[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f8nyjcsB9QfzS7K5aMz6VcVJJM5wa-JssLaQ0GO9rZZw":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":46},"a60a2ad0-47b9-4a01-a06d-d0cfbf943246","hungarian-online-store-fined-27300-for-missing-privacy-notice","622ff3a5-dc8c-4859-a9c1-e4978e742f5e","Hungarian Online Store Fined €27,300 for Missing Privacy Notice","A Hungarian online store operator was fined HUF 10,000,000 (~€27,300) by NAIH for failing to publish a compliant privacy notice on its website, violating GDPR's core transparency and accountability principles. The missing notice omitted critical information including processing purposes, legal bases, data retention periods, and recipient disclosures — all mandatory under GDPR Article 13\u002F14. This case highlights that GDPR compliance is not optional even for smaller operators, and that regulators are actively enforcing transparency requirements. Failure to provide clear privacy information erodes user trust and exposes organizations to significant financial and reputational harm.","**Immediate actions:**\n- Conduct a full audit of your website to ensure a compliant privacy notice is published and accessible from all data collection points.\n- Verify that your privacy notice explicitly covers processing purposes, legal bases, retention periods, and data recipients as required by GDPR Articles 13 and 14.\n\n**Long-term improvements:**\n- Establish a periodic (at least annual) GDPR compliance review process covering all customer-facing data collection mechanisms.\n- Assign a dedicated Data Protection Officer (DPO) or compliance owner responsible for maintaining up-to-date privacy documentation.\n- Integrate privacy notice requirements into the launch checklist for any new website, product, or service feature.\n\n**Training & awareness measures:**\n- Train marketing, legal, and development teams on GDPR transparency obligations so privacy notices are created correctly from the outset.\n- Subscribe to regulatory guidance updates from relevant DPAs to stay informed of evolving enforcement expectations.",[12,13,14,15,16,17,18,19],"GDPR Article 5(1)(a) – Principle of transparency","GDPR Article 5(2) – Accountability principle","GDPR Article 13 – Information to be provided where personal data are collected from the data subject","GDPR Article 14 – Information to be provided where personal data have not been obtained from the data subject","GDPR Article 24 – Responsibility of the controller","NIST Privacy Framework PR.PO-P1 – Policies, processes, and procedures for managing data","CIS Control 18 – Application Software Security","ISO\u002FIEC 27701:2019 – Privacy Information Management (PIMS)","published","2026-08-11T10:20:38.260357+00:00","2026-08-11T10:20:37.956+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=NAIH_(Hungary)_-_NAIH-4462-5-2026&diff=52657&oldid=0","naih-hungary-naih-4462-5-2026-064a54","NAIH (Hungary) - NAIH-4462-5-2026",[28,34,40],{"id":29,"name":30,"slug":31,"description":32,"color":33},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":35,"name":36,"slug":37,"description":38,"color":39},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":41,"name":42,"slug":43,"description":44,"color":45},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]