NAIH (Hungary) - NAIH-450-7-2026: Difference between revisions

From GDPRhub
No edit summary
m Link to document added
 
Line 12: Line 12:


|Original_Source_Name_1=NAIH
|Original_Source_Name_1=NAIH
|Original_Source_Link_1=https://naih.hu/hatarozatok-vegzesek
|Original_Source_Link_1=https://naih.hu/hatarozatok-vegzesek?download=1559:tajekoztatasi-hianyossagok-webaruhaz-adatkezelese-soran
|Original_Source_Language_1=Hungarian
|Original_Source_Language_1=Hungarian
|Original_Source_Language__Code_1=HU
|Original_Source_Language__Code_1=HU

Latest revision as of 08:43, 5 August 2026

NAIH - NAIH-450-7-2026
Authority: NAIH (Hungary)
Jurisdiction: Hungary
Relevant Law: Article 5(1)(a) GDPR
Article 12(1) GDPR
Article 13(1) GDPR
Article 13(2) GDPR
Type: Investigation
Outcome: Violation Found
Started: 09.04.2026
Decided: 12.05.2026
Published: 24.07.2026
Fine: 15000000.0 HUF
Parties: n/a
National Case Number/Name: NAIH-450-7-2026
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Hungarian
Original Source: NAIH (in HU)
Initial Contributor: av

The DPA fined the operator of an online store HUF 15,000,000 (€41,500) for not providing its customers concise, transparent, and intelligible information on the purposes, legal basis, and duration of processing and data transfers to third countries.

English Summary

Facts

The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The period under review extended from January 2020 to November 2025. During this time, the company had multiple privacy notices in force, as well as other documents that contained relevant information on the processing of personal data.

Holding

The DPA found the controller guilty of multiple GDPR violations and issued it a fine of HUF 15,000,000 (€41,500). In addition, it ordered the controller to bring its processing operations in compliance with the GDPR by amending the information system used on its website, in particular the data processing provisions of the general terms and conditions and the data processing notices related to prize contests.

First, the DPA held that the controller had violated the principle of transparency laid down in Article 5(1)(a) GDPR: several separate documents contained partially conflicting, irrelevant, and incomplete information regarding the processing of personal data. The information was not organised within a uniform, transparent system.

Second, the DPA determined that the controller had failed to provide concise, transparent, and intelligible information regarding the purposes and the legal basis for each processing activity and therefore infringed Article 12(1) GDPR.

Finally, the DPA found infringements of Articles 13(1) and 13(2) GDPR – the controller had not provided the data subjects all information necessary when personal data is collected from data subjects. In particular, the controller had failed to adequately distinguish the purposes and the legal bases for each processing operation, recipients of personal data, and retention periods. The controller’s website also contained contradictory information on whether or not personal data was transferred to the United States.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Hungarian original. Please refer to the Hungarian original for more details.

