NAIH (Hungary) - NAIH-5209-29/2025

From GDPRhub
NAIH - NAIH-5209-29/2025
Authority: NAIH (Hungary)
Jurisdiction: Hungary
Relevant Law: Article 5(1)(b) GDPR
Article 5(1)(a) GDPR
Article 6(1)(e) GDPR
Article 6(1) GDPR
Article 13(1) GDPR
Article 13(2) GDPR
Article 58(1)(e) GDPR
Type: Investigation
Outcome: Violation Found
Started:
Decided: 02.12.2025
Published:
Fine: 1,000,000 HUF
Parties: Magyar Állam Tulajdonosainak Társulásával (MATT)
National Case Number/Name: NAIH-5209-29/2025
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Hungarian
Original Source: NAIH (in HU)
Initial Contributor: ap

The DPA fined two so-called 'sovereign citizens' and founding members of an organisation providing identity documents for a non-existing state €1,300 each. The organisation processed personal data without a valid legal basis and did not provide data subjects with adequate information.

English Summary

Facts

The Association of Hungarian State Owners (Magyar Állam Tulajdonosainak Társulásával, MATT) is an organisation that denies the existence of Hungary and its constitutional law. The DPA began an ex-officio investigation after receiving a report from a whistleblower (the data subject). This report highlighted potential criminal and data protection concerns; according to the data subject, new members were obliged to provide their personal data when joining through several forms. These included declarations of citizenship and nationality (separate from the Hungarian citizenship), as well as a claim for co-ownership of Hungary. The controller processed personal data such as first and last names, addresses and identification numbers. These documents did not include information on how the data was processed.

In its investigations, the DPA considered both the organisation and the two senior officials as controllers. However, the DPA only imposed a fine on the two individuals. For clarity, the summary will refer to the individuals as the controllers, and the organisation as MATT. The controllers objected to the DPA processing their data (including information from police reports), as it violated their rights under the GDPR. In addition, they argued that MATT is a collective name for its members and not an organisation and therefore cannot process data, as well as that EU regulations do not apply because the Hungarian State created by MATT was not an EU Member State.

Holding

The DPA first dismissed the arguments of the controllers, and stated that the GDPR is applicable and the DPA was competent to investigate the case. In addition, the DPA had a valid legal basis to process data obtained from police investigations under Article 6(1)(e) GDPR, as well as Article 58(1)(e) GDPR. Finally, the DPA determined that MATT and two senior members were joint controllers; the latter had an important role in the creation and operation of MATT, including determining the purposes and means of data processing. In practice, however, the DPA acknowledged that MATT could not be held accountable as it was not a legal entity.

The DPA found a violation of Article 5(1)(b) GDPR. According to the principle of purpose limitation, the controller must choose a clear and lawful purpose for data processing. The processing activities carried out by MATT did were not lawful, as they aimed to create a new parallel legal system to Hungary. While the rule of law allows individuals to believe in any ideology, the DPA stated that the purpose of processing data to provide individuals with separate identity documents was not valid, especially as these activities were carried out in a misleading manner. This is also linked to Article 5(1)(a) GDPR. The DPA considered that MATT did not process personal data fairly or lawfully, as the identity cards gave members the impression that they could become citizens of a non-existent state, and were exempt of their actual legal obligations. Since the controllers processed data unlawfully, the DPA also found a violation of Article 6(1) GDPR, as they processed data without a valid legal basis.

Finally, the DPA found a violation of Articles 13(1) and (2) GDPR, for not providing adequate information to data subjects. The controllers did not provide data subjects with information related to the data processing activities before they filled in the forms. The exception was the guide provided by the website on private student services. However, the DPA did not consider this sufficient to inform data subjects of all data processing activities.

