NAIH (Hungary) - NAIH-4462-5-2026

From GDPRhub
NAIH - NAIH-4462-5-2026 (also referred to as NAIH-4462-4/2026)
Authority: NAIH (Hungary)
Jurisdiction: Hungary
Relevant Law: Article 5(1)(a) GDPR
Article 5(2) GDPR
Article 12(1) GDPR
Article 13(1) GDPR
Type: Investigation
Outcome: n/a
Started: 09.04.2025
Decided: 30.04.2026
Published: 24.07.2026
Fine: 10000000.0 HUF
Parties: n/a
National Case Number/Name: NAIH-4462-5-2026 (also referred to as NAIH-4462-4/2026)
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Hungarian
Original Source: NAIH (in HU)
Initial Contributor: av

The DPA fined an online store operator HUF 10,000,000 (€27,300) as there was no privacy notice available on the store’s website. In particular, information on the purposes and the legal bases of processing, the storage periods, and the recipients of personal data was missing.

English Summary

Facts

The DPA initiated an investigation into the processing of the personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The controller’s main business activity was the wholesale distribution of beverages. The personal data of the data subjects was processed on the website of the online store for registration, placing orders, billing, communication, delivery, creation of user accounts, and newsletter subscription.

During the period under review, i.e. between January 2020 and October 2025, no standalone privacy notice was available on the website. The previously archived privacy notice and the data processing section included in the general terms and conditions described the processing operations in a rather brief and general manner. The controller argued that the inaccessibility of the privacy notice followed from a technical error that was corrected upon discovery.

Holding

The DPA found that the controller had violated Articles 5(1)(a), 5(2), 12(1), 13(1)(a), (c), and (e) as well as 13(2)(a)–(e) GDPR and issued it a fine of HUF 10,000,000 (€27,300). When issuing the fine, the DPA took into account that the identified infringements followed from systemic inadequacies of the privacy notice and were of continuous nature. In addition, the DPA ordered the controller to develop and publish a uniformly structured privacy notice that is aligned with its actual processing operations.

First, the DPA identified a violation of the principle of transparency laid down in Article 5(1)(a) GDPR: the information provided to data subjects about the processing of their personal data was either incomplete or completely absent, and changes could not be tracked.

Second, the DPA held that the controller had violated the principle of accountability set forth in Article 5(2) GDPR, as it had failed to submit appropriate documentation covering the period under review. In addition, the controller’s data processing practices could not be continuously monitored or subsequently verified based on the documentation it had provided.

Finally, the DPA confirmed that the controller had not complied with the requirements laid down in Articles 12(1), 13(1)(a), (c) and (e), and 13(2)(a)–(e) GDPR. Due to the lack of a privacy notice, the controller could not demonstrate that it had provided data subjects with the information required under Article 13 GDPR apart from brief, general statements in the archived privacy notice and the general terms and conditions. The controller had thus failed to provide the data subjects clear and differentiated information regarding the purpose and legal basis for each processing operation. Furthermore, the controller had not adequately identified the recipients or the storage period of personal data or information on the data subjects' rights. Due to the form and scope of the information provided, the controller had also infringed Article 12(1) GDPR.

Comment

The national case number of this decision is NAIH-4462-5/2026 on the NAIH website, but NAIH-4462-4/2026 in the PDF document.

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Hungarian original. Please refer to the Hungarian original for more details.

Case No.: NAIH-4462-4/2026. Subject: Decision in an ex officio data protection

       Background: NAIH-15138/2025 administrative proceeding
 NAIH-9722/2025.

 Case Officer:




                                            DECISION



 The National Authority for Data Protection and Freedom of Information (hereinafter: the Authority), with respect to the […]
 website (hereinafter: the Website), regarding the data processing practices of the online store operating on the Website
      , specifically regarding prior notification, against […]
hereinafter: the Company, as the operator of the online store operating on the Website, pursuant to
the Regulation on the protection of natural persons with regard to the processing of personal data and

      the free movement of such data, and repealing Directive 95/46/EC
Regulation (EU) 2016/679 (hereinafter: General Data Protection Regulation or
      GDPR), the
Authority hereby issues the following decisions.


 1. The Authority finds that the Company negligently violated
         -   Article 5(1)(a) of the General Data Protection Regulation;

 -   Article 5(2) of the General Data Protection Regulation;

 -   Article 12(1) of the General Data Protection Regulation;

         -   Article 13(1)(a), (c), and (e) of the General Data Protection Regulation; and
 -   Article 13(2)(a) through (e) of the General Data Protection Regulation.


      2. In light of the identified violations—pursuant to Article 58(2)(d) of the GDPR

—the Authority hereby orders the Company, ex officio, to amend the
      data processing notice practices on the Website under review
to remedy the deficiencies identified in paragraphs (76) through (112) of this decision, and to ensure that
      is actually made available to data subjects.
 The Company is required to develop a uniformly

 structured privacy notice aligned with its actual data processing operations and to publish it on the Website, which
      is easily accessible to data subjects, transparent, understandable, and clearly worded, and
 which, for each data processing activity, specifies in particular the purpose and legal basis of the data processing, the
      data being processed, the recipients or categories of recipients, the duration of the data processing or the
criteria for determining it, as well as information regarding the data subjects’ rights and how to exercise them

. The Company is also required to ensure that the privacy notice is
 continuously available on the Website and that its availability is not interrupted for technical reasons;
      and is also required to document the individual versions of the notice, their effective dates, and the dates of their publication in such
a way that compliance with the GDPR can be verified at a later date. The
Company is required to demonstrate compliance by submitting the amended privacy notice to the Authority

in such a way that the amendments are clearly identifiable.


      3. Due to the violations set forth in paragraph 1,

........................................................................................................................................................................................................................................................................
      1055 Budapest Tel.: +36 1 391-1400 naih.hu/adatkezelesi-tajekoztatok
      9–11 Falk Miksa Street KR ID: 429616918 ugyfelszolgalat@naih.hu 2




10,000,000 HUF, that is, ten million forints
                                           data protection fine


.

 * * *

 The Company must take the measures prescribed in Section 2 within

      , together with supporting evidence,
to the Authority.

      The data protection fine must be paid within 30 days of this decision becoming final to the
Authority’s forint account for the collection of centralized revenues (10032000-

      01040425-00000000 Centralized Collection Account, IBAN: HU83 1003 2000 0104 0425
 0000 0000). When transferring the amount, please reference case number NAIH-4462/2026. BÍRS.
.

If the Company fails to meet its obligation to pay the data protection fine by the deadline, it

      it shall be required to pay a late payment penalty to the above account number. The late payment penalty shall be equal to the statutory
interest rate, which corresponds to the central bank’s
base rate in effect on the first day of the calendar half-year affected by the delay.

      In the event of failure to comply with the obligations set forth in Section 2, as well as failure to pay the data protection fine and the

late payment penalty, the Authority shall order the enforcement of this decision.

      There is no right to administrative appeal against this decision; however, it may be challenged in administrative
 court by filing a complaint addressed to the Budapest Metropolitan Court
 within 30 days of notification. The complaint must be submitted to the Authority electronically, which

will forward it to the court together with the case files. A request for a hearing must be
indicated in the complaint. For those not eligible for full exemption from personal fees,
the administrative court fee is 30,000 HUF; the case is subject to the right to record a fee entry. Legal representation is mandatory
in proceedings before the Budapest
Regional Court.




                                             STATEMENT OF REASONS



 I. Course of the Proceedings

 I.1. The Administrative Inspection


(1)   On April 9, 2025, the Authority decided to initiate an administrative inspection regarding the data processing activities of the online store operating on the […] website
      , covering preliminary information regarding compliance with the
General Data Protection Regulation, under case number NAIH-9722/2025.

(2)   On June 16, 2025, the Authority conducted an unannounced inspection, which consisted of

viewing the website, making backups, and performing a test registration.




