{"id":2093,"date":"2026-09-15T14:24:52","date_gmt":"2026-09-15T14:24:52","guid":{"rendered":"https:\/\/dmp.hu\/?p=2093"},"modified":"2026-09-15T14:24:52","modified_gmt":"2026-09-15T14:24:52","slug":"lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores","status":"publish","type":"post","link":"https:\/\/dmp.hu\/en\/data-protection\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\/","title":{"rendered":"Lessons Learned from the National Data Protection and Freedom of Information Authority\u2019s Practice Concerning Privacy Notices for Online Stores"},"content":{"rendered":"<h2><b>I. Introduction<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">In the first half of 2026, the Hungarian National Authority for Data Protection and Freedom of Information (hereinafter: <\/span><b>the Authority<\/b><span style=\"font-weight: 400;\">) brought four decisions concerning deficiencies and incorrect or inaccurate wording in privacy notices relating to online stores <\/span><i><span style=\"font-weight: 400;\">(NAIH-4021-1\/2026., NAIH-450-7\/2026., NAIH-4462-4\/2026. and NAIH-11443-3\/2026)<\/span><\/i><span style=\"font-weight: 400;\">. As a sanction imposed in the proceedings, the Authority ordered the <\/span><b>Companies, as data controllers, to pay administrative fines<\/b><span style=\"font-weight: 400;\">. The fines <\/span><b>ranged from HUF 200,000 to HUF 15,000,000<\/b><span style=\"font-weight: 400;\">. Although, according to the Authority\u2019s opinion and reasoning, these fines were proportionate, in our view the cases presented below contain lessons that all data controllers should learn in order to avoid the imposition of similar administrative fines.<\/span><\/p>\n<h2><b>II. Facts and Problems<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">All of the cases presented were initiated ex officio. As a first step, the Authority inspected at the data controllers without prior notice, examining compliance with <\/span><i><span style=\"font-weight: 400;\">Regulation (EU) 2016\/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\/46\/EC<\/span><\/i><span style=\"font-weight: 400;\"> (hereinafter: <\/span><b>the GDPR<\/b><span style=\"font-weight: 400;\"> or <\/span><b>Regulation<\/b><span style=\"font-weight: 400;\">). This was mostly about the examination of the privacy notices, policies and other documents available on the Companies\u2019 websites and requesting statements from the data controllers \u2013 where it was needed. These measures also served to clarify the facts; below, we highlight the main recurring problems related to the facts of the cases.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">During the analyzations, the Authority identified deficiencies in the Companies\u2019 privacy-notice practices as the most important problem. A persistent problem was that information in connection with the data subject\u2019s personal data controlling was inconsistent, too general, terminologically incorrect, or not shown.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">It was also a recurring problem that, although data controllers included the information required under <\/span><b>Article 13(1)\u2013(2) of the GDPR<\/b><span style=\"font-weight: 400;\"> in their privacy notices, they did not present it in a single, consistent and transparent data protection document. The problem with providing information across multiple documents (e.g. policies, general terms and conditions, notices concerning prize draws, blogs, etc.) was that these documents didn\u2019t form a coherent and transparent system.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The Authority also found fault with a Company providing information in its privacy notice <\/span><b>without justification<\/b><span style=\"font-weight: 400;\">. According to the facts of the case, the Company included data subjects\u2019 rights relating to processing by automated decision-making and profiling in its notice, even though the Authority\u2019s investigation made it clear that these kinds of data processing weren\u2019t used.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">It was problematic in many data controllers\u2019 cases that they applied privacy notices that were based on repealed legislation. At this point we shouldn\u2019t just mention the danger of applying repealed legislation, but it\u2019s necessary to take a look on the Authority\u2019s practice on law interpretation: it is seen from the legal cases, that the notices\u2019 fault was also the fact, that the data controllers used the <\/span><b>terminological system<\/b><span style=\"font-weight: 400;\"> of the <\/span><i><span style=\"font-weight: 400;\">Act CXII of 2011 on Informational Self-Determination and Freedom of Information<\/span><\/i><span style=\"font-weight: 400;\"> (hereinafter: <\/span><b>Infotv.) and GDPR mixed and inconsistent. <\/b><span style=\"font-weight: 400;\">We can see from the Authority\u2019s decisions that when it comes to the evaluation of the privacy documents, the Authority prefers the ones that are based on the GDPR\u2019s rulings and terminology.