Back to Feed
PolicyAug 11, 2026

NAIH (Hungary) - NAIH-4462-5-2026

Hungary's NAIH fines an online store operator HUF 10M for missing privacy notice.

Summary

Hungary's National Authority for Data Protection and Freedom of Information (NAIH) has fined an online store operator HUF 10,000,000 (approximately €27,300) for failing to provide a privacy notice on its website. The investigation revealed missing information regarding processing purposes, legal bases, storage periods, and data recipients. The DPA cited violations of GDPR's transparency and accountability principles, ordering the operator to publish a compliant privacy notice.

Full text

Help NAIH (Hungary) - NAIH-4462-5-2026: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 09:59, 11 August 2026 view source Av (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators126 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 09:59, 11 August 2026 NAIH - NAIH-4462-5-2026 Authority: NAIH (Hungary) Jurisdiction: Hungary Relevant Law: Article 5(1)(a) GDPR Article 5(2) GDPR Article 12(1) GDPR Article 13(1) GDPR Type: Investigation Outcome: n/a Started: 09.04.2025 Decided: 30.04.2026 Published: 24.07.2026 Fine: 10000000.0 HUF Parties: n/a National Case Number/Name: NAIH-4462-5-2026 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Hungarian Original Source: NAIH (in HU) Initial Contributor: av The DPA fined an online store operator HUF 10,000,000 (€27,300) as there was no privacy notice available on the store’s website. In particular, information on the purposes and the legal bases of processing, the storage periods, and the recipients of personal data was missing. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The DPA initiated an investigation into the processing of the personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The controller’s main business activity was the wholesale distribution of beverages. The personal data of the data subjects was processed on the website of the online store for registration, placing orders, billing, communication, delivery, creation of user accounts, and newsletter subscription. During the period under review, i.e. between January 2020 and October 2025, no standalone privacy notice was available on the website. The previously archived privacy notice and the data processing section included in the general terms and conditions described the processing operations in a rather brief and general manner. The controller argued that the inaccessibility of the privacy notice followed from a technical error that was corrected upon discovery. Holding The DPA found that the controller had violated Articles 5(1)(a), 5(2), 12(1), 13(1)(a), (c), and (e) as well as 13(2)(a)–(e) GDPR and issued it a fine of HUF 10,000,000 (€27,300). When issuing the fine, the DPA took into account that the identified infringements followed from systemic inadequacies of the privacy notice and were of continuous nature. In addition, the DPA ordered the controller to develop and publish a uniformly structured privacy notice that is aligned with its actual processing operations. First, the DPA identified a violation of the principle of transparency laid down in Article 5(1)(a) GDPR: the information provided to data subjects about the processing of their personal data was either incomplete or completely absent, and changes could not be tracked. Second, the DPA held that the controller had violated the principle of accountability set forth in Article 5(2) GDPR, as it had failed to submit appropriate documentation covering the period under review. In addition, the controller’s data processing practices could not be continuously monitored or subsequently verified based on the documentation it had provided. Finally, the DPA confirmed that the controller had not complied with the requirements laid down in Articles 12(1), 13(1)(a), (c) and (e), and 13(2)(a)–(e) GDPR. Due to the lack of a privacy notice, the controller could not demonstrate that it had provided data subject with the information required under Article 13 GDPR apart from brief, general statements in the archived privacy notice and the general terms and conditions. The controller had thus failed to provide the data subjects clear and differentiated information regarding the purpose and legal basis for each processing operation. Furthermore, the controller had not adequately identified the recipients or the storage period of personal data or information on the data subjects' rights. Due to the form and scope of the information provided, the controller had also infringed Article 12(1) GDPR. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Hungarian original. Please refer to the Hungarian original for more details. Case No.: NAIH-4462-4/2026. Subject: Decision in an ex officio data protection Background: NAIH-15138/2025 administrative proceeding NAIH-9722/2025. Case Officer: DECISION The National Authority for Data Protection and Freedom of Information (hereinafter: the Authority), with respect to the […] website (hereinafter: the Website), regarding the data processing practices of the online store operating on the Website , specifically regarding prior notification, against […] hereinafter: the Company, as the operator of the online store operating on the Website, pursuant to the Regulation on the protection of natural persons with regard to the processing of personal data and the free movement of such data, and repealing Directive 95/46/EC Regulation (EU) 2016/679 (hereinafter: General Data Protection Regulation or GDPR), the Authority hereby issues the following decisions. 1. The Authority finds that the Company negligently violated - Article 5(1)(a) of the General Data Protection Regulation; - Article 5(2) of the General Data Protection Regulation; - Article 12(1) of the General Data Protection Regulation; - Article 13(1)(a), (c), and (e) of the General Data Protection Regulation; and - Article 13(2)(a) through (e) of the General Data Protection Regulation. 2. In light of the identified violations—pursuant to Article 58(2)(d) of the GDPR —the Authority hereby orders the Company, ex officio, to amend the data processing notice practices on the Website under review to remedy the deficiencies identified in paragraphs (76) through (112) of this decision, and to ensure that is actually made available to data subjects. The Company is required to develop a uniformly structured privacy notice aligned with its actual data processing operations and to publish it on the Website, which is easily accessible to data subjects, transparent, understandable, and clearly worded, and which, for each data processing activity, specifies in particular the purpose and legal basis of the data processing, the data being processed, the recipients or categories of recipients, the duration of the data processing or the criteria for determining it, as well as information regarding the data subjects’ rights and how to exercise them . The Company is also required to ensure that the privacy notice is continuously available on the Website and that its availability is not interrupted for technical reasons; and is also required to document the individual versions of the notice, their effective dates, and the dates of their publication in such a way that compliance with the GDPR can be verified at a later date. The Company is required to demonstrate compliance by submitting the amended privacy notice to the Authority in such a way that the amendments are clearly identifiable. 3. Due to the violations set forth in paragraph 1, ........................................................................................................................................................................................................................................................................ 1055 Budapest Tel.: +36 1 391-1400 naih.hu/adatkezelesi-tajekoztatok 9–11 Falk Miksa Street KR ID: 429616918 ugyfelszolgalat@naih.hu 2 10,000,000 HUF, that is, ten million forints data protection fine . * * * The Company must take the measures prescribed in Section 2 within , together with supporting evidence, to the Authority. The data protection fine must be paid within 30 days of this decision becoming final to th

Entities

NAIH (vendor)