      1. The form designated NAIH_K01 is used to initiate administrative proceedings: NAIH_K01 form (September 16, 2019)
      The form can be filled out using the general form-filling program (ÁNYK program).
 The form is available at the following link: https://naih.hu/kozig-hatarozat-birosagi-felulvizsgalata 3


(3)   After reviewing the Website, the Authority identified a suspected violation regarding
 the adequacy of the data processing notice related to the operation of the online store.


 I.2. Administrative Proceedings

(4)   The Authority concluded its official inspection and, pursuant to Section 60 (1)

, on October 28, 2025, under case number NAIH-15138/2025, initiated a data protection
procedure covering the Website’s data processing
practices, specifically the data processing notice
      authority proceeding, in which it also utilized data and documents from previous official inspections and audits.
 The proceeding did not extend to examining other data protection requirements,
 nor to a comprehensive review of the Company’s data processing procedures.


(5)   The Authority may examine compliance with the provisions of the General Data Protection Regulation—applicable as of May 25, 2018—
. The Authority refrained from examining the period
 prior to January 1, 2020.

(6)   The period under review lasted until the initiation of this proceeding; therefore, the period following
 the initiation of the proceeding is not included.


(7)   Based on the foregoing, the period under review extends from January 1, 2020, to the date of initiation of this proceeding, that is,
 October 28, 2025.

      I.2.1. Clarification of the Facts

(8)   In its order dated October 28, 2025, case number NAIH-15138-2/2025,
      notified the Company of the initiation of the data protection authority proceedings and

called upon it to submit a statement for the purpose of clarifying the facts.

(9)   In its response letter dated November 17, 2025, filed under case number NAIH-15138-4/2025,
the Company stated that during the period under review, it generated the data processing documentation using the […] system
      and embedded them into the Website from there. According to its statement, the documents
were up to date; however, due to a change in the external service provider’s system
      caused the embedding to “malfunction,” so the privacy notice did not appear on the Website. As a

result, the relevant content was not accessible via the “Privacy Policy” link
      was also unavailable.

(10) They were unable to determine the exact time the error occurred, as it was related to a
 modification to the external service provider’s system, about which they had not received separate notification.
      However, they stated that upon detecting the error, they took immediate steps to correct it, and currently

 the privacy notice is directly and independently accessible on the Website.

(11) The Company further emphasized that, in its opinion, the error may have occurred after March 2025, during a one-year
re-deployment process, and that it had no intention of misleading the data subjects or
providing them with incomplete information.


(12) According to the Company’s statement, during the period under review, there were no
GTCs published as separate versions that differed substantially from one another. Based on its presentation, the Company applied the
GTC generated by the […] system, which was automatically updated as part of the service to reflect
changes in legislation. Accordingly, the Company did not maintain separate versions, and was unable to submit any earlier
GTC documents with different content.


(13) According to its statement, the Company uses cookies that are technically necessary on the website, as well as
 […] cookies for statistical and marketing purposes related to its services, and […] 4


 related cookies. It stated that the use of non-essential cookies is
based on the prior consent of the data subjects, and that information regarding these cookies was

included in the privacy policy, which was available via a separate link. 

(14) At the same time, the Company expressly acknowledged that, during the period under review, the cookie
notice was not displayed in an appropriate, standalone format on the Website. According to the Company’s statement,
      following the Authority’s inquiry, it introduced a cookie management solution that appears
 upon the first visit, allows users to accept or

 reject cookies by category, and ensures that, in the absence of consent, only strictly necessary
      will function.

(15) Users may withdraw their consent via the cookie management interface or through their browser
settings. The Company also indicated that it had not received

      it had not received any specific technical recommendations regarding the implementation of cookie management.

(16) In the Company’s view, the primary cause of the incomplete or inadequate information
was the same technical error that also affected the availability of the privacy notice.
      It explained that it used a single, comprehensive document in its […] system, which
included the data controller’s identification details, the purpose and legal basis of data processing, the

      rights of data subjects, the legal framework, and the relevant
provisions of the General Terms and Conditions.

(17) According to the Company, due to a fault in the external system, this document was either not
      or was not properly available on the Website; therefore, the detailed information was not actually
accessible. The error was corrected upon discovery, and as a result, the

data processing information has once again become fully and transparently available on the
      Website.

(18) The Company uses a simple pre-entry declaration mechanism, under which
the visitor declares whether they are over or under 18 years of age. It was explained that,
during the operation of the system, no date of birth or other personal data is requested;

access is granted or denied solely based on the user’s declaration, and no
separate data fields need to be filled out.

(19) In his view, the age verification process does not involve data processing capable of identifying the data subject;
the solution serves exclusively a functional purpose, namely
      restricting access to alcoholic beverages. A brief notice appears on the interface

stating that the site is accessible only to those 18 years of age or older, and by accessing the site, the user
declares that they are of legal age.

(20) The Company provided annual, estimate-based data on visitors to the Website,
according to which […] people visited the site in 2020, […] in 2021, […] people, in 2023 […] people, in 2024
 […] people, and in 2025 […] people visited the site. The number of customers, i.e., the number of orders,

      during the same period was […] in 2020, […] in 2021, […] in 2022, […]
      people, […] people in 2024, and […] people in 2025.

(21) The Company attached several screenshots to support its statement. These include, on the one hand,
 an email dated March 6, 2025, which states that during the use of the embedded
 codes, an “error message 1002” appeared, caused by a discrepancy in the domain names
      ([…] and […]), which may have led to the embedding not functioning properly. Furthermore, based on the attached

invoice, it can be established that on March 5, 2025, the Company
      for the […] service, which covered the use of two domains ([…] and […]). 5


(22) The Company also attached additional correspondence in which, during communication with the web service provider,
      also raised technical issues related to the settings and subscription restrictions,

in connection with which the system displayed error code “1002.”

(23) In its order dated November 24, 2025, case number NAIH-15138-5/2025, the Authority
called upon the Company to submit a further statement in order to clarify the facts of the case. The Authority requested
 that the Company verify what privacy notices it provided during the period under review,
 and identify the previous

      , their scope of application, and the date of their publication, and to attach the documents containing substantive amendments
and proof of their publication. The Authority also requested
      that the attached form be used for each document in the response.

(24) In its response dated December 11, 2025, registered under No. NAIH-15138-6/2025,
      submitted a single completed form without a statement, which contained data exclusively regarding the GTC

document. On the form, the Company indicated the versions effective as of July 1, 2016,
      and the version effective as of February 23, 2022, noting in the latter
case that a comprehensive, uniform amendment had been made. As proof of publication, the Company
      provided URL links and Wayback Machine archives.


(25) In its order dated March 17, 2026, case number NAIH-4462-1/2025, the Authority
      called upon the Company to submit a further statement in order to clarify the facts of the case, and
 urged it to submit all documents and technical information on the basis of which
 the duration of the occurrence or existence of the error related to the display of the privacy notice on the Website
      could be approximately determined, and
 once again requested a detailed description of the content of the privacy notice, the scope of document versions,
 their validity, publication, and amendments, as well as
      verification of the relevant documents and their publication.


(26) In its response dated April 2, 2026, filed under reference number NAIH-4462-2/2025, the Company
      that it had already submitted to the Authority all documents at its disposal, as well as
the materials obtained from the IT specialist responsible for operating the Website.
According to the Company, it is unable to obtain any further documents, and

      in his view, he had already answered the Authority’s questions to the best of his knowledge.

(27) In its order No. NAIH-4462-3/2026, dated April 7, 2026, the Authority informed the
      Company that the evidentiary proceedings had been concluded and that it could review the evidence uncovered during the clarification of the facts
in accordance with the rules governing access to documents and could submit further

motions for evidence.

(28) The Company did not state that it intended to exercise its right to inspect the documents, nor did it make

any further motions for evidence.

