NAIH (Hungary) - NAIH-359-10/2026
| NAIH - NAIH-359-10/2026 | |
|---|---|
| Authority: | NAIH (Hungary) |
| Jurisdiction: | Hungary |
| Relevant Law: | Article 6(1) GDPR Article 9(1) GDPR Article 12(4) GDPR Article 17 GDPR |
| Type: | Complaint |
| Outcome: | Upheld |
| Started: | 02.12.2024 |
| Decided: | 29.05.2026 |
| Published: | |
| Fine: | 25,000,000 HUF |
| Parties: | Blikk Kft. |
| National Case Number/Name: | NAIH-359-10/2026 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | Hungarian |
| Original Source: | NAIH (in HU) |
| Initial Contributor: | ap |
The DPA fined a news website HUF 25,000,000 (approximately €70,590) for unlawfully publishing the personal data of a data subject in articles related to court proceedings they were involved in.
English Summary
Facts
Blikk Kft. (the controller) is a company that operates a news website. In 2024, a data subject filed a complaint with the DPA. According to the data subject, the controller published two articles that contained a significant amount of their personal data without their consent. The articles included a blurred picture of the data subject, as well as their name (former and current, but initials for their last name), former place of employment, information related to the data subject’s gender reaffirming surgery, and information related to court proceedings they were involved in. Before filing the complaint to the DPA, the data subject also requested the controller to remove their picture and full name from the articles. However, the data subject did not receive a response.
The controller argued that publishing the article was a matter of public interest in connection to investigative journalism. The controller claimed that the data in the article did not allow third parties to identify the data subject, and therefore it was not processing personal data when publishing the articles. The controller also claimed to have deleted the articles at the request of the DPA. Finally, the controller stated that the lack of response to the data subject’s request for erasure was due to an administrative error.
The DPA investigated the lawfulness of the processing from the data subject’s complaint, and did an ex-officio investigation on the data subject’s erasure request.
Holding
The DPA first clarified that the controller processed personal data. The DPA stated that the definition of personal data is broad, and that the combined information made the data subject easily identifiable to third parties. The DPA also clarified that while a person’s gender alone is not sensitive personal data, data relating to the data subject’s gender identity and medical procedures fall in the scope of sensitive personal data under Article 9 GDPR. Finally, the DPA stated that the use of initials could not be considered a security measure to prevent unlawful processing of personal data.
The DPA found a violation of Articles 6(1) and 9(1) GDPR. The DPA considered that the controller processed the data subject’s personal data unlawfully, as it could have covered the court proceedings without disclosing the data subject’s data. According to the DPA, the press generally relies on legitimate interest (Article 6(1)(f) GDPR) when processing personal data. However, the controller argued that it did not process personal data. Therefore, it did not assess whether less intrusive means were available, and did not conduct a balancing test for the rights and interests involved. The DPA concluded that the controller did not have a legal basis under Article 6(1)(f) GDPR. The DPA did not consider it necessary to assess whether the exceptions under Article 9(2) GDPR apply, as the controller did not have a legal basis to process the data in any case. Finally, the DPA noted that the controller had acted in bad faith by including this information, by reporting the data subject’s explicit objection to having their name and picture included in the articles.
The DPA also found a violation of Article 12(4) GDPR, as the controller did not take any measures in response to the data subject’s erasure request.
The DPA fined the controller HUF 25,000,000 (approximately €70,590). The DPA considered the harm done to the data subject and the fact that sensitive personal data was processed as aggravating factors. The DPA also took into consideration the fact that the controller later voluntarily deleted the articles entirely.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Hungarian original. Please refer to the Hungarian original for more details.
…………………………………………………………………………………………………... 1055 Budapest Tel.: +36 1 391-1400 naih.hu/adatkezelesi-tajekoztatok Falk Miksa utca 9-11. KR ID: 429616918 ugyfelszolgalat@naih.hu Case number: NAIH-359-10/2026 NAIH-7459/2025 NAIH-14033/2024 Subject: decision granting the request D E R U S I O N The National Data Protection and Freedom of Information Authority (hereinafter referred to as the Authority) has, at the request of […] (hereinafter referred to as the Applicant) represented by the Háttér Company Association (registered office: 1136 Budapest, Balzac u. 8-10. fszt. 1.), Blikk Kft. (1122 Budapest, Városmajor utca 11. cjsz: 01- 09-187043 24873862#cégkapu, tax number: 24873862-2-43; hereinafter referred to as: The Applicant) and its legal successor, IndaNext Hungary Limited Liability Company (1122 Budapest, Városmajor utca 11.; cjsz: 01-09-061743, tax number: 10237580-2-43, hereinafter referred to as the “Obligation”), in the data protection authority proceedings initiated regarding the publication and deletion of personal data about the Applicant in articles published on the website www.blikk.hu, makes the following decisions: I. The Authority grants the Applicant’s request and condemns the Applicant, because the Applicant’s personal and sensitive personal data were published in articles published on the Applicant’s website (article titled “[…]” published on […] and article titled “[…]” published on […]) without legal basis. By doing so, the Respondent intentionally infringed Article 6(1)(f) and Article 9(1) of Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as the General Data Protection Regulation). II. The Authority ex officio condemns the Respondent for infringing Article 12(4) of the General Data Protection Regulation by failing to notify the Applicant of the reason for not fulfilling the data subject's request for erasure. III. Due to the infringement established in points I and II, the Authority ex officio orders the Respondent to pay a data protection fine of HUF 25,000,000, i.e. twenty-five million forints. IV. The Authority, pursuant to Section 61 (2) c) of Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information (hereinafter referred to as the Information Act), ex officio orders the publication of its final decision by publishing the identification data of the Applicant and the Obligor on the Authority’s website. The fine must be paid within 30 days of the date on which this decision becomes final to the Authority’s centralized revenue collection account (10032000-01040425- 00000000 Centralized collection account IBAN: HU83 1003 2000 0104 0425 0000 0000). When transferring the amount, the reference number “NAIH-359/2026 FINE.” number should be referred to. 2 If the Obligor fails to comply with his obligation to pay the fine within the deadline, he shall be obliged to pay a late payment surcharge. The rate of the late payment surcharge is the statutory interest, which is the same as the central bank base interest rate valid on the first day of the calendar half-year affected by the delay. In the event of non-payment of the fine and the late payment surcharge, the Authority shall order the enforcement of the decision. There is no right of administrative appeal against this decision, but it may be challenged in an administrative lawsuit by means of a statement of claim addressed to the Metropolitan Court within 30 days of its notification. The statement of claim shall be submitted to the Authority, electronically1, which shall forward it to the court together with the case documents. The request for a hearing shall be indicated in the statement of claim. For those who do not benefit from the full personal fee exemption, the administrative lawsuit fee is HUF 30,000, and the lawsuit is subject to the right to record the subject fee. Legal representation is mandatory in the procedure before the Metropolitan Court. R E A T I O N I N G I. Procedure: (1) On December 2, 2024, the Applicant submitted an application to the Authority regarding the unlawful disclosure of his personal data (NAIH-14033-1/2024), and supplemented his application on December 19, 2024 (NAIH-14033-2/2024). (2) On February 19, 2025, the Authority called on the Applicant to remedy the deficiencies (NAIH-7459- 1/2025). The Applicant’s response was received on 26 February 2025 (NAIH-7459-2/2025). (3) On 12 March 2025, the Authority made a website backup of the articles affected by the request (NAIH-7459-3/2025). (4) On 13 March 2025, the Authority called on the Applicant to make a statement (NAIH- 7459-4/2025), the Applicant made the statement in its response received on 27 March 2025 (NAIH-7459-5/2025). (5) On 15 April 2025, the Authority again backed up the content of the websites affected by the request (NAIH-7459-6/2025). (6) The Authority also called on the Applicant to make a statement on 16 April 2025 (NAIH-7459- 7/2025), who responded in his letter received on 30 April 2025 (NAIH-7459-8/2025). (7) The Authority notified the parties of the completion of the evidentiary procedure and of their rights to inspect documents and make statements. (NAIH7459-9/2025, NAIH-7459-10/2025). (8) On 12 December 2025, the Applicant’s legal representative submitted a request for inspection of documents (NAIH-7459-112025), which the Authority granted in its order no. NAIH-359-2/2026. (9) The Applicant submitted a request for access to the documents in the document filed under number NAIH-359-1/2026, which the Authority granted in its order No. NAIH-359-3/2026. (10) The Applicant, having knowledge of the documents of the procedure, made a statement in the document filed under number NAIH-359-4/2026, and the Respondent's statement was filed under number NAIH-359-5/2026. (11) The Authority called on the Respondent's representative to prove his authority to represent the Obligor under number NAIH-359-6/2026, who sent the power of attorney under number NAIH-359-7/2026. (12) In its order NAIH-359-8/2026, the Authority determined that the Obligor shall succeed the Applicant in the proceedings. (13) In its note NAIH-359-9/2026, the Authority included in the case file the company information data of Blikk Kft. and IndaNext Kft. effective on 9 February 2026. 