Case No.: NAIH-450-7/2026.
Background: NAIH-
15402/2025.
NAIH-9728/2025.
Case Officer:
Subject: Decision in an ex officio data protection
authority proceeding
DECISION
The National Authority for Data Protection and Freedom of Information (hereinafter: the
Authority), with respect to the websites […] (hereinafter: the Website) and […] (hereinafter: the
Blog), regarding the data processing practices of the online store operating on the Website,
including, in particular, the provision of prior information, concerning […] (registered office: […];
company registration number: […]; tax ID: […]; hereinafter: “Company”), as the operator of the
online store operating on the Website, regarding the protection of natural persons with respect to
the processing of personal data and the free movement of such data, and repealing Directive
95/46/EC, Regulation (EU) 2016/679 (EU) (hereinafter: General Data Protection Regulation or
GDPR) regarding the processing of personal data of natural persons and repealing Directive
95/46/EC.
1. The Authority finds that the Company negligently violated
- Article 5(1)(a) of the General Data Protection Regulation;
- Article 12(1) of the General Data Protection Regulation;
- Article 13(1)(a), (c) through (f) of the General Data Protection Regulation; and
- Article 13(2)(a) through (f) of the General Data Protection Regulation.
2. In light of the identified violations, the Authority—pursuant to Article 58(2)(d) of the GDPR—
hereby orders the Company ex officio to amend the information system used on the Website
under review—including, in particular, the Website Notice, the data processing provisions of the
General Terms and Conditions, the data processing notices related to sweepstakes, and the Blog
Notice—in order to remedy the deficiencies identified in this decision, and to ensure that the
information complies with the GDPR and is provided in a concise, transparent, understandable,
and easily accessible form, using clear and plain language, and aligned with the actual data
processing operations; in this context, the Company is required to eliminate parallel, conflicting,
or mutually incompatible information solutions, clearly define the relationship between individual
documents, and remove outdated references to legislation and terminology not based on the
GDPR framework; present information regarding data subjects’ rights and remedies accurately
and in an easily understandable manner in accordance with the structure set forth in the
Regulation; furthermore, clearly define for each data processing activity the categories of data
processed, the purposes, the legal bases, recipients or categories of recipients, and retention
periods—including data processing related to cookies—and to clarify the roles and
responsibilities of data controllers in accordance with actual operations.
The Company is required to provide evidence of compliance by submitting the amended privacy
notice to the Authority in such a way that the changes are clearly identifiable.
........................................................................................................................................................................................................................................................................
1055 Budapest Tel.: +36 1 391-1400 naih.hu/data-protection-notice
9-11 Falk Miksa Street KR ID: 429616918 ugyfelszolgalat@naih.hu
2
3. Due to the violations established in Section 1, the Authority has imposed
a data protection fine of 15,000,000 Ft, that is,
fifteen million forints
.
* * *
The Company must provide written confirmation to the Authority, together with supporting
evidence, that it has taken the measures prescribed in Section 2 within 30 days of this
decision becoming final.
The data protection fine must be paid within 30 days of this decision becoming final to the
Authority’s forint account for the collection of centralized revenues (10032000-01040425-
00000000 Centralized Collection Account, IBAN: HU83 1003 2000 0104 0425
0000 0000). When transferring the amount, please cite reference number NAIH-450/2026.
FINE.
If the Company fails to meet its obligation to pay the data protection fine by the deadline, it shall
be required to pay a late payment penalty to the above account number. The rate of the late
payment penalty is the statutory interest rate, which corresponds to the central bank’s base rate
in effect on the first day of the calendar half-year affected by the delay.
In the event of failure to comply with the obligations set forth in Section 2, or failure to pay the
data protection fine and the late payment penalty, the Authority shall order the enforcement of
this decision.
There is no right to an administrative appeal against this decision, but it may be challenged in
administrative litigation by filing a complaint with the Budapest Metropolitan Court within 30 days
of notification. The complaint must be submitted to the Authority electronically1, which will forward
it to the court together with the case file. A request for a hearing must be included in the
complaint. For those not eligible for full exemption from personal fees, the administrative litigation
fee is 30,000 HUF; the case is subject to the right to charge a fee based on the subject matter.
Legal representation is mandatory in proceedings before the Budapest Metropolitan Court.
R E A S O N I N G
I. Procedural Steps
I.1. The Administrative Inspection
(1) On April 9, 2025, the Authority decided to initiate an administrative inspection regarding the data
processing by the online store operating on the Website and the Blog, including preliminary
notification, concerning compliance with the General Data Protection Regulation, under case
number NAIH-9728/2025.
(2) On November 4, 2025, the Authority conducted an unannounced inspection, which consisted of
viewing the Website and making a backup copy.
1 The form designated NAIH_K01 is used to initiate administrative proceedings: NAIH_K01 form (September 16, 2019).
The form can be completed using the General Form-Filling Program (ÁNYK program).
The form is available at the following link: https://naih.hu/kozig-hatarozat-birosagi-felulvizsgalata
3
(3) After reviewing the Website and the Blog, the Authority identified a suspected violation regarding
the adequacy of the preliminary data processing notice related to the operation of the online
store.
I.2. Administrative Proceedings
(4) The Authority concluded its official inspection and, pursuant to Section 60(1) of Act CXII of 2011
on the Right to Informational Self-Determination and Freedom of Information (hereinafter: the
Information Act), on November 12, 2025, under case number NAIH-15402/2025, an
administrative data protection proceeding covering the Website’s data processing practices—
specifically, the prior data processing notice—in which it also utilized the data and documents
from the previous official inspection and review. The proceedings did not extend to an
examination of other data protection requirements or to a comprehensive review of the
Company’s data processing procedures.
(5) The Authority may assess compliance with the provisions of the General Data Protection
Regulation—applicable as of May 25, 2018. According to the Company’s statement, the online
store began operations in 2020; therefore, the Authority refrained from examining the period prior
to January 1, 2020.
(6) The period under review extended until the initiation of this proceeding; therefore, the period
following the initiation of the proceeding is not included.
(7) Based on the foregoing, the period examined by the Authority in this proceeding is: January 1, 2020 –
November 12, 2025.
I.2.1. Clarification of the Facts
(8) In its order dated November 12, 2025, file number NAIH-15402-1/2025, the Authority notified the
Company of the initiation of the data protection authority proceeding and requested that it submit
a statement to clarify the facts of the case.
(9) In its response letter dated December 12, 2025, filed under reference number NAIH-15402-
7/2025, the Company stated that […] was registered on […] and began operating the […] online
commerce platform in 2020. According to the Company, it entrusted […] with data protection
duties as of July 13, 2022, and that entity also performed the duties of a data protection officer.
The Company further stated that concerns arose in 2024 regarding the external expert’s
activities, which led to the termination of the engagement agreement. The Company emphasized
that, in its view, it had no intention of engaging in unlawful data processing and acted in the belief
that its data protection documents and processes complied with legal requirements. According to
its statement, as a result of the present proceedings, it has begun reviewing its privacy notices
and preparing amendments thereto.
(10) To clarify the facts of the case, the Authority requested that the Company verify which data
protection notices were available on the Website during the period under review, as well as to
submit previous versions of the privacy notices and related documents, along with their effective
dates, publication dates, and any amendments, and to confirm their publication. The Authority
also requested that the Company use the form attached to the order for each document when
responding. In its statement, the Company explained that the form attached to the order had not
been sent to it; therefore, it submitted its response in this document and made the related
documents available to the Authority in a password-protected, compressed folder titled
“Reference Documents.” Among the documents attached to its statement, the Company identified
the privacy notice, the privacy notice related to the sweepstakes, the cookie policy, and the
sweepstakes rules, and confirmed their availability via links on the Website.
4
(11) In its statement, the Company argued that publishing the data protection provisions in several
separate documents serves to uphold the principle of transparency. In its view, the Website’s
privacy notice describes the general data processing activities carried out on the Website, while a
separate privacy notice applies to data processing related to prize contests, so that data subjects
can directly access information pertaining to that specific data processing. The Company further
stated that information regarding the use of cookies is also contained in a separate cookie policy. 
According to its statement, this three-document structure—the Website’s privacy notice, the
sweepstakes privacy notice, and the cookie notice—provides data subjects with clear and
targeted information regarding the terms of each data processing activity. The Company asserts
that this approach is also in line with industry practice.
(12) According to the Company’s statement, at the time the data processing notice was prepared, the
property serving as the Company’s registered office could be identified by its cadastral number,
as the property did not yet have a street address. The Company explained that in 2024, the local
government reclassified the property, and its address was changed to […], which was updated in
the company’s records; however, the privacy notice was not amended. According to the Company,
it carries out procurement, central administrative, warehousing, and IT activities at its
headquarters ([…]). Warehousing activities take place at its facilities ([…]; […]), while its branches
([…]; […]) handle financial, marketing, HR, customer service, IT development, and legal activities.
(13) According to the Company, the data processing purpose listed in Section 2.4 of the Privacy
Notice effective as of July 2, 2025, was related to a previous function under which the product
page displayed information about which person, by first name, from which municipality had most recently
purchased the given product. The Company stated that it discontinued this practice as of April 23,
2024, and currently only the name of the town is displayed. The Company further stated that
Sections 2.7 and 2.8 of the Notice contain identical wording, which it claims is the result of an
editorial inaccuracy. According to its statement, Section 2.7 pertains to the sending of newsletters
to users, while Section 2.8 concerns marketing communications directed at marketplace partners
and suppliers. According to the Company, in practice, it sends marketing messages in both cases
based on consent and does not engage in telemarketing activities. The Company stated that the
data processing described in Section 2.17 of the Privacy Policy was related to the publication of
user reviews regarding products and partners. It stated that since 2024, it has not engaged in this
data processing in a manner where the user’s first name appears alongside the reviews;
currently, reviews are published without the first name or only with the first name provided by the
user. The Company indicated that it intends to correct the inaccuracies identified during the
review of the Privacy Notice.
(14) In its statement, the Company explained that the phrasing “planned duration of data processing”
in Section 2 of the Notice is inaccurate, as it could misleadingly suggest that the data retention
periods specified there are merely planned periods. According to the Company, it has in fact
applied and complied with the data retention periods specified in the Notice for each data
processing activity. The Company further stated that it determined the data retention periods in
accordance with the principle of limited storage and considers them binding upon itself. According
to its statement, it will remove the term “planned” from the document during the review of the
Privacy Notice.
(15) According to the Company’s statement, the data processing described in Section 2.2 of the
Privacy Notice relates to the issuance and retention of invoices and other mandatory documents
related to the fulfillment of purchases made through the online store. The Company
5
stated that it determined the data retention period based on Section 169(1)–(2) of Act C of 2000
on Accounting, which stipulates that accounting documents must be retained for at least 8 years.
Accordingly, the duration of data processing extends until the last business day of March
following the expiration of the eighth year after the invoice was issued. It further stated that
deletion is not currently carried out as part of an automated process; however, it considers the
automation of this process to be a development priority. The Company also indicated that in
certain cases—for example, in the event of a longer warranty period—the retention period for
documents may be aligned with the duration of the warranty, which may exceed the 8-year
period.
(16) According to the Company, it has no direct information regarding the partners involved in data
transfers as specified in Section 10 of the Prospectus—specifically […], […], ([…]), […], ([…]),
[…], […], […], […], […], and […]—the Company has no direct information regarding whether
these service providers engage in profiling. The Company stated that, in accordance with industry
practice, online advertising providers may use profiling methods to ensure effective advertising;
however, the Company has not obtained direct information regarding this practice nor has it taken
any specific measures in this regard. According to its statement, data transfers to such providers
are automated and typically occur through the placement of the providers’ cookies following the
user’s consent; data transfers cease when the cookies are deleted or expire.
(17) The Company stated that it does not use automated decision-making—whether based on
profiling or otherwise—in the course of its operations, and currently has no plans to introduce
such solutions. According to the Company, profiling is not necessary for the operation of the main
service available on the Website, and therefore it refrains from using it. The Company further
stated that the recommendations appearing on the Website—such as “People who bought this
also bought,” “Top picks according to our customers,” “Most Popular Gift Items,” or “Newest
Products in This Category”—are not based on user profiling but are displayed based on data from
transactions conducted on the Website and other objective data.
(18) The Company stated that it cannot provide an explanation as to why the recipients of data
transfers were not specifically named in Section 7 of the Privacy Notice, or why the individual
recipients were not clearly assigned to the designated recipient categories. The Company further
stated that it could not explain the criteria used to list the partners mentioned in Section 10 of the
Notice, nor why they were listed in a separate section. According to its statement, the Company’s
objective in revising the Privacy Notice is to provide data subjects with more comprehensive
information regarding the recipients of data transfers or their categories, taking into account the
considerations set forth in the judgment of the Court of Justice of the European Union in Case C-
154/21.
(19) According to the Company, the inclusion of the term “Authority” in Section 7 of the Privacy Notice,
in the context of information regarding data processors, is incorrect because, on the one hand, it
has not been specified which body is meant by this term, and, second, in its view, given Article
4(9) of the GDPR, naming the authorities as recipients is not necessarily justified. The Company
further argued that the phrasing “Joint Data Controller: Marketplace Partners” is also inaccurate,
as, according to the Company, there is no joint data processing between the Company and the
marketplace partners. The partners act as independent data controllers with respect to the
personal data provided during a purchase or inquiry. The Company indicated that these
inaccuracies will be corrected during the review of the Privacy Notice.
(20) In its statement, the Company argued that the wording of Section 8.2 of the Privacy Notice is
inaccurate; however, it asserted that it did not intend to restrict data subjects’ right to access their
personal data in practice. It stated that if a data subject were to request a copy of the camera
recordings, the Company would fulfill the request in accordance with the relevant legal
6
. According to the Company, the camera system operates exclusively on the premises of the […]
warehouse for property protection purposes; the recordings are retained for one month, and to
date, a copy of the recordings has been provided to the police on only one occasion; no such
request has been received from a private individual. The Company further stated that only a small
number of private individuals visit the warehouse premises, and the primary purpose of the
camera surveillance is property protection.
(21) According to the Company, […] was designated as the data protection officer in Section 1 of the
Privacy Notice. The Company stated that […] will no longer perform these duties as of December
1, 2024, as the service agreement between the parties has been terminated. The Company
further stated that, in its view, the conditions set forth in Article 37(1) of the GDPR are not met,
and therefore it does not consider the appointment of a data protection officer necessary.
According to its statement, the Company intends to review its data protection documents and
processes with the involvement of an external expert in the future, and plans to take measures to
strengthen data protection awareness and ensure the continuous performance of data protection
tasks.
(22) In its statement, the Company explained that it cannot provide a justification for the provisions
regarding restriction and erasure set forth in Section 8.3 of the Prospectus, and does not intend to
retain them during the review of the Prospectus. At the same time, it stated that, in its view,
specifying the purpose of the restriction is significant for the data controller insofar as, based on
the reason indicated by the data subject among the cases specified in Article 18(1)(a)–(d) of the
GDPR, the reason specified by the data subject may clarify the basis for the restriction and the
legal framework for the related data processing operations to the data controller.
(23) According to the Company’s statement, it determines whether the partners listed in Section 10 of
the Privacy Notice act as data controllers or data processors based on the contracts concluded
with them and the terms and conditions they have published. According to the Company’s
information, […] and […] ([…]) act as data processors, while […] ([…]), […], […], […], […], and
[…] are classified as data controllers. The Company further indicated that it currently has no
cooperation with […]. 
(24) The Company stated that, through the provision in Section 10.1 of the Privacy Notice, it intended
to provide information regarding the transfer of data to […] ([…]) and thereby comply with the
relevant legal and contractual obligations. According to the Company’s statement, users’ personal
data—specifically, the customer’s name, email address, billing and shipping addresses, and data
related to the purchase—are transferred to […] during the payment process. The Company has
stated that it does not intend to continue informing data subjects in this manner in the future and
plans to place the notice regarding data transfer at the final step of the purchase process, prior to
redirection to the payment page.
(25) According to the Company, as part of its cooperation with […] (hereinafter: […]), following a
purchase, it transmits the customer’s email address, as well as the name and identification
number of the purchased product, to […]. According to the Company, the purpose of the data
transfer is to enable […] to contact the customer regarding a purchase review, and based on the
reviews collected in this manner, the […] online store may gain or lose its “trusted store” rating
on the […] platform. According to the Company’s statement, to the best of its knowledge, […]
does not use the personal data received in this manner for any purpose other than requesting
feedback. The Company further indicated that it intends to review the terms of the cooperation
again during the review of its data processing documents.
(26) The Company stated that in 2022, […] offered to provide advertising services to the Company,
and a testing process was initiated to evaluate the potential use of these services. According to
the Company, the testing was unsuccessful; therefore, no service agreement was concluded
between the parties, and […] did not actually perform any data control or data processing
7
activities for the Company. The Company asserts that it is likely that […] was listed in the
Prospectus even during the testing period, in preparation for potential future cooperation. The
Company further indicated that it will remove references to […] during the review of the
Prospectus.
(27) The Company explained that the abbreviation “SSC” appearing in Section 11 of the Prospectus
actually refers to the “Standard Contractual Clauses” (SCC) document issued by the European
Commission, while “DPA” stands for “Data Processing Agreement.” The Company acknowledged
that the use of English-language abbreviations without explanation does not promote transparent
disclosure, and further indicated that the references, in their current form, are not always well-founded.
The Company further stated that data transfers to third countries are made exclusively
to the data processors identified in Section 10 of the Prospectus, which, according to the
Company, are listed in the official registry of certified organizations under the EU–U.S. Data
Privacy Framework. The Company indicated that, during the review of the Privacy Notice, it
intends to amend the information regarding data transfers to third countries.
(28) The Company stated that the warning in Section 3 of the Notice (“Possible consequence of failure
to provide data: the purpose of data processing cannot be fulfilled.”) is intended to convey that if
the data subject does not provide the necessary personal data, the specific purpose of data
processing cannot be achieved. According to the Company, for example, in the absence of the
data necessary for a purchase and related communication, it is not possible to complete the
purchase, while in the case of certain services—such as sending newsletters—failure to provide
the data will result in the inability to use the service in question. According to the Company’s
statement, it strives to require users to provide only the data necessary for the provision of the
service on a mandatory basis.
(29) In its statement, the Company explained that it had previously taken measures regarding the
processing of data related to cookies used on the Website, about which it had informed the
Authority in connection with the notice bearing case number NAIH/11301-2/2025. The Company
noted that, according to the Authority’s notification dated November 26, 2025, it had taken the
necessary measures and submitted the documents verifying their implementation to the Authority.
According to the Company’s statement, it maintains the arguments presented in the previous
case in the present proceedings as well, and requested that the Authority take into account the
information provided and verified in that case in the present proceedings as well.
(30) According to the Company’s statement, it has not been accepting incoming phone calls since
March 2025; the customer service system directs interested parties to use the online contact
form. Prior to this, for incoming calls, a voice message played during the hold time informed the
caller that the conversation was being recorded for quality assurance purposes and that a copy of
the recording could be provided free of charge upon request; the message also stated that if the
caller did not consent to the recording, an online contact option was available. The Company
further stated that, by default, it retained recorded calls for 180 days. According to the Company,
for outgoing calls, the operator provided information about the recording at the start of the
conversation; however, it was also possible, at the caller’s request, to have the call returned via a
line that was not recorded.
(31) According to the Company, when drafting the Notice, it decided to present information regarding
data subjects’ rights in a condensed form due to space constraints. The Company acknowledged
that an adequate explanation of data subjects’ rights is a fundamental requirement of the GDPR;
therefore, during the review of the Notice, it intends to ensure a more detailed presentation of
these rights that meets the legal
8
requirements. The Company further stated that the number of cases in which data subjects
exercised their rights was low, and that it handled such requests in every instance in accordance
with the data subjects’ needs.
(32) The Company stated that the wording in Section 12 of the Privacy Notice is incorrect, as data
subjects are entitled to information not only regarding the purpose and legal basis of data
processing. The Company acknowledged that data subjects are entitled to access all information
specified in Article 15 of the GDPR.
(33) According to the Company, the approach set forth in Section 12.2 of the Privacy Notice is
incorrect, and it does not intend to maintain it in the future. The Company stated that the
conditions set forth in Article 12 of the GDPR
, under which the data controller may charge a reasonable fee, taking into account the
circumstances of the case, or may refuse to take action if the request is manifestly unfounded
or—in particular due to its repetitive nature—excessive.
(34) The Company has stated that its data processing practices do not include any data processing
based on Article 6(1)(e) of the GDPR, i.e., the exercise of official authority. According to the
Company, this legal basis is not applied; therefore, the relevant reference will be removed during
the review of the Privacy Notice.
(35) The Company indicated that the Prospectus’s current structure does not fully meet the
transparency requirement, as while the information is included, it is not always presented in a way
that is easily comprehensible and understandable to the relevant parties. The Company
explained that its goal in revising the Privacy Notice is to create a document with a clearer, more
logical structure and language that is easy to understand. It further stated that, in its view, the
nature of its data processing activities is generally known to online shoppers; however, it strives
to provide information in the future that presents its data processing practices in a way that is
unambiguous to data subjects and reinforces their sense of security.
(36) The Company states that it cannot provide a substantive explanation for the large number of
typos and confusing errors in the Privacy Notice, and believes that these can be attributed to a
lack of due diligence in reviewing the document. The Company further indicated that it will
immediately begin reviewing the Privacy Notice and, as part of that process, will correct the
identified errors, omissions, and inaccuracies.
(37) The Company explained that the phrase “by participating, you expressly accept” in the first
sentence of the Privacy Notice dated September 1, 2023 […] regarding the sweepstakes
conducted in cooperation with its Partners, as well as the phrase “gives their express consent,”
reflect a previously applied practice whereby an interaction initiated by the user—such as clicking