The DPA found a violation of Articles 5(1)(a), 5(1)(b), 6(1), 13(1) and 13(2) GDPR. As a result, the DPA fined the two individuals HUF500,000 (approximately €1,300) each. In addition, the DPA prohibited the individuals from processing this data without a legal basis and providing adequate information, and ordered them to delete the personal data processed in the relevant documents.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Hungarian original. Please refer to the Hungarian original for more details.

........................................................................................................................................................................................................................................................................................
1055 Budapest Tel.: +36 1 391-1400 naih.hu/adatkezelesi-tajekoztatok
Falk Miksa utca 9-11. KR ID: 429616918 ugyfelszolgalat@naih.hu
Case number: NAIH-5209-29/2025. Subject: decision establishing an infringement
in ex officio proceedings
D E R U C T I O N
The National Authority for Data Protection and Freedom of Information (hereinafter: Authority)
in the data protection authority proceedings initiated ex officio against István Bende and Béla Berencsi as clients, for the purpose of examining the compliance of the data processing operations relating to the Hungarian State Owners Association (hereinafter: MATT) with Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: General Data Protection Regulation)
makes the following
decisions.
The period examined runs from 25 May 2018 until 31 January 2025, the date of the initiation of the data protection authority proceedings.
1. The Authority finds István Bende and Miklós Béla Berencsi guilty of having intentionally infringed, as data controllers:
- the principle of fair processing as set out in Article 5(1)(a) of the General Data Protection Regulation;
- the principle of purpose-limited processing as set out in Article 5(1)(b) of the General Data Protection Regulation;
- Article 6(1) of the General Data Protection Regulation, as it processes personal data without a legal basis, and
- Article 13(1)-(2) of the General Data Protection Regulation, as it failed to provide information.
2. Furthermore, the Authority finds MATT guilty of having infringed, as an association of natural persons, as data controller, as set out in point V.4.1 of the grounds for the decision:
- the principle of fair processing as set out in Article 5(1)(a) of the General Data Protection Regulation;
- the principle of purpose-specific data processing pursuant to Article 5(1)(b) of the General Data Protection Regulation;
- Article 6(1) of the General Data Protection Regulation, as it processes personal data in the absence of a legal basis
and
- Article 13(1)-(2) of the General Data Protection Regulation, as it did not provide
information.
3. The Authority prohibits, with effect from the date of receipt of this decision, the processing of data by István Bende and Béla Miklós Berencsi for an unlawful purpose, unfairly, without a legal basis and without adequate information. To this end, the Authority obliges István Bende and Béla Miklós Berencsi to delete all unlawfully processed personal data, in the following documents, in both electronic and paper versions:
1. “application form for submitting a co-ownership claim against the Hungarian State”;
2. “declaration of citizenship” (and its version on behalf of a minor child and on behalf of an incapacitated adult);
3. “application for a certificate entitling to unlimited public space use and free parking”;
2
4. “application for an identification card for the owner of the Hungarian State” (and its version for a minor child).
Data deletion may also be carried out by destroying the above documents.
4. The Authority further obliges Bende István to delete the personal data stored in the “Publicly Authorized Data and Address Register of the Republic of Hungary” and the “Publicly Authorized Vehicle Register of the Republic of Hungary”.
5. The Authority obliges Bende István to pay a data protection fine of 500,0000, i.e. five hundred thousand forints, for the violations established above.
6. The Authority orders Miklós Béla Berencsi to pay a data protection fine of 500,000 HUF for the violations established above.
7. The Authority shall publish this decision on its website, indicating the identification data (name) of the clients.
8. The Authority shall further reject István Bende's objections concerning the Authority's jurisdiction, based on the provisions of Chapter V.2 of the decision.
István Bende and Miklós Béla Berencsi shall, within 30 days of receipt of this decision, prove in writing to the Authority that they have taken the measures prescribed in points 3 and 4, together with the submission of supporting evidence and a deletion protocol.
The data protection fines must be paid within 30 days of receipt of this decision to the Authority's centralized revenue collection target settlement forint account (10032000-
01040425-00000000 Centralized collection account IBAN: HU83 1003 2000 0104 0425
0000 0000). When transferring the amounts, reference must be made to the NAIH-5209/2025. BÍRS.
number.
If István Bende and Béla Miklós Berencsi fail to comply with their obligation to pay the fine by the deadline, they shall be obliged to pay a late payment surcharge to the above account number. The amount of the late payment surcharge is the statutory interest, which is the same as the central bank base rate in force on the first day of the calendar half-year affected by the delay.
In the event of failure to comply with the obligations under points 3 and 4, and failure to pay the data protection fines and late payment charges, the Authority shall order the enforcement of the decision.
Until the expiry of the deadline for filing an action to challenge the decision, or until the final decision of the court in the event of an administrative lawsuit, the data affected by the disputed data processing shall not be deleted or destroyed.