1 The form NAIH_K01 is used to initiate the administrative proceedings: NAIH_K01 form (2019.09.16) The form can be completed using the general form filling program (ÁNYK program). https://www.naih.hu/kozig-hatarozat-birosagi-felulvizsgalata 3 II. Clarification of the request and the facts (14) According to the request, on […], a news item entitled “[…]” (hereinafter: article1)2 was published on the website www.blikk.hu, which contained numerous personal details of the Applicant. (15) The Applicant cited the entire article in the request, the content of which is as follows. (16) “[…] .” (17) The Applicant stated that, as stated in the article, he did not consent to the taking of his photograph or the inclusion of his name. It follows that it would not have been possible to publish the photograph of him even if his face was not recognizable, not least because he could be recognized by others from other comments referring to his physical features (“[…]”, “[…]”), and related biographical elements (“former name”, “date of employment”, “former workplace”), which are detailed in the article. The Applicant published both his former and current full name and the photograph taken of him in the article, which, in his opinion, violated his right to privacy and the provisions on the processing of personal data. The Applicant stated that he expressly objected to his name or image appearing in any form or on any forum in connection with the above-mentioned court proceedings. The mixing of alleged or real information related to gender-affirming intervention constitutes unlawful processing of his health data, in […] the legal recognition of gender took place, then the gender and for the transfer of his first name in the registry book, but he did not state anywhere that when and what interventions he had, his data regarding his alleged or real surgery are considered special data. He did not consent to their disclosure, and this topic did not even arise in the lawsuit. (18) According to the application, the Applicant made public personal data (first name, previous workplace, previous name, gender identity, alleged or real fact of gender confirmation intervention, image) that can be found on the Internet, and thus became a data controller, and as such, the scope of the GDPR extends to him, and the basic principles and other rules of the GDPR also apply to his activities. The fact that the data controller has no legal basis for the processing of the personal data made public (previous and current first name, health and biographical data, gender identity, supplemented by a photograph of the Applicant with his characteristic physical features ([…])), his position according to implements unlawful data processing, and in addition, in his opinion, the conditions for the application of a preliminary interim measure are met (the published data is special data), i.e. in his opinion, the data should be made inaccessible immediately, regardless of the person or identifiability of the infringer. If we consider the article as having the objective report on the trial of a particular, interesting legal proceeding, it would not have been necessary to publish his full name (previous and current), his health and biographical data, and his photograph (unique based on his characteristic physical features). (19) On […], the Applicant sent an electronic message to the email addresses […]@blikk.hu and online@blikk.hu with the subject of a request for removal, in which he requested the removal of his photograph and his names. The letter was not answered, and the article was available in its unchanged form at the time of the request was. (20) In view of the above, the Applicant requested the Authority's assistance to terminate the unlawful data processing as soon as possible, and also to intervene immediately due to the serious infringement that he considered to have occurred, and therefore requested the application of the interim measure. 2 […] 4 (21) In the supplement to the Applicant's application received on […], he stated that on […], a new article was published on the website www.blikk.hu, entitled “[…]” (hereinafter: article 2)3, which again contains a number of his personal data. The Applicant quoted some wording from the article verbatim, the full content of the article is as follows. (22) “[…].” (23) On […], the Applicant sent a message to the e-mail addresses […]@blikk.hu and online@blikk.hu through its lawyer, requesting the removal of its photograph and first names. No reply was received to this letter either. (24) The Applicant requested the Authority to conduct a data protection authority procedure and to, based on Section 61/A of the Infotv., to oblige the service provider to temporarily remove the published data, and to prohibit the unlawful data processing, order the deletion of the unlawfully processed personal data, and impose a fine. (25) The Authority NAIH-7459-1-2025. In its order No. , the Applicant was called upon to remedy the deficiencies in order to indicate exactly which data he was complaining about and requesting their removal. In response to the request for remedy, the Applicant listed that he was requesting the deletion of his current and former first names, his image – the creation of which he expressly objected to – his main biographical data (“[…]”) and data relating to his characteristic appearance (“[…]”). (26) In response to the Authority's call, the Applicant explained in its statement filed under number NAIH-7459-5/2025 in relation to both articles that the […] initials of the person concerned by the presented matter of public interest, the data affected by the content of the article are the first name, former first name of the person concerned, the description of the case, a photograph of the person concerned from behind, information about the person concerned's life, information about the person concerned's appearance, and the circumstances of the trial recorded in the article. The purpose of the publication of the articles is to inform the public about the matter of public interest in connection with fact-finding journalism. Citing the definition of personal data in Article 4(1) of the General Data Protection Regulation, he explained that the Respondent had thoroughly and carefully examined whether personal data appeared in the articles, and that the journalist had taken care when writing the article to ensure that the data he had obtained was not disclosed in anonymised form or not at all. Referring also to data security measures, he explained that he had ensured that the data obtained for the purpose of reporting was not made public in any way and that the person concerned could not be identified by third parties, either directly or indirectly, based on the information appearing in the content of the article, since the data and information described were not sufficient for the reader of the article to establish the identity of the person concerned without any doubt. As a result of the consideration of the legal aspects, the Applicant established that since the person concerned cannot be identified on the basis of the information recorded in the articles, no data processing activity will be carried out in connection with the publication of the articles. (27) In its response to the Authority's questions, the Applicant stated that it had received the requests for deletion sent by the Applicant's lawyers, to which no power of attorney was attached, their right to represent could not be established, therefore, in its opinion, they are considered to be legally unmade and incapable of producing legal effects. Nevertheless, unfortunately, due to an administrative error, the letters were not answered and were not brought before a person with decision-making competence. In order to avoid a similar occurrence in the future, the Respondent took immediate action, in which its managing director issued a resolution and obliged all relevant employees of the editorial office to involve the Respondent's legal staff in all such cases in order to assess and handle the cases appropriately. The Respondent attached a copy of the aforementioned resolution to its statement. (28) As regards the legal basis and purpose of the processing of personal data in the articles, it explained what had been described earlier, namely that due to the unidentifiability of the data subject, no data processing activity was carried out, and therefore there was no need to determine a legal basis. In this regard, the Respondent did not perform a balancing test, but assessed and evaluated the data protection circumstances that support the legality of the publication of the articles, as presented in paragraph (26). (29) In the rest of its statement, the Respondent provided information that although, in their opinion, no personal data was processed in connection with the articles, they immediately deleted the two referenced articles upon receipt of the Authority’s order. (30) Finally, they discussed the social role and obligation of journalism and the