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The Authority also raised issues concerning the choice of legal basis for processing in several cases. Based on the Authority\u2019s decisions, it is considered problematic where a Company, as data controller uses <\/span><b>either an incorrect legal basis or several legal bases that have no meaningful relationship with one another.<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Finally, it is important to highlight that in several decisions it emerged that the reason for non-compliance with the Regulation was a privacy notice <\/span><b>generated by a digital system, which produced the notice in a template-based and unstructured format.<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Authority therefore established infringements on the axis of these problems. In each case, the inappropriate content or form of the privacy notice provided the basis for imposing a <a href=\"https:\/\/dmp.hu\/en\/data-protection\/\">data protection<\/a> fine. In many instances, the data controllers appeared to be motivated merely by the <\/span><b>aim of achieving apparent formal compliance<\/b><span style=\"font-weight: 400;\"> with the GDPR, while the <\/span><b>actual, specific purpose<\/b><span style=\"font-weight: 400;\"> intended by the legislation appeared less clearly to have been achieved. It therefore seems appropriate, before assessing these problems from a legal perspective, to consider the GDPR\u2019s purpose with regard to privacy notices.<\/span><\/p>\n<h2><b>III. The Actual, Specific Purpose of the GDPR \u2013 What Does the Authority Expect?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Article 12 (1) of the GDPR primarily sets out the measures that every data controller is required to take: information must be provided in a <\/span><b><i>concise, transparent, intelligible and easily accessible form, using clear and plain language<\/i><\/b><i><span style=\"font-weight: 400;\">, particularly where any information is addressed specifically to child.<\/span><\/i><span style=\"font-weight: 400;\"> In its decision <\/span><i><span style=\"font-weight: 400;\">NAIH-4462-4\/2026.,<\/span><\/i><span style=\"font-weight: 400;\"> the Authority also referred to the Article 29 Working Party\u2019s <\/span><a href=\"https:\/\/www.edpb.europa.eu\/documents\/guideline\/article-29-working-party-guidelines-on-transparency-under-regulation-2016679_en\" target=\"_blank\" rel=\"noopener\"><b>WP260 rev.01 Guidelines<\/b><\/a><span style=\"font-weight: 400;\">, which specifically explain the concrete meaning of the individual elements of these requirements. Among these, <\/span><b><i>\u201cconciseness and transparency\u201d<\/i><\/b><i><span style=\"font-weight: 400;\"> are particularly important; under point 8 of the Guidelines, this essentially means that \u201cthe information must be clearly distinguished from other non-data-protection information, such as contractual provisions or general terms of use.\u201d<\/span><\/i><span style=\"font-weight: 400;\"> \u201c<\/span><b><i>Ease of access<\/i><\/b><span style=\"font-weight: 400;\">\u201d is also mentionable: according to point 11 of the Guidelines, this means that the data subject should not have to search for the information.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Article 13 (1)\u2013(2) of the GDPR lists in detail the information that must be provided where personal data are collected from the data subject. Here too, the GDPR\u2019s objective is to ensure <\/span><b>transparency and accountability<\/b><span style=\"font-weight: 400;\">, which the Regulation seeks to guarantee at the level of fundamental principles as well. The data processing principles set out in Article 5 of the GDPR perform, among other things, an interpretative function, and it was apparent that the Authority also found breaches of these principles.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In summary, the GDPR aims to ensure that the free flow of data takes place in a transparent and traceable manner. Accordingly, the Authority expects privacy notices to contain information that is <\/span><b>as specific, sufficiently delineated and easy to understand as possible, and that satisfies the requirements of the GDPR not only formally but also substantively, by being aligned with the \u201cactual operation of the processing\u201d.<\/b><\/p>\n<h2><b>IV. Fines and Their Reasoning \u2013 What Factors Does the Authority Consider?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">We believe that the Authority\u2019s practice concerning fines may also provide useful lessons for data controllers seeking to avoid similar sanctions in the future. We therefore present the factors the Authority considered when determining the amounts of the fines imposed.