There is no right of appeal against this decision through administrative means, but it may be challenged in administrative3 proceedings by means of a statement of claim addressed to the Metropolitan Court within 30 days of its notification. The statement of claim shall be submitted to the Authority electronically1,
which shall forward it to the court together with the case documents. The request for a hearing shall be indicated in the statement of claim. For those not entitled to full personal fee exemption, the administrative lawsuit fee is HUF 30,000, and the lawsuit is subject to the right to record the subject matter fee. Legal representation is mandatory in the proceedings before the Metropolitan Court.
JUSTIFICATION
I. P a r e c t i o n s , a r u t i o n s (1) A public interest notification was received by the Authority, in which the public interest complainant stated that he had previously joined the MATT, which denies the existence of Hungary and its Fundamental Law and constitutional system. According to the public interest complainant, in addition to representing views that, in his opinion, may lead to the commission of criminal acts, MATT also does not comply with data protection requirements.
(2) The whistleblower alleged, among other things, that he had provided MATT with his personal data, which were recorded. He had to fill out various forms, which MATT representatives keep with them. Furthermore, during a meeting with a MATT contact, he had to fill out a form claiming ownership of the “Hungarian State”. In this, he had to provide his name, place and date of birth, mother’s name and address. At the same time, he was asked for money for access to documents containing his personal data. (3) The whistleblower also alleged that MATT wants to build its own state based on its own ideology. Its members claim that the “Hungarian State” is owned by the people. According to them, the first owner was Miklós Béla Berencsi, and their “Prime Minister” is István Bende. To his knowledge, several hundred people have already joined the association, including children – thanks to their parents.
(4) According to the public interest whistleblower, MATT has several contact persons and maintains several offices throughout the country. The contact persons receive the members, with whom they fill out the declarations – recording their personal data.
(5) The Authority reviewed the websites of MATT2 and established that MATT as an association
and the persons associated with MATT and operating the website collect and record personal data by filling out the forms available on the website, without publishing any data management information or regulations. These forms, which are available on the website https://magyar-allam-tulajdonosai.com3, are as follows:
1. “application form for submitting a co-ownership claim against the Hungarian State”;
2. “declaration of citizenship” (and its version on behalf of a minor child and
on behalf of an incapacitated adult);
3. “application for a certificate entitling to unlimited use of public space and free parking”;
1 The form called NAIH_K01 is used to initiate an administrative lawsuit: NAIH_K01 form (2019.09.16.)
The form can be filled out using the general form filling program (ÁNYK program).
The form is available from the following link: https://naih.hu/kozig-hatarozat-birosagi-felulvizsgalata
2 https://magyar-allam-tulajdonosai.com and https://optalas.hu
3 https://magyar-allam-
tulajdonosai.com/index.php?stamp=1746696562&req=5C454A234B375726350E6A1228074833344F42163C44
4
4. “application for an identification card for the owner of the Hungarian State” (and its version for a minor child);
5. “declaration of nationality”;
6. “declaration of change of address”;
7. “cooperation agreement for the provision of private student legal relationship, school”;
8. “cooperation agreement for the provision of private student legal relationship, family”;
9. “cooperation agreement for the provision of private student status, study hall and student group”;
10. “enrolment form”;
11. “application for registration of private student status and verification of private student status”.
(6) The personal data to be recorded on the forms are contained in Section III. 3 of the resolution.
(7) In view of the above, the Authority launched an official inspection on 6 June 2024 under the number NAIH-
9048/2024., in the framework of which it checked compliance with the provisions of the law and the General Data Protection Regulation in connection with the data processing carried out by MATT.