media system in informing the public, also referring to the fact that both trials referenced in the articles were marked as matters of public interest by […] on their website. (31) In response to the Authority's call for the Applicant to state whether it considers its application to be devoid of purpose following the deletion of the articles by the Applicant or whether it also requests the Authority to establish the fact of unlawful data processing, the Applicant responded that it requests the Authority to establish the fact of unlawful data processing by the Applicant in relation to the subject matter following the deletion of the articles by the Applicant. According to its position, the persons appearing in the Applicant's articles have materially implemented the fact of unlawful data processing and, merely for the purpose of enriching the article, used personal data that did not contribute to the satisfaction of the public interest or the obligation of the press to provide information, but were personally harmful to the Applicant, given that he became identifiable beyond the narrowest circle of acquaintances. (32) In its statement following the inspection of the file, the Obligor stated that, in its opinion, none of the articles affected by the procedure contain personal data relating to the Applicant. In their opinion, based on the information recorded in the article, the Applicant cannot be identified to third parties (especially beyond the narrowest circle of acquaintances), thus, no data processing activity was carried out in relation to the Applicant's personal data in the affected articles. Based on the submissions, they request the Authority to terminate the procedure while establishing the absence of a violation of the law. (33) In its statement following the inspection of the file, the Applicant maintained its request and expressly disputed the Applicant's statement that no personal data was processed in connection with the contested press releases, citing the fact that the person concerned was allegedly not identifiable. In his opinion, the Respondent's argument is erroneous and legally unfounded, since the totality of the information published in the articles – in particular, his current and former first name, the statements regarding his gender identity and its “change”, statements referring to a health-related, gender-affirming intervention, detailed biographical elements (date of starting work, nature of previous workplace), and a photograph taken of him, showing his characteristic physical features – are capable of indirectly but unambiguously identifying him, especially for his narrower and wider circle of acquaintances. The concept of personal data under Article 4(1) of the GDPR does not require “undoubted” identifiability; it is sufficient if the data subject can be identified by reasonably usable means, which was achieved in this case. The Respondent's claim that the data would have been anonymized is not valid, since the combination of the individual pieces of data effectively eliminated anonymity. The statements in the articles regarding health interventions and gender identity are considered special data, the processing of which would be lawful only on the basis of express consent, but he did not give such consent and even expressly objected to the publication of his name, image and health-related information. Based on all of this, in his opinion, the Respondent cannot be exempted from the provisions of the GDPR and the Infotv. even by referring to his press activities, and unlawful data processing took place in the case at hand, regardless of whether he later removed the contested articles. Therefore, he continued to ask the Authority to establish the fact of unlawful data processing by the Respondent in the proceedings and to make a decision on the merits accordingly. (34) The Authority established, based on the data of the Ministry of Justice's Company Information and Electronic Company Proceedings Service, that Blikk Kft. (Requested) was dissolved on 30 June 2025 due to a transformation - the method of transformation was a merger - and its legal successor according to the company register is IndaNext Kft. (Obligation), and served the following order on the clients. None of the clients brought a court action against the order establishing the legal succession. III. The established facts (35) Two articles were published on the website of the Requested content provider, www.blikk.hu, on […] and […], which reported on a lawsuit in the case of a transgender person. According to the articles, the person concerned underwent gender reassignment surgery and has been living as a transgender person since then, but as a woman. The Applicant requested the removal of certain data in the articles – his image and first names – because, according to him, he could be identified based on the articles. The articles stated that a court proceeding was initiated to review the administrative decision regarding the determination of the pension of a person with the initials […], whose first name had been changed from […] to […], a hearing was held in the case, and then the essence of the judgment rendered is presented in Article 2. The articles include an image of the subject of the article, in which, although his face was covered, his figure and clothing are visible, and a picture taken from behind is also included. The articles also state that the person has […] and started working in […], and that he worked in […] and underwent a sex change operation in […]. In the request sent by the Applicant's legal representative to the email addresses ending in blikk.hu ([…]@blikk.hu, and online@blikk.hu) on […] and […], he requested the removal of his current and former first name and likeness from the articles. The Applicant did not respond to the deletion requests and did not take any action until the initiation of the procedure. Until the initiation of the procedure, the articles were publicly available with their original content, as evidenced by the Authority's website backup made on 12 March 2025. The Applicant deleted the articles in their entirety after receiving the Authority's fact-clarification order on 13 March 2025. IV. Applicable legal provisions in the case: (36) According to Section 2(2) of the Infotv., the General Data Protection Regulation shall apply to data processing falling within the scope of the General Data Protection Regulation with the additions specified in the provisions specified therein. (37) According to Article 4(1) of the General Data Protection Regulation, “personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, a number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person; (38) According to recital (26) of the GDPR, when determining the identification of a natural person, account should be taken of all means, including, for example, an identifier, which can reasonably be expected to be used by the controller or by another person to identify the natural person, directly or indirectly. In determining which means can reasonably be expected to be used to identify a given natural person, all objective factors should be taken into account, such as the cost and time required for identification, taking into account the technologies available at the time of processing and the development of such technologies. (39) According to Article 4(2), ‘processing’ means any operation or set of operations which is performed upon personal data or upon sets of data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction; 7 (40) According to Article 4(7), ‘controller’ means the natural or legal person, public authority, agency or any other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of the processing are determined by Union or Member State law, the controller or the specific criteria for the designation of the controller may also be determined by Union or Member State law; (41) According to Article 4(15) of the GDPR, ‘data concerning health’ means personal data relating to the physical or mental health of a natural person, including data relating to healthcare services provided to that natural person which contain information about the natural person’s health; (42) According to Article 6 of the GDPR, (1) Processing of personal data shall be lawful only if and to the extent that at least one of the following is met: a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes; b) the processing is necessary for the performance of a contract to which the data subject is a party, or in order to take steps at the request of the data subject prior to entering into a contract; c) the processing is necessary for compliance with a legal obligation to which the controller is subject; d) the processing is necessary to protect the vital interests of the data subject or of another natural person; (e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller; (f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data, in particular where the data subject is a child. Point (f) of the first subparagraph shall not apply to processing carried out by public authorities in the performance of their tasks. (2) In order to adapt the application of the rules on processing laid down in this Regulation, Member States may, in order to comply with points (c) and (e) of paragraph 1, maintain or introduce more specific provisions specifying more precisely the specific requirements for processing and taking additional measures to ensure the lawfulness and fairness of processing, including those referred to in Article IX. other specific data processing situations specified in Chapter 1. (3) The legal basis for the processing referred to in points (c) and (e) of paragraph (1) shall be: a) Union law, or b) the law of the Member State to which the controller is subject. The purpose of the processing shall be determined by reference to that legal basis and, in the case of the processing referred to in point (e) of paragraph (1), it shall be necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. This legal basis may contain provisions adapting the application of the rules laid down in this Regulation, including the general conditions governing the lawfulness of processing by the controller, the type of data subject to processing, the data subjects, the legal entities to which the personal data may be disclosed and the purposes of such disclosure, the limitations on the purposes of processing, the period of storage and processing operations, and other processing procedures, including measures necessary to ensure lawful and fair processing, including other specific processing situations as set out in Chapter IX. The Union or Member State law must pursue an objective of public interest and be proportionate to the legitimate aim pursued. 