I. Introduction

In the first half of 2026, the Hungarian National Authority for Data Protection and Freedom of Information (hereinafter: the Authority) brought four decisions concerning deficiencies and incorrect or inaccurate wording in privacy notices relating to online stores (NAIH-4021-1/2026., NAIH-450-7/2026., NAIH-4462-4/2026. and NAIH-11443-3/2026). As a sanction imposed in the proceedings, the Authority ordered the Companies, as data controllers, to pay administrative fines. The fines ranged from HUF 200,000 to HUF 15,000,000. Although, according to the Authority’s opinion and reasoning, these fines were proportionate, in our view the cases presented below contain lessons that all data controllers should learn in order to avoid the imposition of similar administrative fines.

II. Facts and Problems

All of the cases presented were initiated ex officio. As a first step, the Authority inspected at the data controllers without prior notice, examining compliance with Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: the GDPR or Regulation). This was mostly about the examination of the privacy notices, policies and other documents available on the Companies’ websites and requesting statements from the data controllers – where it was needed. These measures also served to clarify the facts; below, we highlight the main recurring problems related to the facts of the cases.

During the analyzations, the Authority identified deficiencies in the Companies’ privacy-notice practices as the most important problem. A persistent problem was that information in connection with the data subject’s personal data controlling was inconsistent, too general, terminologically incorrect, or not shown.

It was also a recurring problem that, although data controllers included the information required under Article 13(1)–(2) of the GDPR in their privacy notices, they did not present it in a single, consistent and transparent data protection document. The problem with providing information across multiple documents (e.g. policies, general terms and conditions, notices concerning prize draws, blogs, etc.) was that these documents didn’t form a coherent and transparent system.

The Authority also found fault with a Company providing information in its privacy notice without justification. According to the facts of the case, the Company included data subjects’ rights relating to processing by automated decision-making and profiling in its notice, even though the Authority’s investigation made it clear that these kinds of data processing weren’t used.

It was problematic in many data controllers’ cases that they applied privacy notices that were based on repealed legislation. At this point we shouldn’t just mention the danger of applying repealed legislation, but it’s necessary to take a look on the Authority’s practice on law interpretation: it is seen from the legal cases, that the notices’ fault was also the fact, that the data controllers used the terminological system of the Act CXII of 2011 on Informational Self-Determination and Freedom of Information (hereinafter: Infotv.) and GDPR mixed and inconsistent. We can see from the Authority’s decisions that when it comes to the evaluation of the privacy documents, the Authority prefers the ones that are based on the GDPR’s rulings and terminology.

The Authority also raised issues concerning the choice of legal basis for processing in several cases. Based on the Authority’s decisions, it is considered problematic where a Company, as data controller uses either an incorrect legal basis or several legal bases that have no meaningful relationship with one another.

Finally, it is important to highlight that in several decisions it emerged that the reason for non-compliance with the Regulation was a privacy notice generated by a digital system, which produced the notice in a template-based and unstructured format.

The Authority therefore established infringements on the axis of these problems. In each case, the inappropriate content or form of the privacy notice provided the basis for imposing a data protection fine. In many instances, the data controllers appeared to be motivated merely by the aim of achieving apparent formal compliance with the GDPR, while the actual, specific purpose intended by the legislation appeared less clearly to have been achieved. It therefore seems appropriate, before assessing these problems from a legal perspective, to consider the GDPR’s purpose with regard to privacy notices.

III. The Actual, Specific Purpose of the GDPR – What Does the Authority Expect?

Article 12 (1) of the GDPR primarily sets out the measures that every data controller is required to take: information must be provided in a concise, transparent, intelligible and easily accessible form, using clear and plain language, particularly where any information is addressed specifically to child. In its decision NAIH-4462-4/2026., the Authority also referred to the Article 29 Working Party’s WP260 rev.01 Guidelines, which specifically explain the concrete meaning of the individual elements of these requirements. Among these, “conciseness and transparency” are particularly important; under point 8 of the Guidelines, this essentially means that “the information must be clearly distinguished from other non-data-protection information, such as contractual provisions or general terms of use.”Ease of access” is also mentionable: according to point 11 of the Guidelines, this means that the data subject should not have to search for the information.