 I.2.2. Established Facts

(29) During its examination of the Website, the Authority found that no

separate privacy policy compliant with the GDPR was available on the Website. Although the Website did feature
a link titled “Privacy Statement,” during the Authority’s inspection, this
      link did not lead to an accessible data processing notice. The Authority therefore proceeded from the premise in its Order No. NAIH-15138-

 2/2025 that no
      accurate, understandable, and transparent privacy policy available to data subjects. 6


(30) The Authority subsequently examined earlier, archived versions of the Website. Based on the Wayback Machine backups from

      September 21, 2020, and October 25, 2021, the Privacy
 Policy subpage was available at that time, but it contained only a brief, general privacy
 policy. According to the essence of this statement, the Company used personal data to

 fulfill orders, issue invoices, send newsletters (with consent),
      and, in the case of package delivery, […] to transfer data to a courier service.
 However, the statement did not separately list, for each data processing activity, the mandatory information required under Article 13 of the GDPR

      , in particular the specific purpose,
legal basis, retention period, and recipients of each data processing activity, as well as the detailed
procedures for exercising the data subject’s rights.


(31) Based on the archived version as of May 27, 2022, the Authority also found that the
Privacy Policy subpage was no longer accessible at that time, but
led to a “404 – Not Found” error. This indicates that the privacy

notice on the Website was not only incomplete in terms of content at certain points in time, but was also
completely inaccessible at other points in time.


(32) The Authority also reviewed the archived versions of the General Terms and Conditions. The versions of the GTC dated September 27, 2020, and
June 17, 2021, contained a chapter on data processing; however, these
data processing provisions did not differ in substance, and both documents

      were published as the GTC effective as of July 1, 2016. This is consistent with the Company’s
statement that there were no GTCs published as separate versions that differed substantially from one another
.


(33) Although the section on data processing in the GTC did contain certain data protection information,
it was not sufficient to fulfill the information obligation under the GDPR. Rather than
presenting the circumstances of data processing in a separate and clear structure

related to each specific instance of data processing, it used general, partly boilerplate, and outdated
wording. It presented the legal basis for data processing and the rights of data subjects partly
based on the former logic of the Information Act, referred to registration in the

data protection registry, and furthermore did not contain comprehensive information differentiated by each data processing activity, as required
      .


(34) In its statements, the Company claimed that it applied the General Terms and Conditions (GTC) generated by the […] system,
which, according to the Company, were automatically updated as part of the service. It further
stated that it did not maintain separate versions and was unable to submit an earlier version of the GTC

with different content. The Company attributed the error regarding the availability of the disclosure
to a technical problem; however, it was unable to substantiate with documentation the exact time the error occurred,
its duration, or its progression. 


(35) Despite repeated requests from the Authority, the Company failed to submit a data processing notice
or version control document that would have made it possible to determine exactly what information regarding data processing was available to data subjects
      exact content of the privacy notice available to data subjects

during the period under review, its effective dates, when it was published, and when and how
 its content was amended. Subsequently, the Company expressly stated that it had already submitted
      documents at its disposal had already been submitted, and it had no

possibility of obtaining additional documents. 7


(36) To summarize the above, according to the facts established by the Authority, the Company’s data processing

      practices were problematic on three levels. 1. During the Authority’s inspection, no
standalone data processing notice was available. 2. The previously archived Privacy Statement was merely
      a brief, general text that did not fully include the content required under Article 13 of the GDPR

. 3. The data processing section included in the General Terms and Conditions did not remedy this deficiency, as it did not
      provide differentiated, up-to-date, and GDPR-compliant information for each specific data processing activity.


 I.2.2.1. Identity of the Data Controller


(37) The Company is the operator of the Website and the domain holder.

(38) The Company’s primary activity is “wholesale of beverages.”

(39) Pursuant to Section 3 of Act XXXIV of 2004 on Small and Medium-Sized Enterprises and the Support of Their Development,
      , a microenterprise is defined as an enterprise with a total number of employees
of fewer than 10 and annual net sales or total assets not exceeding the forint equivalent of 2

million euros. According to available data, in 2025
 the Company employed […] people, and its annual net sales were […] HUF, based on which the Company
 qualifies as a small enterprise.

 I.2.2.2. The Data Processing Notice Published on the Website

(40) During the administrative proceedings, the Company did not submit a

data processing notice for the period under review that would have allowed for a substantive assessment
      could have been substantively assessed. The Company did not verify what specific
content the notice on the Website contained, nor did it provide supporting documentation regarding its
publication, scope, and amendments.

(41) The Authority examined the Company’s data protection

notification practices based on the available evidence—in particular, the forensic
backups of the Website and the archived versions of the Website. According to the archived content, a link titled
 “Privacy Statement” was available on the Website, which was a brief, general description. The document
 did not contain the mandatory information elements required under Article 13 of the GDPR; for further details
      , it directed users to the link for the General Terms and Conditions. Its content
reads as follows: “PRIVACY STATEMENT—The personal
      (name, address, phone number, etc.) and your user data will be processed in accordance with the Data Protection Act
solely for the purpose of issuing the invoice necessary to fulfill the order you placed

      and, with your consent, for our own advertising purposes (newsletter). We
will not disclose the data to any third parties other than the […]
courier service, which is necessary to fulfill the specific order (i.e., in the case of package delivery). The transfer of data to third parties
may only take place with your prior, explicit consent.
For a detailed description, please see our General Terms and Conditions! ([…])” (emphasis
 added by the Authority).


(42) The content of subsequent archived versions remained essentially unchanged; however, the Authority
 also identified an archived version in which the Privacy Policy was
      not available at all, and the link led to a “404 – Not Found” error. This latter archived version—from 2022—
indicates that, during part of the period under review, the Company also failed to
      provided accessible privacy information to data subjects.


(43) The Authority found that previously, the General Terms and Conditions (as per the annex to Memorandum No. NAIH-9722-3/2025
      , as of June 2, 2025, hereinafter: GTC) also contained, albeit sporadically,
 brief provisions on data protection and data processing.                                                  8




(44) The first page of the GTC listed the hosting provider’s details; page 5 contained
general statements regarding the storage of digital content in the database and the
      encryption and encoding of “sensitive data,” as well as
 information in the description of the purchase process stating that the customer could choose
 between an order method requiring registration and one that did not involve saving data. On page 6
of the GTC, under the heading “Data Processing Notice,” the data controller’s identification details and
contact information were listed, and a separate section titled “The

      : legal framework, legal basis, purpose, scope of personal data processed, and duration of data processing
,” but no substantive, case-by-case explanation of the data processing activities was provided under this heading.
      On pages 6–7 of the GTC, there is general information regarding the use of cookies, the section titled “Additional
Data Processing Activities,” and the section on data processors—left blank
      with no names or contact information for data processors—data security measures,
data subjects’ rights, the Authority’s mailing address and email address, as well as
information regarding registration in the data protection registry
      .


(45) The Authority also examined other sections of the Website; however, information regarding the essential
circumstances of data processing was not available on other pages or under other menu items.

(46) The Authority also examined other sections of the Website and the purchasing process in

order to determine what operations involving the processing of personal data actually take place
on the Website. In its memorandum No. NAIH-9722-2/2025, the Authority determined
that the Website also allowed private individuals to place orders and
register. Several types of purchasing processes were available on the Website: logging in
as a registered customer,   placing an order without registration,   and   placing an order    with a new
registration. During the “placing an order with a new registration” process, the required
information included full name, phone number, email address, ZIP code, city, street, and
house number, as well as a password. The order interface also offered the

option to subscribe to a newsletter; however, this was not a mandatory part of the purchasing process.