8 (43) Pursuant to Article 9 of the General Data Protection Regulation (1) The processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health and personal data concerning a natural person's sex life or sexual orientation shall be prohibited. (2) Paragraph 1 shall not apply where: a) the data subject has given his or her explicit consent to the processing of those personal data for one or more specific purposes, unless Union or Member State law provides that the prohibition referred to in paragraph 1 cannot be lifted by the data subject's consent; b) the processing is necessary for the controller or the data subject to comply with the obligations and exercise specific rights of the controller or the data subject arising from legal provisions governing employment, social security and social protection, if Union or Member State law, which also provides for appropriate safeguards to protect the fundamental rights and interests of the data subject, or a collective agreement in accordance with Member State law, allows this; c) the processing is necessary to protect the vital interests of the data subject or of another natural person, if the data subject is unable to give consent due to physical or legal incapacity; d) the processing is carried out in the framework of the legitimate activities of a foundation, association or any other non-profit organisation with political, ideological, religious or trade union aims, carried out with appropriate guarantees, on condition that the processing relates exclusively to current or former members of such an organisation or to persons who are in regular contact with the organisation in relation to its objectives and that the personal data are not made available to persons outside the organisation without the consent of the data subjects; e) the processing concerns personal data which the data subject has expressly made public; f) the processing is necessary for the establishment, exercise or defence of legal claims or when courts are acting in their judicial capacity; * g) processing is necessary for reasons of substantial public interest, based on Union or Member State law, which is proportionate to the aim pursued, respects the essence of the right to the protection of personal data and provides for suitable and specific measures to safeguard the fundamental rights and interests of the data subject; h) processing is necessary for preventive health or occupational health purposes, to assess the employee's ability to work, to make a medical diagnosis, to provide health or social care or treatment, or to manage health or social systems and services, based on Union or Member State law or pursuant to a contract with a health professional, subject to the conditions and safeguards referred to in paragraph 3; (i) processing is necessary for reasons of public interest in the field of public health, such as protection against serious cross-border threats to health or ensuring a high quality and safety of healthcare, medicinal products and medical devices, and is carried out on the basis of Union or Member State law which provides for suitable and specific safeguards for the rights and freedoms of the data subject, in particular as regards professional secrecy; (j) processing is necessary for archiving purposes in the public interest, scientific and historical research purposes or statistical purposes in accordance with Article 89(1), on the basis of Union or Member State law which is proportionate to the aim pursued, respects the essence of the right to the protection of personal data and provides for suitable and specific measures to safeguard the fundamental rights and interests of the data subject; (3) The personal data referred to in paragraph (1) may be processed for the purposes referred to in point (h) of paragraph (2) only if the processing of such data is carried out by or under the responsibility of a professional who is subject to the obligation of professional secrecy laid down in Union or Member State law or in rules laid down by the competent authorities of the Member States, or by another person who is also subject to the obligation of professional secrecy laid down in Union or Member State law or in rules laid down by the competent authorities of the Member States. (4) Member States may maintain or introduce additional conditions, including restrictions, for the processing of genetic data, biometric data and data concerning health. (44) Article 17 of the General Data Protection Regulation provides that (1) The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay, and the controller shall have the obligation to erase personal data concerning him or her without undue delay where one of the following grounds applies: (a) the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; (b) the data subject withdraws his or her consent to the processing pursuant to point (a) of Article 6(1) or point (a) of Article 9(2) (1) and there is no other legal ground for the processing; (c) the data subject objects to the processing pursuant to Article 21(1) and * there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2); (d) the personal data have been processed unlawfully; (e) the personal data must be erased for compliance with a legal obligation to which the controller is subject under Union or Member State law; (f) the personal data were collected in connection with the offering of information society services referred to in Article 8(1). (2) Where the controller has made personal data public and is required to erase them pursuant to paragraph (1), the controller shall take reasonable steps, taking into account available technology and the cost of implementation, including technical measures, to inform the controllers processing the data that the data subject has requested erasure of links to or copies or replications of the personal data. (45) Pursuant to Article 12 of the General Data Protection Regulation, the controller shall facilitate the exercise of the data subject's rights under Articles 15 to 22. In the cases referred to in Article 11(2), the controller shall not refuse to comply with the data subject's request to exercise the rights under Articles 15 to 22 unless it demonstrates that the data subject cannot be identified. (3) The controller shall inform the data subject without undue delay, and in any event within one month of receipt of the request, of the action taken on the request pursuant to Articles 15 to 22. Where necessary, taking into account the complexity of the request and the number of requests, this period may be extended by a further two months. The controller shall inform the data subject of the extension of the period, stating the reasons for the delay, within one month of receipt of the request. Where the data subject has submitted the request electronically, the information shall be provided, where possible, by electronic means, unless the data subject otherwise requests. (4) If the controller does not take action on the request of the data subject, it shall, without delay and at the latest within one month of receipt of the request, inform the data subject of the reasons for not taking action and of the right to lodge a complaint with a supervisory authority and to exercise its right to a judicial remedy. (5) The information provided pursuant to Articles 13 and 14 and any information and action taken pursuant to Articles 15 to 22 and 34 shall be provided free of charge. Where the data subject's request is manifestly unfounded or excessive, in particular because of its repetitive nature, the controller may: a) charge a reasonable fee, taking into account the administrative costs incurred in providing the requested information or taking the action requested, or b) refuse to act on the request. The burden of proof that the request is manifestly unfounded or excessive shall be borne by the controller. 