Article 13 (1)–(2) of the GDPR lists in detail the information that must be provided where personal data are collected from the data subject. Here too, the GDPR’s objective is to ensure transparency and accountability, which the Regulation seeks to guarantee at the level of fundamental principles as well. The data processing principles set out in Article 5 of the GDPR perform, among other things, an interpretative function, and it was apparent that the Authority also found breaches of these principles.

In summary, the GDPR aims to ensure that the free flow of data takes place in a transparent and traceable manner. Accordingly, the Authority expects privacy notices to contain information that is as specific, sufficiently delineated and easy to understand as possible, and that satisfies the requirements of the GDPR not only formally but also substantively, by being aligned with the “actual operation of the processing”.

IV. Fines and Their Reasoning – What Factors Does the Authority Consider?

We believe that the Authority’s practice concerning fines may also provide useful lessons for data controllers seeking to avoid similar sanctions in the future. We therefore present the factors the Authority considered when determining the amounts of the fines imposed.

In decision NAIH-4021-1/2026., the Authority ordered one Company to pay a data protection fine of HUF 200,000 solely for a negligent infringement of Article 12(1) of the GDPR. In determining the sanction, the Authority considered that the less severe legal consequence, namely a warning, might not necessarily have a sufficient deterrent effect against further infringements. The Authority also assessed aggravating and mitigating circumstances arising during the proceedings: aggravating circumstances included the continuing nature of the infringement and systemic, repeated findings of liability in the past; mitigating circumstances included negligence, the status of the Company as a micro-enterprise, the fact that the infringement affected only a small number of data subjects, and the Company’s efforts, after the period under review, to implement a lawful and effective privacy notice.

Decision NAIH-11443-3/2026. imposed a fine of HUF 2,000,000, likewise for negligent infringements of Article 12 (1) and Article 13 (1)–(2) of the Regulation. Based on the uniform criteria applied for determining fines, aggravating circumstances included the infringement affecting a large number of data subjects and the unlawful situation having persisted for a long period. The Authority nevertheless regarded negligence, the absence of previous findings of liability, the amendment of the privacy notice, and the fact that the Authority exceeded the statutory time limit for handling the case as mitigating circumstances.

Under decision NAIH-4462-4/2026., the data controller was required to pay a data protection fine of HUF 10,000,000. The specific feature of this case was that, as already mentioned, the Authority also assessed breaches of the principles set out in Article 5 of the GDPR in addition to the inadequacy of the information obligations under Articles 12–13 of the Regulation. The systemic nature of the infringement, its continuous duration, and the high number of data subjects were again treated as aggravating circumstances. Mitigating circumstances included the absence of previous findings of liability, negligence, the Authority’s exceeding of the statutory time limit for handling the case, and the Company’s measures taken during the proceedings to remedy the infringement.

Finally, with regard to decision NAIH-450-7/2026., the highest fine was imposed: HUF 15,000,000 for failure to comply with Articles 12–13 of the GDPR. The Authority again regarded the continuing nature of the infringement and the conduct aimed at a restrictive interpretation of the GDPR rules as aggravating circumstances. Further aggravating circumstances included the high number of data subjects affected and a previous finding of liability for an infringement. Mitigating circumstances included the handling time limit, negligence, and measures taken to terminate the unlawful situation.