(47) The Authority further found that on the data entry page during the purchasing
process, there was a checkbox for accepting the General Terms and Conditions, and
accepting this was a prerequisite for a successful order. However, based on the available screenshots,
no separate notice regarding the essential circumstances of personal data processing appeared
during the order process involving registration,

      , nor was there any separate information element that would have drawn the data subject’s attention to
 the purpose, legal basis, duration, and recipients of the data processing, or to the data subject’s rights
. Users were required to accept the General Terms and Conditions (GTC) during the purchase process;
however, the Authority found that the data processing provisions contained in the GTC
      did not provide the comprehensive and easily understandable information required for each specific data processing activity
under Article 13 of the GDPR.


(48) Based on the foregoing, the Authority determined that the Website did in fact
      personal data processing on the Website, at least for the purposes of registration, order fulfillment, invoicing,
maintaining contact, shipping, creating a user account, and, optionally,
subscribing to the newsletter. In contrast, no privacy notice was made available to data subjects on the Website
that would have described these actual data processing operations
for each specific processing activity in a clear and comprehensive manner.



 II. Applicable Legal Provisions

(49) Pursuant to Article 2(1) of the General Data Protection Regulation, the General Data Protection
Regulation applies to the processing of personal data, whether fully or partially automated,
as well as to the non-automated processing of personal data 9


      that form part of a filing system or are intended to
be included in a filing system.


(50) Pursuant to Section 2(2) of the Information Act, the General Data Protection Regulation shall be applied with the
supplements specified in the provisions indicated therein.

(51) Pursuant to Section 38(2) of the Information Act, the Authority is responsible for monitoring and promoting the protection of personal data,
as well as the right of access to data of public interest and data made public in the public interest,
      , as well as to promote the free flow of personal data

within the European Union.

(52) Pursuant to Section 38(2a) of the Information Act, the duties and powers established for the supervisory
      shall be exercised by the Authority with respect to legal entities subject to the jurisdiction of Hungary,
as specified in the General Data Protection Regulation and this Act.


(53) Pursuant to Section 38(3)(b) of the Information Act, within the scope of its responsibilities under Sections 38(2) and (2a),
as specified in this Act, the Authority shall, in particular, upon the request of the data subject and
      ex officio, data protection authority proceedings. 

(54) Pursuant to Section 60/A(1) of the Information Act, the administrative
deadline in proceedings before the data protection authority is one hundred and fifty days.


(55) Pursuant to Section 60(1) of the Information Act, in order to ensure the enforcement of the right to the protection of personal data,
the Authority shall initiate a data protection authority proceeding upon the data subject’s request to that effect and
may initiate such a proceeding ex officio.

(56) Pursuant to Section 71(2) of the Information Act: “The Authority may use documents, data, or other means of evidence lawfully obtained

 during its proceedings in other proceedings.”

(57) Pursuant to Section 99 of Act CL of 2016 on General Administrative Procedure (hereinafter: Ákr.)
, the Authority—within the scope of its jurisdiction—shall verify compliance with the
      and the fulfillment of the provisions set forth in enforceable decisions.

(58) Pursuant to Section 103(1) of the Ákr., in ex officio proceedings, the provisions of this Act applicable to

      shall apply, subject to the exceptions set forth in this chapter.

(59) Pursuant to Article 4(1) of the General Data Protection Regulation: “personal data” means any information relating to an identified
      or identifiable natural person (“data subject”);
an identifiable natural person is one who can be identified, directly or indirectly, in particular
by reference to an identifier such as a name, an identification number, location data, an online identifier, or to the
      one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social

identity of that natural person.”

(60) According to Article 4(2) of the General Data Protection Regulation: “processing” means any
      data or data sets, whether by automated or non-automated means,
 including collection, recording, organization, structuring, storage,
      adaptation or alteration, retrieval, consultation, use, disclosure by transmission,
dissemination or otherwise making available, alignment or

combination, restriction, erasure, or destruction.”

(61) Pursuant to Article 4(7) of the General Data Protection Regulation: “controller” means the natural
or legal person, public authority, agency, or any other body that
      determines the purposes and means of the processing of personal data, either alone or jointly with others
; where the purposes and means of processing are determined by Union or Member State law 10


      , Union or Member State law may also specify the controller or the specific criteria for designating the controller.”


(62) Pursuant to Article 5(1)(a) of the General Data Protection Regulation: “The processing of personal
data:
(a) must be carried out lawfully, fairly, and in a transparent manner in relation to the data subject
(“lawfulness, fairness, and transparency”);”

(63) According to Article 5(2) of the General Data Protection Regulation: “The controller shall be responsible for

      and must be able to demonstrate such compliance
 (“accountability”).”

(64) Pursuant to Article 12(1)–(6) of the General Data Protection Regulation: “(1) The controller
 shall take appropriate measures to ensure that the data subject is provided with all information
 regarding the processing of personal data referred to in Articles 13 and 14, as well as all information provided pursuant to Articles 15–22 and
      34, in a concise, transparent, intelligible, and easily accessible

form, using clear and plain language, particularly in the case of any information
addressed to children. The information must be provided in writing or by other means—including,
where appropriate, by electronic means. At the request of the data subject, oral information
may also be provided, provided that the identity of the data subject has been verified by other means.”

(65) According to Article 13 of the General Data Protection Regulation: “(1) Where personal data relating to a data subject
 are collected from the data subject, the controller shall, at the time of obtaining the personal data,

 provide the data subject with all of the following information:
      a) the identity and contact details of the data controller and, where applicable, the data controller’s representative;
 b) the contact details of the data protection officer, where applicable;
      c) the purposes of the intended processing of personal data and the legal basis for the processing;
 d) in the case of processing based on Article 6(1)(f), the legitimate interests of the controller or
 a third party;
      e) where applicable, the recipients or categories of recipients of the personal data, if any;

 f) where applicable, the fact that the controller intends to transfer personal data to a third country or to an international
 organization, as well as the existence or absence of a Commission
      adequacy decision, or, in the case of a transfer referred to in Article 46, Article 47, or
the second subparagraph of Article 49(1), an
      appropriate and suitable safeguards, as well as a reference to the means of obtaining copies of them
 or to their availability.
 (2) In addition to the information referred to in paragraph (1), the data controller shall,

      at the time of collection, in order to ensure fair and transparent
data processing, the data controller shall inform the data subject of the following additional information:
      a) the period for which the personal data will be stored, or, if this is not possible, the criteria
 used to determine that period;
 b) the data subject’s right to request from the data controller access to personal
      , to have it rectified, erased, or restricted, and
to object to the processing of such personal data, as well as

the data subject’s right to data portability;
      (c) in the case of processing based on Article 6(1)(a) or Article 9(2)(a),
 the right to withdraw consent at any time,
      which does not affect the lawfulness of the processing carried out on the basis of consent prior to withdrawal;
      d) the right to lodge a complaint with a supervisory authority;
 e) whether the provision of personal data is required by law or based on a contractual obligation,

      or is a prerequisite for entering into a contract, whether the data subject is required to
provide the personal data, and the possible consequences of
failing to provide such data; 11


      f) the existence of automated decision-making referred to in Article 22(1) and (4), including
 profiling, as well as, at least in these cases, the logic applied and

      , the significance of such processing, and the
expected consequences for the data subject.
(3) If the data controller intends to further process personal data for a purpose other than that for which they were collected
      , the controller must, prior to such further processing, inform the data subject
of this different purpose and of all relevant additional information referred to in paragraph (2).
      (4) Paragraphs (1), (2), and (3) do not apply if and to the extent that the data subject already
 possesses the information.”