10 (6) Without prejudice to Article 11, if the controller has reasonable doubts as to the identity of the natural person submitting the request pursuant to Articles 15 to 21, it may request the provision of further information necessary to confirm the identity of the data subject. (46) According to Section 10 of Act CIV. of 2010 on Freedom of the Press and Basic Rules for Media Content (hereinafter referred to as the Smtv.), everyone has the right to be adequately informed about local, national and European public affairs and about events of importance to the citizens of Hungary and members of the Hungarian nation. The media system as a whole shall be responsible for providing credible, rapid and accurate information on these matters and events. (47) According to Article 25 of the General Data Protection Regulation (1), the controller shall, taking into account the state of the art and the costs of implementation, the nature, scope, circumstances and purposes of the processing and the varying likelihood and severity of the risks to the rights and freedoms of natural persons, implement appropriate technical and organisational measures, such as pseudonymisation, both when determining the means of processing and during the processing, in order to ensure the effective implementation of data protection principles, such as data minimisation, and to incorporate into the processing appropriate safeguards to meet the requirements of this Regulation and to protect the rights of data subjects. (48) According to Article 32 of the GDPR (1) The controller and the processor shall implement appropriate technical and organisational measures, taking into account the state of the art and the costs of implementation, the nature, scope, circumstances and purposes of the processing and the risks of varying likelihood and severity to the rights and freedoms of natural persons, to ensure a level of data security appropriate to the risk, including, where applicable: (a) pseudonymisation and encryption of personal data; (b) ensuring the continued confidentiality, integrity, availability and resilience of systems and services used to process personal data; (c) the ability to restore access to and the availability of personal data in a timely manner in the event of a physical or technical incident; (d) a procedure for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures taken to ensure the security of the processing. (2) When determining the appropriate level of security, explicit account shall be taken of the risks presented by the processing, in particular the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data transmitted, stored or otherwise processed. (3) The controller or processor may use adherence to approved codes of conduct in accordance with Article 40 or to an approved certification mechanism in accordance with Article 42 as part of the demonstration that it meets the requirements set out in paragraph 1 of this Article. (4) The controller and the processor shall take measures to ensure that natural persons who have access to personal data, acting under the direction of the controller or the processor, only process such data on instructions from the controller, unless they are required to do so by Union or Member State law. (49) Article 58 of the General Data Protection Regulation (2) The supervisory authority shall, acting in its corrective capacity: (b) take action against the controller or the processor where the processing activities infringe the provisions of this Regulation; 11 (50) According to Article 83 of the GDPR (1) Each supervisory authority shall ensure that administrative fines imposed pursuant to this Article for infringements referred to in paragraphs (4), (5) and (6) are effective, proportionate and dissuasive in each individual case. (2) Administrative fines shall be imposed in addition to or instead of the measures referred to in points (a) to (h) and (j) of Article 58(2), depending on the circumstances of the case. When deciding whether to impose an administrative fine and when setting the amount of the administrative fine, due regard shall be had in each case to the following: a) the nature, gravity and duration of the infringement, taking into account the nature, scope or purpose of the processing in question, the number of data subjects affected by the infringement and the extent of the damage suffered by them; b) whether the infringement was intentional or negligent; c) any measures taken by the controller or processor to mitigate the damage suffered by data subjects; d) the level of responsibility of the controller or processor, taking into account the technical and organisational measures taken by it pursuant to Articles 25 and 32; e) any relevant infringements previously committed by the controller or processor; (f) the extent of cooperation with the supervisory authority in order to remedy the breach and mitigate any negative effects of the breach; g) the categories of personal data affected by the breach; h) the manner in which the supervisory authority became aware of the breach, in particular whether the controller or processor notified the breach and, if so, in what detail; i) where the controller or processor concerned has previously been subject to one of the measures referred to in Article 58(2) in the same matter, the compliance with those measures; j) whether the controller or processor has adhered to approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42; and k) other aggravating or mitigating factors relevant to the circumstances of the case, such as financial gain gained or loss avoided as a direct or indirect consequence of the infringement. (3) Where a controller or processor infringes several provisions of this Regulation in relation to the same processing operation or to linked processing operations, whether intentionally or negligently, the total amount of the fine shall not exceed the amount applicable to the most serious infringement. (4) Infringements of the following provisions shall be punishable, in accordance with paragraph 2, by administrative fines of up to EUR 10 000 000 or, in the case of undertakings, up to 2% of the total worldwide annual turnover of the preceding financial year, whichever is the higher: a) the obligations laid down in Articles 8, 11, 25 to 39, 42 and 43 for the controller and the processor; b) the obligations laid down in Articles 42 and 43 for the certification body; (c) the obligations laid down in Article 41(4) in respect of the control body; (5) Infringements of the following provisions shall be punishable, in accordance with paragraph 2, by administrative fines of up to EUR 20,000,000 or, in the case of undertakings, up to 4% of the total annual worldwide turnover of the preceding financial year, whichever is the higher: a) the principles of processing, including the conditions for consent, in accordance with Articles 5, 6, 7 and 9; b) the rights of data subjects in accordance with Articles 12 to 22; c) the transfer of personal data to a recipient in a third country or to an international organisation in accordance with Articles 44 to 49; d) obligations under the law of the Member States adopted pursuant to Chapter IX; 12 e) failure to comply with the instructions of the supervisory authority pursuant to Article 58(2) or to temporarily or permanently restrict data processing or to suspend data flows, or failure to provide access in violation of Article 58(1). (51) 61/A of the Infotv. Pursuant to Section (1), the Authority may, as a temporary measure, oblige the electronic data processor, the hosting service provider specified in the Act on Certain Issues of Electronic Commerce Services and Services Related to the Information Society, or the intermediary service provider also providing hosting services (hereinafter collectively: the party obliged to remove) to temporarily remove data published via an electronic communications network (hereinafter referred to as: electronic data) for the purpose of preventing the unlawful processing of personal data, in order to prevent the unlawful processing of personal data (hereinafter referred to as: electronic data) due to the publication of which the Authority is conducting a data protection authority procedure or an official inspection, if, in the absence of such a measure, the delay would result in an irremediable and serious infringement of the right to the protection of personal data and the published data a) is a child, or b) is sensitive data or criminal personal data. (2) The order on the temporary removal of electronic data shall be communicated to the party obliged to remove without delay. The party obliged to remove shall be obliged to temporarily remove the electronic data within one working day following the notification of the Authority’s order on the interim measure. (3) The Authority shall terminate the temporary removal of the electronic data and order the restoration of the electronic data if the reason for ordering it has ceased to exist. (4) The temporary removal of the electronic data shall be terminated upon the final completion of the Authority’s data protection procedure or upon the conclusion of the official inspection. (5) In the cases specified in paragraphs (3) and (4), the Authority shall oblige the party obliged to remove to restore the electronic data. (6) The order on the restoration of the electronic data shall be notified to the party obliged to remove without delay. The party obliged to restore shall be obliged to restore the electronic data within one working day following the notification of the order. (7) The order specified in paragraph (6) shall be served on the person entitled to access the electronic data if his/her identity and availability are known based on the information provided so far in the procedure. (8) An independent legal remedy shall be available against the decision taken on the temporary removal of electronic data. (9) The Authority may impose a procedural fine of between one hundred thousand and twenty million forints on the person obliged to remove the data who fails to comply with his/her obligation under this Section. (52) Pursuant to Section 60 (2) of the Infotv., an application for the initiation of a data protection authority procedure may be submitted in the case specified in Article 77 (1) of the General Data Protection Regulation. (53) According to Article 77(1) of the General Data Protection Regulation, without prejudice to other administrative or judicial remedies, each data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or the place of the alleged infringement, if, in the opinion of the data subject, the processing of personal data concerning him or her infringes this Regulation. (54) Unless otherwise provided for in the General Data Protection Regulation, the provisions of Act CL. of 2016 on General Administrative Procedure (hereinafter referred to as the Ákr.) shall apply to the data protection authority procedure initiated on request, with the derogations specified in the Infotv. (55) According to Section 35(1) of the Ákr., a request is a statement by the client requesting the conduct of an official procedure or a decision of the authority in order to assert his or her right or legitimate interest. (56) Section 47 of the Act on Personal Data Protection (1) The authority shall terminate the procedure if c) the procedure has become unfounded. 