the “Enter” button—was interpreted by the service providers as acceptance of the terms of
participation and consent to data processing. The Company indicated that this approach is
inadequate in its current form and plans to amend it during the review of the relevant documents
to ensure that data processing is transparent and lawful.
(38) The Company stated that the
“Privacy Statement” referred to in Section 2 of the information notice regarding this sweepstakes
is available on the […] page, where, in addition to the general data processing notice, the data
processing notice for sweepstakes is also available. According to the Company, users can return
to the prize contest data processing notice from the referenced page. The Company further
explained that, in its view, all information related to the specific data processing purpose must be
provided in one place, and cross-references or click-throughs do not promote transparent
disclosure of information; therefore,
9
during the review of the relevant documents, it intends to amend the sweepstakes privacy notice
accordingly.
(39) According to the Company’s report, the number of data subjects participating in the sweepstakes
during the period under review was as follows: […] people in 2020, […] people in 2021, […]
people in 2022, […] people in 2023, […] people in 2024, and […] people in 2025. 
(40) According to the Company, it publishes the winners of the sweepstakes on social media platforms
([…], […]), listing only the winner’s first name, in order to reinforce the credibility of the
sweepstakes. According to the Company’s statement, no other personal data is disclosed. It
further stated that, to its knowledge, no objections or requests for deletion were received from the
winners either before or after the publication, and users did not question the credibility of the
sweepstakes.
(41) In order to clarify the facts of the case, the Authority requested that the Company verify the
privacy notice used on the Blog during the period under review, as well as to submit previous
versions of the Data Processing and Privacy Notice and the General Terms and Conditions,
including their effective dates, publication dates, and any amendments, and to confirm their
availability. In its statement, the Company identified the Data Processing and Privacy Notice,
which is currently available on the Blog and effective as of September 2, 2022, as well as
the Blog Terms and Conditions of Use document, effective as of September 2, 2022, and
confirmed their availability by providing web links.
(42) The Company explained that, in order to enable users to post comments on the Blog, it requested
that users provide their name and email address so that it could apply a minimal filter against
anonymous comments. It stated that the data retention period specified in Section 6.1.1 of the
Blog’s Data Processing and Privacy Notice—until the data subject withdraws their consent—
means that comments and the personal data associated with them are retained for as long as the
comment remains available on the website, and in the event of withdrawal of consent, they will be
deleted along with the comment. The Company further indicated that it is reviewing the data
processing procedure described in Section 6.1.2 and plans to amend it during the review of the
Blog’s Data Processing and Privacy Notice.
(43) The Company stated that it does not directly transfer personal data to a third country in the
course of operating the Blog; however, it uses solutions provided by third-party service providers
to improve the user experience and measure traffic. The Company explained that these service
providers place cookies on users’ devices—with the exception of necessary cookies—based on
the user’s consent, through which data processing may take place. The Company further
indicated that its goal is the continuous development of its services and the improvement of the
user experience.
(44) The Company explained that, with regard to cookie management on the Blog, it has implemented
the […] solution used on the Website. According to its statement, the cookie banner was last
updated on November 26, 2025, at which time the Company changed the previously English-language
information to Hungarian and began clarifying the related information and correcting the
links. The Company indicated that the development of information and settings related to cookie
management is ongoing and is expected to be completed by December 31, 2025.
(45) According to the Company’s statement, since the Blog’s launch on June 28, 2022, no requests
from data subjects have been received that would have required the application of a fee; thus, the
provision set forth in Section 5.6 of the Blog’s Data Processing and Privacy Notice has not been
applied in practice. The Company further indicated that, during the review of the Blog’s Data
Processing and
10
Privacy Notice, it intends to amend this provision in accordance with the requirements set forth in
Article 12 of the GDPR.
(46) The Company indicated that the Blog Data Processing and Privacy Notice contains an incorrect
legal reference, as it lists the Information Act (Infotv.)
. According to the Company, this is an incorrect approach, and it intends to correct it during the
review of the Blog Data Processing and Privacy Notice by including a reference to the GDPR and
explaining its provisions.
(47) The Company explained that it interprets the wording in Section 8.1 of the Blog Data Processing
and Privacy Policy as reflecting a data controller’s perspective, according to which the data
controller’s activities—within certain limits—may also be influenced by the decisions of the data
protection authority. At the same time, the Company pointed out that, in its view, the fact of
cooperation between the data controller and the authority, as well as activities carried out to
ensure the protection of fundamental rights, are not circumstances that would justify their
inclusion in the Blog Data Processing and Privacy Policy; therefore, it plans to delete this
provision during the review of the document.
(48) According to the Company, the reason for providing information on data processing in two
separate documents is to ensure that Blog visitors receive information exclusively about the data
processing activities carried out on the Blog. It stated that, in its view, there is no justification for
burdening Blog users with details of the data processing activities conducted on the Website,
given the different functions of the two platforms, the different services they offer, and the partially
different user bases. According to the Company, given the limited nature of the data processing
activities on the Blog, providing this information in a separate document ensures that data
subjects receive a purpose-specific explanation of the relevant information.
(49) The Company attached the following documents to its response:
• Appendix 1: Personal Data Form;
• Appendix No. 2: A .zip compressed folder titled “Reference Documents” (Data Protection
Documents, Contracts).
(50) In its order dated January 12, 2026, case number NAIH-450-1/2026, the Authority requested the
Company to submit a further statement in order to clarify the facts of the case.
(51) In its response letter dated February 3, 2026, filed under case number NAIH-450-3/2026, filed
under case number NAIH-450-3/2026, the Company responded to the Authority’s request by
stating that on December 12, 2025, it had electronically provided the Authority with 28 data
processing statements and data processing notices related to the Website and the online store
operating there; it also indicated that the
document titled “adatkezelesi-tajekoztato-2024-09-09-tol.pdf” had been included twice among the
attachments by mistake. The Company stated that, in addition, it had also submitted three data
processing notices related to prize contests. According to the Company’s statement, it submitted
a total of 21 version control forms as attachments to this statement—19 of which relate to the
Website and 2 to the prize contests—and also attached the forms for those documents for which
no new versions had been issued.
(52) The Company explained that data transfers related to the […] payment service are a necessary
part of the transaction; data transfers under the […] “Trusted Store” program serve to collect
customer reviews; and […] acts solely as a data processor for the purpose of sending
newsletters. The Company stated that no cooperation was established with […], and therefore no
data transfer took place. The Company further explained that the use of major technology
platforms is intended to optimize advertisements, which
11
it considers necessary for the operation of the service and beneficial to users. According to its
statement, it has sought to minimize the scope of data transfers and to ensure that data flow
processes remain transparent and limited. The Company indicated that it continuously reviews its
practices and documentation regarding data transfers.
(53) The Company explained that, starting in April 2021, it has been using a cookie management
solution provided by the […] service provider on its Website, which automatically manages and
displays the type, purpose, duration, and owner of the cookies used. It stated that the cookie
panel allows users to accept, reject, or customize cookies, and that cookies requiring consent are
placed only after the data subject has given their consent. According to the Company, […]
prepares regular reports on the cookies used; based on these reports, the most recent change
took place on December 3, 2025, when a feature was introduced that allows only essential
cookies to be used. The Company further indicated that detailed information regarding cookie
management is provided through the cookie panel, as well as the cookie notice and the privacy
policy available on the Website, and that it uses […] to ensure that cookies requiring consent are
used only with the user’s prior consent.
(54) According to the Company’s report, the number of visitors to the Website during the period under
review was as follows: […] in 2021, […] in 2022, […] in 2023, […] in 2024, and […] in 2025.
(55) In response to the Authority’s request, the Company stated that the content of the Blog’s Data
Processing and Privacy Notice has not changed since the site’s launch on September 2, 2022.
According to the Company, a review of this document has begun and is currently underway as
part of this proceeding. In light of this, the Company attached a version control form pertaining to
the referenced document.
(56) The Company stated that it did not use the […] service, while the use of […] began following the
website’s launch on September 2, 2022. The Company explained that, prior to the entry into force
of the Data Privacy Framework, data transfers to the United States were based on the Standard
Contractual Clauses adopted by the European Commission and used by […], which it considered
to be an appropriate safeguard under Article 46 of the GDPR. It stated that, following the
determination of […]’s adequacy under the Data Privacy Framework, the legal basis for data
transfers changed to Article 45(1) of the GDPR. According to the Company, data subjects were
informed in advance via the cookie panel and the Blog’s Data Processing and Privacy Notice. 
(57) The Company stated that, as of September 2, 2022, it has been using the […] system to operate
the Blog, within which it utilized the […] plugin to manage cookies. According to the Company,
this solution provided users with information about the types and functions of the cookies used
and allowed them to accept or reject them. The Company indicated that it had made a separate
document available regarding its cookie management practices prior to November 26, 2025, but
does not have any more detailed information than that. As of November 26, 2025, the Blog also
uses the […] service, which provides standardized information regarding the types, purposes,
duration, and management of cookies, as well as the option for users to grant, reject, or adjust
their consent. According to the Company, its cookie management practices have not changed
since then, and information is provided to users via the cookie panel.
12
(58) According to the Company, the number of visitors to the Blog during the period under review was
as follows: […] in 2022, […] in 2023, […] in 2024, and […] in 2025.
(59) The Company emphasized that the data processing procedures and practices it has established
were developed in connection with the operation of the online store and marketplace, and any
changes made to them were also aligned with these operations. The Company also indicated that
it has begun reviewing its data processing documents in order to provide more accurate and
transparent information to data subjects. The Company also pointed out that the number of
requests from data subjects for data erasure has been low in recent years, which, in its view,
indicates the satisfaction of data subjects. The Company further requested that the Authority take
into account, during the proceedings, its efforts to improve data protection documents and ensure
lawful data processing.
(60) The Company attached the following documents to its response:
• Appendix 1: Version control forms .zip;
• Appendix 2: […] history .zip;
• Appendix 3: Document titled “Cookie Use – […].blog.”
(61) In its order dated March 13, 2026, case no. NAIH-450-4/2026, the Authority requested the
Company to submit a further statement in order to clarify the facts of the case.
(62) In its response letter dated April 8, 2026, filed under case number NAIH-450-5/2026, the
Company stated that the discrepancy noted by the Authority was due to an administrative error,
as a result of which the document titled “Privacy Policy-2020-10-20-on.pdf” was submitted with an
incorrect filename. According to its statement, the document in question was in fact in effect
between June 9, 2020, and October 20, 2020, which corresponds to the validity period of the
other document previously submitted, and this was correctly indicated on the version verification
form sent later. The Company also attached the privacy notice in effect between October 21,
2020, and November 9, 2020, which it made available to the Authority as an annex to this
statement.
(63) According to the Company, the name of the document titled “data-protection-statement-2021-01-
22-on.pdf” was incorrect due to an administrative error. According to its statement, the document
was actually in effect between November 10, 2020, and July 14, 2021, a period that was correctly
indicated on the submitted version verification form. The Company also indicated that it does not
have a separate privacy policy in effect as of January 22, 2021; however, it attached the
document used during that period as an appendix to this statement.
(64) According to the Company’s statement, the privacy notice related to the sweepstakes dated May
16, 2022, was in effect until August 30, 2023, after which it was replaced,
effective September 1, 2023, by the privacy notice currently in use for prize draws organized in
cooperation with […] and its partners. The Company further stated that no further amendments
were made to this document, and no new version was created.
(65) According to the Company’s statement, with regard to the Blog Data Processing and Privacy
Notice and the Blog General Terms and Conditions, only the documents currently available on
the website have been prepared and published; no earlier versions of these were created.
(66) In its statement, the Company explained that it verifies the requested CMS-based version history
using database extracts and screenshots from its proprietary system, which record the creation
date, validity
13
period, and version history of each document. Furthermore, regarding the privacy notices related
to the sweepstakes, the Company intended to substantiate the dates of storage and publication of
the documents with data derived from the server-side file structure. Regarding the Blog, the
Company stated that the publication date displayed on the […] administrative interface (October
1, 2021) does not reflect the actual publication date, but rather the date the system was installed,
while the Blog actually launched on June 28, 2022, when the privacy notice was also published;
however, the system did not record this date. The Company further indicated that user activity
related to the Blog was low.
(67) The Company attached the following documents to its response:
• Appendix 1: privacy-statement-2020-10-21 - 2020-11-09.pdf
• Appendix 2: privacy-statement-2020-11-10 - 2021-07-14.pdf
• Appendix 3: data-protection-statement-history.png
• Appendix 4: server_lottery_docs.png
• Appendix 5: blog_data_protection.png
(68) In its order No. NAIH-450-6/2026 dated April 9, 2026, the Authority informed the Company that
the evidentiary proceedings had been concluded and that, subject to the rules governing access
to documents, the Company may review the evidence uncovered during the clarification of the
facts and may submit further motions for evidence.
(69) The Company did not state whether it intended to exercise its right to inspect the documents, nor
did it submit any further motions for evidence.
I.2.2. Findings of Fact
I.2.2.1. Identity of the Data Controller
(70) The Company is the operator of the Website and the domain user. In the Privacy Notice, it
identifies itself as the data controller, while it indicates that it acts as a joint data controller with
respect to certain partners.
(71) The Company’s primary activity is “retail brokerage of a mixed product range.”
(72) Pursuant to Section 3 of Act XXXIV of 2004 on Small and Medium-Sized Enterprises and the Support of
Their Development,
a medium-sized enterprise is defined as an enterprise with a total workforce of fewer than 250
employees and annual net sales revenue not exceeding the forint equivalent of 50 million
euros, or a balance sheet total not exceeding the forint equivalent of 43 million euros. According
to the Company’s annual report, in 2024 it employed […] people and had annual net sales of […]
HUF, based on which—according to the available data—it qualifies as a medium-sized
enterprise.
I.2.2.2. The Website’s Data Processing Documents
(73) With regard to the period under review, the Authority examined the Privacy Notice published on
the Website and effective as of July 2, 2025, as well as the documents submitted by the
Company (previous versions of the Website Privacy Statement, information related to the
Sweepstakes, the Blog Data Processing and Privacy Notice, and the Blog Terms and Conditions
of Use) as well as the documents generated during the on-site inspection and included in Record
No. NAIH-9706-2/2025.
14
(74) The Authority identified three main versions of the Website Notices submitted by the Company for
the period under review; within these versions, additional variants—which were not considered
separate versions but rather modifications to the given version—could also be distinguished, and
the Authority also examined the changes in their content:
- The first version is the Privacy Policy in effect from May 24, 2018, through January 31,
2020 (hereinafter: Notice No. 1). Changes to this version:
• Privacy Policy effective from February 1, 2020, through March 22, 2020 (hereinafter:
1.1. Notice);
• Privacy Policy effective from March 23, 2020, through March 25, 2020 (hereinafter:
1.2. Notice);
• Privacy Policy in effect from March 26, 2020, through May 18, 2020 (hereinafter:
1.3. Notice);
• Privacy Policy in effect from May 19, 2020, through June 8, 2020 (hereinafter:
1.4. Notice);
• Privacy Policy effective from June 9, 2020, through October 20, 2020 (hereinafter:
1.5. Notice);
• Privacy Policy effective from October 21, 2020, through November 9, 2020 (hereinafter:
1.6. Notice);
• Privacy Policy effective from November 10, 2020, through July 14, 2021 (hereinafter:
1.7. Notice).
- The second version is the Privacy Policy effective from July 15, 2021, through April 6,
2022 (hereinafter: Notice No. 2), with the following amendments:
• the Privacy Policy effective from April 7, 2022, through April 24, 2022 (hereinafter:
2.1. Notice);
• the Privacy Policy effective from April 25, 2022, through May 17, 2022 (hereinafter:
2.2. Notice);
• the Privacy Policy effective from May 18, 2022, through August 30, 2022 (hereinafter:
2.3. Notice);
• Privacy Policy effective from August 31, 2022, through October 27, 2022 (hereinafter:
2.4. Notice);
• Privacy Policy effective from October 28, 2022, through May 23, 2023 (hereinafter:
2.5. Notice).
- The third version is the Data Processing Notice effective from May 24, 2023, through
September 8, 2024 (hereinafter: Notice No. 3), with the following amendments:
• Effective from September 9, 2024, through July 1, 2025, the Data
Processing Policy (hereinafter: Policy 3.1);
• Effective from July 2, 2025, the Data Processing Notice
(hereinafter: Notice 3.2).
II. Applicable Legal Provisions
(75) Pursuant to Article 2(1) of the General Data Protection Regulation, the General Data Protection
Regulation applies to the processing of personal data, whether fully or partially automated, as
well as to the non-automated processing of personal data that forms part of a filing system or is
intended to form part of a filing system. 
(76) Pursuant to Section 2(2) of the Information Act, the General Data Protection Regulation shall
apply, subject to the additions specified in the provisions cited therein.
15
(77) Pursuant to Section 38(2) of the Information Act, the Authority is responsible for monitoring and
promoting the protection of personal data, as well as the right of access to data of public interest
and data made public in the public interest, and for facilitating the free flow of personal data within
the European Union.
(78) Pursuant to Section 38(2a) of the Information Act, the Authority exercises the tasks and powers
established for the supervisory authority in the General Data Protection Regulation with respect to
legal entities subject to Hungarian jurisdiction, as specified in the General Data Protection
Regulation and this Act.
(79) Pursuant to Section 38(3)(b) of the Information Act, within the scope of its responsibilities under
Sections 38(2) and (2a), the Authority shall, in particular, conduct data protection proceedings at
the request of the data subject or on its own initiative, as specified in this Act.
(80) Pursuant to Section 60/A(1) of the Information Act, the administrative deadline for data protection
authority proceedings is one hundred fifty days.
(81) Pursuant to Section 60(1) of the Information Act, in order to ensure the enforcement of the right to
the protection of personal data, the Authority shall initiate a data protection proceeding
upon the data subject’s request to that effect and may initiate such a proceeding ex officio.
(82) Pursuant to Section 71(2) of the Information Act: “The Authority may use documents, data, or
other evidence lawfully obtained in the course of its proceedings in other proceedings.”
(83) Pursuant to Section 99 of Act CL of 2016 on General Administrative Procedure (hereinafter: Ákr.)
, the Authority—within the scope of its jurisdiction—monitors compliance with the provisions set forth in
the law, as well as the fulfillment of the terms of enforceable decisions.
(84) Pursuant to Section 103(1) of the Ákr., in ex officio proceedings, the provisions of this Act
applicable to proceedings initiated upon request shall apply, subject to the exceptions set forth in
this chapter.
(85) Pursuant to Article 4(1) of the General Data Protection Regulation: “personal data” means any
information relating to an identified or identifiable natural person (“data subject”); “identifiable”
means a natural person who can be identified, directly or indirectly, in particular by reference to
an identifier such as a name, an identification number, location data, an online identifier, or to one
or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or
social identity of that natural person.”
(86) According to Article 4(2) of the General Data Protection Regulation: “processing” means any
operation or set of operations performed on personal data or on sets of personal data, whether or
not by automated means, including collection, recording, organization, structuring, storage,
adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or
otherwise making available, alignment or combination, restriction, erasure, or destruction.”
(87) Pursuant to Article 4(7) of the General Data Protection Regulation: “controller” means the natural
or legal person, public authority, agency, or any other body that, alone or jointly with others,
determines the purposes and means of the processing of personal data; if the purposes and
means of processing are determined by Union or Member State law, Union or Member State law
may also determine the controller or specific criteria for designating the controller.”
(88) Pursuant to Article 5(1)(a) of the General Data Protection Regulation: “Personal data:
16
(a) be processed lawfully, fairly, and in a transparent manner in relation to the data subject
(“lawfulness, fairness, and transparency”);”
(89) According to Article 5(2) of the General Data Protection Regulation: “The controller shall be
responsible for compliance with paragraph 1 and shall be able to demonstrate such compliance
(‘accountability’).”
(90) According to Article 6(1) of the General Data Protection Regulation: “The processing of personal
data is lawful only if and to the extent that at least one of the following applies:
a) the data subject has given consent to the processing of his or her personal data for one or
more specific purposes;
b) the processing is necessary for the performance of a contract to which the data subject is a
party, or for taking steps at the request of the data subject prior to entering into a contract;
c) the processing is necessary for compliance with a legal obligation to which the controller is subject;
d) the processing is necessary to protect the vital interests of the data subject or of another
natural person;
e) the processing is necessary for the performance of a task carried out in the public interest or
in the exercise of official authority vested in the data controller;
f) the processing is necessary for the purposes of the legitimate interests pursued by the
controller or by a third party, except where such interests are overridden by the interests or
fundamental rights and freedoms of the data subject that require the protection of personal data, in
particular where the data subject is a child.
Subparagraph (f) of the first paragraph shall not apply to processing carried out by public
authorities in the performance of their official duties.”
(91) According to Article 7(3) of the General Data Protection Regulation: “The data subject has the
right to withdraw consent at any time. Withdrawal of consent shall not affect the lawfulness of
processing based on consent prior to its withdrawal. The data subject must be informed of this
before consent is given. Withdrawal of consent must be made as easy as giving it.”
(92) Pursuant to Article 12(1)–(6) of the General Data Protection Regulation: “(1) The controller shall
take appropriate measures to ensure that the data subject is provided with all information
regarding the processing of personal data referred to in Articles 13 and 14, as well as all
information referred to in Articles 15–22 and
34, in a concise, transparent, intelligible, and easily accessible form, using clear and plain
language, particularly in the case of any information addressed to children. The information must
be provided in writing or by other means, including, where appropriate, by electronic means. At
the request of the data subject, information may also be provided orally, provided that the identity
of the data subject has been verified by other means.”
(93) According to Article 13 of the General Data Protection Regulation: “(1) Where personal data
relating to a data subject are collected from the data subject, the controller shall, at the time of
collection, provide the data subject with all of the following information:
a) the identity and contact details of the controller and, where applicable, the controller’s representative;
b) the contact details of the data protection officer, if any;
c) the purposes of the intended processing of personal data and the legal basis for the processing;
d) in the case of processing based on Article 6(1)(f), the legitimate interests of the data controller
or a third party;
e) where applicable, the recipients of the personal data or categories of recipients, if any;
f) where applicable, the fact that the controller intends to transfer personal data to a third country
or to an international organization, as well as the existence or absence of an adequacy decision
by the Commission, or, in the case of data transfers referred to in Article 46, Article 47, or the
second subparagraph of Article 49(1), the
17
appropriate and suitable safeguards, as well as a reference to the means of obtaining copies of
them or to their availability.
(2) In addition to the information referred to in paragraph (1), the data controller shall, at the time
the personal data are collected, in order to ensure fair and transparent processing, provide the
data subject with the following additional information:
a) the period for which the personal data will be stored, or, if that is not possible, the criteria used
to determine that period;