(8) During the official inspection, the Authority held witness hearings in order to clarify the facts. In this context, the Authority heard a total of eight people
– among others – István Bende and Miklós Béla Berencsi, the two leading figures of MATT. Minutes were taken of the hearings. The hearing of István Bende is recorded in Annex NAIH-9048-52/2024 to the NAIH-5209-
8/2025. Note, and the hearing of Miklós Béla Berencsi is also recorded in Annex NAIH-9048-80/2024 to the NAIH-5209-8/2025. Note.
is contained in Annex No. 
. The hearing of additional witnesses is also contained in Annexes No. 
NAIH-9048-49/2024., 
NAIH-9048-50/2024., 
NAIH-9048-51/2024., 
NAIH-9048-54/2024., 
NAIH-9048-72/2024., 
NAIH-9048-73/2024. to the record No. 
NAIH-5209-8/2025.
.
(9) The Authority's IT specialist - also during the official inspection - made a complete, forensic backup of the two websites of MATT4 and the contents found on them. A record was made of the forensic backup, which is included in Annex No. 
NAIH-9048-27/2024. to the record No. 
NAIH-5209-8/2025.
. Annex No. 
(10) During the official inspection, the Authority also learned from information on the Internet5 that the police had various cases and procedures related to MATT, and therefore turned to the
[police] for information, requesting the sending of the documents in connection with which personal data is being processed. The [police] complied with the Authority's
request.
(11) According to one of the documents sent by the [police] – Annex No. 
NAIH-9048-19/2024 to the memorandum No. NAIH-5209-8/2025 – the […]
Police Department also conducted a search at one of the MATT branches, during which it seized IT equipment. In view of this, the Authority requested that copies of the records and electronic documents containing personal data stored on the IT devices seized during the search be sent, which request was complied with by the police. The documents received are annexes to the memorandum numbered NAIH-5209-8/2025, numbered NAIH-9048-44/2024.
(12) The […] Police Department also sent the Authority data sheets containing personal data – annexes NAIH-559-2/2025, NAIH-559-9/2025 to the NAIH-5209-8/2025 note – which it seized during the search conducted at the residence of István Bende on 13 December 2024.
(13) The description of the documents sent by the police authorities is contained in Section III.4 of the decision.
(14) Based on the information revealed during the official inspection, the Authority closed the official inspection on 31 January 2025 due to a suspected violation of the provisions of the General Data Protection Regulation and on the same day initiated an ex officio data protection official procedure against the two managers of MATT, István Bende and Miklós Béla Berencsi, as clients.
I I . A U T I O N T I O N P R O C E D I O N
(15) The subject of the data protection authority procedure was the general data processing practices of István Bende and Béla Miklós Berencsi
in connection with MATT, the “Republic of Hungary”.
(16) The period under examination runs from 25 May 2018 until the date of the initiation of the data protection authority procedure.
(17) The Authority used the documents, data and other means of evidence of the data protection authority inspection initiated under the number NAIH-9048/2024 in the present data protection authority procedure,
about which the record number NAIH-5209-8/2025 was prepared. The annexes to the record are the documents of the authority inspection initiated under the number NAIH-9048/2024.
(18) The Authority notified István Bende of the initiation of the data protection authority procedure in its order No. 
NAIH-5209-1/2025 dated 31 January 2025, in which order
it also called on him to make a statement in order to clarify the facts.
(19) The Authority notified Miklós Béla Berencsi of the initiation of the procedure in its order No. 
NAIH-5209-2/2025, also dated 31 January 2025, in which order
it also called on him to make a statement in order to clarify the facts.
(20) István Bende responded to the Authority’s orders in a letter sent by post on 18 February 2025
(registered under number NAIH-5209-3/2025), while Miklós Béla Berencsi responded to the Authority’s orders in two electronic letters sent from the e-mail address […] on 25 February 2025 (registered under numbers NAIH-5209-4/2025 and NAIH-5209-5/2025).
(21) Furthermore, in its order dated 28 February 2025, number NAIH-5209-6/2025
, the Authority contacted the […] Police Headquarters requesting further information.