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In decision <\/span><i><span style=\"font-weight: 400;\">NAIH-4021-1\/2026<\/span><\/i><span style=\"font-weight: 400;\">., the Authority ordered one Company to pay a data protection fine of HUF 200,000 solely for a negligent infringement of Article 12(1) of the GDPR. In determining the sanction, the Authority considered that the less severe legal consequence, namely a warning, might not necessarily have a sufficient deterrent effect against further infringements. The Authority also assessed aggravating and mitigating circumstances arising during the proceedings: <\/span><b>aggravating circumstances included the continuing nature of the infringement and systemic, repeated findings of liability in the past; mitigating circumstances included negligence, the status of the Company as a micro-enterprise, the fact that the infringement affected only a small number of data subjects, and the Company\u2019s efforts, after the period under review, to implement a lawful and effective privacy notice.<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Decision <\/span><i><span style=\"font-weight: 400;\">NAIH-11443-3\/2026<\/span><\/i><span style=\"font-weight: 400;\">. imposed a fine of HUF 2,000,000, likewise for negligent infringements of Article 12 (1) and Article 13 (1)\u2013(2) of the Regulation. Based on the uniform criteria applied for determining fines, <\/span><b>aggravating circumstances included the infringement affecting a large number of data subjects and the unlawful situation having persisted for a long period. The Authority nevertheless regarded negligence, the absence of previous findings of liability, the amendment of the privacy notice, and the fact that the Authority exceeded the statutory time limit for handling the case as mitigating circumstances.<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Under decision <\/span><i><span style=\"font-weight: 400;\">NAIH-4462-4\/2026.<\/span><\/i><span style=\"font-weight: 400;\">, the data controller was required to pay a data protection fine of HUF 10,000,000. The specific feature of this case was that, as already mentioned, the Authority also assessed breaches of the principles set out in Article 5 of the GDPR in addition to the inadequacy of the information obligations under Articles 12\u201313 of the Regulation. <\/span><b>The systemic nature of the infringement, its continuous duration, and the high number of data subjects were again treated as aggravating circumstances. Mitigating circumstances included the absence of previous findings of liability, negligence, the Authority\u2019s exceeding of the statutory time limit for handling the case, and the Company\u2019s measures taken during the proceedings to remedy the infringement.<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Finally, with regard to decision <\/span><i><span style=\"font-weight: 400;\">NAIH-450-7\/2026<\/span><\/i><span style=\"font-weight: 400;\">., the highest fine was imposed: HUF 15,000,000 for failure to comply with Articles 12\u201313 of the GDPR. The Authority again regarded the <\/span><b>continuing nature of the infringement and the conduct aimed at a restrictive interpretation of the GDPR rules as aggravating circumstances. Further aggravating circumstances included the high number of data subjects affected and a previous finding of liability for an infringement. Mitigating circumstances included the handling time limit, negligence, and measures taken to terminate the unlawful situation.<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Overall, it can be concluded that the Authority\u2019s practice concerning fines follows a fairly consistent set of criteria. In addition to referring to the EDPB Guidelines 04\/2022, these criteria, in relation to the cases discussed here, can be summarised as follows:<\/span><\/p>\n<ul>\n<li><span style=\"font-weight: 400;\"> Size and financial resources of the data controller<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">\u2022 Intentionality \u2013 whether negligence has been established<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">\u2022 Duration and continuity of the infringement<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">\u2022 Systemic nature of the infringement<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">\u2022 Previous finding of liability for an infringement<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">\u2022 Conduct of the data controller during the proceedings<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">\u2022 Number of data subjects<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">\u2022 Exceeding of statutory time limits<\/span><\/li>\n<\/ul>\n<h2><b>V. Lessons Learned \u2013 What Do We Recommend?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">The data protection fines imposed were therefore, according to the Authority, effective, proportionate and deterrent. Their imposition was justified, but there is no doubt that the obligation to pay the fines adversely affected the financial position of the companies concerned. In summary, with a view to prevention, we seek to highlight a number of lessons and recommendations in response to the problems listed in Section II.