b) the data subject’s right to request from the controller access to and rectification or erasure of
personal data concerning him or her, or restriction of processing, and to object to the processing
of such personal data, as well as the data subject’s right to data portability;
c) in the case of data processing based on Article 6(1)(a) or Article 9(2)(a), the right to withdraw
consent at any time, which does not affect the lawfulness of the data processing carried out on
the basis of consent prior to withdrawal;
d) the right to lodge a complaint with a supervisory authority;
e) whether the provision of personal data is required by law or a contractual obligation, or is a
prerequisite for entering into a contract, whether the data subject is required to provide the
personal data, and the possible consequences of failing to provide such data;
f) the fact of automated decision-making referred to in Article 22(1) and (4), including profiling, as
well as, at least in these cases, the logic applied and comprehensible information regarding the
significance of such processing and the expected consequences for the data subject.
(3) If the controller intends to carry out further processing of personal data for a purpose other
than that for which the data were collected, the controller must inform the data subject of that
different purpose and of all relevant additional information referred to in paragraph (2) prior to
such further processing.
(4) Paragraphs (1), (2), and (3) do not apply if and to the extent that the data subject already
possesses the information.”
(94) According to Article 14 of the General Data Protection Regulation: “(1) Where personal data have
not been obtained from the data subject, the controller shall provide the data subject with the
following information:
a) the identity and contact details of the controller and, where applicable, the controller’s representative;
b) the contact details of the data protection officer, if any;
c) the purpose of the intended processing of the personal data and the legal basis for the processing;
d) the categories of personal data concerning the data subject;
e) the recipients of the personal data or, where applicable, the categories of recipients;
f) where applicable, the fact that the controller intends to transfer the personal data to a recipient
in a third country or to an international organization, as well as the existence or absence of an
adequacy decision by the Commission, or, in the case of a transfer referred to in Article 46, Article
47, or the second subparagraph of Article 49(1), as well as a reference to the means of obtaining
copies of such safeguards or to their availability. 
(2) In addition to the information referred to in paragraph (1), the data controller shall provide the
data subject with the following supplementary information necessary to ensure fair and
transparent data processing with respect to the data subject:
a) the period for which the personal data will be stored, or, if that is not possible, the criteria used
to determine that period;
b) if the processing is based on Article 6(1)(f), the legitimate interests of the controller or a third
party;
c) the data subject’s right to request from the controller access to and rectification or erasure of
personal data concerning him or her, or restriction of processing, and to object to the processing
of personal data, as well as the data subject’s right to data portability;
18
d) in the case of data processing based on Article 6(1)(a) or Article 9(2)(a), the right to withdraw
consent at any time, which does not affect the lawfulness of the data processing carried out on
the basis of consent prior to withdrawal;
e) the right to lodge a complaint with a supervisory authority;
f) the source of the personal data and, where applicable, whether the data is derived from
publicly available sources; and
g) the fact of automated decision-making, including profiling, referred to in Article 22(1) and (4),
and, at least in those cases, the logic applied and meaningful information regarding the
significance of such processing and the expected consequences for the data subject.
(3) The data controller shall provide the information referred to in paragraphs (1) and (2) as follows:
a) taking into account the specific circumstances of the processing of personal data, within a
reasonable period of time from the collection of the personal data, but no later than one month;
b) if the personal data are used for the purpose of contacting the data subject, at least at the time
of the first contact with the data subject; or
c) if the data is expected to be disclosed to other recipients, no later than the first time the
personal data is disclosed.
(4) If the data controller intends to carry out further processing of personal data for a purpose
other than that for which the data were collected, the data controller must inform the data subject
of this different purpose and of all relevant additional information referred to in paragraph (2) prior
to such further processing.
(5) Paragraphs (1) through (4) do not apply if and to the extent that:
a) the data subject already has the information;
b) the provision of the information in question proves impossible or would involve a
disproportionate effort, in particular for archiving purposes in the public interest, scientific or
historical research purposes, or statistical purposes; in the case of data processing carried out in
accordance with the conditions and safeguards set forth in Article 89(1), or where the obligation
referred to in paragraph (1) of this Article would be likely to render impossible or seriously
jeopardize the achievement of the purposes of such data processing. In such cases, the data
controller must take appropriate measures—including making the information publicly available—
to protect the data subject’s rights, freedoms, and legitimate interests;
c) the collection or disclosure of the data is expressly required by Union or Member State law
applicable to the data controller, which provides for appropriate measures to safeguard the data
subject’s legitimate interests; or
d) the personal data must remain confidential pursuant to a professional secrecy obligation under
Union or Member State law, including a statutory obligation of secrecy.”
(95) According to Article 15 of the General Data Protection Regulation: (1) The data subject has the
right to obtain from the controller confirmation as to whether or not personal data concerning him
or her are being processed, and, where such processing is taking place, the right to access the
personal data and the following information:
a) the purposes of the processing;
b) the categories of personal data concerning the data subject;
c) the recipients or categories of recipients to whom the personal data have been or will be
disclosed, including, in particular, recipients in third countries or international organizations;
d) where applicable, the envisaged period for which the personal data will be stored, or, if that is
not possible, the criteria used to determine that period;
e) the data subject’s right to request from the controller the rectification, erasure, or restriction of
processing of personal data concerning him or her, and to object to the processing of such
personal data;
f) the right to lodge a complaint with a supervisory authority;
g) if the data were not collected from the data subject, any available information regarding their
source;
19
h) the existence of automated decision-making, including profiling, referred to in Article 22(1) and
(4), and, at least in those cases, meaningful information about the logic involved, as well as the
significance and the envisaged consequences of such processing for the data subject.
(2) Where personal data are transferred to a third country or to an international organization, the
data subject has the right to be informed of the appropriate safeguards pursuant to Article 46
regarding the transfer.
(3) The data controller shall provide the data subject with a copy of the personal data undergoing
processing. For any additional copies requested by the data subject, the data controller may
charge a reasonable fee based on administrative costs. If the data subject submitted the request
electronically, the information must be provided in a commonly used electronic format, unless the
data subject requests otherwise.
(4) The right to request copies referred to in paragraph (3) shall not adversely affect the rights
and freedoms of others.”
(96) According to Article 18 of the General Data Protection Regulation: “(1) The data subject has the
right to obtain from the controller restriction of processing upon request if any of the following
applies:
a) the data subject contests the accuracy of the personal data; in this case, the restriction shall
apply for a period enabling the controller to verify the accuracy of the personal data;
b) the processing is unlawful, and the data subject opposes the erasure of the data and requests
the restriction of its use instead;
c) the data controller no longer needs the personal data for the purposes of processing, but the
data subject requires it to establish, exercise, or defend legal claims; or
d) the data subject has objected to the processing pursuant to Article 21(1); in this case, the
restriction applies for as long as it remains to be determined whether the controller’s legitimate
grounds override those of the data subject.
(2) If the processing is restricted pursuant to paragraph (1), such personal data may be
processed—with the exception of storage—only with the data subject’s consent, or for the
establishment, exercise, or defense of legal claims, or for the protection of the rights of another
natural or legal person, or for reasons of an important public interest of the Union or of a Member
State.
(3) The controller shall inform the data subject, at whose request the processing has been
restricted pursuant to paragraph (1), in advance of the lifting of the restriction on processing.”
(97) Pursuant to Article 22 of the General Data Protection Regulation: “(1) The data subject shall have
the right not to be subject to a decision based solely on automated processing—including
profiling—that produces legal effects concerning him or her or similarly significantly affects him or
her.
(2) Paragraph (1) shall not apply if the decision:
a) is necessary for the conclusion or performance of a contract between the data subject and the
data controller;
b) is permitted by Union or Member State law applicable to the data controller, which also
provides for appropriate measures to safeguard the data subject’s rights, freedoms, and
legitimate interests; or
c) is based on the data subject’s explicit consent.
(3) In the cases referred to in points (a) and (c) of paragraph (2), the controller shall take
appropriate measures to safeguard the data subject’s rights, freedoms, and legitimate interests,
including at least the right of the data subject to request human intervention by the
controller, to express his or her point of view, and to contest the decision.
(4) The decisions referred to in paragraph (2) may not be based on the special categories of personal
data referred to in Article 9
(1), unless Article 9(2)(a) or (g) applies and appropriate measures have been taken to protect the
data subject’s rights, freedoms, and legitimate interests.”
20
(98) Pursuant to Article 26(2) of the General Data Protection Regulation: “(2) The agreement referred
to in paragraph (1) shall set out the roles of the joint controllers in relation to data subjects and
their relationship with them. The essence of the agreement shall be made available to the data
subject.”
(99) According to Article 37 of the General Data Protection Regulation: “(1) The controller and the
processor shall designate a data protection officer in any case where:
a) data processing is carried out by public authorities or other bodies performing public tasks,
with the exception of courts acting in their judicial capacity;
b) the core activities of the data controller or data processor involve data processing operations
which, by virtue of their nature, scope, and/or purposes, require the regular and systematic
monitoring of data subjects on a large scale;
c) the core activities of the controller or processor involve the processing of special categories of
personal data as defined in Article 9 and data relating to criminal convictions and offenses
referred to in Article 10 on a large scale.
(2) The group of companies may also designate a single data protection officer if that officer is
easily accessible from all locations where the group operates. 
(3) If the data controller or data processor is a public authority or another body performing public
functions, a joint data protection officer may be appointed for several such bodies, taking into
account the organizational structure and size of the bodies in question.
(4) In cases other than those set forth in paragraph (1), the data controller or data processor, or
associations and other organizations representing categories of data controllers or data
processors, may appoint a data protection officer, or, if required by Union or Member State law,
are required to appoint one. The data protection officer may act on behalf of such associations
and other organizations representing data controllers or data processors.
(5) The data protection officer shall be designated on the basis of professional competence and,
in particular, expert-level knowledge of data protection law and practice, as well as suitability to
perform the tasks referred to in Article 39.
(6) The data protection officer may be an employee of the data controller or the data processor,
or may perform his or her duties under a service contract.
(7) The data controller or data processor shall publish the contact details of the data protection
officer and communicate them to the supervisory authority.”
(100) According to Article 45 of the General Data Protection Regulation: “(1) Personal data may be
transferred to a third country or to an international organization if the Commission has determined
that the third country, a territory or one or more specified sectors within that third country, or the
international organization in question ensures an adequate level of protection. No specific
authorization is required for such data transfers.
(2) In assessing the adequacy of the level of protection, the Commission shall take into account,
in particular, the following factors:
a) the rule of law, respect for human rights and fundamental freedoms, relevant general and
sector-specific legislation, including provisions on public security, defense, and national security,
as well as criminal law provisions; provisions governing public authorities’ access to personal
data; and the enforcement of such legislation; data protection rules, professional rules, and
security measures, including rules governing the onward transfer of personal data to another third
country or international organization that must be complied with within that country or
international organization; case law, as well as whether the data subjects whose personal data
are being transferred have effectively enforceable rights, including effective administrative and
judicial remedies;
b) whether there is one or more independent and effective supervisory authorities in the third
country in question—and whether the international organization in question is subject to the
supervision of such an authority—that is responsible for ensuring compliance with data protection
rules
21
and enforcement, possesses, among other things, appropriate enforcement powers, and is
responsible for providing assistance and advice to data subjects regarding the exercise of their
rights, as well as for cooperating with the supervisory authorities of the Member States;
furthermore,
c) the international obligations of the third country or international organization in question, or its
obligations arising from other legally binding agreements or legal instruments, as well as from its
participation in multilateral or regional systems—in particular those relating to the protection of
personal data.
(3) Following an assessment of the adequacy of the level of protection, the Commission may, by
means of implementing acts, determine that a third country, a territory of a third country, or one or
more specified sectors thereof, or an international organization, ensures an adequate level of
protection within the meaning of paragraph (2). The implementing act shall provide for a
mechanism for periodic review, to be carried out at least every four years, taking into account all
relevant developments in the third country or international organization concerned. The
implementing act shall specify its territorial and sectoral scope of application and, where
applicable, designate the supervisory authority or authorities referred to in paragraph 2(b). The
implementing act shall be adopted in accordance with the examination procedure referred to in
Article 93(2).
(4) The Commission shall keep under review developments in third countries and international
organizations that may affect the implementation of paragraph 3 of this Article and of decisions
adopted pursuant to Article 25(6) of Directive 95/46/EC.
(5) The Commission shall determine, on the basis of the available information, in particular the
review referred to in paragraph 3 of this Article, whether a third country, a territory, or a specific
sector of a third country, or an international organization no longer ensures an adequate level of
protection within the meaning of paragraph 2 of this Article, and, to the extent necessary, repeal,
amend, or suspend the previous decision referred to in paragraph 3 of this Article by means of an
implementing act, without retroactive effect. Such implementing acts shall be adopted in
accordance with the examination procedure referred to in Article 93(2).
In duly justified cases of extreme urgency, the Commission shall adopt immediately applicable
implementing acts in accordance with the procedure referred to in Article 93(3).
(6) The Commission shall initiate consultations with the third country or international organization
regarding the resolution of the situation leading to the decision referred to in paragraph (5).
(7) A decision pursuant to paragraph (5) shall not affect the transfer of personal data to the third
country, a territory within a third country, or one or more specified sectors thereof, or to the
international organization in question, pursuant to Articles 46–49.
(8) The Commission shall publish in the Official Journal of the European Union and on its website
a list of third countries, territories within third countries, and specific sectors, as well as
international organizations, for which it has determined that they do or no longer ensure an
adequate level of protection.
(9) Decisions adopted by the Commission pursuant to Article 25(6) of Directive 95/46/EC shall
remain in force until they are amended, replaced, or repealed by a Commission decision adopted
in accordance with paragraph (3) or (5) of this Article.”
(101) According to Article 46 of the General Data Protection Regulation: “(1) In the absence of a
decision pursuant to Article 45(3), the controller or processor may transfer personal data to a third
country or an international organization only if the controller or processor has provided
appropriate safeguards, and only on condition that enforceable rights and effective legal
remedies are available to data subjects.
(2) Without specific authorization from the supervisory authority, the appropriate safeguards
referred to in paragraph (1) may consist of the following:
22
a) a legally binding and enforceable legal instrument between public authorities or other bodies
performing public functions;
b) binding corporate rules pursuant to Article 47;
c) general data protection clauses adopted by the Commission in accordance with the
examination procedure referred to in Article 93(2);
d) standard data protection clauses adopted by a supervisory authority and approved by the
Commission in accordance with the examination procedure referred to in Article 93(2);
e) an approved code of conduct pursuant to Article 40, together with a binding and enforceable
commitment by the data controller or data processor in a third country to apply appropriate
safeguards, including those relating to the rights of data subjects; or
f) an approved certification mechanism pursuant to Article 42, together with a binding and
enforceable commitment by the data controller or data processor in a third country to apply
appropriate safeguards, including with respect to the rights of data subjects.
(3) With the authorization of the competent supervisory authority, the following, in particular, may
serve as appropriate safeguards referred to in paragraph (1):
a) contractual provisions between the controller or processor and the controller, processor, or
recipient of personal data in the third country or within the international organization; or
b) provisions to be incorporated into an administrative agreement between public authorities or
other bodies performing public tasks, including provisions regarding the enforceable and effective
rights of data subjects.
(4) In the cases referred to in paragraph 3 of this Article, the supervisory authority shall apply the
consistency mechanism referred to in Article 63.
(5) Authorizations issued by a Member State or a supervisory authority pursuant to Article 26(2)
of Directive 95/46/EC shall remain in force until, where necessary, the supervisory authority
amends, replaces, or revokes them. Decisions adopted by the Commission pursuant to Article
26(4) of Directive 95/46/EC shall remain in force until, where necessary, they are amended,
replaced, or repealed by a Commission decision adopted in accordance with paragraph 2 of this
Article.”
(102) Pursuant to Article 58(2) of the General Data Protection Regulation: “When acting in its corrective
capacity, the supervisory authority shall:
a) warn the controller or processor that certain proposed processing operations are likely to
infringe the provisions of this Regulation;
b) reprimand the controller or processor if its data processing activities have infringed the
provisions of this Regulation;
c) instruct the data controller or data processor to comply with the data subject’s request to
exercise their rights under this Regulation;
d) instruct the data controller or data processor to bring its data processing operations into
compliance with the provisions of this Regulation—in a specified manner and within a specified
time frame, where applicable;
[…]
i) impose an administrative fine in accordance with Article 83, in addition to or in lieu of the
measures referred to in this paragraph, depending on the circumstances of the case; and
j) order the suspension of data flows to a recipient in a third country or to an international
organization.”
(103) Pursuant to Article 83(2) and (5) of the General Data Protection Regulation: “[…]
(2) Administrative fines shall be imposed, in addition to or in lieu of the measures referred to in
points (a) through (h) and (j) of Article 58(2), depending on the circumstances of the case.  When
determining whether an administrative fine is necessary, or when
23
determining the amount of the administrative fine, due consideration must be given in each
individual case to the following:
a) the nature, severity, and duration of the violation, taking into account the nature, scope, or
purpose of the data processing in question, as well as the number of data subjects affected by
the violation and the extent of the harm they have suffered;
b) whether the violation was intentional or negligent;
c) any measures taken by the data controller or data processor to mitigate the damage suffered
by the data subjects;
d) the extent of the data controller’s or data processor’s liability, taking into account the
provisions of Articles 25 and 32;
e) any relevant prior infringements committed by the controller or the processor;
f) the extent of cooperation with the supervisory authority to remedy the infringement and mitigate
any negative effects of the infringement;
g) the categories of personal data affected by the breach;
h) the manner in which the supervisory authority became aware of the infringement, with
particular regard to whether the controller or processor reported the infringement and, if so, in
what detail;
i) if any of the measures referred to in Article 58(2) had previously been imposed on the data
controller or data processor in question—in the same matter—compliance with those measures;
j) whether the data controller or data processor has complied with approved codes of conduct
pursuant to Article 40 or approved certification mechanisms pursuant to Article 42; and
k) other aggravating or mitigating factors relevant to the circumstances of the case, such as
financial gain or avoided loss resulting directly or indirectly from the infringement.
[…]
(5) Violations of the following provisions shall be subject—in accordance with paragraph (2)—to
an administrative fine of up to EUR 20,000,000 or, in the case of undertakings, up to 4% of their
total worldwide annual turnover in the preceding financial year, whichever of the two amounts is
higher:
a) the principles of data processing—including the conditions for consent—in accordance with
Articles 5, 6, 7, and 9;
b) the rights of data subjects in accordance with Articles 12–22;
c) the transfer of personal data to a recipient in a third country or to an international organization
in accordance with Articles 44–49;
d) the obligations under Member State law adopted pursuant to Chapter IX;
e) failure to comply with an instruction from the supervisory authority pursuant to Article 58(2), or
with a request to temporarily or permanently restrict data processing or suspend data flows, or
failure to grant access in violation of Article 58(1).
[…]”
(104) Pursuant to Article 5(3) of Directive 2002/58/EC of the European Parliament and of the Council of
July 12, 2002, concerning the processing of personal data and the protection of privacy in the
electronic communications sector (“Electronic Communications Privacy Directive”): “Member
States shall ensure that the storage of data in a subscriber’s or user’s terminal equipment, or
access to data stored therein, is permitted only on condition that the subscriber or user concerned
has given his or her prior consent on the basis of clear and comprehensive information provided
in accordance with Directive 95/46/EC, including information on the purposes of the data
processing. This provision shall not prevent technical storage or technical access whose sole
purpose is the transmission of a communication over an electronic communications network, or
which is strictly necessary for the provider to provide an information society service explicitly
requested by the subscriber or user.”
24
III. Decision
III.1. The Requirement for Prior Notice of Data Processing
(105) The purpose of the information obligations set forth in Articles 12–14 of the General Data
Protection Regulation (GDPR) is to ensure that the data subject can learn in advance about the
manner and circumstances of the processing of their personal data and can monitor the
processing throughout its entire duration. The GDPR ensures this in several ways and regulates
the right to information. These rights enable data subjects to review data processing even before
it begins, to effectively monitor it throughout its entire duration, and to exercise any additional
rights they may have or seek legal remedies.
(106) The system of appropriate information provided for in the General Data Protection Regulation
serves to ensure that the data subject is aware of which of their personal data will be processed,
by which data controller, for what purpose, on what legal basis, and for how long. This is essential
for the data subject to be in a position to effectively exercise their rights.
(107) Pursuant to Article 12(1) of the General Data Protection Regulation, the data controller shall take
appropriate measures to provide the data subject with all information regarding the processing of
personal data referred to in Articles 13 and 14, as well as all information required under Articles
15–22 and 34, in a concise, transparent, understandable, and easily accessible form, expressed
clearly and in plain language. Incomplete or ambiguous information—particularly, but not
exclusively, regarding the purpose and legal basis—may directly affect the data subject’s ability to
exercise their rights.
(108) Articles 13 and 14 of the General Data Protection Regulation set forth the requirements, content,
and specific rules regarding information, based on two perspectives. On the one hand,
Article 13 governs the information provided when personal data is collected from the data subject
by data controllers, while Article 14 sets forth the rules for situations where personal data is not
obtained from the data subject by data controllers.
(109) With regard to data processing by online stores, since personal data is collected directly from
data subjects, the central element of the obligation to provide information is Article 13(1)–(2) of
the General Data Protection Regulation, which lists the essential circumstances of data
processing about which the data controller must provide information.
(110) As part of this prior notification, the data controller must strive to ensure that data subjects receive