(22) The police department responded and sent additional information in its letter dated 16 April 2025 (registered under number NAIH-5209-7/2025).
(23) In its order number NAIH-5209-12/2025 dated 25 August 2025, the Authority informed István Bende that he could examine the evidence uncovered during the clarification of the facts in the data protection authority procedure, taking into account the rules on access to documents, and make further evidentiary motions.
6
(24) The Authority also informed Miklós Béla Berencsi of the same in its order number NAIH-5209-13/2025, also dated 25 August 2025.
(25) In response to the Authority’s order, István Bende, in his letter dated 11 September 2025
(registered under number NAIH-5209-16/2025), provided information that he maintained the content of his previously submitted submissions. These are his statements, relevant to the present case:
- his objection to the Authority’s order NAIH-9048-
12/2024 dated 12 August 2024;
- his reply to the Authority’s order NAIH-5209-1/2025 dated 18 February 2025.
(26) István Bende further stated in his letter that he acknowledged the General Data Protection Regulation and considered it to be the governing regulation for the protection of personal data. His objection relates to the Authority’s jurisdiction.
(27) He also objected to the Authority's data processing.
(28) He also wished to exercise his right of access to documents, requesting that the entire document of the public interest notification be made available. Regarding access to documents, the Authority granted him limited access to documents, with the exception of personal and protected data that he could not access, in its order No. NAIH-5209-19/2025 dated 22 September 2025, from 10 a.m. on 7 October 2025, or, if this time is not convenient for him, from 2 p.m. on 9 October 2025. In its order, the Authority requested István Bende to indicate immediately upon receipt of the request at which time he wished to exercise his right of access to documents.
(29) István Bende did not respond to the Authority's order, he did not appear at the Authority on 7 October 2025, and he appeared without notice on 9 October 2025. A report No. NAIH-5209-22/2025 was drawn up on the inspection of the documents. It was recorded in this report that István Bende requested a copy of the documents of the proceedings, at which request the Authority sent a copy of the documents as an attachment to its order No. NAIH-5209-23/2025 dated 15 October 2025. (30) Furthermore, in his letter dated 11 September 2025 (registered under number NAIH-5209-16/2025), István Bende proposed the appointment of an expert to examine citizenship data, objected to the Authority's jurisdiction and therefore requested the suspension of the proceedings until the Authority could credibly prove that it was an authority of the "Hungarian State". Regarding jurisdictional issues, he reserves the right to apply to a court for a preliminary ruling, and to the European Court of Human Rights regarding the right to a fair trial and the right to privacy and the protection of personal data. (31) After reviewing the documents of the proceedings, István Bende submitted in his letter dated 3 November 2025 (registered under number NAIH-5209-26/2025) that he maintained his objection to jurisdiction.
(32) He submitted that the documents received by the Authority from the police included documents containing personal data that could not have been the subject of the Authority's investigation, as they had been seized for a different purpose and in the context of a different procedure.
In his opinion, the use of such data may be contrary to the principles of lawfulness, purpose limitation and data economy laid down in Article 5(1)(a), (b) and (c) of the General Data Protection Regulation, as well as to the rules on the assessment of evidence laid down in Section 62 of the Code of Civil Procedure. He requested that the Authority not take the indicated 7 original police documents into consideration when making a decision, if their source and legal basis for their use were not proven. (33) According to István Bende, during the police seizure, the owner of the data carrier was not warned of his right to refuse to examine the contents of the seized data carrier, based on Section 314 (1)-(2) of Act XC of 2017 on Criminal Procedure (hereinafter: Be.), if it contains data that no other authority can lawfully access. Therefore, in István Bende's opinion, examining the contents of the data carrier and transmitting it to the Authority is unlawful from both a procedural and data protection perspective, and the data obtained in this way cannot be used as evidence in the Authority's proceedings and should be excluded from the decision-making process. (34) István Bende further does not consent to the Authority downloading, copying, archiving or using in the proceedings the materials available on the websites of the MATT or other community registers in this case, unless he has the prior, express consent of the affected parties.