13 V. Decision of the Authority (57) In accordance with the application, the Authority examined whether the Applicant performed unlawful data processing, whether it unlawfully disclosed the Applicant's data, and examined ex officio the fulfillment of the data subject's requests for deletion. V.1. Identifiability of the data subject and the scope of the data processed (58) In order to make a determination on the legality of the disclosure of personal data, it is first necessary to examine whether the Applicant can be identified on the basis of the Articles, taking into account that the basis for the concept and processing of personal data is that it relates to an identifiable person. The General Data Protection Regulation is permissive in the area of identifiability when it defines identifiability in such a way that any method that can be used to identify the data subject must be taken into account. (59) The name and image of a person can clearly be considered such data. In general, naming a person with a monogram and obscuring their image can be considered a kind of pseudonymisation, but the individual circumstances of the case must always be examined. In the case at issue, the Applicant has named the Applicant’s former – […] – and current – […] – first name, as well as the […]. monogram, from which it can be clearly concluded that the last member of the monogram currently stands for the name […]. Since the three-member monogram is, based on general experience4, considered to be less common than the two-member monogram, the monogram, together with the precisely specified first name, significantly narrows the range of persons who may be affected by the articles. However, in addition to the first names, the initials and the obscured image, the articles also contain other data and images –[…] – that make the subject of the articles clearly identifiable to third parties. (60) The articles reported on a legal case involving a transgender person. (61) According to the Authority’s consistent practice, “a person’s gender cannot be considered as special data in itself, as this data does not refer to the health status or sexual habits of the person concerned. However, the Authority considers that the change of gender and the personal data related to it are considered special data even if the registration procedure is not followed by medical treatment or surgery (note: in this case, alleged or real data on the fact of surgery were also disclosed). This is because the change of gender is carried out for psychological reasons, in order to restore or preserve mental health, on the basis of a medical diagnosis or expert opinion, and the official or physiological change of gender status or condition has or may have an impact on the sexual life and mental state of the person concerned”5. The Authority considers data on transgender status to be health data pursuant to Article 4(15) of the General Data Protection Regulation. (62) The Applicant indicated the unlawful disclosure of data relating to his gender identity in the context of his infringement of rights. The Applicant complained about the processing of alleged or real information relating to gender-affirming surgery as unlawful processing of his health data. The Applicant claimed that he never stated when and what kind of surgery he had, and that the data relating to his alleged or real surgery were classified as sensitive data. He did not consent to their disclosure, and this issue did not even arise in the lawsuit (NAIH-14033-1/2024). (63) The Applicant indicated the data relating to his alleged or real surgery as his health data, however, in the Authority's opinion, it was not only this in itself, but the disclosure of the fact of his transgender status that resulted in the disclosure of health data. (64) In the photograph published in Article 1, the Applicant’s face was blurred out (other details of the photograph are not), so his facial features are unrecognizable, and the caption below it reads “[…] did not allow us to show his face / Photo: […]”, and in another photograph in Article 1, the person in the photograph can be seen from behind, the caption 4 The Central Statistical Office does not keep records of this data. 5 Report of the Commissioner for Fundamental Rights in Case No. AJB-883/2016, Section 3.3 14 “As a transgender person, he fights for his early retirement pension in court / Photo: […]”. This photograph was also published in Article 2 with the same caption. (65) The Authority, having examined the two photographs together with the captions assigned to them, established from the available data that the Applicant is depicted in them. The Respondent did not make a contrary claim - that the photographs do not show the Applicant - and the captions clearly indicate that the subject of the article can be seen in them. “Picture illustration” is the usual general phrase in cases where a given article does not publish a photograph of the subject of the article, but uses another photograph to illustrate what is to be said. In the present cases, the captions referred to the Applicant by his first name and introduced him by describing the essence of the litigation. (66) Regarding the images of the Applicant published in the articles, the Authority states that their publication makes the Applicant identifiable, despite the fact that his face is covered, based on the further content of the articles. (67) Based on the above, the two articles resulted in the disclosure of special personal data, namely his transgender status, due to their content, and the entire content of the articles is suitable for identifying the Applicant based on his biographical data and images of his physique and appearance. (68) The Authority does not consider the disclosure of the monogram as a data security measure, but in its opinion, the Applicant acted in this way in order to comply with Article 25 of the General Data Protection Regulation, however, the failure to disclose the full name in itself did not serve as a sufficient measure to avoid unlawful data processing. V.2. Legal basis for the disclosure of the data (69) The Applicant referred to the fact that the subject of the articles is a matter of public interest, which the press is obliged to report on pursuant to Section 10 of the Smtv. (70) In relation to any data processing activity, it can be said that in the case of data processing, the purpose of the processing must be taken into account, and if the purpose can be achieved without the processing of personal data, then it must be carried out in such a way. (71) The Authority’s position is that the substantive content of the case – whether someone claimed a pension corresponding to their new gender after gender reassignment, what administrative decision was made in the case, and what judgment the court rendered during the judicial review of the decision – could have been disclosed even without the publication of the Applicant’s personal data. Therefore, the Respondent unnecessarily disclosed the Applicant's personal data in order to inform the public about a matter of public interest. (72) The legal basis for the disclosure of data is both the consistent practice of the Authority and, according to case law, in the case of the press, the legitimate interest referred to in Article 6(1)(f) of the GDPR. (73) According to Article 6(1)(f) of the GDPR, the processing of personal data is lawful if the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, unless such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data. It is of paramount importance that the processing of data may not constitute a disproportionate restriction on the rights and interests of the data subject, even if the legitimate interests of the controller are invoked. (74) In order for the legitimate interest of the data controller to be legitimately invoked as a legal basis for data processing, in addition to identifying the legitimate interest, the data controller must also consider whether it is necessary for the exercise of the legitimate interest, i.e. the data controller must examine whether alternative solutions are available to it by which the legitimate interest can be exercised without data processing or by means that are less restrictive than the planned data processing. (75) Since the Respondent did not consider the subject of the article to be identifiable, he did not consider the disclosure of its contents to be data processing, and therefore, according to his statement, he did not perform a balancing test. He did all this based on the subjective opinion of the Respondent. 