Back to all lessons
Awareness Lessons
2 months ago

Hungarian Retailer Fined €41,500 for Opaque GDPR Privacy Notices

An Hungarian online store accumulated GDPR violations over nearly six years by failing to clearly communicate to customers how their personal data was collected, processed, and retained. The company also provided conflicting information about transfers of personal data to third countries, compounding the transparency failures. This case illustrates that privacy compliance is not a one-time checkbox but requires ongoing governance, review, and accurate documentation. Regulators will look back across extended timeframes, meaning even legacy policy failures carry significant financial and reputational risk.

Tactical Insight

Immediate actions

  • Audit all customer-facing privacy notices to ensure data processing purposes, legal bases, and retention periods are stated clearly and consistently.
  • Resolve any contradictions regarding third-country data transfers by mapping data flows and updating notices to reflect accurate recipient countries and transfer mechanisms (e.g., SCCs, adequacy decisions).

Long-term improvements

  • Establish a Privacy Notice Review cycle (at least annually) tied to product and vendor change management processes.
  • Appoint or designate a Data Protection Officer (or privacy lead) responsible for maintaining and versioning all privacy documentation.
  • Implement a Data Mapping and Records of Processing Activities (RoPA) register to ensure notices always reflect actual data practices.

Detection & Monitoring measures

  • Schedule periodic internal privacy compliance audits that cross-check published privacy notices against live data processing activities.
  • Monitor regulatory guidance and NAIH/EDPB enforcement decisions to proactively identify gaps before formal investigations are triggered.