Back to Feed
GDPRJul 24, 2026

CJEU - C‑769/22 - European Commission v Hungary

CJEU rules Hungary's law allowing broad access to sexual offender records violates GDPR Article 10.

Summary

The Court of Justice of the European Union (CJEU) found that Hungary's amended law on criminal records violated GDPR Article 10 by allowing overly broad access to information about individuals convicted of sexual offences against children. The law permitted any adult relative or guardian of a minor to request and share such sensitive data without sufficient safeguards, precision, or proportionality controls. The court concluded Hungary failed to meet GDPR requirements for processing criminal conviction data and breached the fundamental right to data protection under the EU Charter.

Full text

Help CJEU - C‑769/22 - European Commission v Hungary: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 09:50, 22 April 2026 view sourceAp (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators754 editsmTag: Visual edit← Older edit Latest revision as of 13:13, 24 July 2026 view source Ap (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators754 editsm Tag: Visual edit Line 17: Line 17: |GDPR_Article_Link_3=|GDPR_Article_Link_3= |EU_Law_Name_1=Art. 8(2) CFREU|EU_Law_Name_1=Art. 8(2) CFR |EU_Law_Link_1=https://www.europarl.europa.eu/charter/pdf/text_en.pdf|EU_Law_Link_1=https://www.europarl.europa.eu/charter/pdf/text_en.pdf |EU_Law_Name_2=|EU_Law_Name_2= Line 52: Line 52: In 2021 the Commission sent a formal letter to Hungary contesting the amending law's compliance with EU law. After some unproductive back-and-forth, the Commission escalated the case to the CJEU, requesting the CJEU to declare the amending law incompatible with EU law.In 2021 the Commission sent a formal letter to Hungary contesting the amending law's compliance with EU law. After some unproductive back-and-forth, the Commission escalated the case to the CJEU, requesting the CJEU to declare the amending law incompatible with EU law. The European Commission filed four pleas, claiming that Hungary violated of a long list of provisions from primary and secondary EU law<ref>The Commission alleged the violation of Articles 1, 7, 8(2), 11 and 21 CFREU; Article 2 TEU; Article 56 TFEU; Article 3(2) of the Directive on electronic commerce; Articles 16 and 19 of the Services Directive, Article 9(1)(c)(ii) of the AVMS Directive; and [[Article 10 GDPR]].</ref>. Only the Commission's fourth plea invokes data protection law- specifically, [https://www.europarl.europa.eu/charter/pdf/text_en.pdf Article 8(2) of the EU Charter of Fundamental Rights (CFREU)] ("Protection of personal data") and [[Article 10 GDPR]] ("Processing of personal data relating to criminal convictions and offences").The European Commission filed four pleas, claiming that Hungary violated of a long list of provisions from primary and secondary EU law<ref>The Commission alleged the violation of Articles 1, 7, 8(2), 11 and 21 CFREU; Article 2 TEU; Article 56 TFEU; Article 3(2) of the Directive on electronic commerce; Articles 16 and 19 of the Services Directive, Article 9(1)(c)(ii) of the AVMS Directive; and [[Article 10 GDPR]].</ref>. Only the Commission's fourth plea invokes data protection law- specifically, [https://www.europarl.europa.eu/charter/pdf/text_en.pdf Article 8(2) of the EU Charter of Fundamental Rights (CFR)] ("Protection of personal data") and [[Article 10 GDPR]] ("Processing of personal data relating to criminal convictions and offences"). '''The fourth plea: [[Article 10 GDPR]]''''''The fourth plea: [[Article 10 GDPR]]''' Line 58: Line 58: The alleged violation of the GDPR relates to the amended law's rules on access to information about individuals convicted of sexual offences against children. The law amended the ''"Law on the criminal record system"'' and made documents about sexual offences accessible to a broad audience. Under the new rules, any adult who is either a relative or a guardian of a minor ("authorised person"), has the right to access and share information about individuals convicted of sexual offences against children (the data subjects) from bodies with access to registered data.The alleged violation of the GDPR relates to the amended law's rules on access to information about individuals convicted of sexual offences against children. The law amended the ''"Law on the criminal record system"'' and made documents about sexual offences accessible to a broad audience. Under the new rules, any adult who is either a relative or a guardian of a minor ("authorised person"), has the right to access and share information about individuals convicted of sexual offences against children (the data subjects) from bodies with access to registered data. The Commission claimed that the amended law failed to specify with sufficient clarity who is authorised to submit a data request and, therefore, did not provide sufficient guarantees for the rights and freedoms of data subjects regarding the conditions of access to their personal data. On these grounds, the Commission claimed that the amended law infringed Article 10 of the GDPR (as well as [https://www.europarl.europa.eu/charter/pdf/text_en.pdf Art. 8(2) CFREU]).The Commission claimed that the amended law failed to specify with sufficient clarity who is authorised to submit a data request and, therefore, did not provide sufficient guarantees for the rights and freedoms of data subjects regarding the conditions of access to their personal data. On these grounds, the Commission claimed that the amended law infringed Article 10 of the GDPR (as well as [https://www.europarl.europa.eu/charter/pdf/text_en.pdf Art. 8(2) CFR]). In its defense, Hungary argued that the law accurately identified "authorised persons" when read in light of the definition of "relatives" in the Hungarian civil code. Additionally, Hungary claimed that there were two additional criteria access to personal data under Hungarian law: the authorised person must consider the relevant data to be probably necessary, and it must be disproportionately difficult for them to access the subjects' data if they are not disclosed.In its defense, Hungary argued that the law accurately identified "authorised persons" when read in light of the definition of "relatives" in the Hungarian civil code. Additionally, Hungary claimed that there were two additional criteria access to personal data under Hungarian law: the authorised person must consider the relevant data to be probably necessary, and it must be disproportionately difficult for them to access the subjects' data if they are not disclosed. Line 68: Line 68: * (iii) it was disproportionately difficult for the authorized person to access the data otherwise.* (iii) it was disproportionately difficult for the authorized person to access the data otherwise. Hungary claimed that these criteria were clearly defined and provided sufficient safeguards for data subjects. On this basis, Hungary argued that the amended law complied with [[Article 10 GDPR]] and [https://www.europarl.europa.eu/charter/pdf/text_en.pdf 8(2) CFREU].Hungary claimed that these criteria were clearly defined and provided sufficient safeguards for data subjects. On this basis, Hungary argued that the amended law complied with [[Article 10 GDPR]] and [https://www.europarl.europa.eu/charter/pdf/text_en.pdf 8(2) CFR]. === Advocate General Opinion ====== Advocate General Opinion === Line 81: Line 81: Second, the AG considered that requirements (ii) and (iii) (''i.e.'': the probable necessity of the disclosure, and the difficulty of otherwise accessing the data) were overly generic and were to be assessed by the authorized person themselves. The AG argued that such a self-declaratoty regime lent itself to abuse and deprived the disclosing body of any control over the necessity and proportionality of the disclosure. For this reason, the AG opined that the amending law failed to provide the required safeguards for data subjects.Second, the AG considered that requirements (ii) and (iii) (''i.e.'': the probable necessity of the disclosure, and the difficulty of otherwise accessing the data) were overly generic and were to be assessed by the authorized person themselves. The AG argued that such a self-declaratoty regime lent itself to abuse and deprived the disclosing body of any control over the necessity and proportionality of the disclosure. For this reason, the AG opined that the amending law failed to provide the required safeguards for data subjects. On these grounds, the AG opined that the amended law was disproportionate and violated [[Article 10 GDPR]] as we

Entities

European Commission (vendor)Court of Justice of the European Union (CJEU) (vendor)