(66) Pursuant to Article 22 of the General Data Protection Regulation: “(1) The data subject has the right not to
be subject to a decision based solely on automated processing—including profiling—
that produces legal effects concerning him or her or similarly significantly
      .
 (2) Paragraph (1) shall not apply where the decision:
 a) is necessary for the conclusion or performance of a contract between the data subject and the data controller

;
      (b) is authorized by Union or Member State law to which the data controller is subject,
 which also provides for appropriate measures to safeguard the data subject’s rights, freedoms, and legitimate interests;
 or
      c) is based on the data subject’s explicit consent.
 (3) In the cases referred to in points (a) and (c) of paragraph (2), the data controller shall take appropriate
 measures to protect the data subject’s rights, freedoms, and legitimate interests

      , including, at a minimum, the data subject’s right to request human
 intervention by the data controller, to express his or her point of view, and to object to the decision.
      (4) The decisions referred to in paragraph (2) may not be based on special categories of personal data
 referred to in Article 9
 (1), unless points (a)
      or (g) of Article 9(2) applies, and appropriate measures have been taken
 to protect the data subject’s rights, freedoms, and legitimate interests.”


(67) Pursuant to Article 58(2) of the General Data Protection Regulation: “The supervisory authority,
 acting in its corrective capacity, shall:
 (a) issue a warning to the controller or processor that certain proposed data processing
 activities are likely to infringe the provisions of this Regulation;
      (b) issue a reprimand to the controller or processor if its data processing activities
 have infringed the provisions of this Regulation;
 (c) order the controller or processor to comply with the data subject’s request

      ;
 d) order the controller or processor to bring its data processing operations into compliance with the provisions of this Regulation,
 where applicable, in a specified manner and within a specified time frame;
      […]
 i) impose an administrative fine in accordance with Article 83, depending on the circumstances of the case,
 in addition to or in lieu of the measures referred to in this paragraph; and

      j) order the suspension of data flows to a recipient in a third country or to an international organization
.”

(68) Pursuant to Article 83(2) and (5) of the General Data Protection Regulation: “[…]
      (2) Administrative fines shall be imposed, depending on the circumstances of the case, in addition to or in lieu of the measures referred to in Article 58(2)
(a) through (h) and (j). 
      When determining whether an administrative fine should be imposed, and when

 setting the amount of the administrative fine, due consideration must be given in each individual case
 to the following: 12


      a) the nature, gravity, and duration of the violation, taking into account the nature, scope, or purpose of the data processing
 in question, as well as the number of data subjects affected by the violation and the

      extent of the damage suffered by them;
 b) whether the infringement was intentional or negligent;
 c) any measures taken by the data controller or data processor to mitigate
 the damage suffered by the data subjects;
      d) the degree of liability of the data controller or data processor, taking into account the
 technical and organizational measures implemented by them pursuant to Articles 25 and 32;
      e) any relevant prior infringements committed by the controller or processor;

 f) the extent of cooperation with the supervisory authority to remedy the infringement and mitigate any negative effects of the infringement;
      ;
 g) the categories of personal data affected by the breach;
 h) how the supervisory authority became aware of the breach, with particular regard to
      whether the data controller or data processor reported the breach, and if so, to what
degree of detail;
 i) whether any of the measures referred to in Article 58(2) had previously been ordered against the data controller or data processor in question—in the same

      matter—compliance with the
measures in question;
      j) whether the data controller or data processor has complied with
 approved codes of conduct under Article 40 or approved certification
 mechanisms under Article 42; and
      k) other aggravating or mitigating factors relevant to the circumstances of the case,
such as financial gain

or avoided loss resulting directly or indirectly from the infringement.
      […]
 (5) Violations of the following provisions shall be subject—in accordance with paragraph (2)—to an administrative fine of up to 20
,000,000 EUR, or, in the case of undertakings, to a fine
      up to 4% of the total annual worldwide turnover in the preceding fiscal year,
whichever is higher:
      (a) the principles of data processing—including the conditions for consent—in accordance with Articles 5, 6, 7, and 9;

(b) the rights of data subjects in accordance with Articles 12–22;
      (c) the transfer of personal data to a recipient in a third country or to an international organization
 in accordance with Articles 44–49;
 (d) obligations under Member State law adopted pursuant to Chapter IX;
      e) failure to comply with an instruction from the supervisory authority pursuant to Article 58(2), or with a

      or, in violation of Article 58(1), a failure to grant access;
 […]”
[…]”

(69) Directive 2002/58/EC of the European Parliament and of the Council of July 12, 2002, concerning the
 processing of personal data and the protection of privacy
      (“Electronic Communications Privacy Directive”) Article 5(3) provides: “Member

States shall ensure that the storage of data in a subscriber’s or user’s terminal equipment
      is permitted only on the condition that
 the subscriber or user concerned has given his or her prior consent, based on clear and comprehensive information—including, inter alia, the purposes of the data processing—provided in accordance with Directive 95/46/EC
      —including, among other things, information on the purposes of the data processing—
has given his or her prior consent. This provision does not preclude
 technical storage or technical access whose sole purpose is the transmission of communications
 via an electronic communications network, or which is

      user has expressly requested, and which is strictly necessary for the provider to
provide an information society service.” 13


 III. Decision


      III.1. The Requirement for Prior Information on Data Processing

(70) The purpose of the information obligations set forth in Articles 12–14 of the General Data Protection Regulation
 is to ensure that the data subject can
      in advance and can monitor the processing throughout its entire duration
. The GDPR ensures this in several ways and regulates the right to information
. These rights enable data subjects to review the processing

      it begins, to effectively monitor it throughout its
entire duration, and to exercise any additional rights they may have or
seek legal remedies.

(71) The system of appropriate information in the General Data Protection Regulation serves to ensure that
the data subject is aware of which of their personal data will be processed, by which data controller, for what
purpose, on what legal basis, and for how long. This is essential to ensure that the
      to be in a position to effectively exercise their rights as data subjects.

(72) Pursuant to Article 12(1) of the General Data Protection Regulation, the data controller shall take appropriate

measures to ensure that the data subject is provided with all information relevant to the processing of personal data
      , as referred to in Articles 13 and 14, and all information
 required under Articles 15–22 and 34,
 in a concise, transparent, intelligible, and easily accessible
      , expressed clearly and in plain language. Incomplete or
ambiguous information—particularly, but not exclusively, regarding the purpose and legal basis—
may directly affect the data subject’s ability to exercise their rights.


(73) Articles 13 and 14 of the
General Data Protection Regulation set forth the requirements, content, and specific rules regarding information, based on two aspects. On the one hand,
 Article 13 governs the information to be provided when personal data is collected from the data subject by
 data controllers; on the other hand, Article 14 sets forth the rules for situations where personal data
 was not obtained from the data subject by the data controllers.

(74) With regard to data processing by online stores, since personal data is

 collected from the data subjects, a central element of the obligation to provide information is
      Regulation, which lists the essential data processing
circumstances about which the data controller must provide information.

(75) In the context of prior information, the data controller must strive to ensure that data subjects
receive as complete and accurate a picture as possible of the processing of their personal data, since only
in this way can they assess how a given data processing operation affects them. Paragraphs

(1) and (2) of Article 13 of the General Data Protection Regulation specify the
minimum information regarding the circumstances of data processing that data controllers must provide to
      data subjects; however, this does not preclude the data controller from providing
 more detailed information.


 III.2. The Data Processing Notice Published on the Website



(76) The Authority found that, for the period under review, the Company failed to demonstrate
that it had provided data subjects with a privacy notice containing the information required under Article 13 of the GDPR. Despite the Authority’s repeated requests, the Company did not

submit a privacy notice or any other document from which the specific content of the privacy notice
applied during the period under review, as well as its effective start and end
      dates, the method of publication, and any amendments could be traced 14


. The Company expressly stated that it had already submitted all
      documents at its disposal, and that it has no means of obtaining additional documents, from which it

follows that it cannot provide further evidence supporting compliance with the obligation to provide information
.

(77) At the same time, the Authority examined the available electronic evidence—in particular the
forensic backups of the Website (Record No. NAIH-15138-3/2025) and the

      archived versions of the website (Annex to Order No. NAIH-15138-2/2025)—
 to examine the content actually available on the Website. The archived documents examined constitute the annexes to Record No. NAIH-9722-
 3/2025. Of the available archived

snapshots, the Authority examined in particular those recorded on September 21, 2020, and October 25, 2021.