as complete and accurate a picture as possible of the processing of their personal data, as this is
the only way for them to assess how a given data processing operation affects them. Article
13(1)–(2) of the General Data Protection Regulation specifies the minimum circumstances of data
processing about which data controllers must inform data subjects; however, this does not
preclude the data controller from providing more detailed information.
III.2. Data Processing Information Provided on the Website
III.2.1. The Data Processing Notice System
(111) The Authority first determined that the Company’s data processing notice practices during the
period under review were not implemented within a uniform, transparent system. Information
regarding data processing appeared in several separate documents and on different interfaces,
including in the notices related to the Website, in documents related to prize contests, in the data
processing notice related to the Blog, and in the data protection provisions of the General Terms
and Conditions (GTC) applicable to the Blog. The Authority
25
considers that it is not objectionable in and of itself for a data controller to use multiple notices tailored to
different data processing situations; however, this is subject to the condition that it be clear to the
data subject which document applies to which data processing activity and which platform, and
that the documents be consistent with one another and their relationship to each other be clearly
traceable.
The Company’s information system did not meet these requirements. It was not possible to
clearly determine from the documents reviewed exactly which data processing activities and
which platforms each notice covered. In particular, there was overlap between the privacy notices
related to the Website, the Blog Data Processing and Privacy Notice, and the data protection
provisions of the Blog’s Terms of Use, while these documents did not form a coherent information
system built upon one another.
(112) The Authority emphasizes that the requirement of transparency does not merely mean the formal
provision of information, but rather that the data subject must actually be able to understand the
essential circumstances of the data processing based on the information provided, specifically the
purpose, legal basis, and conditions of data processing, the parties involved in data processing,
and the options for exercising their rights. In the Authority’s view, the information system under
review did not meet this requirement, as the information regarding data processing appeared in
multiple separate documents that followed partially divergent logics.
(113) The documents did not refer to one another or did not do so appropriately, and they
failed to clarify which information the data subject should consider authoritative in the given data
processing situation. In the Authority’s assessment, the overlaps were not merely formal in
nature. Discrepancies were evident among the documents, particularly with regard to the legal
bases for data processing, the scope of recipients and data processors, and the description of
data transfers. For example, data processing related to the Blog was not governed exclusively by
the Blog’s Data Processing and Privacy Notice; the Website’s Notice also included a data
processing purpose related to blog registration, and the General Terms and Conditions (GTC)
applicable to the Blog also contained privacy provisions. However, these documents did not
present the legal basis, recipients, and conditions of data processing according to the same logic,
nor did they always present the same content. The Authority further found that the terminology
and structure of the documents were inconsistent and, in several cases, did not align with the
framework of the GDPR but instead partially reflected the logic of the previous data protection
regulations. In this regard, the Authority specifically noted that, during the period under review,
the Company’s privacy notices also referred to data processing based on the exercise of public
authority, even though the Company, as an online store engaged in commercial activities, did not
actually carry out such data processing. The Company itself stated that it would remove this
reference from the privacy notice. 
(114) The Authority also took into account that the Privacy Notice related to the Website included data
processing activities that were not directly related to services provided to Website visitors or
online store customers, but rather, for example, to camera surveillance carried out in warehouse,
security, or workplace environments. The inclusion of these data processing activities in the
Website’s general information further complicated understanding of exactly which group of data
subjects and which data processing situations the document applied to.
(115) The Authority also took into account the Company’s statements made during these proceedings,
which confirmed the identified shortcomings on several points. The Company itself acknowledged
that the structure and logic of the data processing documents do not fully meet the requirement of
transparency in all respects, and further stated that it had begun reviewing certain notices “to
provide more transparent and accurate information.” The Company was also unable to provide a
clear explanation
26
regarding the logic behind the structure of the notice and the listing of the various parties
involved.
(116) In the Authority’s view, the information system structured in this manner did not enable data
subjects to easily and effectively understand for what purposes, on what legal basis, with the
involvement of which recipients, and under what conditions their personal data were processed
when using the given platform or service. The problem, therefore, was not merely that the
information appeared in multiple documents, but that these documents could not be properly
linked to one another, their content partly overlapped and partly differed, and they did not provide
a consistent, transparent picture of the Company’s data processing practices.
(117) In light of all this, the Company violated the principle of transparency set forth in Article
5(1)(a) of the GDPR.
III.2.2. Information Provided by Each Document
III.2.2.1. Information Notice No. 1, effective as of May 24, 2018
(118) The Authority found that Privacy Notice No. 1, effective as of May 24, 2018,
Notice, effective as of May 24, 2018, did not comply with the requirements set forth in Article
12(1) of the GDPR, according to which the data controller is required to provide the data subject
with the information specified in Articles 13 and 14 in a concise, transparent, intelligible, and
easily accessible form, using clear and plain language.
(119) In this regard, the Authority notes that, overall, the structure, language, and conceptual
framework of Information Notice No. 1 did not enable the data subject to obtain a clear, internally
consistent, and easily understandable picture of the data processing.
(120) Already in its introductory section, Notice No. 1 used such general wording that conflated different
data processing situations, stating: “By using the Website, utilizing any of its services or
applications, or initiating such use, you, as a User, consent to the processing of your personal
data in accordance with the provisions of this Privacy Policy.” In contrast, later sections of the
document cited not only consent but also the performance of a contract, a legal obligation, and a
legitimate interest as possible legal bases. Thus, even in its basic structure, Information Notice
No. 1 did not clearly distinguish between the various data processing situations and gave the
impression that the use of the website, as such, constituted general consent to all data
processing.
(121) The Authority further found that Notice No. 1 did not contain a clear, separate description for each
data processing activity from which the data subject could have determined exactly for what
purpose, within the framework of what data processing operation, on what legal basis, and for
how long the Company processes their specific personal data. The relevant information was
scattered throughout Chapters I, III, IV, V, and VI, appearing in some cases repetitively and in
others inconsistently. For example, the document did not clearly state that the customer’s name
and address are processed in connection with invoicing and the retention of accounting records,
for the purpose of complying with a legal obligation, subject to a specified retention period.
Instead, Information Notice No. 1 was based on a general consent framework, while in other
sections it also referred to contract performance, legal obligations, and legitimate interests.
(122) The general consent logic was further reinforced by the provision in Section III.6 of Notice No. 1,
which states that by entering into any contract falling within the scope of the policy, data subjects
“expressly accept this Policy as well.” In its
27
ruling, the Authority held that this wording erroneously presented the acknowledgment of the data processing notice
as a binding legal acceptance and further reinforced the misleading impression that the use of the
service or the conclusion of a contract could be interpreted as general consent to data
processing.
(123) The conceptual framework of Notice No. 1 also failed to meet the requirement for clear and
comprehensible information. Chapter II expressly provided that “The terms used in the Data
Processing Notice shall be interpreted in accordance with the concepts defined in the interpretive
provisions of Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of
Information (Info Act) ....” and subsequently outlined the terminology used in the Info Act. In
addition, Chapter I included the following: “Data Processing Registration Number: […]; […]” was
also included. In the Authority’s view, given that the Act’s entry into force was contingent upon the
GDPR becoming applicable, the conceptual framework based on the Info Act and the emphasis
on the previous registration numbers did not convey an information system that was clear, up-to-date,
and actually helpful to data subjects in accordance with the GDPR.
(124) The Authority notes that, among the data used to identify the data controller, the data controller
listed a data processing registration number that no longer exists under current regulations and
has no legal significance. Given that the legal institution of the data protection registry maintained
by the Authority ceased to exist as of May 25, 2018, the continued use of the registration number
is misleading to data subjects, creating the impression that the data processing is listed in some
official registry or has undergone official approval. The Authority notes that even prior to May 25,
2018, the data processing registration number did not certify the lawfulness of data processing; it
merely served to identify the data processing in order to facilitate data subjects’
understanding of the matter. Any information in the notice that does not correspond to reality or
that relates to a situation that does not correspond to reality must be omitted. For example,
information regarding data processing operations that were not actually carried out, legal bases
and data subject rights that are not applicable to the data processing in question, and—among
other things—information concerning a data protection register that has already been
discontinued is unnecessary and misleading and must therefore be deleted in all cases.
(125) The Authority also notes that the wording of Information Notice No. 1 was linguistically incorrect,
editorially disjointed, repetitive, or incomplete in numerous places. An example of this is several
sections of Chapter X, where the rules regarding the Information Act, the GDPR, the rights of
data subjects, and the data controller’s procedures are presented consecutively but not in a
consistent logical order. Equally confusing is Section 3 of Chapter XVIII, which incorporates the
rule on keeping records of data processing activities in accordance with Article 30 of the GDPR
into the text of the privacy notice intended for data subjects without clarifying what function this
serves from the data subject’s perspective.
(126) In several places, Information Notice No. 1 used legal references and terminology that do not
align with the GDPR framework. For example, when describing data security requirements, the
notice did not base its information on the system of technical and organizational measures set
forth in Article 32 of the GDPR; instead, it referred to the Information Act and described the data
security provisions in general terms that were difficult for data subjects to follow. This further
reinforced the conclusion that Notice No. 1 did not follow the modern and clear information
structure required by the GDPR.
(127) Based on the foregoing, the Authority determined that, due to the overall structure, language,
legal reasoning, and, in several instances, contradictory or ambiguous wording of Notice No. 1,
the Company had violated Article 12(1) of the GDPR.
(128) The Authority found that Notice No. 1 did not provide clear, specific, and identifiable information
regarding the legal basis for each data processing activity.
28
(129) According to Section 2 of Chapter III of Privacy Notice No. 1, “The Data Controller …
processes personal data … on the basis of the Data Subjects’ voluntary, informed, and explicit
consent pursuant to Section 5(1) of the Information Act, or if necessary to fulfill a relevant legal
obligation, or to pursue the legitimate interests of the data controller or a third party...” In addition,
Section 5 of Chapter III lists several legal bases under Article 6(1) of the GDPR in succession:
“the data subject has given consent,” “processing is necessary for the performance of a contract,”
“processing is necessary for compliance with a legal obligation to which the controller is subject,”
“processing is necessary for the purposes of the legitimate interests pursued by the controller or
by a third party.” In contrast, Section IV, Point 1 states once again that “In the course of data
processing related to the operation and services of the Website, the collection and processing of
personal data is based on the data subject’s voluntary consent.”
(130) Section 1 of Chapter IV of the 1st Privacy Notice generally provided that data processing related
to the operation and services of the Website is based on the data subject’s voluntary consent,
while Section 7 of the same chapter already stipulated that the collected personal data may be
processed without further separate consent for the purpose of fulfilling the Service Provider’s
legal obligations, or to pursue its own or a third party’s legitimate interests, without requiring
further separate consent, and even after the user has withdrawn their consent. In the Authority’s
view, these provisions presented the legal basis for data processing in a manner that was
inconsistent with one another and were likely to mislead data subjects as to whether the
processing of their data was in fact based on consent, the performance of a contract, a legal
obligation, or a legitimate interest. 
(131) In the Authority’s view, these provisions do not make it clear to the data subject which specific
data processing activities are based on which specific legal grounds. Information Notice No. 1
lists the legal grounds side by side but does not assign them to specific data processing
operations. For example, it is not clear whether consent, performance of a contract, a legal
obligation, or a legitimate interest is the actual legal basis for online purchases, invoicing, data
transfers to courier services, customer service interactions, reviews, marketing communications,
or sweepstakes. In the absence of this information, the data subject is unable to assess the legal
basis on which their personal data is being processed, and consequently, the conditions for
exercising their individual rights are not transparent to them.
(132) For example, Section 3 of Chapter V defines the scope of data processed during a purchase as follows:
“Purchase: Data processed during an online purchase: name, email address, phone number,
address … list of purchased products”; however, Privacy Notice No. 1 does not clearly specify
the legal basis for this. Similarly, Section VI, Point 4 provides for the transfer of data to […], but
it does not clarify the specific legal basis for such data transfer to the data subject. Section V,
Paragraph 5, regarding marketing communications, and Section VI, Paragraph 3, already suggest
a consent-based approach, but these are not separated from the data processing necessary for
the purchase.
(133) Based on the foregoing, the Authority determined that the Company violated its obligation under
Article 13
(1)(c) of the GDPR.
(134) The Authority found that Information Notice No. 1 did not provide accurate, coherent information
regarding the recipients of data transfers or the categories of recipients that was clearly linked to
the specific data processing activities.
(135) Section 2 of Chapter I of Information Notice No. 1 states that “Partners selling products on the
Service Provider’s Website and its affiliated sites act as independent data controllers with respect
to the personal data provided during the purchase or inquiry process.”
29
At the same time, Sections 2–3 of Chapter I designate […] as data processors, along with […],
[…], […], […], and […]. Sections 1–4 of Chapter VIII, however, describe data transfers partly to
partners and partly to other recipients, but do not clarify the exact capacity in which each party
acts, nor do they specify which specific data processing purposes each data transfer relates to.
(136) It is particularly problematic that Section 4 of Chapter VIII of Information Notice No. 1
refers to data transfers to “joint controllers and/or data processors,” while other parts of the
document do not identify with sufficient precision who qualifies as a joint controller or whether
such a capacity actually exists, nor do they clearly distinguish between the roles of data controller
and data processor.
(137) The Authority emphasizes that the legal significance of identifying recipients or categories of
recipients is not merely a matter of form. Pursuant to Article 13(1)(e) of the GDPR, the data
subject must be informed of the recipients or categories of recipients to whom their personal data
may be disclosed. This information only fulfills its purpose if it allows the data subject to
determine, at a minimum, the purpose of the data processing associated with the specific recipient or
category of recipients and the role they play in the data processing. Notice No. 1 did not meet this
requirement, as it merely listed several parties but did not clarify for what purpose, with respect to
which categories of data, and in what capacity they would be subject to data transfer or data
processing.
(138) In the Authority’s view, the document also failed to describe the roles of external service
providers—particularly social media and advertising providers—in sufficient detail to allow the
data subject to clearly determine whether a given service provider was acting as a data
processor, an independent data controller, or in some other data processing capacity.
(139) The Authority therefore determined that the Company had violated the requirement set forth in Article
13(1)
(e).
(140) The Authority found that Notice No. 1 did not provide the detailed and unambiguous information
required by Article 13 of the GDPR regarding data processing related to the cookies used on the
Website.
(141) Chapter XV of Notice No. 1 merely states in general terms that “The Service Provider … uses
‘cookies’ …” and identifies the purposes of cookies as providing “a more comprehensive service”
and
“convenience features,” but it does not clearly describe the specific data processing purposes,
legal bases, scope of data processed, data retention period, or recipients associated with each
cookie.
(142) Notice No. 1 also fails to distinguish between cookies necessary for the website’s operation and
those requiring consent, and does not provide clear information regarding the legal basis for the
use of each type of cookie.
(143) The Company itself stated in these proceedings that it only later modified its information practices
regarding cookie management on the Website and, beginning in April 2021, has been using the
cookie panel provided by the […] service provider, which displays information on the type,
function, and duration of cookies. The Company further stated that the information regarding
cookie management was developed in greater detail within the framework of this system.
(144) Based on the foregoing, the Authority determined that the Company violated Article 13
(1)(c) and (e), as well as Article 13(2)(a).
30
(145) The Authority found that Privacy Notice No. 1 provided contradictory and incomplete information
regarding data transfers to third countries.
(146) According to Section 5 of Chapter VIII of Notice No. 1, “The Data Controller informs Data
Subjects that it does not transfer Data Subjects’ personal data abroad (outside the European
Union, to a non-EEA country), except with the Data Subject’s express consent...” In contrast,
Section 2 of Chapter XVII expressly provides that “The information stored by cookies (including
the User’s IP address) is stored on servers located in the United States.”
(147) In the Authority’s view, the two provisions clearly contradict each other. On the one
hand, Privacy Notice No. 1 generally excludes data transfers outside the EU; on the other hand, it
itself states that, within the framework of […]’s services, data is stored in the United States. It is
not clear to the data subject from this whether data is transferred to a third country.
(148) Furthermore, Information Notice No. 1 does not adequately describe the safeguards applicable to
such data transfers. Section 5 of Chapter VIII merely states that data transfers take place “with
safeguards in accordance with the provisions of the GDPR,” but does not describe the content,
nature, or availability of these safeguards, nor does it explain how data subjects can access
them.
(149) Inaccurate disclosure of recipients and data transfers is particularly significant in the context of
data transfers to third countries, since if the recipient is an organization outside the EEA, the data
subject must be informed, pursuant to Article 13(1)(f) of the GDPR, of the fact of the data transfer,
the existence or absence of an adequacy decision, and the appropriate or suitable safeguards
and how to access them. Notice No. 1 did not provide specific and verifiable information of this
nature in this regard.
(150) Based on the foregoing, the Authority determined that the Company violated Article 13
(1)(f) of the GDPR.
(151) The Authority found that the First Privacy Notice did not provide adequate, accurate, and
unambiguous information regarding the duration of data retention and the criteria for determining
it, covering all data processing activities.
(152) Although the table in Chapter VI lists retention periods for several data processing purposes,
these are not always clear, nor do they always correspond unambiguously to the legal basis and
nature of the specified data processing. For example, in the case of “Newsletter Distribution” and
“Sending telephone messages,” Privacy Notice No. 1 specifies the retention period as “until
revoked,” whereas the description of telephone notifications (“regarding any issues with the order,
its success, the status of the package, etc.”) does not clearly refer to communications for purely
marketing purposes. As a result, it is not clear to the data subject what different data retention
rules apply to communications related to the purchase versus marketing communications.
(153) Similarly, in the case of “Package Delivery,” the phrase “Until withdrawal” is used, which clearly
does not provide adequate information about data processing related to the fulfillment of a
purchase, the actual duration of which is not determined by the withdrawal of consent. In the case
of “Writing a Review” data processing, Notice No. 1 states that reviews are “stored and made
available on an ongoing basis,” from which the data subject cannot determine what specific
duration this entails or under what conditions the data processing will cease.
31
(154) Section 4 of Chapter IX further increases the uncertainty by providing the following summary:
“The duration of data processing extends until the time periods specified in the data processing
purposes, but as a general rule, until the purpose of data processing is fulfilled … and finally, until
the data subject withdraws their consent …” This wording does not make it clear exactly
according to what logic each specific data processing operation is terminated. Consequently, the
data subject cannot determine how long their personal data will actually be retained.
(155) The Authority therefore found that the Company had violated Article 13(2)
(a).
(156) The Authority found that Notice No. 1 provided information on the data subject’s rights in an
inappropriate structure, with insufficient clarity, and with content that was, in part, inaccurate. 
(157) Chapter X of Notice No. 1 and, in part, its subsequent sections provide information on data
subjects’ rights that is extensive but structurally disjointed and mixed in content. The text
simultaneously refers to the Information Act and the GDPR, describes certain rights multiple
times in varying formats, and in several instances it is unclear which rule applies to the
exercise of a given data subject right.
(158) Sections 5–8 of Chapter X explicitly describe the right to object based on Section 21 of the Infotv.,
while other sections of the First Notice also refer to the GDPR. According to Section X, Point 12,
the information provided covers “the information specified in Section 15(1) of the Infotv.”, rather
than primarily the right of access under Article 15 of the GDPR. Section 16 of Chapter X also
describes cases where information provided to data subjects may be omitted or restricted, mixing
references to the Information Act and the GDPR in a way that is difficult for data subjects to
follow.
(159) Particularly problematic is Section X, Paragraph 23, which states that in the event of a violation of
their rights, data subjects “may exercise their rights before the arbitration tribunal designated in
the Data Controller’s generally applicable and currently valid general terms and conditions” and
may also turn to the NAIH. In the Authority’s view, such a provision is misleading in the context of
data subjects’ enforcement of their rights and is likely to present the data subject’s remedies in an
ambiguous manner.
(160) Based on the foregoing, the Authority determined that the Company violated Article 13
(2)(b) of the GDPR.
(161) The Authority found that Notice No. 1 did not provide sufficiently differentiated and clear
information regarding the right to withdraw consent.
(162) Privacy Notice No. 1 generally applies the logic of consent to the Website’s entire data
processing system. This includes the introductory provision stating that by using the Website, the
user consents to the processing of their data, as well as Sections 1–2 of Chapter IV, which
generally attribute data processing related to the Website’s operation to consent. In contrast,
other sections of Privacy Notice No. 1 also mention data processing based on contractual
obligations, legal obligations, and legitimate interests.
(163) The Authority finds the general wording in Notice No. 1 particularly concerning, as it states that
the Company may be entitled to continue processing the data subject’s personal data even after
consent is withdrawn, based on a legal obligation or legitimate interest. It is not in itself impossible
that the processing of certain personal data may continue to be necessary after the withdrawal of
consent on the basis of another, independent legal basis; however, the data controller must set
forth the conditions for this in advance and unambiguously, linking them to a specific purpose of
data processing and a specific legal basis. In contrast, Information Notice No. 1 formulated the
continued processing of data as a general, undifferentiated possibility, from which the data
subject could not determine
32
which data processing activities would cease as a result of the withdrawal of consent, and which
data processing activities could continue on a different legal basis.
(164) Under this structure, it is not clear to the data subject to which data processing activities the right to
withdraw consent actually applies. Although Section 3 of Chapter X provides detailed provisions
on the withdrawal of consent given for marketing-related communications, it is not clearly evident
from the document as a whole which data processing activities—such as those related to
purchases, customer service, delivery, or other operations—are actually based on consent as a
legal basis. Consequently, it is not clear to the data subject in which cases of data processing
they may exercise their right to withdraw consent and in which cases they may not.
(165) The Authority therefore determined that the Company violated Article 13(2)
(c) of the GDPR, as it failed to provide clear information—specific to each data processing activity—
regarding the right to withdraw consent and its actual consequences.