Overall, it can be concluded that the Authority’s practice concerning fines follows a fairly consistent set of criteria. In addition to referring to the EDPB Guidelines 04/2022, these criteria, in relation to the cases discussed here, can be summarised as follows:

  • Size and financial resources of the data controller
    • Intentionality – whether negligence has been established
    • Duration and continuity of the infringement
    • Systemic nature of the infringement
    • Previous finding of liability for an infringement
    • Conduct of the data controller during the proceedings
    • Number of data subjects
    • Exceeding of statutory time limits

V. Lessons Learned – What Do We Recommend?

The data protection fines imposed were therefore, according to the Authority, effective, proportionate and deterrent. Their imposition was justified, but there is no doubt that the obligation to pay the fines adversely affected the financial position of the companies concerned. In summary, with a view to prevention, we seek to highlight a number of lessons and recommendations in response to the problems listed in Section II.

The most important lesson from the decisions is that a general privacy notice is not sufficient. Instead of providing general information on data processing, data controllers should specify as concretely, clearly and accurately as possible the purposes, retention periods, legal bases, etc. for processing data subjects’ personal data. The WP260 rev.01 Guidelines provide practical examples in this area, and it is therefore advisable to use the Guidelines as a starting point when drafting a privacy notice. This lesson also applies to consistency of terminology: it is beneficial to use the GDPR’s terminology and to identify statutory provisions accurately and consistently. It is also recommended that notices be prepared on the basis of legislation currently in force and that amendments to legislation and changes in its validity be monitored.

It is also advisable to ensure that all the substantive elements required by Article 13 of the Regulation are included. At the same time, as the “other side” of this requirement, it is important to note that excessive and unnecessary amounts of information reduce the transparency and clarity of documents. A similar logic applies to specifying the legal basis. In relation to identifying multiple legal bases, the Authority stated: “It does not comply with the Regulation if the data controller indicates several legal bases in parallel for the same purpose assigned to the same processing activity. […] The appropriate legal basis must be indicated separately.” It is therefore recommended that legal bases also be specified accurately and consistently.

We emphasise that the Authority’s decisions should not be interpreted as meaning that providing information in multiple data protection documents is itself problematic. What constituted an infringement was that the information contained in multiple documents was presented in an irregular and confusing manner. Accordingly, it is advisable to systematise the notices and present them in a structured manner, both in terms of their individual structure and form and in terms of their relationship to one another.

Finally, it appears justified to draw attention to the risks inherent in system-generated or template-based privacy notices. The decisions show that, for some data controllers, this was the reason for notices being unstructured, incoherent and unclear. However, the Authority also stated that the data controller is responsible for the human review and verification of notices generated by such systems. In any event, it is recommended that privacy notice templates be treated critically and kept up to date, and that documents generated by digital systems be reviewed by humans.

Keeping these recommendations and, among other things, the fundamental principles in mind is an essential requirement for ensuring that data processing and the provision of information about such processing are carried out lawfully.

The article was prepared on the basis of decisions NAIH-4021-1/2026., NAIH-450-7/2026., NAIH-4462-4/2026. and NAIH-11443-3/2026.

Dr. Péter Miklós
Attila Saly
7th September 2026

This website is maintained by Dr. Miklós Péter Ákos, attorney at law registered in the Budapest Bar Association (registered office: 1117 Budapest, Völgycsillag utca 4., 6. emelet 02. a., tax number: 42982117-2-41, BAR ID number: 36079442) in accordance with the laws and internal regulations applicable to lawyers, which, together with information on client rights, is accessible at www.magyarugyvedikamara.hu. The blog posts and articles on the website do not constitute specific legal advice, an offer or a solicitation. It is intended to inform the website visitors about the areas of expertise of Dr. Miklós Péter Ákos attorney at law. The website has been prepared in accordance with the Hungarian Bar Association (MÜK) Presidium's Resolution No. 2/2001 (IX.3.) on the "Content of the website of the Hungarian Bar Association" and with the provisions of Chapter 10 of the MÜK's Rules of Procedure No. 6/2018 (26.III.). Legal notice​

Web: ZK DESIGN - Ügyvédhonlap

dr. Miklós Péter adatvédelmi jogász
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website.