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The most important lesson from the decisions is that a general privacy notice is not sufficient. Instead of providing general information on data processing, data controllers <\/span><b>should specify as concretely, clearly and accurately as possible<\/b><span style=\"font-weight: 400;\"> the purposes, retention periods, legal bases, etc. for processing data subjects\u2019 personal data. The WP260 rev.01 Guidelines provide practical examples in this area, and it is therefore advisable to use the Guidelines as a starting point when drafting a privacy notice. This lesson also applies to consistency of terminology: <\/span><b>it is beneficial to use the GDPR\u2019s terminology and to identify statutory provisions accurately and consistently<\/b><span style=\"font-weight: 400;\">. It is also recommended that notices be prepared on the basis of <\/span><b>legislation currently in force<\/b><span style=\"font-weight: 400;\"> and that amendments to legislation and changes in its validity be monitored.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">It is also advisable to <\/span><b>ensure that all the substantive elements required by Article 13 of the Regulation are included<\/b><span style=\"font-weight: 400;\">. At the same time, as the \u201cother side\u201d of this requirement, it is important to note that <\/span><b>excessive and unnecessary amounts of information reduce the transparency and clarity of documents<\/b><span style=\"font-weight: 400;\">. A similar logic applies to specifying the legal basis. In relation to identifying multiple legal bases, the Authority stated: <\/span><i><span style=\"font-weight: 400;\">\u201cIt does not comply with the Regulation if the data controller indicates several legal bases in parallel for the same purpose assigned to the same processing activity. [\u2026] The appropriate legal basis must be indicated separately.\u201d<\/span><\/i> <b>It is therefore recommended that legal bases also be specified accurately and consistently.<\/b><\/p>\n<p><span style=\"font-weight: 400;\">We emphasise that the Authority\u2019s decisions should not be interpreted as meaning that providing information in multiple data protection documents is itself problematic. What constituted an infringement was that the information contained in multiple documents was presented in an irregular and confusing manner. Accordingly, <\/span><b>it is advisable to systematise the notices and present them in a structured manner, both in terms of their individual structure and form and in terms of their relationship to one another.<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Finally, it appears justified to draw attention to the risks inherent in system-generated or template-based privacy notices. The decisions show that, for some data controllers, this was the reason for notices being unstructured, incoherent and unclear. However, the Authority also stated that the data controller is responsible for the human review and verification of notices generated by such systems. <\/span><b>In any event, it is recommended that privacy notice templates be treated critically and kept up to date, and that documents generated by digital systems be reviewed by humans.<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Keeping these recommendations and, among other things, the fundamental principles in mind is an essential requirement for ensuring that data processing and the provision of information about such processing are carried out lawfully.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The article was prepared on the basis of decisions NAIH-4021-1\/2026., NAIH-450-7\/2026., NAIH-4462-4\/2026. and NAIH-11443-3\/2026.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Dr. P\u00e9ter Mikl\u00f3s<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">Attila Saly<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">7th September 2026<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In the first half of 2026, the Hungarian National Authority for Data Protection and Freedom of Information brought four decisions concerning deficiencies and incorrect or inaccurate wording in privacy notices relating to online stores.<\/p>\n","protected":false},"author":6,"featured_media":2095,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[15],"tags":[],"class_list":["post-2093","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.3 (Yoast SEO v28.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Online Store Privacy Notices: Key Lessons from NAIH<\/title>\n<meta name=\"description\" content=\"Online store privacy notices must be clear, specific and current. NAIH\u2019s 2026 decisions show main GDPR errors, fines and compliance lessons\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/dmp.hu\/en\/data-protection\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Lessons Learned from the National Data Protection and Freedom of Information Authority\u2019s Practice Concerning Privacy Notices for Online Stores\" \/>\n<meta property=\"og:description\" content=\"Online store privacy notices must be clear, specific and current. NAIH\u2019s 2026 decisions show main GDPR errors, fines and compliance lessons\" \/>\n<meta property=\"og:url\" content=\"https:\/\/dmp.hu\/en\/data-protection\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\/\" \/>\n<meta property=\"og:site_name\" content=\"dr. Mikl\u00f3s P\u00e9ter adatv\u00e9delmi