungary Data Privacy Laws: GDPR, NAIH Enforcement & Compliance Guide (2026)

Frequently Asked Questions

What is Hungary's primary national data protection law?

Hungary's main national data-protection statute is Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information (the Info Act). It supplements the GDPR with national procedural rules, freedom-of-information obligations, and sector-specific adjustments. The GDPR takes precedence where conflicts arise. The Info Act is notable for applying to all data processing in Hungary regardless of sector, including law enforcement and national security.

Who enforces data protection law in Hungary?

The National Authority for Data Protection and Freedom of Information (NAIH) is Hungary's supervisory authority under GDPR Article 51. It holds the full GDPR enforcement toolkit: investigations, audits, binding corrective orders, processing bans, and administrative fines up to EUR 20 million or 4% of worldwide annual turnover. The NAIH also enforces freedom-of-information obligations under the Info Act, giving it a dual mandate unusual among EU data-protection authorities.

Can Hungarian employers use employee consent as the legal basis for workplace monitoring?

No. The NAIH has declared that employee consent cannot be freely given due to the inherent power imbalance in employment relationships. Employers must identify alternative legal bases: legitimate interests under GDPR Article 6(1)(f) (with a documented balancing test), contractual necessity under Article 6(1)(b), or a legal obligation under Article 6(1)(c). This applies to all forms of workplace data processing, including CCTV surveillance, email monitoring, GPS tracking, and biometric access systems.

What was Hungary's largest GDPR fine?

The NAIH's record fine was HUF 250 million (approximately EUR 653,000) imposed on Budapest Bank in 2022 for using AI to analyse customer emotions during telephone calls. The bank deployed the system without a valid legal basis, adequate transparency, or consent mechanisms. The case became a reference enforcement action cited by other EU data-protection authorities considering AI-processing cases.

What are the breach notification timelines in Hungary?

Controllers must notify the NAIH within 72 hours of becoming aware of a personal data breach that poses a risk to individuals' rights and freedoms, using the NAIH's online Personal Data Breach Reporting System, in Hungarian. If the breach poses a high risk, affected individuals must also be notified directly. The 2024 Cybersecurity Act adds a separate incident-reporting obligation for essential and important entities; both the GDPR notification and the cybersecurity notification must be fulfilled independently.

When must a Data Protection Officer be appointed in Hungary?

A DPO is mandatory for public authorities and bodies (except courts acting in their judicial capacity), and for controllers or processors whose core activities involve large-scale, regular, and systematic monitoring of individuals, or large-scale processing of special-category data or criminal-conviction data. Hungary adds a procedural requirement: DPO contact details must be registered with the NAIH online, whether appointment is mandatory or voluntary.

How does Hungary's EU AI Act implementation affect GDPR compliance?

Hungary enacted Act LXXV of 2025 to implement the EU AI Act domestically, with most provisions effective 1 December 2025. The NAIH remains the competent authority for data-protection aspects of AI deployments. The NAIH requires Data Protection Impact Assessments for any AI system that processes personal data, regardless of the EU AI Act risk classification. Controllers deploying AI in automated decision-making, emotion recognition, or customer profiling must ensure both EU AI Act compliance and a valid GDPR legal basis.

What are Hungary's rules on international data transfers?

Hungary follows the standard GDPR framework. Transfers outside the EEA require an adequacy decision, appropriate safeguards (most commonly Standard Contractual Clauses with Transfer Impact Assessments), or an Article 49 derogation. The NAIH must be notified of certain derogation-based transfers. Additionally, Act LXIX of 2024 on Cybersecurity introduces data-localisation obligations requiring certain administrative bodies, state-owned enterprises, and essential or important entities to retain defined categories of operational data on infrastructure physically located in Hungary.

What is the constitutional basis for data protection in Hungary?

Article VI(3) of Hungary's Fundamental Law (the constitution, effective 2012) guarantees the right to personal data protection. This constitutional basis is reinforced by the Hungarian Constitutional Court's landmark Decision 15/1991, which recognised informational self-determination as a fundamental constitutional right more than a decade before the GDPR. Hungarian courts and the NAIH treat data-protection violations as constitutional infringements subject to proportionality analysis, not merely regulatory non-compliance.

What is Hungary's age of digital consent?

Hungary set the age of digital consent at 16, maintaining the GDPR's default threshold under Article 8(1). Children under 16 require parental or guardian authorisation to consent to information-society services. Services that rely on consent from users in this age bracket must implement verifiable age-check mechanisms.

Updates

Full audit-and-evolve refresh. Added sections on EU AI Act (Act LXXV of 2025, effective 1 December 2025), 2024 NAIH enforcement statistics (HUF 335 million total, 38 decisions), EDPB 2025 CEF right-to-erasure results, 2026 data-minimisation case, Act LXIX of 2024 Cybersecurity Act data-localisation rules, expanded employee monitoring, DPO registration requirement, constitutional foundation detail, and practical compliance guide. Word count expanded from approximately 2,420 to approximately 5,800 words.

Initial publication. Covered Info Act, NAIH structure, Budapest Bank AI fine, employee monitoring, age of consent, breach notification, cross-border transfers, and 2025 NAIH enforcement priorities.

Sources and References

  1. NAIH Official(naih.hu).gov
  2. Info Act English Text (NAIH)(naih.hu).gov
  3. Fundamental Law of Hungary(legislationline.org)
  4. Act LXIX of 2024 Cybersecurity (njt.hu)(njt.hu).gov
  5. NAIH 2024 Cases Analysis(dmp.hu)
  6. DLA Piper Budapest Bank AI Fine(privacymatters.dlapiper.com)
  7. Fox Rothschild 2026 Data Minimisation(dataprivacy.foxrothschild.com)
  8. Act LXXV of 2025 AI Implementation(regulations.ai)
  9. CMS Hungary AI Guide(cms.law)
  10. EDPB CEF 2025 Right to Erasure Report(edpb.europa.eu).gov
  11. EDPB CEF 2026 Transparency(edpb.europa.eu).gov
  12. CMS GDPR Enforcement Tracker Hungary(cms.law)
  13. Chambers Hungary 2025(practiceguides.chambers.com)
  14. White & Case GDPR Implementation Hungary(whitecase.com)
  15. ICLG Hungary 2025-2026(iclg.com)
  16. EC Rule of Law Report Hungary 2025(commission.europa.eu).gov
  17. EC Hungary Rule of Law Dec 2024(ec.europa.eu).gov
  18. CMS LawNow NAIH Breach Management 2025(cms-lawnow.com)
Share: