[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fMmf3_WF2s8W17XYQZ9-JNxI_ocgiy-ppf7qtSrBGvs8":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":40},"e88a000b-88ac-4312-acea-586aeaffb105","hungarian-online-store-fined-for-outdated-non-transparent-privacy-notice","e31b67be-6a53-4899-8591-adeaecfccb06","Hungarian Online Store Fined for Outdated, Non-Transparent Privacy Notice","An online store in Hungary was fined €5,500 after NAIH found its privacy notice — unchanged since 2018 — failed to provide clear, complete, and intelligible information about how customer data was processed. The violations spanned cookies, registration, billing, and third-party data transfers, all of which lacked specified legal bases and data retention periods. This case highlights that privacy documentation is not a one-time exercise; it must be actively maintained to reflect current data practices and evolving regulatory standards. Failing to update privacy notices exposes organizations to regulatory penalties and erodes user trust. GDPR compliance requires ongoing governance, not just initial implementation.","**Immediate actions:**\n- Conduct a full audit of all current privacy notices, cookie banners, and consent mechanisms to identify outdated or incomplete disclosures.\n- Update privacy documentation to explicitly state the legal basis for each processing activity, data retention periods, and details of any third-party data transfers.\n\n**Long-term improvements:**\n- Establish a recurring privacy notice review cycle (at minimum annually) triggered by regulatory changes, new processing activities, or product updates.\n- Assign a dedicated Data Protection Officer (DPO) or privacy owner responsible for maintaining documentation accuracy and regulatory alignment.\n- Implement a privacy governance register to track all data processing activities, their legal bases, and associated documentation update history.\n\n**Detection & Monitoring measures:**\n- Set automated calendar reminders or workflow triggers to flag privacy notices that have not been reviewed within a defined period (e.g., 12 months).\n- Include privacy notice compliance checks as part of regular internal audits and third-party assessments.",[12,13,14,15,16,17,18,19],"GDPR Article 13 – Information to be provided where personal data are collected from the data subject","GDPR Article 14 – Information to be provided where personal data have not been obtained from the data subject","GDPR Article 5(1)(a) – Principle of transparency","GDPR Article 12 – Transparent information, communication and modalities","NIST Privacy Framework PR.PO-P1 – Policies, processes, and procedures for managing data","CIS Control 3 – Data Protection","ISO\u002FIEC 27701 Section 7.3 – Privacy notice","ITIL – Continual Service Improvement (applied to privacy policy lifecycle management)","published","2026-07-23T14:20:20.442778+00:00","2026-07-23T14:20:20.129+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=NAIH_(Hungary)_-_NAIH-11443-3\u002F2026&diff=52457&oldid=0","naih-hungary-naih-11443-3-2026-31d25e","NAIH (Hungary) - NAIH-11443-3\u002F2026",[28,34],{"id":29,"name":30,"slug":31,"description":32,"color":33},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":35,"name":36,"slug":37,"description":38,"color":39},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]