Back to Feed
PolicyAug 11, 2026

NAIH (Hungary) - NAIH-4462-5-2026

Hungary's NAIH fines online store operator HUF 10M for missing privacy notice.

Summary

Hungary's National Data Protection Authority (NAIH) has fined an online store operator HUF 10,000,000 (approximately €27,300) for failing to provide a privacy notice on its website. The DPA found violations of GDPR principles, including accountability and the requirement to provide clear information on data processing purposes, legal bases, storage periods, and recipients. The lack of a comprehensive privacy notice meant data subjects were not adequately informed about how their personal data was being handled.

Full text

Help NAIH (Hungary) - NAIH-4462-5-2026: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 10:02, 11 August 2026 view sourceAv (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators126 editsTag: Visual edit← Older edit Latest revision as of 17:50, 11 August 2026 view source Fm (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators118 editsm Tag: Visual edit Line 109: Line 109: Second, the DPA held that the controller had violated the principle of accountability set forth in [[Article 5 GDPR|Article 5(2) GDPR]], as it had failed to submit appropriate documentation covering the period under review. In addition, the controller’s data processing practices could not be continuously monitored or subsequently verified based on the documentation it had provided. Second, the DPA held that the controller had violated the principle of accountability set forth in [[Article 5 GDPR|Article 5(2) GDPR]], as it had failed to submit appropriate documentation covering the period under review. In addition, the controller’s data processing practices could not be continuously monitored or subsequently verified based on the documentation it had provided. Finally, the DPA confirmed that the controller had not complied with the requirements laid down in [[Article 12 GDPR|Articles 12(1),]] [[Article 13 GDPR|13(1)(a), (c) and (e)]], and [[Article 13 GDPR|13(2)(a)–(e) GDPR]]. Due to the lack of a privacy notice, the controller could not demonstrate that it had provided data subject with the information required under [[Article 13 GDPR]] apart from brief, general statements in the archived privacy notice and the general terms and conditions. The controller had thus failed to provide the data subjects clear and differentiated information regarding the purpose and legal basis for each processing operation. Furthermore, the controller had not adequately identified the recipients or the storage period of personal data or information on the data subjects' rights. Due to the form and scope of the information provided, the controller had also infringed [[Article 12 GDPR|Article 12(1) GDPR]]. Finally, the DPA confirmed that the controller had not complied with the requirements laid down in [[Article 12 GDPR|Articles 12(1),]] [[Article 13 GDPR|13(1)(a), (c) and (e)]], and [[Article 13 GDPR|13(2)(a)–(e) GDPR]]. Due to the lack of a privacy notice, the controller could not demonstrate that it had provided data subjects with the information required under [[Article 13 GDPR]] apart from brief, general statements in the archived privacy notice and the general terms and conditions. The controller had thus failed to provide the data subjects clear and differentiated information regarding the purpose and legal basis for each processing operation. Furthermore, the controller had not adequately identified the recipients or the storage period of personal data or information on the data subjects' rights. Due to the form and scope of the information provided, the controller had also infringed [[Article 12 GDPR|Article 12(1) GDPR]]. == Comment ==== Comment == Latest revision as of 17:50, 11 August 2026 NAIH - NAIH-4462-5-2026 Authority: NAIH (Hungary) Jurisdiction: Hungary Relevant Law: Article 5(1)(a) GDPR Article 5(2) GDPR Article 12(1) GDPR Article 13(1) GDPR Type: Investigation Outcome: n/a Started: 09.04.2025 Decided: 30.04.2026 Published: 24.07.2026 Fine: 10000000.0 HUF Parties: n/a National Case Number/Name: NAIH-4462-5-2026 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Hungarian Original Source: NAIH (in HU) Initial Contributor: av The DPA fined an online store operator HUF 10,000,000 (€27,300) as there was no privacy notice available on the store’s website. In particular, information on the purposes and the legal bases of processing, the storage periods, and the recipients of personal data was missing. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The DPA initiated an investigation into the processing of the personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The controller’s main business activity was the wholesale distribution of beverages. The personal data of the data subjects was processed on the website of the online store for registration, placing orders, billing, communication, delivery, creation of user accounts, and newsletter subscription. During the period under review, i.e. between January 2020 and October 2025, no standalone privacy notice was available on the website. The previously archived privacy notice and the data processing section included in the general terms and conditions described the processing operations in a rather brief and general manner. The controller argued that the inaccessibility of the privacy notice followed from a technical error that was corrected upon discovery. Holding The DPA found that the controller had violated Articles 5(1)(a), 5(2), 12(1), 13(1)(a), (c), and (e) as well as 13(2)(a)–(e) GDPR and issued it a fine of HUF 10,000,000 (€27,300). When issuing the fine, the DPA took into account that the identified infringements followed from systemic inadequacies of the privacy notice and were of continuous nature. In addition, the DPA ordered the controller to develop and publish a uniformly structured privacy notice that is aligned with its actual processing operations. First, the DPA identified a violation of the principle of transparency laid down in Article 5(1)(a) GDPR: the information provided to data subjects about the processing of their personal data was either incomplete or completely absent, and changes could not be tracked. Second, the DPA held that the controller had violated the principle of accountability set forth in Article 5(2) GDPR, as it had failed to submit appropriate documentation covering the period under review. In addition, the controller’s data processing practices could not be continuously monitored or subsequently verified based on the documentation it had provided. Finally, the DPA confirmed that the controller had not complied with the requirements laid down in Articles 12(1), 13(1)(a), (c) and (e), and 13(2)(a)–(e) GDPR. Due to the lack of a privacy notice, the controller could not demonstrate that it had provided data subjects with the information required under Article 13 GDPR apart from brief, general statements in the archived privacy notice and the general terms and conditions. The controller had thus failed to provide the data subjects clear and differentiated information regarding the purpose and legal basis for each processing operation. Furthermore, the controller had not adequately identified the recipients or the storage period of personal data or information on the data subjects' rights. Due to the form and scope of the information provided, the controller had also infringed Article 12(1) GDPR. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Hungarian original. Please refer to the Hungarian original for more details. Case No.: NAIH-4462-4/2026. Subject: Decision in an ex officio data protection Background: NAIH-15138/2025 administrative proceeding NAIH-9722/2025. Case Officer: DECISION The National Authority for Data Protection and Freedom of Information (hereinafter: the Authority), with respect to the […] website (hereinafter: the Website), regarding the data processing practices of the online store operating on the Website , specifically regarding prior notification, against […] hereinafter: the Company, as the operator of the online store operating on the Website, pursuant to the Regulation on the protection of natural persons with regard to the proces

Entities

NAIH (vendor)