NAIH (Hungary) - NAIH-450-7-2026
Hungary's NAIH fines an online store operator €41,500 for GDPR transparency violations.
Summary
Hungary's National Authority for Data Protection and Freedom of Information (NAIH) has fined an online store operator HUF 15,000,000 (€41,500) for multiple GDPR violations. The investigation, initiated in April 2025, found the company guilty of violating the principle of transparency by providing conflicting, irrelevant, and incomplete information across various privacy documents. The NAIH also ordered the operator to amend its website's information system, including its terms and conditions and sweepstakes notices, to comply with GDPR.
Full text
Help NAIH (Hungary) - NAIH-450-7-2026: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editNewer edit →VisualWikitext Revision as of 08:15, 5 August 2026 view sourceFm (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators115 editsm Tag: Visual edit← Older edit Revision as of 08:37, 5 August 2026 view source Av (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators117 editsTag: Visual editNewer edit → Line 98: Line 98: === Facts ====== Facts === The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The period under review extended from January 2020 to November 2025. During this time, the company had multiple privacy notices in force, as well as other documents that contained relevant information on the processing of personal data.The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The period under review extended from January 2020 to November 2025. During this time, the company had multiple privacy notices in force, as well as other documents that contained relevant information on the processing of personal data. === Holding ====== Holding === The DPA found the controller guilty of multiple GDPR violations and issued it a fine of HUF 15,000,000 (€41,500). In addition, it ordered the controller to bring its processing operations in compliance with the GDPR by amending the information system used on its website, in particular the data processing provisions of the general terms and conditions and the data processing notices related to sweepstakes.The DPA found the controller guilty of multiple GDPR violations and issued it a fine of HUF 15,000,000 (€41,500). In addition, it ordered the controller to bring its processing operations in compliance with the GDPR by amending the information system used on its website, in particular the data processing provisions of the general terms and conditions and the data processing notices related to prize contests. First, the DPA held that the controller had violated the principle of transparency laid down in [[Article 5 GDPR|Article 5(1)(a) GDPR]]: several separate documents contained partially conflicting, irrelevant, and incomplete information regarding the processing of personal data. The information was not organised within a uniform, transparent system.First, the DPA held that the controller had violated the principle of transparency laid down in [[Article 5 GDPR|Article 5(1)(a) GDPR]]: several separate documents contained partially conflicting, irrelevant, and incomplete information regarding the processing of personal data. The information was not organised within a uniform, transparent system. Revision as of 08:37, 5 August 2026 NAIH - NAIH-450-7-2026 Authority: NAIH (Hungary) Jurisdiction: Hungary Relevant Law: Article 5(1)(a) GDPR Article 12(1) GDPR Article 13(1) GDPR Article 13(2) GDPR Type: Investigation Outcome: Violation Found Started: 09.04.2026 Decided: 12.05.2026 Published: 24.07.2026 Fine: 15000000.0 HUF Parties: n/a National Case Number/Name: NAIH-450-7-2026 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Hungarian Original Source: NAIH (in HU) Initial Contributor: av The DPA fined the operator of an online store HUF 15,000,000 (€41,500) for not providing its customers concise, transparent, and intelligible information on the purposes, legal basis, and duration of processing and data transfers to third countries. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The period under review extended from January 2020 to November 2025. During this time, the company had multiple privacy notices in force, as well as other documents that contained relevant information on the processing of personal data. Holding The DPA found the controller guilty of multiple GDPR violations and issued it a fine of HUF 15,000,000 (€41,500). In addition, it ordered the controller to bring its processing operations in compliance with the GDPR by amending the information system used on its website, in particular the data processing provisions of the general terms and conditions and the data processing notices related to prize contests. First, the DPA held that the controller had violated the principle of transparency laid down in Article 5(1)(a) GDPR: several separate documents contained partially conflicting, irrelevant, and incomplete information regarding the processing of personal data. The information was not organised within a uniform, transparent system. Second, the DPA determined that the controller had failed to provide concise, transparent, and intelligible information regarding the purposes and the legal basis for each processing activity and therefore infringed Article 12(1) GDPR. Finally, the DPA found infringements of Articles 13(1) and 13(2) GDPR – the controller had not provided the data subjects all information necessary when personal data is collected from data subjects. In particular, the controller had failed to adequately distinguish the purposes and the legal bases for each processing operation, recipients of personal data, and retention periods. The controller’s website also contained contradictory information on whether or not personal data was transferred to the United States. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Hungarian original. Please refer to the Hungarian original for more details. Case No.: NAIH-450-7/2026. Background: NAIH- 15402/2025. NAIH-9728/2025. Case Officer: Subject: Decision in an ex officio data protection authority proceeding DECISION The National Authority for Data Protection and Freedom of Information (hereinafter: the Authority), with respect to the websites […] (hereinafter: the Website) and […] (hereinafter: the Blog), regarding the data processing practices of the online store operating on the Website, including, in particular, the provision of prior information, concerning […] (registered office: […]; company registration number: […]; tax ID: […]; hereinafter: “Company”), as the operator of the online store operating on the Website, regarding the protection of natural persons with respect to the processing of personal data and the free movement of such data, and repealing Directive 95/46/EC, Regulation (EU) 2016/679 (EU) (hereinafter: General Data Protection Regulation or GDPR) regarding the processing of personal data of natural persons and repealing Directive 95/46/EC. 1. The Authority finds that the Company negligently violated - Article 5(1)(a) of the General Data Protection Regulation; - Article 12(1) of the General Data Protection Regulation; - Article 13(1)(a), (c) through (f) of the General Data Protection Regulation; and - Article 13(2)(a) through (f) of the General Data Protection Regulation. 2. In light of the identified violations, the Authority—pursuant to Article 58(2)(d) of the GDPR— hereby orders the Company ex officio to amend the information system used on the Website under review—including, in particular, the Website Notice, the data processing provisions of the General Terms and Conditions, the data processing notices related to sweepstakes, and the Blog Notice—in order to remedy the deficiencies identified in this decision, and to ensure that the information complies with the GDPR and is provided in a concise, transparent, understandable, and easily accessible form, using clear and plain l