[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5cV-h__oO4l8JxcRVW9xwBz10rhYw2jpKs_sDZ_3GDQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"44cf3d50-5d22-4e6c-8192-10cd636211bb","hungarian-online-store-fined-41500-for-gdpr-transparency-failures-1785925295811","a09e901e-eabe-4958-88d7-e36f98b236d5","Hungarian Online Store Fined €41,500 for GDPR Transparency Failures","An online store operator in Hungary was fined HUF 15,000,000 (€41,500) after NAIH found its privacy documentation to be conflicting, irrelevant, and incomplete — a direct violation of GDPR's transparency principle under Article 5(1)(a) and Article 13\u002F14. The root cause was a failure to maintain consistent, accurate, and user-intelligible privacy information across all customer-facing documents, including terms and conditions and sweepstakes notices. This matters because transparency is a foundational GDPR principle: users must be able to clearly understand how their data is collected, used, and stored. Organisations that treat privacy notices as a one-time checkbox exercise rather than a living compliance obligation expose themselves to significant regulatory and reputational risk.","**Immediate actions:**\n- Conduct a full audit of all customer-facing privacy documents (privacy policy, T&Cs, cookie notices, sweepstakes notices) to identify and resolve conflicting or incomplete information.\n- Appoint a responsible owner (e.g., DPO or Legal Counsel) to review and sign off on all privacy-related content before publication.\n\n**Long-term improvements:**\n- Establish a document governance process that ensures privacy notices are reviewed and updated whenever data processing activities change.\n- Implement a centralised privacy information repository to prevent version conflicts across different website sections and campaigns.\n- Train marketing, legal, and product teams on GDPR transparency requirements so privacy obligations are considered at the design stage of any new initiative.\n\n**Detection & monitoring measures:**\n- Schedule periodic compliance reviews (at least annually) using a GDPR transparency checklist aligned to Articles 13 and 14 requirements.\n- Introduce a process to cross-check all promotional or campaign-specific notices (e.g., sweepstakes) against the master privacy policy before launch.",[12,13,14,15,16,17,18,19,20],"GDPR Article 5(1)(a) – Principle of Transparency","GDPR Article 12 – Transparent Information and Communication","GDPR Article 13 – Information to be Provided Where Personal Data Collected from Data Subject","GDPR Article 14 – Information Where Personal Data Not Obtained from Data Subject","NIST SP 800-53 PT-2 (Authority to Process Personally Identifiable Information)","NIST SP 800-53 PT-5 (Privacy Notice)","CIS Control 3 – Data Protection","ISO\u002FIEC 27701:2019 – Privacy Information Management (Section 7.3 – Obligations to PII Principals)","ITIL Service Design – Information Security and Compliance Management","published","2026-08-05T10:21:35.929153+00:00","2026-08-05T10:21:35.51+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=NAIH_(Hungary)_-_NAIH-450-7-2026&diff=52624&oldid=52621","naih-hungary-naih-450-7-2026-4d1ac1","NAIH (Hungary) - NAIH-450-7-2026",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":36,"name":37,"slug":38,"description":39,"color":40},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":42,"name":43,"slug":44,"description":45,"color":46},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]