Back to Feed
PolicyAug 5, 2026

NAIH (Hungary) - NAIH-450-7-2026

Hungary's NAIH fines an online store operator HUF 15M for GDPR transparency violations.

Summary

Hungary's National Data Protection Authority (NAIH) has fined an online store operator HUF 15,000,000 (€41,500) for multiple GDPR violations. The investigation, spanning from January 2020 to November 2025, found the company guilty of failing to provide clear, transparent, and intelligible information to customers regarding data processing purposes, legal bases, and retention periods. The authority also cited conflicting information on data transfers to third countries.

Full text

Help NAIH (Hungary) - NAIH-450-7-2026: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 08:37, 5 August 2026 view sourceAv (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators117 editsTag: Visual edit← Older edit Latest revision as of 08:43, 5 August 2026 view source Fm (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators115 editsm Tag: Visual edit Line 12: Line 12: |Original_Source_Name_1=NAIH|Original_Source_Name_1=NAIH |Original_Source_Link_1=https://naih.hu/hatarozatok-vegzesek|Original_Source_Link_1=https://naih.hu/hatarozatok-vegzesek?download=1559:tajekoztatasi-hianyossagok-webaruhaz-adatkezelese-soran |Original_Source_Language_1=Hungarian|Original_Source_Language_1=Hungarian |Original_Source_Language__Code_1=HU|Original_Source_Language__Code_1=HU Latest revision as of 08:43, 5 August 2026 NAIH - NAIH-450-7-2026 Authority: NAIH (Hungary) Jurisdiction: Hungary Relevant Law: Article 5(1)(a) GDPR Article 12(1) GDPR Article 13(1) GDPR Article 13(2) GDPR Type: Investigation Outcome: Violation Found Started: 09.04.2026 Decided: 12.05.2026 Published: 24.07.2026 Fine: 15000000.0 HUF Parties: n/a National Case Number/Name: NAIH-450-7-2026 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Hungarian Original Source: NAIH (in HU) Initial Contributor: av The DPA fined the operator of an online store HUF 15,000,000 (€41,500) for not providing its customers concise, transparent, and intelligible information on the purposes, legal basis, and duration of processing and data transfers to third countries. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The period under review extended from January 2020 to November 2025. During this time, the company had multiple privacy notices in force, as well as other documents that contained relevant information on the processing of personal data. Holding The DPA found the controller guilty of multiple GDPR violations and issued it a fine of HUF 15,000,000 (€41,500). In addition, it ordered the controller to bring its processing operations in compliance with the GDPR by amending the information system used on its website, in particular the data processing provisions of the general terms and conditions and the data processing notices related to prize contests. First, the DPA held that the controller had violated the principle of transparency laid down in Article 5(1)(a) GDPR: several separate documents contained partially conflicting, irrelevant, and incomplete information regarding the processing of personal data. The information was not organised within a uniform, transparent system. Second, the DPA determined that the controller had failed to provide concise, transparent, and intelligible information regarding the purposes and the legal basis for each processing activity and therefore infringed Article 12(1) GDPR. Finally, the DPA found infringements of Articles 13(1) and 13(2) GDPR – the controller had not provided the data subjects all information necessary when personal data is collected from data subjects. In particular, the controller had failed to adequately distinguish the purposes and the legal bases for each processing operation, recipients of personal data, and retention periods. The controller’s website also contained contradictory information on whether or not personal data was transferred to the United States. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Hungarian original. Please refer to the Hungarian original for more details. Case No.: NAIH-450-7/2026. Background: NAIH- 15402/2025. NAIH-9728/2025. Case Officer: Subject: Decision in an ex officio data protection authority proceeding DECISION The National Authority for Data Protection and Freedom of Information (hereinafter: the Authority), with respect to the websites […] (hereinafter: the Website) and […] (hereinafter: the Blog), regarding the data processing practices of the online store operating on the Website, including, in particular, the provision of prior information, concerning […] (registered office: […]; company registration number: […]; tax ID: […]; hereinafter: “Company”), as the operator of the online store operating on the Website, regarding the protection of natural persons with respect to the processing of personal data and the free movement of such data, and repealing Directive 95/46/EC, Regulation (EU) 2016/679 (EU) (hereinafter: General Data Protection Regulation or GDPR) regarding the processing of personal data of natural persons and repealing Directive 95/46/EC. 1. The Authority finds that the Company negligently violated - Article 5(1)(a) of the General Data Protection Regulation; - Article 12(1) of the General Data Protection Regulation; - Article 13(1)(a), (c) through (f) of the General Data Protection Regulation; and - Article 13(2)(a) through (f) of the General Data Protection Regulation. 2. In light of the identified violations, the Authority—pursuant to Article 58(2)(d) of the GDPR— hereby orders the Company ex officio to amend the information system used on the Website under review—including, in particular, the Website Notice, the data processing provisions of the General Terms and Conditions, the data processing notices related to sweepstakes, and the Blog Notice—in order to remedy the deficiencies identified in this decision, and to ensure that the information complies with the GDPR and is provided in a concise, transparent, understandable, and easily accessible form, using clear and plain language, and aligned with the actual data processing operations; in this context, the Company is required to eliminate parallel, conflicting, or mutually incompatible information solutions, clearly define the relationship between individual documents, and remove outdated references to legislation and terminology not based on the GDPR framework; present information regarding data subjects’ rights and remedies accurately and in an easily understandable manner in accordance with the structure set forth in the Regulation; furthermore, clearly define for each data processing activity the categories of data processed, the purposes, the legal bases, recipients or categories of recipients, and retention periods—including data processing related to cookies—and to clarify the roles and responsibilities of data controllers in accordance with actual operations. The Company is required to provide evidence of compliance by submitting the amended privacy notice to the Authority in such a way that the changes are clearly identifiable. ........................................................................................................................................................................................................................................................................ 1055 Budapest Tel.: +36 1 391-1400 naih.hu/data-protection-notice 9-11 Falk Miksa Street KR ID: 429616918 ugyfelszolgalat@naih.hu 2 3. Due to the violations established in Section 1, the Authority has imposed a data protection fine of 15,000,000 Ft, that is, fifteen million forints . * * * The Company must provide written confirmation to the Authority, together with supporting evidence, that it has taken the measures prescribed in Section 2 within 30 days of this decision becoming final. The data protection fine must be paid within 30 days of this decision becoming final to the Authority’s forint account for the collection of centralized revenues (10032000-01040425- 00000000 Centralized Collection Acc

Entities

NAIH (vendor)