(78) In the above snapshots, the Privacy Policy subpage was accessible; however, it contained only
 brief, general information with the following content: “The personal data you provide
 (name, address, phone number, etc.) and your user data will be used, in accordance with the Data Protection
 Act, solely for the purpose of issuing the invoice necessary to fulfill the order you placed

      and, with your consent, for our own advertising purposes
 (newsletter). We will not transfer the data to any other third party—including
      to the […] courier service; we do not transfer it to any other third parties. The transfer of data to third parties

 may only take place after you have given your prior, explicit consent
.”


(79) The Authority found that this notice did not comply with the requirements set forth in Article 13(1)
of the GDPR. The notice did not include the
information necessary to identify the data controller or its contact details, nor did it provide

clear and differentiated information for each data processing activity regarding the purpose and
legal basis of the data processing. In the case of data processing related to billing, the controller failed to specify the
legal basis based on a statutory obligation, while for data processing for marketing purposes, the controller inaccurately defined the

legal basis of consent as “consent.” 

(80) The Authority further found that the notice did not identify the recipients of the personal data
with sufficient detail, as the reference to “[…] courier service” did not

      it possible to unambiguously identify the recipient or to assess its role
 in the data processing. Furthermore, the notice did not contain information regarding the retention period of the personal data
 or the criteria used to determine it.


(81) The Authority noted that the notice did not provide adequate information regarding the data subjects’
 rights and how to exercise them; it did not address the

      , the right to lodge a complaint with the supervisory authority, or the fact that the
provision of data is based on a legal obligation and the consequences of
      failure to do so; thus, the requirements set forth in Article 13(2) of the GDPR were not met either.


(82) The Authority further found that the information, by referring to the “Data Protection Act,”
      did not reflect the current legal framework.


(83) Based on the foregoing, the Authority determined that the Company violated Article 13
      (1)(a), (c), and (e), as well as Article 13(2)(a)–(e), and, due to the


      , due to the form and scope of the information provided, it also failed to meet the requirements set forth in Article 12(1) of the GDPR

.

(84) The Authority found that the archived versions of the General Terms and Conditions available on the Website also contained a chapter on data processing
      . In this regard, the Authority examined the versions of the GTC archived on September 27, 2020,
 and June 17, 2021. A comparison of the two documents

      reveals that they contain no discrepancies with regard to data processing provisions;
their structure and content are identical, and both were indicated as effective
as of July 1, 2016.

(85) The Authority notes, first and foremost, that the practice whereby the data controller provides
      as part of the General Terms and Conditions, embedded among other content elements,
 to data subjects. The requirement for transparent and easily accessible information

      that the data subject be able to access information regarding data processing in a single location, in a uniform
structure, and in a targeted manner, even in a separate document. In contrast, in the present
case, the information regarding data processing appeared in the GTC, integrated into its structure,
      scattered throughout the GTC, even though a separate section titled “Privacy Policy”

existed on the Website; thus, the data subject could not reasonably be expected to search the GTC for additional material
details regarding data processing.


(86) In this regard, the Authority refers to paragraph 33 of WP260 rev.01, the WP29 guidelines on the application of Articles 13 and 14,
which states that the data controller must take active steps
      to make the information available to the data subject, and the data subject should not be expected

 to search for it among other information—such as general terms and conditions—
 on their own. According to the guidelines, the privacy notice must be available in one place or in a
single document, in an easily accessible manner.


(87) The Authority further found that the content of the data processing section of the GTC did not
meet the requirements under the GDPR. The document did not describe with sufficient

 detail and clarity what data processing activities actually take place on the Website,
 for what specific purposes, on what legal basis, with what data transfers, and
 for what duration. The Authority found that the GTC did not contain the
 information required under Article 13(1)(c) and (e) of the GDPR, specifically the

 specific purpose and legal basis of each data processing activity, as well as the exact scope of recipients. Furthermore, the document
did not comply with the requirements set forth in Article 13(2)(a), (c), and (e)
either, as it did not specify the retention period for personal data or the criteria for determining

      , the detailed procedures for exercising the data subject’s rights, and the
basis for the data disclosure   as well as the
consequences of failure to comply. The Authority further notes that although certain parties—in particular the

hosting provider—were mentioned in the GTC, it was not clearly
      defined whether these organizations participate in data processing as data controllers or
data processors, and certain sections pertaining to data processors

remained without content.

(88) The section on data processing contained general categories and a general description

regarding cookies; however, it did not clarify exactly what types of
      cookies it actually uses, what legal basis applies to them, who the relevant recipients or 16


 third parties are, and how long the data processing lasts; thus, data subjects were unable to

 ascertain the actual content of the data processing in this regard either.

(89) The data processing notice included in the GTC presented the legal basis for data processing and the rights of data subjects
not based on the GDPR framework, but typically following the previous regulatory
logic of the Infotv. In this context, the legal basis for data processing related to cookies

was explicitly identified as consent pursuant to Section 5(1)(a) of the Information Act,
while the notice did not include a clear, data-processing-specific
      as required by Article 6 of the GDPR, for each specific data processing operation
. In the General Terms and Conditions, certain elements of the data processing notice appeared intermingled with copyright and
      other provisions not related to data processing; furthermore, under the
heading “Data Processing Notice,” in several instances only headings and lists appeared
without any actual content. The document is difficult to navigate and not sufficiently structured,

which suggests that the text was generated by an automated system and was not intended to
describe actual data processing practices.

(90) Although the information on data subject rights listed certain rights (in particular the
 rights to access, rectification, erasure, restriction of processing, and the right to object),
      its presentation did not follow the structure and substantive requirements set forth in the GDPR

. The notice applied legal concepts and an approach characteristic of the Infotv.,
      specifically by mentioning the right to “blocking” and by including
references to the provisions of the Infotv., and furthermore, it did not define the deadlines and conditions for exercising these rights in accordance with
      in accordance with Article 12(3) of the GDPR.

(91)  The Company referred in the GTC to the obligation to register with the data protection registry. The information provided in this regard, citing the provisions of the Information Act, gives the

impression that data processing activities are linked to some official registry.

(92) The Authority notes that the legal institution of the data protection registry ceased to exist on May 25, 2018,
with the entry into force of the GDPR; thus, the reference thereto during the period under review
is considered obsolete. Information of this nature is likely to give data subjects
the impression that the data processing is listed in an official registry

or has undergone official inspection or approval.

(93) The Authority notes that even prior to its termination, the data protection registry did not
certify the lawfulness of data processing; it served solely to record data processing activities
. In light of this, reference to the defunct legal institution in the present case
 is unnecessary and misleading. The Authority further found that the supervisory authority’s

 contact information was not listed up to date, as the General Terms and Conditions contained an outdated mailing address
.

(94) The Authority emphasizes that, when providing information, the data controller is required to omit any
 information that does not comply with the applicable legal framework or that distorts the actual situation
. The reference to the discontinued data protection registry constitutes such information; therefore,

its inclusion does not comply with the information requirements under the GDPR.

(95) In the Authority’s view, based on the foregoing, it cannot be established that the Company,
during the period under review, ensured the accessibility of information regarding data processing
in accordance with the requirements set forth in Article 12(1) of the GDPR. Under
 that provision, the data controller is required to provide the information to data subjects
 in a form that is easily accessible, transparent, and understandable. In contrast, in the present

 case, the Company was unable to demonstrate the existence and content of a privacy notice
      privacy notice with appropriate content and that could be identified in a timely manner. The Authority found that,
based on the available evidence, during certain phases of the period under review, only 17


      incomplete notices were available, which did not meet the requirements set forth in Article 13 of the GDPR,
while during other periods, no notice was available at all. The

      Authority notes that in the latter case, this is not merely a matter of incomplete information, but
 a complete failure to fulfill the obligation to provide information.

