Hungarian Online Store Fined for Outdated, Non-Transparent Privacy Notice
An online store in Hungary was fined €5,500 after NAIH found its privacy notice — unchanged since 2018 — failed to provide clear, complete, and intelligible information about how customer data was processed. The violations spanned cookies, registration, billing, and third-party data transfers, all of which lacked specified legal bases and data retention periods. This case highlights that privacy documentation is not a one-time exercise; it must be actively maintained to reflect current data practices and evolving regulatory standards. Failing to update privacy notices exposes organizations to regulatory penalties and erodes user trust. GDPR compliance requires ongoing governance, not just initial implementation.
Tactical Insight
Immediate actions
- Conduct a full audit of all current privacy notices, cookie banners, and consent mechanisms to identify outdated or incomplete disclosures.
- Update privacy documentation to explicitly state the legal basis for each processing activity, data retention periods, and details of any third-party data transfers.
Long-term improvements
- Establish a recurring privacy notice review cycle (at minimum annually) triggered by regulatory changes, new processing activities, or product updates.
- Assign a dedicated Data Protection Officer (DPO) or privacy owner responsible for maintaining documentation accuracy and regulatory alignment.
- Implement a privacy governance register to track all data processing activities, their legal bases, and associated documentation update history.
Detection & Monitoring measures
- Set automated calendar reminders or workflow triggers to flag privacy notices that have not been reviewed within a defined period (e.g., 12 months).
- Include privacy notice compliance checks as part of regular internal audits and third-party assessments.