(166) The Authority found that Information Notice No. 1 did not provide information regarding the right
to lodge a complaint with the supervisory authority in a sufficiently clear and appropriate context
as required by the GDPR.
(167) Although Section XII, Point 1 states that the data subject “may initiate an investigation with the
National Authority for Data Protection and Freedom of Information,” the information
regarding the enforcement of rights is inconsistent, because Section 23 of Chapter X
simultaneously identifies arbitration as a forum for enforcing rights. In the Authority’s view,
including arbitration in this manner among the remedies available in the event of a violation of the
data subject’s rights is misleading and does not provide the data subject with a clear picture of
their actual right to lodge a complaint and the system of legal remedies.
(168) The Authority emphasizes that the right to lodge a complaint with a supervisory authority is one of
the fundamental safeguards of the GDPR, intended to provide the data subject with a clear and
direct avenue for redress. The uncoordinated and, in part, misleading presentation of the
remedies in Information Notice No. 1 is likely to cause uncertainty for the data subject and
effectively hinder the effective exercise of their rights.
(169) Based on the foregoing, the Authority determined that the Company violated Article 13
(2)(d).
III.2.2.2. Amendments to Prospectus No. 1
(170) Prospectus 1.1, effective as of February 1, 2020, did not substantially remedy the previously
existing disclosure deficiencies; it largely retained the same content, and the amendments
introduced did not constitute a separate, new violation of the law, nor did they remedy the previously
existing violation.
(171) Information Notice 1.2, effective as of March 23, 2020, introduced, as a substantive new element
compared to the previous Information Notice 1.1, the inclusion of a separate section detailing
data transfers related to the payment service provider. Although the amendment described the
scope of the transferred data in greater detail, it still failed to clarify the legal basis for data
transfer, did not coherently integrate the nature of […] into the overall addressee structure of
Notice 1.2, and
the phrase “I acknowledge” presented the legal basis for data transfer in a misleading manner. The
amendment therefore did not substantially remedy the previously existing shortcomings.
33
(172) Information Notice 1.3, effective as of March 26, 2020, is the version that took effect on the 23rd day of
March 2020, immediately preceding the one effective as of March 26, 2020
March 23, 2020, which was in effect as of March 23, 2020, regarding the transfer of data to […],
but it did not remedy the ambiguous presentation of the legal basis for the data transfer—which
was based on the phrase “I acknowledge”—nor did it sufficiently clarify the roles of the recipients.
The amendment therefore did not give rise to a new violation, but it did maintain the previously
identified violation.
(173) The Authority found that Privacy Notice 1.4, effective as of May 19, 2020, introduced a new
data processing element compared to the previous version regarding the […]-related customer
satisfaction survey and the transfer of email addresses for this purpose. However, Notice 1.4
does not provide clear and comprehensive information in this regard, as it defines the legal basis
for data processing in a contradictory and insufficiently precise manner, fails to clarify the role and
status of […] as a recipient, and does not contain adequate information regarding the duration of
data processing.
(174) In light of the foregoing, the Authority finds that the amendment to Section 1.4 of the Privacy Notice not
only resulted in the persistence of the previous deficiencies but, in connection with the
introduction of a new data processing activity, the Company violated Article 13(1)(c) and (e)
and Article 13(2)(a) of the GDPR.
(175) The Privacy Notice 1.5, effective as of June 9, 2020, substantially amended the information
regarding the identity and contact details of the data protection officer compared to the previous
version. The Authority determined that this change, in and of itself, did not constitute a new,
separate violation; however, the amendment did not remedy the previously identified deficiencies
regarding legal bases, data transfers, retention periods, and transparent information, and thus the
prior state of non-compliance remained unchanged.
(176) Privacy Notice 1.6, effective as of October 21, 2020, was substantially amended from the
previous version in that Chapter VIII was supplemented with a new Section 8, which provides for
the transfer of data to […]. According to this amendment, the data transfer covers cookies and
browsing data stored during the customer’s browsing session, as well as the email address,
billing, and shipping information in the event of a purchase. The other provisions of Notice 1.6
remain substantively unchanged.
(177) In the Authority’s assessment, this amendment does not result in a new violation of the law;
however, it maintains the previously identified deficiencies in their original form and extends them
to an additional recipient. Notice 1.6 still fails to provide clear and comprehensive information
regarding data transfers as required by Article 13(1)(e) of the GDPR, particularly with respect to
the precise definition of the purposes of data processing, the legal bases, and the roles of the
recipients.
(178) Privacy Notice 1.7, effective as of November 10, 2020, introduced not merely formal
clarifications but substantive changes compared to the previous Privacy Notice 1.6 regarding the
description of data processors and the physical environment of data processing. While the
previous version identified […] as the organization assisting in providing the IT infrastructure, the
newer Notice named […] in this role and also modified the description of the location and
circumstances of data processing. 
(179) Notice No. 1.7 did not substantially remedy the previously existing deficiencies in the information
provided; it largely retained the same content, and the amendments introduced did not constitute
a separate, new violation of the law, nor did they remedy the previously existing state of noncompliance.
III.2.2.3. Prospectus No. 2, effective as of July 15, 2021
34
(180) The Authority found that Information Notice No. 2 contained not merely formal changes compared
to the previous version, but had also undergone substantial changes in its structure and level of
detail. The individual data processing operations—in particular those related to orders, marketing,
online payments, complaint handling, reviews, sweepstakes, customer service, and “data
processing related to the last order”—were presented in separate chapters, and data processors
and their roles were also covered in a separate chapter.
(181) The Authority found that, taken as a whole, the Privacy Notice does not present a unified,
coherent data processing system, but rather consists of elements that are partly contradictory
and not adequately coordinated.
(182) At the same time, the Authority notes that this structural and substantive revision did not, in and
of itself, result in the cessation of the previously existing violation. The second Privacy Notice
continued to retain the substantive shortcomings of the earlier versions, specifically the
inconsistent and intermingled presentation of legal bases, the unjustified overemphasis on
consent, the mixed description of data subjects’ rights—partly following the logic of the GDPR
and partly that of the Information Act—and the opaque description of data processing related to
cookies and web analytics tools. All of this confirms that the amendments did not give rise to a
new violation but rather resulted in the continuation of the previous state of non-compliance.
(183) The Authority emphasizes that Notice No. 2 underwent such extensive structural and substantive
changes compared to the previous version that it should be considered a separate, new data
processing notice. Accordingly, the Authority assessed the information gaps contained therein
independently, regardless of whether they had also appeared in part in the previous versions.
(184) In the Authority’s view, Notice No. 2 not only retained the previous deficiencies but also
constituted separate violations with respect to the newly introduced or modified data processing
activities.
(185) The Authority therefore assessed the amendments to the Second Privacy Notice on a case-by-case
basis: on the one hand, it noted the persistence of the previously existing deficiencies, and
on the other hand, it examined any new violations related to newly introduced or substantially
modified data processing activities.
(186) The Authority found that, in the new version, regarding certain data processing activities—in particular
“Data Processing Related to the Last Order,” as well as the more detailed marketing and
behavioral data processing operations—Privacy Notice No. 2 did not provide specific and
unambiguous information tailored to the specific characteristics of the respective data processing
operations. The shortcomings identified in this regard relate in particular to the determination of
legal bases, data transfers, and the description of how each data processing operation functions.
(187) In the Authority’s view, if the Second Notice fails to provide the specific and transparent
information required by Article 13 of the GDPR with respect to newly introduced or substantially
modified data processing operations, this should be assessed not merely as a continuation of the
previous deficiency, but as a new, separate violation. In the present case, the Authority
determined that the deficiencies related to certain data processing operations within the new
structure constitute such a separate violation.
(188) The Authority found that, despite the structural reorganization, the Second Privacy Notice continued to
retain the substantive deficiencies of previous versions in
several respects; in particular, the legal bases were still presented in a way that conflated them
and failed to differentiate them by data processing activity—especially through the use of consent
as a general, quasi-“default” legal basis—the description of data subjects’ rights was
inconsistent, following partly the logic of the GDPR and partly
35
the logic of the Information Act, which did not ensure a clear and precise understanding of how to
exercise those rights; the scope of data transfers and recipients associated with each data
processing operation was not consistently presented in relation to the specific purpose of the data
processing; retention periods were in many cases still defined in general, imprecise, or
conditional terms (“until withdrawal,” “until the purpose ceases to exist”), and the descriptions of
data processing activities related to cookies, web analytics, and advertising services remained
fragmented and difficult to follow. Despite the revised structure, the above shortcomings meant
that Notice No. 2 did not provide clear, transparent, and distinct information regarding the
individual data processing activities, which continued to result in a violation of the requirements
set forth in Article 12(1) of the GDPR.
(189) The Authority also specifically determined that the Notice contained an internal contradiction
regarding the presentation of the legal bases: Sections III.2 and III.6 generally link the processing
of personal data to the data subject’s consent or to the acceptance of the Privacy Notice, while
Chapters IV–XI assign different legal bases for specific data processing operations, in
accordance with Article 6(1) of the GDPR. This contradiction fails to make it clear to data subjects
on what legal basis each specific data processing activity actually takes place, which resulted in a
violation of the requirements set forth in Article 12(1) of the GDPR.
(190) The Authority further found that, in several instances, the scope of the personal data processed
as indicated in the summary table in Chapter XIII of the Privacy Notice does not correspond to the
detailed descriptions of the individual data processing operations provided in Chapters IV–XI. In
particular, with regard to data processing related to online payments, the detailed description lists
the username, last name, first name, address, phone number, email address, and bank account
number as processed data, while the summary table lists a narrower scope of data for the same
data processing activity. Such a discrepancy renders the information inconsistent and does not
meet the requirement for clear and transparent information set forth in Article 12(1) of the GDPR.
(191) The Authority found that, with regard to certain data processing activities introduced in the new
version or substantially modified, Notice No. 2 contains deficiencies that can be considered
separate violations of the law.
(192) Regarding the introduction of “Data Processing Related to the Last Order” as a separate data
processing activity, Notice No. 2 does not define the actual content and operation of the data
processing with sufficient specificity. Although it specifies the scope of the data processed (first
name, city), as well as “enhancing the user experience” as the purpose of data processing, the
latter is presented solely in a general, undefined manner, and it is not clear to which specific
function, service, or display solution the data processing relates (e.g., personalized interface,
recommendations, identification of returning users). Notice No. 2 also fails to explain the logic
behind the data processing, what events trigger it, or how it relates to the user’s previous activity.
Furthermore, despite the reference to consent as the legal basis, it is not explained how consent
is specifically obtained (e.g., via a separate checkbox, setting, or pop-up window), at what time,
under what conditions, or to which data processing operations it applies. As a result, it is not
clearly established for data subjects for what purpose and on what legal basis their personal data
are processed in this context, and consequently, the Company has violated Article 13(1)
(c).
(193) With regard to marketing and behavior-based data processing, the Privacy Notice in Section 2
of the Privacy Notice does indicate that the data controller analyzes users’ “purchasing habits” and
“user behavior,” but in this context, it does not provide clear and explicit information as to whether
the data processing involves profiling within the meaning of Article 4(4) of the GDPR. Notice No.
2 does not explain the logic behind such data processing—in particular, what data is used, what
methods are employed, and on what basis users’
36
— nor does it address the significance of this type of data processing or its expected
consequences for data subjects (e.g., personalized offers, display of different content, targeted
advertising). In this context, the 2nd Privacy Notice also states in another section that the data
controller’s activities constitute “regular and systematic, large-scale monitoring of data subjects”;
however, the substantive basis for this classification—the specific data processing operations on
which it is based, as well as a description of the associated data processing logic and
consequences—is entirely absent. The reference to “large-scale monitoring” is thus not linked to
specific data processing practices and does not make it clear to data subjects exactly what kind
of monitoring is taking place, based on which data categories, and how this affects them.
Due to these shortcomings in Notice No. 2, data subjects are not provided with adequate
information regarding the essential characteristics, significance, and expected consequences of
automated data processing and profiling, as a result of which the Company has violated Article
13(2)(f) of the GDPR. 
(194) The legal bases for each of the re-regulated data processing activities are set forth in Section
2 of the Information Notice—with simultaneous, undifferentiated references to Article 6(1)(a), (b), (c),
and (f) of the GDPR—without clearly specifying which legal basis actually applies to the specific data
processing purpose in question. In several places, Notice No. 2 states that the data controller
processes data “pursuant to Article 6(1) of the GDPR” and then lists the possible legal bases one
after another; however, it is not clear, for example, on which legal basis a specific data
processing activity related to marketing, customer service, or behavioral analysis is actually
carried out. Furthermore, the legal basis of consent is in several instances linked to data
processing activities that, by their nature, are more closely associated with the performance of a
contract or a legitimate interest; moreover, the specific method and timing of obtaining consent
are not described. When relying on the legal basis of legitimate interests, Notice No. 2 does not
describe the specific legitimate interest of the data controller or a third party, does not refer to the
essential aspects of the balancing of interests, and does not make it possible to understand what
justifies the data processing in relation to the data subject’s interests. As a result, it is not clearly
established for data subjects on what legal basis their personal data is being processed, and
consequently, the Company has violated Article 13(1)(c) and (d) of the GDPR.
(195) With regard to the newly identified data processors and recipients, while the Second Notice lists
several organizations, it does not clearly link their roles to the specific purposes of data
processing. The list of recipients is disconnected from the description of the data processing
operations, so it is not clear, for example, exactly which data is transferred for marketing
purposes, web analytics services, customer service communications, or online payments, for
what purpose, and to which specific organizations. In several instances, Privacy Notice No. 2
contains only general categories or lists, without presenting the actual operation and scope of
data transfers as they relate to the specific data processing activity. As a result, the system of
data transfers is not transparent to data subjects, and the Company has therefore violated
Article 13(1)(e) of the GDPR.
(196) The Authority further found that, in several instances, the scope of the personal data processed
as indicated in the summary table in Chapter XIII of the Privacy Notice does not correspond to the
detailed descriptions of the individual data processing operations provided in Chapters IV–XI. In
particular, with regard to data processing related to online payments, the detailed description lists
the username, last name, first name, address, phone number, email address, and bank account
number as the data being processed, while the summary table lists a narrower scope of data for
the same data processing activity. Such a discrepancy renders the information inconsistent and
fails to meet the requirement for clear and transparent information set forth in Article 12(1) of the
GDPR.
37
(197) Furthermore, Notice No. 2 addresses the issue of data transfers to third countries in a contradictory
manner. On the one hand, it explicitly states that the data controller does not transfer personal
data outside the European Union; at the same time, however, it refers to the use of several
services—in particular web analytics and advertising providers—whose operations may in fact
result in the transfer of data to a third country, specifically the United States. In this regard, Notice
No. 2 does not provide clear information on whether such data transfers take place and, if so,
under what safeguards—such as an adequacy decision, general terms and conditions, or other
safeguards—and how these are accessible to data subjects. With this contradictory and
incomplete information, the Company has violated Article 13(1)(f) of the GDPR. The Authority
finds that such contradictory information does not allow data subjects to verify the actual
circumstances of the data transfer.
(198) Finally, in several cases, the retention periods associated with newly introduced or substantially
modified data processing operations continue to be defined in general and conditional terms,
such as “until consent is withdrawn,” “until the purpose ceases to exist,” or “until the legal
relationship terminates,” without Information Notice No. 2 specifying a concrete, objective,
and predictable duration or clear criteria on the basis of which the data subject could actually
assess the duration of the data processing. Such phrasing does not allow for a prior and clear
understanding of the temporal scope of data processing, as a result of which the Company
violated Article 13(2)(a) of the GDPR.
(199) The Authority further found that, in the case of certain data processing activities, the Privacy
Notice applies an 8-year retention period to certain categories of data by referring to Section
169(2) of Act C of 2000 on Accounting, even though the retention of such data cannot be derived
from the cited legislation. In particular, with regard to data processing related to online
payments—such as usernames, phone numbers, and email addresses—as well as the retention
of product images and videos in the context of complaint handling and warranties, the Privacy
Notice generally links these retention requirements to accounting obligations. This information is
inaccurate and does not allow data subjects to clearly ascertain the duration of data processing,
which reinforces the violation of Article 13(2)(a) of the GDPR.
III. 2.2.4. Amendments to the 2nd Privacy Notice
(200) The Authority found that Notice 2.1, effective as of April 7, 2022, did not introduce a completely
new information system compared to the previous version; however, it modified the content of
certain sections on data processing, particularly regarding data processors and data transfers
related to data processing for marketing purposes. Compared to the previous version, the 2.1
Privacy Notice explicitly named […] and […], and defined in greater detail the scope of data
transferred to these organizations and their roles in data processing for marketing purposes. In
addition, the list of data processors in Chapter I was revised, as some of the organizations
previously listed there were replaced by others.
(201) At the same time, the Authority notes that the vast majority of these amendments did not result in
the creation of a new violation of the law, but rather confirm the persistence of previously
identified deficiencies in the information provided and their continuation in a new structure.
Section 2.1 of the Privacy Notice continued to contain the substantive errors of previous versions,
including, in particular, the inconsistent and confusingly intertwined presentation of legal bases,
the unjustified overemphasis on consent, the mixed description of data subjects’ rights—which
followed a logic based partly on the GDPR and partly on the Information Act—as well as the
fragmented and difficult-to-understand description of data processing activities related to cookies,
web analytics tools, and data processing for marketing purposes.
38
(202) The Authority emphasizes that the mere fact that certain parties and data categories related to
marketing data processing have been listed in greater detail does not constitute a new violation if
the substance of the deficiencies in the information provided remains unchanged. Accordingly,
the mere fact that Section 2.1 provides a more detailed list of the data processed in the context of
data processing for marketing purposes or lists the data processors in a new structure, provided
that it remains unclear to the data subjects how the individual data processing operations actually
function, on what legal basis they are carried out, and exactly which organizations play what roles
in them.
(203) The Authority found that, with regard to data processing for marketing purposes, Section 2.1 of
the Notice identifies the individual data processors and the scope of the data they process in
greater detail than the previous version. With regard to […] and […], Notice 2.1 now specifically
defines the types of data transferred and the individual elements of data processing. However,
this level of detail does not amount to a substantive clarification of the information provided, as it
remains unclear which organization acts in what capacity and in connection with which specific
data processing purpose during each data processing operation, and what logic governs the data
transfers.
(204) The Authority notes that this deficiency cannot be considered a new violation, as the structural
lack of transparency regarding information related to recipients and data processors was also
present in the previous Notice No. 2, effective as of July 15, 2021. The current version does not
introduce any new deficiencies in this regard, but rather contains a more detailed—though still
unclear—presentation of the previous, inadequate information practices, which confirms the
continuation of the prior non-compliance.
(205) The Authority further found that Privacy Notice 2.1 continues to address the issue of data
transfers to third countries in a contradictory manner in the current version. Although, on the one
hand, it excludes data transfers outside the European Union, on the other hand, it specifically
names a service provider based in a third country ([…]) to which personal data is or may be
transferred. However, this circumstance also cannot be assessed as a new violation, but rather
as an extension of the incomplete and contradictory information regarding data transfers to third
countries that already existed in the previous Privacy Notice, which confirms the continued
breach of the obligations under Article 13(1)(e) and (f) of the GDPR. 
(206) The Authority found that Privacy Notice 2.2, effective as of April 25, 2022,
has been substantially amended compared to the previous version
in that the […] ([…]) service is explicitly mentioned in the 2.2 Privacy Notice, both among the
data processors used and in the section concerning external web analytics and ad-serving
companies. According to the amended text, […] places tracking cookies on users’ devices for
remarketing purposes and monitors visitors’ online behavior.
(207) The Authority notes that this amendment did not result in the elimination of the previously existing
information gaps, but rather involved the insertion of a new entity—related to behavioral tracking
and remarketing—into an information system that was already inadequate to begin with. Although
Section 2.2 of the Privacy Notice names the […] service, it does not make clear exactly in what capacity this
party participates in the data processing, which specific personal data of data subjects are
processed, the exact legal basis for the data processing, the duration of the processing, or to
which recipients the data are transferred and along what data transfer chain.
(208) The Authority further found that, with regard to the data processing related to […], Section 2.2 of
the Notice also fails to provide clear and comprehensive information tailored to the specific
characteristics of the data processing in question regarding the operation of remarketing and the
tracking of users’ online behavior,
39
its logic, and its impact on data subjects. In this regard, Section 2.2 of the Notice does not
adequately address the legal basis, does not clearly link the recipients to the purpose of data
processing, and does not contain sufficiently specific information regarding the duration of data
processing either.
(209) The Authority found that the amendment effective as of April 25, 2022, did not remedy the
previously identified deficiencies in the information provided; thus, the infringing situation
persisted. However, the explicit mention of […] ([…]) as a remarketing and tracking service
signifies an expansion of the scope of the data processing activities under review; in this regard,
Section 2.2 of the Privacy Notice still does not contain the information required under Article 13(1)(c) of the
GDPR regarding the legal basis for data processing, clear and comprehensive information
regarding the recipients under Article 13(1)(e), and the retention period under Article 13(2)(a). In
this regard, the amendment does not establish a new category of violation but constitutes a
further manifestation of the previously established violation.
(210) The Authority found that Privacy Notice 2.3, effective as of May 18, 2022, contained
substantive changes compared to the previous version regarding provisions related to product
reviews and data processing for marketing purposes. On the one hand, the amendment
stipulated that personal data included in product reviews would also be used for marketing
purposes; on the other hand, it allowed for the uploading of photographs associated with reviews
and, in this context, the processing and publication of images. In the Authority’s view, these
amendments do not merely represent the persistence of previous deficiencies in the information
provision but introduce new elements of data processing that must be assessed independently.
However, Privacy Notice 2.3 does not provide sufficiently specific and clear information
regarding the purpose of data processing, its legal basis, the recipients, and the duration of data
processing; thus, data subjects are unable to fully understand the essential circumstances of the