(96)  In the present case, the violation does not stem from specific
      deficiencies in a data processing notice with known content, but rather from the fact that the Company failed to demonstrate that it
had provided the information required under Article 13 to the data subjects at all. Based on the available
 evidence, only a general statement that did not contain the required elements

 could be identified; furthermore, during certain periods, a complete lack of information was
 established. 

(97) The Company did not demonstrate that, during the period under review, it had provided data subjects with the mandatory data processing notice
 required under Article 13 of the GDPR at all. However,
 based on the available evidence, it can be established that during certain
 periods, only a brief, general statement was available, which did not

      contained information regarding the data controller’s identification and contact details, did not
provide clear and differentiated information for each data processing activity regarding the purpose and
      legal basis for each data processing activity, and did not adequately identify the recipients of the personal data, the
retention period or the criteria for determining it, as well as information regarding the data subject’s rights, the
exercise of those rights, and the right to lodge a complaint with the supervisory authority. Based on all of the above
      , the Authority found that the Company had violated Article 13(1)
(a), (c), and (e) of the GDPR, as well as the requirements set forth in Article 13(2)(a)–(e).


      III.3. The Principle of Transparency

(98) Article 5(1)(a) of the General Data Protection Regulation stipulates that personal
      data must be processed lawfully, fairly, and in a manner that is transparent to the data subject
. The requirement of transparency means that, based on the information provided,
the data subject must be able to effectively understand and grasp the purposes for which their personal data is processed, the

      legal basis, and under what circumstances their personal data is processed, who is involved in the processing, and
how they can exercise their rights.

(99) In the Authority’s view, merely
      formally comply with the information obligations set forth in Articles 12–13 of the GDPR; rather,
it requires that the data processing as a whole be effectively traceable,
understandable, and interpretable for data subjects. The requirement of transparency thus extends to the

entire data processing practice and encompasses the accessibility of the information, the
clarity of its content, and its continuity over time.

(100) The Authority found that the Company’s data processing disclosure practices during the period under review
were not suitable for enabling data subjects to understand the data processing. Based on the
available evidence, the information was incomplete during certain periods and
      periods it was entirely absent, meaning that data subjects did not have access to

consistent and comprehensive information regarding data processing.

(101) The Authority took into account that certain documents available on the Website—in particular
the section on data processing contained in the General Terms and Conditions—were not suitable for remedying this deficiency. The data processing provisions
contained in the General Terms and Conditions did not present the
      circumstances of data processing in a separate and unambiguous structure, but rather    used general, partly formulaic, and partly outdated

wording. Although the document contained certain identifying
information, as well as a general description of cookies and certain data subject rights, it
      it did not provide data subjects with clear information that was differentiated by data processing activity and aligned with actual
operations. 18




(102) The Authority emphasizes that, based on the content of the data processing notice, the legal bases for the individual data processing
      operations could not be clearly identified. The notice
did not clearly assign a legal basis under Article 6(1) of the GDPR
to each data processing purpose. In the Authority’s view, as a result of these shortcomings, the
notice does not meet the requirement that data subjects
be able to clearly understand the legal basis
on which their personal data is processed.


(103) Transparency is further undermined by the fact that the content of the available documents
was not based on the framework of the GDPR but partly reflected the previous provisions of the Information Act
. The outdated references to legislation and the structure that does not follow the logic of the GDPR
combined result in the information provided being unsuitable for a
clear and up-to-date presentation of data processing practices.


(104) In the Authority’s view, the circumstances identified collectively indicate that the Company
failed to ensure that the information was designed and operated at a level that would have guaranteed
its substantive adequacy, up-to-date status, and continuous availability. The
 repeated occurrence of gaps in the information, as well as the fact that its content and
 availability could not be clearly tracked during the period under review,
      resulted in the essential circumstances of data processing not being
transparent to the data subjects.


(105) Based on the foregoing, the Authority concluded that the Company’s data processing practices were not
      transparent, as data subjects were not provided with access to the essential
circumstances of data processing, the information was not continuously available, and its
content, temporal scope, and changes could not be tracked. The Authority therefore
 determined that the Company’s obligation to provide information on data processing pursuant to Articles 12–13 of the GDPR
 did not meet the fundamental requirement of Article 5(1)(a) of the GDPR

 either.

      III.4. The Principle of Accountability

(106) Based on the principle of accountability under Article 5(2) of the GDPR, the data controller
      is not only required to comply with the requirements set forth in the GDPR but must also
be able to demonstrate such compliance. This principle requires the data controller to operate an internal

regulatory, documentation, and record-keeping system from which the
      the content of data processing practices, their evolution over time, and regulatory compliance can be
 clearly established even retrospectively.

(107) In the present case, the Authority found that the Company did not
 comply with these requirements. The Company was unable to present the versions of the privacy notices in effect during the period under review,
failed to provide evidence of their publication, did not specify the duration of their validity,

      , nor could it demonstrate the substantive changes between the individual versions. In
 this context, the Company expressly stated that it had already submitted
 all documents at its disposal and that there was no
      possible to obtain any further documents.

(108) In the Authority’s view, this circumstance indicates that the Company did not possess
any documentation from which the content of the data processing notice applied during the period under review

      and its changes during the period under review could subsequently be determined. The fact that the Company
submitted a completed version verification form exclusively regarding the GTC, while
      it was unable to comply with the request specifically directed at data protection documents,
 supports the conclusion that the data processing notice was not adequately documented and
 traceable.                                                   19




(109) In this regard, the Authority also took into account that, based on the available evidence, the
actual accessibility of the notice was not ensured. The Company itself acknowledged the
accessibility issue; however, it was unable to determine when it arose or how long it
lasted, nor could it substantiate this with documentation.


(110) In the Authority’s view, all of this supports the conclusion that the Company was unable to
track and verify when, with what content, and by what means
the information was available to the data subjects. This circumstance constitutes a failure to fulfill
 the obligation to provide information.

(111) The Authority emphasizes that the violation of the principle of accountability is not merely due to the fact that

      the Company was unable to submit appropriate documents
for the period under review, but also that it did not operate a system that would have enabled the
continuous monitoring and subsequent verification of data processing practices.  The
lack of document versions, the lack of proof of publication, and the
indeterminacy of the time frame collectively result in the Company being unable to
demonstrate its compliance with the GDPR.


(112) Based on the foregoing, the Authority determined that the Company failed to fulfill its
obligation to demonstrate the compliance of its data processing practices, which
constituted a violation of Article 5(2) of the GDPR.

      III.5. Information Provided After the Period Under Review


(113) The present administrative proceeding did not cover the information regarding data processing provided
      , i.e., changes made by the Data Controller to the notice following its
awareness of the proceedings. In imposing the fine, the Authority considers it a mitigating circumstance that the
Company took measures after the proceedings were initiated.




      IV. Legal Consequences

(114) The Authority examined whether the established violations justify the imposition of a data protection fine
on the Company. In this regard, the Authority considered all relevant circumstances of the case pursuant to
      , taking into account
 the criteria set forth in Guideline No. 4/2022 of the European Data Protection Board (hereinafter:
 the Guideline).


(115) In the Authority’s view, given the nature, gravity, duration,
and impact on data subjects of the violations identified in this case, the issuance of a warning cannot be considered a proportionate
sanction. The violations do not consist of isolated, technical shortcomings, but rather of structural
shortcomings affecting several data protection principles and several key provisions of the GDPR;
therefore, the requirements of specific and general prevention

      necessitate the imposition of a data protection fine. 

(116) The Authority notes that the infringements found—breaches of transparency and accountability,
as well as the failure to comply with the obligations to inform data subjects under Articles 12–13—
      — constitute infringements falling within the higher

 category of fines under Article 83(5) of the General Data Protection Regulation.