jog\u00e1sz\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-15T14:24:52+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/dmp.hu\/wp-content\/uploads\/2026\/09\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"800\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"csilla.zkdesign\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"csilla.zkdesign\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/dmp.hu\\\/en\\\/data-protection\\\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/dmp.hu\\\/en\\\/data-protection\\\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\\\/\"},\"author\":{\"name\":\"csilla.zkdesign\",\"@id\":\"https:\\\/\\\/dmp.hu\\\/#\\\/schema\\\/person\\\/df3c24a9ac5c8f1e390798c793646c5d\"},\"headline\":\"Lessons Learned from the National Data Protection and Freedom of Information Authority\u2019s Practice Concerning Privacy Notices for Online Stores\",\"datePublished\":\"2026-09-15T14:24:52+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/dmp.hu\\\/en\\\/data-protection\\\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\\\/\"},\"wordCount\":2115,\"image\":{\"@id\":\"https:\\\/\\\/dmp.hu\\\/en\\\/data-protection\\\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/dmp.hu\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores-1.jpg\",\"articleSection\":[\"Data Protection\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/dmp.hu\\\/en\\\/data-protection\\\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\\\/\",\"url\":\"https:\\\/\\\/dmp.hu\\\/en\\\/data-protection\\\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\\\/\",\"name\":\"Online Store Privacy Notices: Key Lessons from NAIH\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/dmp.hu\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/dmp.hu\\\/en\\\/data-protection\\\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/dmp.hu\\\/en\\\/data-protection\\\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/dmp.hu\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores-1.jpg\",\"datePublished\":\"2026-09-15T14:24:52+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/dmp.hu\\\/#\\\/schema\\\/person\\\/df3c24a9ac5c8f1e390798c793646c5d\"},\"description\":\"Online store privacy notices must be clear, specific and current. NAIH\u2019s 2026 decisions show main GDPR errors, fines and compliance lessons\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/dmp.hu\\\/en\\\/data-protection\\\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/dmp.hu\\\/en\\\/data-protection\\\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/dmp.hu\\\/en\\\/data-protection\\\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\\\/#primaryimage\",\"url\":\"https:\\\/\\\/dmp.hu\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores-1.jpg\",\"contentUrl\":\"https:\\\/\\\/dmp.hu\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores-1.jpg\",\"width\":1200,\"height\":800,\"caption\":\"Lessons Learned from the National Data Protection and Freedom of Information Authority\u2019s Practice Concerning Privacy Notices for Online Stores\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/dmp.hu\\\/en\\\/data-protection\\\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/dmp.hu\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Lessons Learned from the National Data Protection and Freedom of Information Authority\u2019s Practice Concerning Privacy Notices for Online Stores\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/dmp.hu\\\/#website\",\"url\":\"https:\\\/\\\/dmp.hu\\\/\",\"name\":\"dr. Mikl\u00f3s P\u00e9ter adatv\u00e9delmi jog\u00e1sz\",\"description\":\"dr. Mikl\u00f3s P\u00e9ter adatv\u00e9delmi jog\u00e1sz\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/dmp.hu\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/dmp.hu\\\/#\\\/schema\\\/person\\\/df3c24a9ac5c8f1e390798c793646c5d\",\"name\":\"csilla.zkdesign\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/29f20b4a36c99526768bf0983dc1bc7bd60dd0b25ffbffe3d4631aa392d8d603?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/29f20b4a36c99526768bf0983dc1bc7bd60dd0b25ffbffe3d4631aa392d8d603?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/29f20b4a36c99526768bf0983dc1bc7bd60dd0b25ffbffe3d4631aa392d8d603?s=96&d=mm&r=g\",\"caption\":\"csilla.zkdesign\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Online Store Privacy Notices: Key Lessons from NAIH","description":"Online store privacy notices must be clear, specific and current. NAIH\u2019s 2026 decisions show main GDPR errors, fines and compliance lessons","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/dmp.hu\/en\/data-protection\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\/","og_locale":"en_US","og_type":"article","og_title":"Lessons Learned from the National Data Protection and Freedom of Information Authority\u2019s Practice Concerning Privacy Notices for Online Stores","og_description":"Online store privacy notices must be clear, specific and current. NAIH\u2019s 2026 decisions show main GDPR errors, fines and compliance lessons","og_url":"https:\/\/dmp.hu\/en\/data-protection\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\/","og_site_name":"dr. Mikl\u00f3s P\u00e9ter adatv\u00e9delmi jog\u00e1sz","article_published_time":"2026-09-15T14:24:52+00:00","og_image":[{"width":1200,"height":800,"url":"https:\/\/dmp.hu\/wp-content\/uploads\/2026\/09\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores-1.jpg","type":"image\/jpeg"}],"author":"csilla.zkdesign","twitter_card":"summary_large_image","twitter_misc":{"Written