processing of their personal data.
(211) The Authority found that Section 2.3 of the Notice does not provide sufficiently specific and
unambiguous information regarding the use of personal data contained in product reviews for
marketing purposes. Although the section on data processing for marketing purposes already
states that “personal data contained in product reviews used for marketing purposes” will be
processed,
Section 2.3 of the Notice does not specify exactly which personal data this covers, within the
framework of which specific marketing activities, through which data processing operations, and
in what context this takes place. Nor is it clear whether the public publication of the review and
the use of the personal data contained therein for marketing purposes constitute separate data
processing operations, and to what extent, at what time, and through what specific statement
consent is obtained in this regard. For these reasons, it is unclear to the data subjects for what
exact purpose and on what legal basis their personal data are being processed in this context, as
a result of which the Company violated Article 13(1)(c) of the GDPR.
(212) The Authority further found that the uploading of photographs in connection with reviews and the
personal data appearing therein—in particular, the information regarding the processing of
images—also do not fully comply with the requirements of the GDPR. Although Section 2.3 of the
Privacy Notice states that users have the option to upload a photograph and that, if their personal
data appears in it, the data controller will process it based on consent, it does not specify with
sufficient detail exactly on which platform, in what format, to which audience, and for how long the
photograph will be made available, nor does it describe the technical and content-related
parameters under which the publication will take place. Section 2.3 of the Notice refers to some of
these issues in the
“Product Review Policy,” with the result that the data subject cannot understand the content of the
data processing concerning him or her from Section 2.3 of the Notice alone, but must rely on a
combined interpretation with another document. This approach continues to fragment the
information provided and does not ensure that the data subject can understand, based on a
single, clear, and comprehensive set of information, to which recipients, in what manner, and
40
for what data processing purposes their image is made available; as a result, the Company
violated Article 13(1)(e) of the GDPR.
(213) In the Authority’s view, the information regarding the duration of data processing related to the
photograph and likeness is also not sufficiently clear. Although Section 2.3 of the Privacy Notice
defines the duration of data processing related to the review as lasting until the data subject
withdraws their consent, it does not provide adequate information on how the publicly published
photograph or any copies or shares thereof, as well as the technical and practical consequences
of removing the publication, will be handled following the withdrawal of consent. It is therefore
unclear to the data subject how long the content containing their image will actually remain
accessible and what effect the withdrawal will have on content that has already been published.
In light of this, the Company has also violated Article 13
(2)(a) of the GDPR in this regard.
(214) The Authority found that Privacy Notice 2.4, effective as of August 31, 2022, substantially
modified the rules governing data processing related to online payments compared to the
previous version. While the earlier version treated online payments as a single data processing
category, the new version has broken it down into “Advance Transfer” and “Payment by Credit
Card and Card Storage,” and in this context has introduced, as new content, descriptions of data
processing related to card storage and the “OneClick” payment method. The Authority notes,
however, that these amendments did not remedy the information gaps identified in the previous
Version 2.3 of the Privacy Notice; thus, the violation persisted even after the amendment.
(215) The Authority notes that this amendment did not merely involve a structural reorganization of the
previous information but also entailed the introduction of a new data processing element in the
context of online payments. Specifically, Section 2.4 of the Privacy Notice no longer merely states
that the customer’s data is transferred to […] for the purpose of processing online payments, but
also specifies that credit card data is recorded and stored on […]’s platform, and that by using the
“OneClick” payment method, the User can take advantage of a solution designed to simplify
future payments. The Authority finds that the introduction of these new data processing elements
would have provided even greater justification for presenting the information provided to data
subjects in a clear and comprehensive manner.
(216) In the Authority’s view, with regard to data processing related to card storage, Information Notice
2.4 does not specify the specific legal basis for the data processing with sufficient clarity.
Whereas in the case of “Advance Transfer,” the document explicitly cites Article 6(1) of the GDPR
(b) as the legal basis, no such explicit legal basis assigned to the specific data processing
operation appears in the context of “Payment by Credit Card and Card Storage.” From this
perspective, Section 2.4 of the Notice does not clarify whether card storage constitutes data
processing necessary for the performance of the contract or is based on some other legal basis,
even though this issue is essential for the data subject to assess the lawfulness of the data
processing. In light of the foregoing, the Company has violated Article 13
(1)(c).
(217) The Authority found that Section 2.4 of the Privacy Notice does not provide sufficiently
transparent and, in and of itself, comprehensive information regarding the transfer of data related
to credit card payments and the identification of the parties involved in data processing. Although
the document describes the scope of data transferred to […], and notes that the nature and
purpose of the data processing activities carried out by the data processor are available in […]’s
data processing notice, the Authority notes that a reference to the data processor’s own notice
does not exempt the data controller from its obligation to provide information under Article 13 of
the GDPR. 
41
(218) Notice 2.4 does not state clearly and in a manner that is understandable to the data subject on its
own exactly which data processing operations the data transfer relates to, for what purpose, and
in what capacity; furthermore, it does not consistently clarify the relationship between the data
controller and the data processor. The Authority notes that these deficiencies were also present
in the previous Version 2.3 of the Privacy Notice and were not remedied by the current
amendment; thus, the infringing situation remains unchanged. In light of all this, the Company
has violated Article 13(1)(a) and (e) of the GDPR.
(219) The Authority also found that Notice 2.4 does not provide adequate information—directly
accessible to the data subject—regarding the duration of data processing related to card storage.
While the document specifies an 8-year retention period for “Advance Transfer” data processing
in accordance with accounting obligations, it does not clearly state—particularly with regard to
credit card payments and, more specifically, card storage—how long the data processed in this
context, or the information related to solutions facilitating subsequent payments, remains in the
system, under what conditions it may be deleted, or how the data subject may request its
deletion.
(220) The Authority notes that the possible inclusion of information regarding the duration of data
processing in other, external privacy notices does not compensate for the deficiency in the data
controller’s own notice. Privacy Notice 2.4 thus does not enable the data subject to obtain clear,
advance knowledge of the time frame of data processing, as a result of which the Company
violated Article 13(2)(a) of the GDPR.
(221) The Authority found that Privacy Notice 2.5, effective as of October 28, 2022, primarily
amended, compared to the previous version, the name of the data controller ([…]), information
regarding its registered office and business premises, as well as the identity of the data protection
officer and the identification of certain external service providers. However, these changes are
typically of a formal nature and have not resulted in a substantive remedy for the previously
identified deficiencies in the information provided. The boilerplate and vague presentation of the
legal bases, the failure to specify the data subjects and data processors in relation to the
purposes of data processing, and the opaque description of data processing related to cookies,
remarketing, and web analytics remain unchanged; furthermore, with regard to data processing
related to online payments, a reference to the data processor’s privacy notice does not satisfy the
data controller’s own obligation to provide comprehensive and direct information.
III.2.2.5. Privacy Notice No. 3, effective as of May 24, 2023
(222) The Authority notes that Information Notice No. 3, effective as of May 24, 2023, cannot be
considered a structural continuation of Information Notices No. 1 and No. 2, but rather a
document prepared with a new structure, broken down by data processing purposes. In light of
this, the Authority assessed Notice No. 3 independently and examined whether the information
contained therein complies with the requirements set forth in Articles 12 and 13 of the GDPR.
(223) The Authority found that the scope of Notice No. 3 is not sufficiently clear. The document refers
generally to the “website” and to data processing activities managed by the Company; however, it
does not clearly specify exactly which online platforms the Notice covers, particularly the […]
online store, the […] website, or both. Although Section 2.10 of the Notice covers data processing
related to blog registration, separate data processing and usage documents were also associated
with the blog. As a result, it is not clear to the data subject which notice applies in a given data
processing situation. This system of information provision violates the requirement for clear,
transparent, and easily accessible information set forth in
Article 12(1) of the GDPR.
42
(224) In the Authority’s view, Notice No. 3 does not specify with sufficient precision the legal provision
serving as the legal basis for data processing in the case of several data processing purposes. In
particular,
Section 2.2 refers to Article 6(1)(c) of the GDPR in connection with data processing related to
invoicing and mandatory documentation, but fails to specify the specific sector-specific legal
provision that establishes the data processing obligation. The same shortcoming can be identified
in the context of complaint handling under Section 2.14, as well as in the handling of warranty
and guarantee matters under Section 2.15. A mere reference to Article 6(1)(c) of the GDPR does
not, in and of itself, make it clear to the data subject exactly which legal obligation applies to the
data controller. The Company thereby violated Article 13(1)(c) of the GDPR.
(225) The Authority further found that Section 2.2 of the Privacy Notice—in the context of data
processing related to invoicing—also lists certain categories of data, specifically including email
addresses. The Privacy Notice lists data categories—including, in particular, email addresses, the
contact person’s name, and job title—in the context of data processing related to invoicing, for
which the Privacy Notice fails to explain why their processing is necessary to fulfill invoicing and
accounting obligations. Consequently, the Notice does not provide sufficiently precise
information, tailored to the purpose of data processing, regarding the purpose, legal basis, and
scope of the data processed in this context.
(226) Section 2.5 of Notice No. 3 stipulates that, in the case of data processing related to the advance
payment service, the user name, last name, first name, address, phone number, email address,
bank account number, and order number are retained for 8 years following the purchase; however, it does not
explain what specific legal or data processing need justifies retaining this full set of data for eight
years. Merely citing the legal basis of “performance of a contract” does not, in and of itself, make
it clear why it is necessary to retain the entire set of data for such a period following the purchase.
The Company thereby violated Article 13(2)(a) of the GDPR.
(227) Section 2.8 of the 3rd Privacy Notice identifies the data controller’s legitimate interest as the legal
basis for data processing in the context of advertising services, providing information, sending
newsletters, email marketing (eDM), and telephone solicitations, and defines this legitimate
interest as direct marketing. However, the Notice does not specify the exact channels through
which such marketing-related data processing takes place, the specific group of data subjects
involved, or the conditions under which it occurs; furthermore, it does not clarify how the
consent requirements for electronic marketing communications are enforced. Consequently, it is
not clearly established for the data subject on what legal basis the data processing for marketing
purposes takes place, thereby constituting a violation by the Company of Article 13(1)(c) of
the GDPR.
(228) The Authority found that Sections 12.1–12.2 of the 3rd Privacy Notice do not describe the
conditions under which the data subject may exercise their rights in accordance with the requirements of the
GDPR. According to the document, the data controller charges an administrative fee if the data
subject requests information regarding the same data a second time within one month, and
may refuse to comply if the data subject exercises the same right a third time within one
month. This wording in Information Notice No. 3 gives the impression that a repeated request by
the data subject alone can justify the imposition of a fee or the refusal to comply with the request,
whereas the exercise of a data subject’s rights may only be restricted in this manner if the data
controller demonstrates that the request is manifestly unfounded or excessive. In the Authority’s
view, such information is likely to deter the data subject from exercising their rights or to create
uncertainty regarding such exercise. Consequently, the Company violated Article 12(1) of the
GDPR and Article 13(2)(b) of the GDPR.
(229) The Authority also found that, within the scope of “data processing related to the GDPR” as set
forth in Section 2.21 of the 3rd Privacy Notice, the information regarding the retention period does
not comply with the requirements of the GDPR. In this regard, the document states that the
planned duration of data processing is “indefinite,” meaning that it essentially provides for
retention for an unlimited period of time with respect to data subject requests, incidents, and their
documentation
43
data. The Privacy Notice does not specify a specific time period or provide clear, objective criteria
that would allow the data subject to determine how long the data controller will retain the personal
data processed in this context. The phrase “not to be discarded” leaves the time frame for data
processing completely open-ended; therefore, the Company has violated Article 13(2)(a) of
the GDPR in this regard.
(230) With regard to the data processing activity titled “Ensuring IT Business Continuity and Data
Backup” described in Section 2.23 of Privacy Notice No. 3, the Privacy Notice does not
provide sufficiently specific and unambiguous information. According to the document, “all
categories of digital data collected or processed by the Organization” may be processed for this
purpose; however, this definition is so general and unrestricted that the data subject cannot
determine exactly which personal data fall within this scope, what data processing operations are
involved, or what specific purpose they serve. Furthermore, the retention period is not sufficiently
clear, as Privacy Notice No. 3
uses the phrasing “for a maximum of 8 years, or until the data subject’s objection is deemed
valid, provided that this is technically feasible,” which does not establish a clear, foreseeable time
frame. In light of the foregoing, the Company has violated Article 13(1)(c) and Article 13(2)(a)
of the GDPR. 
(231) The Authority further found that Sections 7, 10, and 11 of the 3rd Privacy Notice do not provide
clear and coherent information regarding the description of data processors, recipients, and data
transfers to third countries. Section 7 presents the categories and specific entities of recipients
and data processors in an extremely broad and heterogeneous list—including, among others,
suppliers and partners outside EEA member states, operators of social media sites and websites,
[…] and […] […]—without clearly assigning them to specific data processing purposes and data
categories. Although Section 10 describes certain data transfers in greater detail, this does not
provide a clear overview of the purpose, legal basis, and role of all recipients, data processors,
and data transfers listed in Section 7. Section 11 provides safeguards regarding data transfers to
third countries exclusively with respect to […], while other parts of the Notice indicate that
additional entities outside the EEA may also be involved. As a result, it is not clearly established
for the data subject which of their personal data are transferred to which specific recipients, for
what data processing purposes, in what capacity, or exactly which data transfers to third
countries take place and what safeguards are associated with them. The Company has thereby
violated Article 13(1)(e) and (f) of the GDPR.
(232) The Authority further notes that Privacy Notice No. 3 does not consistently describe the data
processing roles of marketplace partners. According to Section 1 of Privacy Notice No. 3,
partners selling products on the Website act as independent data controllers, while Section 7
refers to marketplace partners as “joint data controllers.” However, during the clarification of the
facts, the Company stated that there is no joint data processing with marketplace partners and
that the reference to joint data processing will be removed from the Privacy Notice. The Authority
therefore did not find a violation of Article 26 of the GDPR in this case; however, it assessed the
contradictory provisions of the Notice in light of the obligation to provide information to data
subjects and parties involved in data processing. Due to these internal contradictions in Notice
No. 3, it was not clear to data subjects in what capacity the marketplace partners were involved in
the processing of their personal data. The Company thereby violated Article 13(1)(e) of the
GDPR.
(233) Finally, the Authority notes that the 3rd Privacy Notice contains several data processing
purposes—in particular, camera surveillance as described in Sections 2.9 and 2.22, as well as
data processing related to events as described in Sections 2.19–2.20—that are not exclusively
related to visitors or customers of the […] online store. The inclusion of these data processing
activities is not unlawful in and of itself; however, combined with the imprecise definition of the
Privacy Notice’s scope, it further increases uncertainty as to exactly which group of data subjects
44
, which platforms, and which data processing situations it applies to. The Authority assessed this
Article 12(1).
III.2.2.6. Amendments to the 3rd Privacy Notice
(234) The Authority found that Notice No. 3.1, effective as of September 9, 2024, was supplemented
with substantially new data transfer elements compared to the previous version. New content
elements included descriptions of data transfers to […], […], […], and […], which are related to
measuring the effectiveness of […]’s advertisements and to web traffic analytics purposes, and in
this context, also cover the—in certain cases. The Authority notes, however, that these
amendments did not remedy the previously identified deficiencies in the information provided; in
particular, the retention periods remained insufficiently specific, the presentation of recipients and
data processors remained fragmented and difficult to follow, and the wording regarding data
subjects’ rights remained imprecise and, in some cases, restrictive.
(235) In the Authority’s view, the data transfers newly described in Sections 10.5–10.8 do not merely
constitute a clarification of the previous information but involve the introduction of new data
processing operations and new categories of recipients. However, Privacy Notice 3.1 does
not assign a specific legal basis to these operations that is independent, clear, and directly
recognizable to the data subject, but merely describes them in a descriptive manner in the section
on data transfers. Furthermore, the exact roles of […], […], […], and […] in data processing are
not clearly defined; thus, Section 3.1 of the Notice does not clarify whether these organizations
participate in data processing as data processors, independent data controllers, or in some other
capacity. Based on the foregoing, the Company has violated its obligation to provide
information under Article 13(1)
(c) and subparagraph (e).
(236) The Authority further found that Section 3.1 of the Privacy Notice does not provide adequate
information regarding the retention periods associated with the newly disclosed data transfers or
the timeframes for data processing. It is not clear for how long the data transferred to […], […],
[…], or […]—whether hashed or otherwise technically transformed—may be used, for what period
they may be linked to ad views or purchases, or when they will be deleted. The Authority notes
that a hashed or encrypted format does not, in and of itself, render clear information regarding the
duration of data processing unnecessary. Therefore, the Company violated Article 13(2)(a) of
the GDPR.
(237) In the Authority’s view, the new amendment also failed to clarify the information regarding data
transfers to third countries. Section 11 of the 3.1. Privacy Notice continues to contain a reference
to safeguards exclusively in relation to […], while other parts of the document continue to mention
the Israeli […], and, as new data transfer elements introduced by this amendment, additional data
processing activities for analytical and marketing purposes involving the use of data subjects’
personal data have been introduced. The Authority notes that deficiencies in the information
regarding data transfers to third countries were also present in earlier versions; however, with the
introduction of the new data transfer operations, the internal contradictions and shortcomings in
Section 3.1. became even more apparent, and they do not make it clear to data subjects in which
cases, to which recipients, and under what safeguards their personal data is transferred outside
the European Economic Area. Shortcomings in the information regarding data transfers to third
countries were present in earlier versions as well, and this amendment has not remedied them.
With the introduction of new data transfer operations, these shortcomings have become even
more apparent; however, the Authority does not find a new, separate violation in this regard.
45
(238) Finally, the Authority notes that the internal date markings in Section 3.1. of the Privacy Notice are also
inconsistent: the content of the document has been substantially expanded, yet the “Effective
Date” remains May 24, 2023, while the document’s closing clause refers to September 9, 2024,
and the version number remains 2.0. In the Authority’s view, this editorial and temporal
inconsistency creates uncertainty for the data subject as to the effective date of the new data
processing rules.
(239) The Authority found that Notice 3.2, effective as of July 2, 2025, contains only limited substantive
changes in structure and content compared to the previous
3.1. Information Notice. Although the amendment resolved the previous inconsistency between
the document’s date, version number, and effective date, it did not remedy the previously
identified shortcomings regarding the content of data processing activities and the information
provided to data subjects.
(240) The Authority found that the amended Section 3.2 of the Privacy Notice introduced, as a new
element, a description of the data transfer to […] in Section 10.9. In this regard, Notice 3.2
specifies the scope of the data processed and the general purpose of the data transfer; however,
it does not make it clear to which specific data processing purpose the data transfer relates, nor
does it specify the legal basis for the data transfer.
(241) The Authority found that the deficiencies regarding the data transfer to […] are identical in
substance to the deficiencies identified in connection with other data transfers described in
Section 3.2 of the Notice—in particular, those concerning additional recipients identified in the
context of data processing for marketing and analytical purposes. Although the Company
expanded the content of Section 3.2 of the Notice by adding […], as a new recipient, this
amendment was not accompanied by a substantive review of the structure of the information
provided; thus, the purpose of the data transfer, its legal basis, and its connection to the individual’s
data processing operations remain unclear in this regard as well. The Authority therefore notes
that these deficiencies do not constitute a new violation but rather confirm the continued
existence and extent of the previously established violations of information disclosure obligations.
(242) Overall, the Authority found that the amendments to the successive versions of the privacy notice
published throughout the entire investigation period did not result in any substantive improvement
in terms of providing adequate information to data subjects. Although later versions formally
expanded the
3.2. content of the Notice, these additions were not accompanied by a systematic reevaluation or
coherent restructuring of the information provided. Consequently, the previously identified
shortcomings persisted throughout the entire review period, while the newly added data
processing elements resulted in further ambiguities and contradictions. In the Authority’s view, the
successive amendments to the notices thus did not contribute to compliance but further impaired
the clarity and comprehensibility of the information provided. 
III.3. Information Related to a Sweepstakes
(243) The Authority found that the Privacy Notice related to the prize drawing dated May 16, 2022
(hereinafter: 1. Prize Draw Notice, attached to the Company’s response letter dated December
12, 2025, registered under No. NAIH-15402-7/2025) did not provide data subjects with the
comprehensive and unambiguous information required by Article 13 of the GDPR.
(244) Although the document does include the purpose of data processing, a portion of the scope of the
data processed, and consent indicated as the legal basis, the information is incomplete or
unclear with respect to several essential elements. The Authority determined that the
46
does not comply with the requirements of the GDPR, as, in addition to data processing based on
consent, it also cites compliance with a legal obligation regarding the retention of winners’ data;
but it does not clearly assign the applicable legal basis to the individual data processing purposes
and categories of data; thus, data subjects cannot determine on what legal basis specific data
processing operations are carried out.
(245) The Authority further notes that the Information Notice for Prize Contest No. 1 does not contain
specific information regarding the particular characteristics of the prize contest in question or
details illustrating the actual circumstances of the data processing; in particular, it does not
provide detailed information on the data processing procedure, the manner in which the data is
used, any potential disclosures, or the parties involved in the data processing. Such a general,
boilerplate formulation of the information does not allow data subjects to actually understand the
specific characteristics of the data processing in question.
(246) The Authority further found that the document does not contain adequate information regarding
the recipients of data transfers and the data processors, as it does not specifically identify them,
nor does it provide information on whether data will be transferred to a third country, or, in the
event of such transfers, what safeguards are in place to protect the rights of data subjects.
(247) The Authority notes that the information regarding the duration of data processing is also unclear,
since, on the one hand, the document specifies a short retention period of no more than 30 days,
while on the other hand it prescribes a retention obligation of several years for certain data,
without clearly distinguishing the retention periods associated with each specific data processing
activity.
(248) The Authority also found that the Information Notice for Prize Draw No. 1 does not contain
