Hungarian Online Store Fined €41,500 for GDPR Transparency Failures
An online store operator in Hungary was fined HUF 15,000,000 (€41,500) after NAIH found its privacy documentation to be conflicting, irrelevant, and incomplete — a direct violation of GDPR's transparency principle under Article 5(1)(a) and Article 13/14. The root cause was a failure to maintain consistent, accurate, and user-intelligible privacy information across all customer-facing documents, including terms and conditions and sweepstakes notices. This matters because transparency is a foundational GDPR principle: users must be able to clearly understand how their data is collected, used, and stored. Organisations that treat privacy notices as a one-time checkbox exercise rather than a living compliance obligation expose themselves to significant regulatory and reputational risk.
Tactical Insight
Immediate actions
- Conduct a full audit of all customer-facing privacy documents (privacy policy, T&Cs, cookie notices, sweepstakes notices) to identify and resolve conflicting or incomplete information.
- Appoint a responsible owner (e.g., DPO or Legal Counsel) to review and sign off on all privacy-related content before publication.
Long-term improvements
- Establish a document governance process that ensures privacy notices are reviewed and updated whenever data processing activities change.
- Implement a centralised privacy information repository to prevent version conflicts across different website sections and campaigns.
- Train marketing, legal, and product teams on GDPR transparency requirements so privacy obligations are considered at the design stage of any new initiative.
Detection & monitoring measures
- Schedule periodic compliance reviews (at least annually) using a GDPR transparency checklist aligned to Articles 13 and 14 requirements.
- Introduce a process to cross-check all promotional or campaign-specific notices (e.g., sweepstakes) against the master privacy policy before launch.