15 (76) In contrast, the Authority Based on the explanations in point 1, it was established that the Applicant was identifiable, so the disclosure of his data constituted data processing, which would have been possible if there had been an appropriate legal basis. (77) The photograph taken from behind explicitly indicates that it was taken and then published in disregard of the Applicant’s objections, which were also acknowledged by the Applicant, as stated in the article. (78) Article 1 quotes the Applicant as saying that he said “please do not take a photograph and do not write my name”. Despite the Applicant’s request, quoted in Article 1, that no photograph be taken of him, the Applicant took two photographs and used the photograph taken from behind in Article 1, and the photograph taken from behind in Article 2. The photograph taken from behind indicates that the Applicant could not have noticed that it was taken. This conduct was assessed by the Authority as bad faith, also taking into account that “please do not take a photograph” can be considered as a protest to the taking of a photograph, so the photograph taken from behind represents a disregard for this protest in a way that would not have been obvious. While the sentence “[…] did not allow us to show his face” below the photograph suggests that the Applicant had only made a request regarding the publication. (79) The legal basis was lacking due to the Applicant’s assessment of the situation, and the disclosure of personal data without an appropriate legal basis can therefore be established. (80) The Authority draws attention, however, to the fact that in the case of the disclosure of sensitive data, it is not sufficient to base the processing on one of the legal grounds set out in Article 6(1); the exception under Article 9 must also be met. (81) According to Article 9(1) of the GDPR, the processing of health data is prohibited in principle and may only be processed if there is a legal basis for the processing pursuant to Article 6(1) or one of the circumstances referred to in Article 9(2). If either of these is absent, the processing is not lawful. There is no exception in Article 9(2) that can be equated with legitimate interest and is applicable in this case, and therefore the processing of sensitive data cannot be based on a legitimate interest unless it is accompanied by compliance with one of the additional conditions set out in Article 9(2). (82) Given that the Authority established in the specific case that the Applicant's data processing did not comply with Article 6(1) of the GDPR, the Authority no longer considered it necessary to examine the existence of the circumstances under Article 9(2) of the GDPR, since the unlawfulness of the data processing can be stated even in the absence thereof. (83) Based on the above, the Authority, granting the Applicant's request, finds that the Applicant published Articles 1 and 2 in such a way that the Applicant's person could be identified based on their content, and by unlawfully publishing the personal and sensitive data contained therein, the Applicant violated the provisions of Article 6(1)(f) and Article 9(1) of the General Data Protection Regulation. The Authority established this in point I of the operative part of the decision. V.3. Handling of the request for deletion (84) In relation to the handling of the request for deletion by the Applicant, the Authority points out the following (85) The Applicant, through its legal representatives, on two occasions – on […] and […] – sent two e-mail addresses each time, requested the deletion of • his current and previous surname; • his image, from the personal data included in the published articles, and in addition to the above, in its application submitted to the Authority, he initiated a decision to remove • the data relating to […] from the biographical data; • the data relating to the description of […] from the data relating to his appearance. (86) The Respondent acknowledged the infringement in its declaration filed under number 7459-5/2025, stating that it had not taken any measures pursuant to Article 12 of the General Data Protection Regulation to comply with the data subject’s requests for erasure. It had not contacted the Applicant or his representatives in order to communicate its request for proof of legal representation, nor had it informed the Applicant of the channel through which the data subject’s request should be submitted in order to ensure that it would reach the person authorised to decide on the matter. (87) By this conduct, the Respondent had infringed Article 12(4) of the General Data Protection Regulation, as the Authority found in point II of the operative part. (88) According to its statement, the Applicant has taken measures for the future in order to ensure that any data subject request received via any channel is forwarded to the unit authorized to make the decision. V.4. Other requests of the Applicant: (89) The Applicant requested that the Authority impose a data protection fine on the Applicant due to the above infringement. (90) The application of this legal consequence does not directly affect the rights or legitimate interests of the Applicant, such a decision of the Authority does not create any rights or obligations for it, therefore, with regard to the application of this legal consequence falling within the scope of the enforcement of the public interest, the Applicant does not qualify as a client in terms of the imposition of a fine pursuant to Section 10 (1) of the Act on the Protection of Personal Data. Since the Act on the Protection of Personal Data does not comply with Article 35(1), there is no place for a request in this regard, this part of the submission cannot be interpreted as a request. According to the judgment of the CJEU in Case C-768/21, paragraph 41, neither Article 58(2) nor Article 83 of the General Data Protection Regulation can be inferred from it that the supervisory authority is obliged to adopt corrective measures, in particular to impose an administrative fine, in every case where it finds an infringement, since in such circumstances it is obliged to react appropriately in order to remedy the deficiency found. A person who has lodged a complaint whose rights have been violated does not have a subjective right to have the supervisory authority impose an administrative fine on the controller. (91) In connection with a request for the imposition of a data protection fine, the Authority is entitled to decide ex officio, in its discretion, on the effective, proportionate and dissuasive measures to be taken against the controller/processor in order to protect personal data, and on the need to impose a sanction, such as an administrative fine, instead of or in addition to them, and on the amount thereof, in the event of such a sanction, in accordance with recitals (148) and (150), Article 58 and Article 83(2) of the General Data Protection Regulation, depending on the circumstances of the case. (92) The Applicant also requested the imposition of an interim measure pursuant to Section 61/A of the Information Act. The Authority did not grant the motion because during the procedure the Applicant deleted both articles in their entirety, they are no longer accessible, and the imposition of an interim measure was not necessary. VI. Legal consequences (93) The Authority granted the Applicant’s request and also established an infringement ex officio. Pursuant to Article 58(2)(b) of the GDPR, the Applicant is found guilty of intentionally infringing Article 6(1)(f), Article 9(1) and Article 12(4) of the General Data Protection Regulation. VI.1. Imposition of a data protection fine (94) The Authority examined ex officio whether it was justified to impose a data protection fine on the Obligor for the established infringements. (95) In this context, the Authority considered all the circumstances of the case on the basis of Article 83(2) of the General Data Protection Regulation and Section 75/A of the Infotv. . In view of the circumstances of the case 17 the Authority concluded that in the case of the infringement revealed in the course of the present proceedings, a warning is not a proportionate and dissuasive sanction, therefore the imposition of a fine is necessary. (96) The Authority first of all took into account that the infringement committed by the Applicant qualifies as an infringement falling within the higher fine category in accordance with Article 83(5)(a)-(b) of the GDPR, as it involved an infringement of the principles of data processing (Articles 6 and 9) and the rights of the data subject, falling within the fine category in accordance with Article 83(5). (97) When determining the amount of the fine, the Authority took into account the provisions of the European Data Protection Board's Guideline No. 4/20226 (hereinafter: the Guideline), which sets out the calculation criteria for imposing administrative fines under the GDPR. In view of this, the amount of the fine was determined on the basis of the following criteria: (98) According to public information7, the net sales revenue of the Obligor in 2024 was HUF 12,119,082 (i.e. twelve billion one hundred and nineteen million eighty-two thousand). (99) Pursuant to Article 83(5) of the General Data Protection Regulation, the Applicant shall be liable to an administrative fine of up to EUR 20,000,000 [static maximum fine], or in the case of undertakings, an amount of up to 4% of the total annual worldwide turnover of the preceding financial year [dynamic maximum fine], whichever is higher. (100)4% of the Obligor's 2024 revenue is HUF 484,763,280, which, at the HUF/EUR exchange rate at the time of the decision (359.13), does not exceed the so-called static fine maximum specified by the regulation, i.e. the amount corresponding to EUR 20,000,000. Since the fine must be calculated based on the higher category that can be imposed in the given case among the static and dynamic amounts and proportionate to it, the Applicant may be imposed an administrative fine of up to EUR 20,000,000 in this case. (101) According to the Guidelines, for infringements falling within the fine category of Article 83(5) of the GDPR, for which the static maximum fine of EUR 20,000,000 is applicable, the net turnover of the undertaking in the previous year and the gravity of the infringement (low, medium or significant) are subject to further examination.8 (102) The Authority has assessed the infringement as significant in the present case, based on the infringements committed, the facts established and the aggravating and mitigating circumstances applicable to the case. (103)In the present case, the net sales revenue of the Obligor in 2024 is 12,119,082 (i.e. twelve billion, one hundred and nineteen million, eighty-two thousand) forints, which, calculated at the current HUF/EUR (359.13) exchange rate, is EUR 33,745,668 – falling within the category of EUR ten million to EUR fifty million specified by the Guidelines in relation to taking into account the economic data of undertakings. (104) According to the Guidelines, if the net turnover of the undertaking in the previous year is between EUR 10 million and EUR 50 million, the maximum amount of the fine that can be imposed for significant infringements is EUR 60,000 (HUF 21,547,800) - EUR 2,000,000 (HUF 718,260,000). (105) In the present case, therefore, taking into account the above management data, the Obligor may be subject to a maximum fine of EUR 2,000,000 (HUF 718,260,000) in relation to the significant infringements committed by it. 6 Guidelines 04/2022 on the calculation of administrative fines under the GDPR (Version 2.0.). Online: https://edpb.europa.eu/system/files/2023-06/edpb_guidelines_042022_calculationofadministrativefines_en.pdf 7 https://e- beszamolo.im.gov.hu/oldal/kereses_megjelenites?b=rjbcTCob8OJa0iRsX6tx1w%3d%3d&so=1&o=Is7WcUWgHsUNzm18qkY7 UA%3d%3d https://e-beszamolo.im.gov.hu/oldal/beszamolo_kereses 8 See the tables on pages 44-46 of the Guidelines (“Step 1” and “Step 2”). 