information regarding whether the provision of data is mandatory or what the consequences are
of failing to provide data, nor does it provide information on the use of automated decision-making
or profiling, or the absence thereof.
(249) In the Authority’s assessment, the designation of consent as the legal basis does not comply with
the requirements of the GDPR, since, according to Prize Contest Information Notice No. 1,
Prize Contest Information Notice, consent to data processing is not given through a separate,
explicit statement, but rather takes place in connection with and as part of participation in the
prize contest. Consent given in this manner does not qualify as voluntary, unambiguous, and
appropriate consent under the GDPR.
(250) Based on the foregoing, the Authority determined that the Company violated Article 13
(1)(c), (e), and (f), as well as Article 13(2)(a) and (e).
(251) The Authority found that, with regard to the prize drawing conducted in cooperation with […],
effective as of September 1, 2023 (hereinafter: 2nd Prize Draw Information), the legal basis for
data processing is uniformly stated as the consent of the data subjects; however, it does not
contain information that would allow data subjects to assess the actual nature of their consent
and its relationship to the data processing activities. The 2nd Prize Draw Information Notice does
not clarify under what conditions the data processing related to participation in the prize draw and
the awarding of prizes takes place, nor how these activities relate to the service used by the data
subject. Consequently, it is unclear to data subjects to what extent consent is truly voluntary and
on what basis the data processing takes place; thus, the 2nd Sweepstakes Notice does not
provide transparent and unambiguous information regarding the legal basis for data processing.
(252) The Authority further found that the 2nd Prize Draw Information Notice does not provide
sufficiently clear and unambiguous information regarding the scope of data controllers. Although
the title and
47
introductory section refer to data processing carried out in cooperation between the Company
and its Partners, the 2nd Prize Contest Information Notice actually identifies only the Company as
the data controller and does not clarify the role of the Partners, specifically whether they act as
independent data controllers, joint data controllers, or data processors. In the absence of such
clarification, data subjects cannot clearly determine which organizations process their
personal data and in what capacity.
(253) The 2nd Sweepstakes Notice also fails to provide sufficiently structured and clear information
regarding data transfers. The identification of recipients varies depending on the specific data
processing activity and is, in some cases, incomplete; furthermore, the role of data processors—
in particular […] and […]—as well as the nature and purpose of the data processing operations
they perform, are not detailed. All of this prevents data subjects from understanding the data flow
processes in which their personal data are involved.
(254) The Authority also found that the 2nd Prize Draw Information Notice contains an internal
contradiction regarding data transfers. Point 1 of the document states, with regard to the data
processed in connection with participation in the prize draw, that “the Company does not transfer
personal data to third parties,” while Section 2, in connection with notifying the winner and
delivering the prize, explicitly provides for the transfer of personal data to […], and also
designates […] and […] as data processors. The Notice also states that these service providers
may transfer personal data to a third country under specific contractual terms. In the Authority’s
view, the relationship between these provisions is unclear: it cannot be unequivocally determined
for the data subject which personal data, in connection with which data processing operation, are
transferred to which recipients or data processors, or when and under what conditions a transfer
to a third country may occur. This internal contradiction violates the requirement for clear and
transparent information set forth in Article 12(1) of the GDPR.
(255) With regard to data transfers to third countries, the 2nd Prize Draw Information Notice merely
states in general terms that data processors may transfer data under specific contractual terms,
but it does not specify the type of safeguards applied, their essential characteristics, or
information relevant to data subjects. Due to this deficiency, data subjects do not receive
adequate information about the conditions and risks associated with the transfer of their personal
data to a third country.
(256) The Authority further found that the provisions regarding data subjects’ rights in the 2nd
Sweepstakes Notice were formulated in a general, boilerplate manner and are not linked to
specific data processing operations or their legal bases. Consequently, the Information Notice for
the 2nd Sweepstakes does not ensure that data subjects actually understand what their rights are
in specific cases and under what conditions they may exercise them.
(257) Based on the foregoing, the Authority finds that the Company has violated its obligation under
Article 12(1) of the GDPR to provide transparent, understandable, and clear information, as well
as its information obligations set forth in Article 13(1)(a), (e), and (f) of the GDPR.
(258) The Authority found that while the Sweepstakes Rules (hereinafter: Sweepstakes Rules),
effective as of October 10, 2022, do contain certain provisions regarding the processing of
personal data, they do not provide the comprehensive and unambiguous information required by
Article 13 of the GDPR. The document does not distinguish between the various purposes of data
processing and the related data processing operations, nor does it provide a clear and
unambiguous presentation of the legal bases for such processing.
48
(259) The Authority further found that the Sweepstakes Rules link participation in the sweepstakes to
data processing for marketing purposes, as they require participants to subscribe to the
newsletter and consent to the use of their data for marketing purposes as a condition of
participation when providing their email address. However, the Sweepstakes Rules do not
provide a separate and clear description of these data processing purposes, so it is not clear to
data subjects for what purposes and under what conditions the various data processing
operations take place.
(260) The Sweepstakes Rules contain incomplete information regarding data transfers and data
processors. Although Section V of the document states that “we do not transfer data to third
parties other than the data processor,” this only implies that the Company uses a data processor;
however, the Rules do not specify the identity or category of the data processor, the scope of
data transferred to the data processor, or the purpose and nature of the data processing.
Consequently, data subjects cannot determine to which data processor their personal data is
transferred in connection with the administration of the sweepstakes, the drawing,
communication, or the delivery of prizes, for what purpose, or for the purpose of performing which
data processing operations. 
(261) The Sweepstakes Rules also do not provide information on whether data transfers to third
countries occur during data processing related to the sweepstakes. The document does not state
whether the data processor or other service provider engaged carries out data transfers outside
the EEA, and if so, under what safeguards. Due to this omission, data subjects do not receive
adequate information regarding the possible transfer of their personal data to a third country.
(262) The Authority further found that the Sweepstakes Rules do not contain information regarding the
duration of personal data storage or the criteria for determining such duration; thus, data subjects
are not provided with adequate information regarding how long their data will be processed.
(263) The Authority notes that, with regard to provisions on data processing, the Sweepstakes Rules
primarily refer to Act CXII of 2011 on the Right to Informational Self-Determination and Freedom
of Information, and do not contain specific and detailed information tailored to individual data
processing operations as required by the GDPR. Furthermore, the Sweepstakes Rules stipulate
that, for matters not regulated therein, the privacy policy available on the Company’s website
shall prevail; this results in fragmented information and fails to ensure that data subjects can
access the full terms and conditions of data processing in a single, transparent location.
(264) Based on the foregoing, the Authority finds that, with respect to the Prize Draw Rules, the
Company has violated its obligation under Article 12(1) of the GDPR to provide transparent,
understandable, and easily accessible information, as well as its obligations under
Article 13(1)(c), (e), and (f), as well as its information obligations set forth in Article 13(2)(a).
III.4. General Terms and Conditions
(265) The Authority found that the Company’s General Terms and Conditions for Consumers and Users
(hereinafter: Website Terms and Conditions) allowed users, during the period from February 1,
2020, to August 31, 2022, to provide their child’s name, gender, and age (broken down by year,
month, and day) during registration.
49
(266) The Authority notes that none of the Company’s privacy notices applicable during the period
under review contained information regarding the processing of this personal data; thus, the data
subjects were not informed of the purpose, legal basis, duration, or recipients of the data
processing.
(267) In the Authority’s assessment, the processing of personal data relating to children in this manner
resulted in a particularly serious lack of transparency. The Authority found that the Company
allowed users to provide data concerning children (specifically, to record information regarding
the children and their dates of birth); however, in this context, the Privacy Notice did not contain
explicit and unambiguous information stating that such data processing would take place.
(268) Under these circumstances, it was not apparent to the data subjects that the data provided would
be processed as personal data relating to children, nor was it clear for what purposes and under
what conditions the Company would process such data. The fact and scope of the data
processing thus remained hidden from the data subjects.
(269) In the Authority’s assessment, the fact that the Company did not specify the processing of
personal data relating to children in the Privacy Notice should be considered a particularly
aggravating circumstance, as this made it impossible for the data subjects not only to understand
the data processing but also to recognize that it was taking place.
(270) Based on the foregoing, the Authority determined that the Company violated Article 13
(1)(c) and (e), as well as its information obligations under Article 13(2)(a)–(d), as it did not
make this information available to data subjects at all.
(271) The Authority further found that Chapter XII of the Website’s General Terms and Conditions
(GTC), effective as of August 31, 2022, does not provide clear and unambiguous information
regarding the legal bases for data processing. Section 12.4 of the GTC gives the impression that
the processing of personal data may take place solely on the basis of the data subject’s consent,
and that in the absence of consent, data processing may only occur in an anonymous manner;
however, based on the Company’s actual data processing practices and other data processing
documents, much of the data processing is based on the performance of a contract, the fulfillment
of a legal obligation, or a legitimate interest. Such wording does not make the actual legal basis
for each data processing operation clear to data subjects; therefore, the information provided
does not meet the requirement for clear and transparent information set forth in Article 12(1) of
the GDPR.
(272) The Authority further found that, according to Section 12.3 of the General Terms and Conditions,
the Company “shall not disclose or transfer personal data to third parties,” a statement that is
inconsistent with the Company’s actual data processing practices and the provisions set forth in
its other data processing documents. The provision fails to account for the involvement of courier
services, payment service providers, IT and marketing service providers, as well as other data
processors and recipients, and thus does not provide data subjects with adequate information
regarding the recipients of their personal data and data transfers.
(273) Consequently, the Company has violated Article 12(1) of the GDPR and Article 13(1)(e) of
the GDPR.
III.5. Information Regarding the Blog
(274) The Authority found that the Data Processing and Privacy Notice (hereinafter: “Blog Notice”)
applicable to the […] website, effective as of September 2, 2022,
50
does contain certain information required under Article 13 of the GDPR regarding data processing
related to posting comments and the exercise of data subjects’ rights, it does not provide
comprehensive, sufficiently clear, and consistent information regarding additional data processing
activities related to the operation of the Website—in particular, the use of cookies, the processing
of IP addresses, and data processing for web analytics and remarketing purposes in connection
with the use of the […] and […] services. In this regard, the Blog Privacy Policy does not present,
in a clear and organized manner, the purpose, legal basis, scope of data processed, retention
period, or the role of recipients for each data processing activity, even though the document itself
states that users’ IP addresses are processed and that […] collects, stores, and uses data in
connection with the use of the Website for remarketing purposes.
(275) The Authority further notes that the Blog Privacy Notice contains an internal contradiction
regarding the information provided on recipients and data transfers. While certain sections of the
document state that the Data Controller does not transfer data to third parties, Section 7.4.2
explicitly describes the use of the […] and […] services, as well as the fact that the information
stored by cookies—including the User’s IP address—is stored on […]’s servers in the United
States and may be transferred to third parties as necessary. However, the Blog Privacy Policy
does not provide adequate information regarding the safeguards in place for such data transfers
to third countries, nor does it clarify the exact role that […] plays in the data processing. As a
result, it is not clear to data subjects to which recipients their personal data is transferred, for what
purposes, and under what legal conditions.
(276) In the Authority’s assessment, the Blog Privacy Notice is not only incomplete with regard to
cookie and analytics data processing but also suffers from general structural and content-related
issues, as the legal basis, duration, and recipients of the data processing are in many cases not
presented clearly and consistently; furthermore, the document is based in part on general,
declarative content rather than actual information regarding data processing.
(277) Based on the foregoing, the Authority determined that the Company violated Article 12 of the GDPR
Paragraph (1), as the Blog Privacy Notice failed to provide data subjects with a concise,
transparent, understandable, and easily accessible presentation of information regarding the
processing of personal data. Furthermore, the Company violated Article 13(1)(c) of the GDPR,
as the legal basis for the processing of cookies, IP addresses, and data for web analytics and
remarketing purposes was not clearly defined; Article 13(1)(e) of the GDPR, as the scope of
recipients and service providers involved in data processing was not presented in a clear and
unambiguous manner; and
Article 13(1)(f) of the GDPR, as it did not provide adequate information regarding the
appropriate safeguards for data transfers to third countries, and Article 13(2)(a) of the GDPR, as
the duration of the data processing in this context and the criteria for determining it were not
adequately described.
III.6. Assessment of the Company’s Statements
(278) In the Authority’s view, the Company cited circumstances in several of its statements that do not
excuse the violation of the obligation to provide information regarding data processing. The mere
fact that the Company claims it had no intention of engaging in unlawful data processing, or that it
acted in the belief that its documents complied with the law, does not affect its liability under the
GDPR. Similarly, the fact that an external expert or a service provider performing the duties of a
data protection officer was involved in drafting the documents is not sufficient to excuse the
violations, as under the GDPR, the data controller itself is responsible in all cases for compliance
and for demonstrating such compliance.
51
(279) The obligation to provide information under Articles 12–13 of the GDPR is not fulfilled merely
because the data controller provides information in multiple documents, or because certain data
processing activities may be presumed to be known to the data subjects. The requirement for
transparent information stipulates that the data controller must present the circumstances of the
data processing to the data subject in a clear, precise, and consistent manner, either in a single
location or at least in a way that is clearly linked; the provision of scattered, inaccurate, or
contradictory information does not satisfy this obligation. 
(280) In the Authority’s view, the Company’s statement that it has no direct information regarding the
data processing practices of certain partners—in particular, whether profiling is taking place—is
also problematic from a data protection perspective, given that the Company itself listed these
partners in its disclosure as recipients or as parties involved in data processing. It follows from the
principle of accountability that the data controller must be aware of the role of the service
providers it engages, the legal nature of the data transfer, and the material circumstances of data
processing affecting the data subjects, and must be able to provide accurate information
regarding these matters. Therefore, an approach whereby the data controller itself cannot explain
why and in what capacity a particular recipient was listed in the notice is unacceptable.
(281) Furthermore, in the Authority’s view, the Company erroneously attached significance to the fact
that, as it claimed, certain contested provisions were not applied in practice, and that the number
of requests, objections, or erasure requests from data subjects was low. A violation of the
information obligation under the GDPR occurs simply through the provision of incomplete,
inaccurate, or misleading information. It is not a prerequisite for establishing a violation that data
subjects actually exercise their rights, file a complaint, or that the data controller applies the
erroneous provision in a specific case. On the contrary, one consequence of inadequate
information may be that the data subject does not recognize their rights or the true nature of the
data processing, and therefore does not seek to enforce their rights.
III.3. Information Provided After the Period Under Review
(282) This administrative proceeding did not cover the period following the initiation of the proceeding
with respect to the data processing notice, i.e., changes made to the data processing notice after
the Company became aware of the proceeding. However, the Authority will take the measures
taken by the Company into account as mitigating circumstances when imposing the fine.
IV. Legal Consequences
(283) The Authority examined whether the established violations justified the imposition of a data
protection fine against the Company. In this regard, the Authority assessed all relevant
circumstances of the case in accordance with
, taking into account the criteria set forth in Guideline No. 4/2022 of the European Data Protection
Board2 (hereinafter: the Guideline).
(284) In the Authority’s view, given the nature, gravity, duration, and impact on data subjects of the
violations identified in this case, issuing a warning cannot be considered a proportionate sanction;
therefore, the requirements of specific and general prevention necessitate the imposition of a
data protection fine.
2 Guideline No. 04/2022 on the calculation of administrative fines under the General Data Protection Regulation (Version 2.1).Online:
https://www.edpb.europa.eu/system/files/2024-01/edpb_guidelines_042022_calculationofadministrativefines_hu_0.pdf
52
(285) The infringements found—violation of the principle of transparency and failure to comply with the
obligations to inform data subjects under Articles 12–13—are classified as infringements falling
within the higher category of fines under Article 83(5) of the General Data Protection Regulation.
(286) In determining the amount of the fine, the Authority took into account the Company’s financial
data. Based on the Company’s publicly available annual report for fiscal year 2024, the
Company’s net revenue was […] HUF, which, according to the classification set forth in the
Guidelines, places it in the category of enterprises with annual revenue between 10 million and
50 million euros.
(287) Pursuant to Article 83(5) of the General Data Protection Regulation, the Company may be subject
to an administrative fine of up to 20,000,000 euros in this case, or an amount not exceeding 4%
of the Company’s total worldwide annual turnover for the preceding fiscal year, whichever of
the two is higher. Four percent of the Company’s 2024 revenue amounts to […] HUF, which does
not exceed the fixed maximum fine; therefore, the statutory upper limit in this case is the amount
equivalent to 20,000,000 euros.
(288) Based on the available information, the Authority did not identify any circumstances that would
indicate that the violations were committed intentionally. Given the nature of the identified
deficiencies, the Authority assessed the violations as negligent in nature.
(289) In determining the amount of the fine, the Authority assessed the following aggravating
circumstances based on the criteria set forth in Article 83(2) of the GDPR:
– Taking into account the nature, gravity, and duration of the violations [Article 83(2)(a) of
the GDPR], the violations found persisted throughout the period under review from
January 1, 2020, to November
12, 2025. The Authority also considered it an aggravating circumstance that the
information provided in one of the Company’s notices regarding the exercise of data
subjects’ rights did not comply with the relevant provisions of the GDPR but interpreted
them restrictively by raising the prospect of charging administrative fees and by
stipulating in advance the possibility of refusing to take action in the event of repeated
requests.
– Regarding the size of the group of data subjects [GDPR Article 83(2)(a)]: traffic to the
Website was exceptionally high during the period under review. According to the
Company, the site was visited by […] people in 2021, […] in 2022, […] in 2023, […] in
2024, and […] in 2025. In addition, a significant number of orders were recorded in the
online store (more than […] in 2024 and more than […] in the first half of 2025). Thus, the
group of data subjects was extremely broad.
– With regard to the existence of prior infringements [GDPR Article 83(2)(e)]: the
Authority had previously found the Company liable in Case No. NAIH-7905/2025, which,
although it did not concern the provision of information on data processing but rather the
ensuring of data subjects’ rights, nevertheless, in the Authority’s view, this circumstance
indicates that the Company’s data protection compliance practices were generally
deficient, and that the Authority’s previous findings did not lead to comprehensive,
system-wide compliance.
(290) In determining the amount of the fine, the Authority assessed the following mitigating
circumstances based on the criteria set forth in Article 83(2) of the GDPR:
- the infringements were committed through negligence; intent was not proven [Article
83(2)(b) of the General Data Protection Regulation];
53
- the Company took measures to remedy the violations [Article 83(2)(f) of the GDPR];
- the Authority exceeded the administrative deadline.
(291) Based on an assessment of all the circumstances of the case, the Authority deemed the
violations to be of a serious nature, given their systemic nature, their duration, and their impact on
a wide range of affected parties.
(292) Taking all of this into account, the Authority determined the amount of the fine not at a level close
to the maximum, but at an amount proportionate to the nature of the violations, the Company’s
economic situation, and the objectives of specific and general prevention. The circumstances set
forth in Article 83(2)(h), (i), and (j) of the GDPR did not apply in this case.
(293) The Authority determined the amount of the fine in the exercise of its statutory discretion. The
Authority imposed a fine that is proportionate to the gravity of the violations and suitable for
achieving the objectives of specific and general deterrence.
(294) Based on the foregoing, the Authority has decided as set forth in the operative part.
V. Other Issues
(295) The Authority’s jurisdiction is defined by Sections 38(2) and (2a) of the Information Act, and its
jurisdiction extends to the entire territory of the country.
(296) This decision of the Authority is based on Sections 80–81 of the Ákr. and Section 61(1) of the
Infotv. The decision becomes final upon its notification pursuant to Section 82(1) of the Ákr.
Pursuant to Section 112 of the Ákr., Section 116(1) and (4)(d) of the Ákr., and Section 114(1) of
the Ákr., an appeal against this decision may be filed through administrative litigation.
* * *
(297) Pursuant to Section 135 of the Ákr., the obligor is required to pay a late payment penalty at the
statutory interest rate if the obligor fails to fulfill a monetary payment obligation by the due date.
(298) Pursuant to Section 6:48(1) of Act V of 2013 on the Civil Code, in the case of a monetary debt,
the obligor is required to pay late payment interest at a rate equal to the central bank’s base rate
in effect on the first day of the calendar half-year affected by the delay, calculated from the date
the delay began.
(299) The rules governing administrative litigation are set forth in Act I of 2017 on Administrative
Procedure (hereinafter: Kp.). Pursuant to Section 12(1) of the Kp., administrative litigation
challenging a decision of the Authority falls within the jurisdiction of the administrative court;
pursuant to Section 13(3)
a) (aa) of the Kp., the Budapest Regional Court has exclusive jurisdiction. Pursuant to Section 27
(1)(b) of the Code of Civil Procedure, legal representation is mandatory in legal disputes over
which the court has exclusive jurisdiction. Pursuant to Section 39(6) of the Code of Civil
Procedure, filing a complaint does not have the effect of suspending the entry into force of
the administrative act.
(300) Pursuant to Section 29(1) of the Kp. and, in light thereof, Section 604 of Act CXXX of 2016 on the
Code of Civil Procedure, and pursuant to Section 19(1)(b) of Act CIII of 2023 on the Digital State
and Certain Rules Governing the Provision of Digital Services, the client’s legal representative is
required to communicate electronically.
54
(301) The time and place for filing the complaint are specified in Section 39(1) of the Code of Civil
Procedure. Information regarding the possibility of requesting a hearing is based on Sections
77(1) and (2) of the Code of Civil Procedure.
(302) The amount of the administrative court fee is determined by Section 45/A(1) of Act XCIII of 1990
on Fees (hereinafter: Itv.). Section 59(1) and Section 62(1)(h) of the Itv. exempt the party
initiating the proceedings from the requirement to pay the fee in advance.
(303) If the Company fails to adequately demonstrate compliance with the prescribed obligations, the
Authority shall deem that the Company has failed to fulfill the obligation by the deadline. Pursuant
to Section 132 of the Ákr., if the Company has not complied with the obligations set forth in the
Authority’s final decision, the decision shall be enforceable. Pursuant to Section 82(1) of the
Administrative Procedure Act, the Authority’s decision becomes final upon notification. Pursuant
to Section 133 of the Administrative Procedure Act, enforcement—unless otherwise provided by
law or government decree—shall be ordered by the authority that issued the decision. Pursuant
to Section 134
, enforcement is carried out by the state tax authority, unless otherwise provided by law, a
government decree, or—in matters within the jurisdiction of a local government—a local
government ordinance. Pursuant to Section 61(7) of the Information Act, with respect to an
obligation set forth in the Authority’s decision to perform a specific act, engage in specific
conduct, tolerate a situation, or cease a certain activity, the Authority shall enforce the decision
Dated: Budapest, date as per the electronic signature
Dr. habil. Attila Péterfalvi,
Chair, Professor