[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fYuJU6DRauEgg4mfAR1f-fNxwxlO270AabUJEqpN99DE":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"146df608-0623-4515-b2be-ff3a2f4477b4","hungarian-media-provider-fined-140k-for-publishing-sensitive-data-map-without-legal-basis","0cc63bc5-06c4-42c0-a13f-88cf01f75198","Hungarian Media Provider Fined €140K for Publishing Sensitive Data Map Without Legal Basis","A Hungarian media service provider was fined €140,590 for unlawfully processing personal data of nearly 200,000 individuals by publishing accessible links to a map containing sensitive information during a pre-election period. The company failed to establish proper legal basis under GDPR Articles 6(1) and 9(1), lacked legitimate interest for processing, and misclassified vulnerable individuals as public figures. This case demonstrates the critical importance of conducting thorough data protection impact assessments before publishing any content that could contain personal data, especially during sensitive periods like elections. Organizations must ensure they have clear legal grounds for processing personal data and cannot assume legitimate interest applies to all data processing activities.","**Immediate actions:**\n- Conduct emergency review of all published content containing potential personal data\n- Establish clear approval workflows requiring legal review before publishing sensitive data\n- Remove or restrict access to any content lacking proper GDPR legal basis\n\n**Long-term improvements:**\n- Implement mandatory Data Protection Impact Assessments (DPIAs) for all content involving personal data\n- Train editorial staff on GDPR requirements and data subject classification\n- Develop clear policies distinguishing between public figures and private individuals\n\n**Compliance measures:**\n- Establish regular compliance audits with data protection authorities\n- Create incident response procedures for potential data protection violations\n- Implement consent management systems for processing sensitive personal data",[12,13,14,15,16,17],"GDPR Article 6(1)","GDPR Article 9(1)","GDPR Article 35 (DPIA)","NIST Privacy Framework","CIS Control 3","ISO 27001 A.18.1.4","published","2026-05-29T10:20:24.702074+00:00","2026-05-29T10:20:24.516+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=NAIH_(Hungary)_-_NAIH\u002F962-10\u002F2026&diff=51767&oldid=51757","naih-hungary-naih-962-10-2026-c56fc3","NAIH (Hungary) - NAIH\u002F962-10\u002F2026",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":33,"name":34,"slug":35,"description":36,"color":37},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]