by":"csilla.zkdesign","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/dmp.hu\/en\/data-protection\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\/#article","isPartOf":{"@id":"https:\/\/dmp.hu\/en\/data-protection\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\/"},"author":{"name":"csilla.zkdesign","@id":"https:\/\/dmp.hu\/#\/schema\/person\/df3c24a9ac5c8f1e390798c793646c5d"},"headline":"Lessons Learned from the National Data Protection and Freedom of Information Authority\u2019s Practice Concerning Privacy Notices for Online Stores","datePublished":"2026-09-15T14:24:52+00:00","mainEntityOfPage":{"@id":"https:\/\/dmp.hu\/en\/data-protection\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\/"},"wordCount":2115,"image":{"@id":"https:\/\/dmp.hu\/en\/data-protection\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\/#primaryimage"},"thumbnailUrl":"https:\/\/dmp.hu\/wp-content\/uploads\/2026\/09\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores-1.jpg","articleSection":["Data Protection"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/dmp.hu\/en\/data-protection\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\/","url":"https:\/\/dmp.hu\/en\/data-protection\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\/","name":"Online Store Privacy Notices: Key Lessons from NAIH","isPartOf":{"@id":"https:\/\/dmp.hu\/#website"},"primaryImageOfPage":{"@id":"https:\/\/dmp.hu\/en\/data-protection\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\/#primaryimage"},"image":{"@id":"https:\/\/dmp.hu\/en\/data-protection\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\/#primaryimage"},"thumbnailUrl":"https:\/\/dmp.hu\/wp-content\/uploads\/2026\/09\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores-1.jpg","datePublished":"2026-09-15T14:24:52+00:00","author":{"@id":"https:\/\/dmp.hu\/#\/schema\/person\/df3c24a9ac5c8f1e390798c793646c5d"},"description":"Online store privacy notices must be clear, specific and current. NAIH\u2019s 2026 decisions show main GDPR errors, fines and compliance lessons","breadcrumb":{"@id":"https:\/\/dmp.hu\/en\/data-protection\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/dmp.hu\/en\/data-protection\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/dmp.hu\/en\/data-protection\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\/#primaryimage","url":"https:\/\/dmp.hu\/wp-content\/uploads\/2026\/09\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores-1.jpg","contentUrl":"https:\/\/dmp.hu\/wp-content\/uploads\/2026\/09\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores-1.jpg","width":1200,"height":800,"caption":"Lessons Learned from the National Data Protection and Freedom of Information Authority\u2019s Practice Concerning Privacy Notices for Online Stores"},{"@type":"BreadcrumbList","@id":"https:\/\/dmp.hu\/en\/data-protection\/lessons-learned-from-the-national-data-protection-and-freedom-of-information-authoritys-practice-concerning-privacy-notices-for-online-stores\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/dmp.hu\/en\/"},{"@type":"ListItem","position":2,"name":"Lessons Learned from the National Data Protection and Freedom of Information Authority\u2019s Practice Concerning Privacy Notices for Online Stores"}]},{"@type":"WebSite","@id":"https:\/\/dmp.hu\/#website","url":"https:\/\/dmp.hu\/","name":"dr. Mikl\u00f3s P\u00e9ter adatv\u00e9delmi jog\u00e1sz","description":"dr. Mikl\u00f3s P\u00e9ter adatv\u00e9delmi jog\u00e1sz","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/dmp.hu\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/dmp.hu\/#\/schema\/person\/df3c24a9ac5c8f1e390798c793646c5d","name":"csilla.zkdesign","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/29f20b4a36c99526768bf0983dc1bc7bd60dd0b25ffbffe3d4631aa392d8d603?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/29f20b4a36c99526768bf0983dc1bc7bd60dd0b25ffbffe3d4631aa392d8d603?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/29f20b4a36c99526768bf0983dc1bc7bd60dd0b25ffbffe3d4631aa392d8d603?s=96&d=mm&r=g","caption":"csilla.zkdesign"}}]}},"_links":{"self":[{"href":"https:\/\/dmp.hu\/en\/wp-json\/wp\/v2\/posts\/2093","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dmp.hu\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dmp.hu\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dmp.hu\/en\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/dmp.hu\/en\/wp-json\/wp\/v2\/comments?post=2093"}],"version-history":[{"count":5,"href":"https:\/\/dmp.hu\/en\/wp-json\/wp\/v2\/posts\/2093\/revisions"}],"predecessor-version":[{"id":2107,"href":"https:\/\/dmp.hu\/en\/wp-json\/wp\/v2\/posts\/2093\/revisions\/2107"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dmp.hu\/en\/wp-json\/wp\/v2\/media\/2095"}],"wp:attachment":[{"href":"https:\/\/dmp.hu\/en\/wp-json\/wp\/v2\/media?parent=2093"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dmp.hu\/en\/wp-json\/wp\/v2\/categories?post=2093"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dmp.hu\/en\/wp-json\/wp\/v2\/tags?post=2093"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}