18 (106)When imposing the fine, the Authority assessed the following circumstances as aggravating circumstances: • the infringement is serious because the Applicant made sensitive data public without an appropriate legal basis [Article 83(2)(a) of the GDPR]; • the Applicant completely ignored the request for the exercise of the data subject’s rights, did not respond to it, and did not take any action following the request, [Article 83(2)(a) of the GDPR]; • the damage suffered by the Applicant is significant because the disclosure of the sensitive data cannot be remedied subsequently, at most the further damage can be mitigated [Article 83(2)(a) of the GDPR]; • the infringement committed by the disclosure of the data is deemed to be intentional, because the Applicant’s public information task could have been carried out without the disclosure of personal data relating to the identifiable data subject [Article 83(2)(b) of the GDPR], • the Authority considers it to be in bad faith that a photo of the identifiable Applicant was published despite his objection, which can be read in the article [Article 83(2)(a) of the GDPR]; • the Applicant has not violated the provisions of the GDPR for the first time, as established in a data protection authority procedure, and has previously committed a relevant infringement as established in Decision No. NAIH-2853-1/2022 [Article 83(2)(e) of the GDPR]; • the infringement committed by the disclosure of the data concerned a special category of personal data [Article 83(2)(g) GDPR] • the Respondent's liability for the infringement is serious, although it took action in accordance with Article 25 of the GDPR by means of a monogrammed communication, this did not prevent the infringement [Article 83(2)(d) GDPR]. (107) When imposing the fine, the Authority assessed the following circumstances as mitigating circumstances: • the Respondent voluntarily deleted the data and articles requested to be deleted in full during the Authority's proceedings, thus they are no longer available on the website on the day of the decision [Article 83(2)(c) GDPR]. (108)The Authority also took into account • The infringement concerned a person in the present proceedings [Article 83 (2) a) GDPR]; • the Respondent has taken measures for the future to ensure that any data subject request received by it through any channel is mandatorily forwarded to the unit authorised to take the decision [Article 83 (2) k) GDPR]. (109)The Authority did not consider the circumstances referred to in Article 83 (2) c), h), j) of the GDPR to be relevant when imposing the fine, as they cannot be interpreted in the context of the specific case. (110)The Authority determined the amount of the fine by exercising its statutory discretion, taking into account the circumstances set out in paragraphs (94)-(96) within the category set out in paragraph (92). (111) The fine imposed is roughly the minimum amount that can be imposed (21,547,800 HUF). (112) The fine imposed is therefore proportionate to the gravity of the infringement, it cannot be considered excessive at all, and it is not a high amount compared to the economic weight of the Obligor and the financial resources at its disposal. 19 (113) Taking the above into account, the Authority has concluded that the imposition of the fine can be considered a justified and proportionate sanction. The Authority has determined the amount of the fine by acting within its statutory discretion. The fine imposed is necessary in order to have sufficient deterrent force in light of the established, serious infringement. VI.2. Publication of the Decision (114) The Infotv. Pursuant to Section 61(2)(c), the Authority may order the publication of its decision by publishing the identification data of the data controller if the gravity of the infringement that has occurred justifies the publication. (115) As the Authority has established in this decision, the infringement committed by the Applicant can be considered to be of high gravity. In addition, the Authority, taking into account both general and special prevention, wishes to emphatically draw attention to the obligations of media service providers regarding the processing of personal data in the content they display, and also wishes to use the public to point out the special importance of the increased and expected protection of personal data. (116) In view of all this, the Authority Based on Section 61 (2) point c), the Authority ex officio ordered the publication of its final decision by publishing the identification data of the Applicant and the Obligor on its own website. (117)Based on the above, the Authority decided as set out in the operative part. VII. Procedural rules (118)The Authority’s competence is determined by Section 38 (2) and (2a) of the Information Act, and its competence extends to the entire territory of the country. (119)The decision is based on Sections 80-81 of the Information Act and Section 61 (1) of the Information Act, and the order is based on Section 47 (1) point c). The decision and the order become final upon their publication based on Section 82 (1) of the Information Act. The Information Act Pursuant to Section 112(1) and (2)(d), Section 116(1) and (4)(d), and Section 114(1), the decision and order may be appealed through administrative proceedings. (120) Considering that the Authority has exceeded the administrative deadline pursuant to Section 60/A (1) of the Information Act, the Applicant is entitled to HUF 10,000, - i.e. ten thousand forints, based on Section 51 b) of the Administrative Procedure Act, either by bank transfer or postal order, at his/her choice, which shall be communicated in writing. * * * (121) The rules of administrative litigation are determined by Act I of 2017 on the Code of Administrative Procedure (hereinafter referred to as the Administrative Procedure Act). Pursuant to Section 12 (1) of the Administrative Procedure Act, administrative litigation against the Authority's decision falls within the jurisdiction of the courts, and the Budapest Metropolitan Court has exclusive jurisdiction over the litigation pursuant to Section 13 (3) a) aa) of the Administrative Procedure Act. Pursuant to Section 27(1)(b), legal representation is mandatory in a lawsuit within the jurisdiction of the court. Pursuant to Section 39(6) of the Code of Civil Procedure, the filing of a claim does not have a suspensive effect on the entry into force of the administrative act. (122) Pursuant to Section 29(1) of the Code of Civil Procedure and, in view of this, Section 604 of the Code of Civil Procedure, Section 19(1)(a)(b) of Act CIII of 2023 on the digital state and certain rules for the provision of digital services, the organization acting as the client pursuant to Section 3 of Act CXCV of 2011 on state finances is obliged to maintain electronic communication. (123) The time and place of filing a claim are determined by Section 39(1) of the Code of Civil Procedure. The information on the possibility of requesting a hearing is based on Section 77(1)-(2) of the Administrative Procedure Act. The amount of the administrative litigation fee is determined by Section 45/A(1) of Act XCIII of 1990 on Fees (hereinafter: the Administrative Procedure Act). Section 59(1) and Section 62(1)(h) of the Administrative Procedure Act exempt the party initiating the proceedings from paying the fee in advance. (124) If the obligated party fails to provide adequate proof of the fulfillment of the prescribed obligations, the Authority shall consider that the obligations have not been fulfilled within the deadline. According to Section 132 of the Administrative Procedure Act, if the obligated party has not fulfilled the obligation set out in the final decision of the Authority, it shall be enforceable. Pursuant to Section 133 of the Act, the enforcement shall be ordered by the authority that made the decision - unless otherwise provided by law or government decree. Pursuant to Section 134 of the Act, the enforcement shall be carried out by the state tax authority - unless otherwise provided by law, government decree or, in the case of a local government, a local government decree. Pursuant to Section 61 (7) of the Information Act, the Authority shall implement the enforcement of the decision in relation to the obligation to perform a specific act, to behave in a specific manner, to tolerate or to cease. Dated: Budapest, according to the electronic signature and time stamp Dr. habil. Attila Péterfalvi President, c. university professor