      Guideline No. 2 04/2022 on the calculation of administrative fines under the General Data Protection Regulation (Version 2.1
      version). Online: https://www.edpb.europa.eu/system/files/2024-
 01/edpb_guidelines_042022_calculationofadministrativefines_hu_0.pdf 20




(117) In determining the amount of the fine, the Authority took into account the Company’s financial
data. The Company’s net revenue in each fiscal year, as reported in the annual
financial statements for the respective year, was as follows:

          -  in the 2020 fiscal year, […] Ft (i.e., […] forints),

 -  in the 2021 fiscal year, […] Ft (i.e., […] forints),
          -  in the 2022 fiscal year, […] Ft (i.e., […] forints),
 -  in the 2023 fiscal year, […] Ft (i.e., […] forints),
          -  in the 2024 fiscal year, […] Ft (i.e., […] forints),
 -  in the 2025 fiscal year, […] Ft (i.e., […] forints).

      In imposing the fine, the Authority based its calculation on the most recent and lowest net revenue,

according to which the Company, based on the categories defined in the European Data Protection Board’s Guideline No. 4/2022,
      , falls within the category of enterprises with revenue exceeding 2 million euros but
 not exceeding 10 million euros.

(118) Pursuant to Article 83(5) of the General Data Protection Regulation, the Company may be subject in this case
 to an administrative fine of up to 20,000,000 euros or an amount not exceeding 4% of the enterprise’s
      financial year, whichever is higher.

The Company’s net revenue for the year 2025 is 4% of
[…] HUF, which does not exceed 20,000,000 euros. 4% of the Company’s net sales revenue for 2025
 amounts to […] HUF, which does not exceed the amount equivalent to 20,000,000 euros; therefore, in the present
      case, the upper limit of the fine is the static maximum set at 20,000,000 euros.

(119) Based on the available information, the Authority did not identify any circumstances
      that would indicate the intentional commission of the violations. The nature of the identified deficiencies
 points to negligence; however, this was not a one-time error but was of a continuous nature,
      and therefore the Authority assessed the violations as being of a grossly negligent nature.


(120) In determining the amount of the fine, the Authority assessed the following aggravating circumstances
      :

 -  with regard to the nature and gravity of the infringements [Article 83(2)(a)

             ], the Authority assessed that the deficiencies identified in this case did not stem merely
from the partial or formal absence of certain elements of the information provided, but rather
indicated a systemic inadequacy in the data processing notice;


          -  with regard to the duration of the infringements [Article 83(2)(a) of the GDPR], the
Authority found that the identified deficiencies were not of a temporary nature,
             but were continuously present during the period under review, and the Company’s data processing

notification practices consistently failed to meet the requirements of the GDPR;

          -  with regard to the size of the group of data subjects [Article 83(2)(a) of the GDPR],

 given that traffic to the Website was significant during the period under review, and based on the Company’s
             , […] individuals visited the Website in 2020, […] in 2021, […] in 2022, […]
             , […] in 2024, and […] in 2025 visited the Website, meaning

 the number of data subjects was high in every year.

(121) In determining the amount of the fine, the Authority assessed the following mitigating circumstances based on the criteria set forth in Article 83(2) of the GDPR: 21


          -  with regard to the absence of previous relevant infringements [Article 83(2)(e) of the GDPR],

that no data protection infringement had previously been established against the Company;

          -  the Company took measures during the proceedings to remedy the violations

 [General Data Protection Regulation, Article 83(2)(f)];

          -  the violations were committed through gross negligence; intent has not been proven [General

Data Protection Regulation, Article 83(2)(b)];

          -  the Authority exceeded the administrative deadline.


 Based on a consideration of all the circumstances of the case, the Authority assessed the infringements, taken
 as a whole and in their entirety, as being of medium severity.

(122) In light of the foregoing, the Authority determined the amount of the fine based on the criteria set forth in Article 83(2) of the GDPR
      , in proportion to the nature and gravity of the infringements, the Company’s economic
situation, and the objectives of specific and general deterrence,

acting within its statutory discretion. The circumstances set forth in Article 83(2)
(c), (h), (i), and (j) did not exist in the present case.

(123) Based on the foregoing, the Authority decided as set forth in the operative part.

      V. Other Issues


(124) The Authority’s powers are defined in Section 38(2) and (2a) of the Information Act, and its jurisdiction
extends to the entire territory of the country.

(125) This decision of the Authority is based on Sections 80–81 of the Administrative Procedure Act and Section 61(1) of the Information Act. The
 decision becomes final upon its notification pursuant to Section 82(1) of the Administrative Procedure Act. Pursuant to Section 112,
      and § 116(1) and (4)(d), as well as § 114(1) of the Ákr.,
 an appeal against this decision may be filed through administrative litigation.


                                                   * * *

(126) Pursuant to Section 135 of the Ákr., the obligor is required to pay a late payment penalty
at a rate equal to the statutory interest rate if the obligor fails to fulfill its monetary payment obligation by the due date.

(127) Pursuant to Section 6:48(1) of Act V of 2013 on the Civil Code,

      in the case of a monetary debt, the debtor is obligated to pay late payment interest at a rate
equal to the central bank’s base rate in effect on the first day of the calendar half-year
affected by the delay, calculated from the date the delay began.

(128) The rules governing administrative litigation are set forth in Act I of 2017 on Administrative Procedure (hereinafter
referred to as “Kp.”). Pursuant to Section 12(1) of the Kp., administrative litigation challenging a decision of the Authority
 falls within the jurisdiction of the courts; pursuant to Section 13(3)

      (a)(aa) of the Kp., the Budapest Regional Court has exclusive jurisdiction. Pursuant to Section 27
(1)(b) of the Kp., in legal disputes in which the regional court has exclusive
      has exclusive jurisdiction, legal representation is mandatory. Pursuant to Section 39(6) of the Civil Procedure Code, the filing of the complaint
does not have the effect of suspending the entry into force of the administrative act.

(129) Pursuant to Section 29(1) of the Code of Civil Procedure and, in light thereof, Section 604 of Act CXXX of 2016
      , as applicable, and pursuant to Section 19(1)(b) of Act CIII of 2023


on the Digital State and Certain Rules Governing the Provision of Digital Services,
      , the client’s legal representative is required to communicate electronically.


(130) The time and place for filing the complaint are specified in Section 39(1) of the Civil Procedure Code. The
information regarding the possibility of requesting a hearing is based on Section 77(1)-(2) of the Code of Civil Procedure
.

(131) The amount of the administrative court fee is determined by Section 45/A(1) of Act XCIII of 1990 on Fees
 (hereinafter: Itv.). The party initiating the proceedings is exempt from the requirement to pay the fee in advance

pursuant to Section 59(1) and Section 62(1)(h) of the Itv.
.

(132) If the Company fails to adequately demonstrate compliance with the prescribed obligations, the Authority
shall deem that the Company has failed to fulfill the obligation by the deadline. Pursuant to Section 132 of the Administrative Procedure Act, if the
Company has not complied with the obligations set forth in the Authority’s final decision, the decision
becomes enforceable. Pursuant to Section 82(1) of the Administrative Procedure Act, the Authority’s decision

      . Pursuant to Section 133 of the Administrative Procedure Act, enforcement—unless otherwise provided by law or
a government decree—shall be ordered by the authority that issued the decision. Pursuant to Section 134
of the Administrative Procedure Act, enforcement—unless otherwise provided by law, a government decree, or,
in matters within the jurisdiction of a local government authority, a local government ordinance—
shall be carried out by the state tax authority. Pursuant to Section 61(7) of the Information Act, with respect to the obligation set forth in the Authority’s decision
to perform a specific act, to engage in specific conduct, to tolerate a situation, or
      cessation—the Authority

shall enforce the decision.

Dated: Budapest, date as per the electronic signature

Dr. habil. Attila Péterfalvi
Chairman, Professor