(35) He further requested the Authority to make a substantive decision in the case, as this is the only way to ensure the possibility of judicial review. He further reserves the right to a preliminary ruling procedure before the Court of Justice of the European Union or to apply to the European Court of Human Rights.
(36) He further requested a written confirmation of the registration number and date of delivery of this statement, and that the document be included in the case file in its unchanged form. He also requested the issuance of an authentic document certificate on the registration of his statement and its annexes.
(37) Béla Miklós Berencsi also wished to exercise his right to inspect documents in view of the Authority's order No. NAIH-5209-13/2025 (submission filed under number NAIH-5209-24/2025).
(38) In its order No. NAIH-5209-25/2025 dated 4 November 2025, the Authority granted Béla Miklós Berencsi limited access to documents, with the exception of personal and protected data that he could not identify, by sending copies of the documents as requested.
(39) After reviewing the documents of the proceedings, Miklós Béla Berencsi submitted in his submission sent on 20 November 2025 (filed under number NAIH-5209-28/2025) that the activities examined in the present case – including parking certificates, identification cards and the management of registers – originated from the self-organisation of the ownership community of the Hungarian State, and not from the individual initiative of natural persons. An early, documented example of this community self-determination is the General Assembly Resolution No. H/3/2020 (15 February 2020), which established certain certification tasks and their organisational bases in a corporate form. The General Assembly, as a corporate body, is the highest decision-making body; the direction, purpose and order of the activities were determined by the will of the community. Community decision-making does not arise from the individual decisions of natural persons, but from the institutionalized, corporate form of community will, which is a way of exercising popular sovereignty. (40) Béla Miklós Berencsi stated that the community initiative was later institutionalized in the form of the Hungarian Central State Registry Office (hereinafter referred to as the KNYH), which was established on the basis of the General Assembly Resolution No. H/11/2020. The KNYH operates as an organizational framework and is the formalized implementer of community decision-making. The KNYH: - has an independent operating system; - is based on community authorization; - manages the registers and issues certificates on behalf of the community. (41) According to the statement of Béla Miklós Berencsi, the operation of the KNYH cannot be classified into any of the categories of data controllers under the General Data Protection Regulation: it is not an administrative body, it is not an economic operator, and it is not a legal entity that falls under the territorial scope of Article 3 of the General Data Protection Regulation. (42) Béla Miklós Berencsi further stated that in the early stages of community organization - the will of the community as part of its implementation – performed technical and administrative tasks. These included, among others, the preparation of documents, IT support and the operation of community communication tools. These tasks did not constitute a definition of data processing purposes or means within the meaning of the General Data Protection Regulation. The term “data controller” used during the witness hearings reflected the everyday terminology of community operation and IT operation, not the legal concept of the General Data Protection Regulation. The witness hearing minutes taken on 17 December 2024 did not contain his words verbatim and were not signed by him due to inaccuracies. (43) According to the statement of Miklós Béla Berencsi, the decision-making structure of the activities examined in this case is clear: - the decisions were made at community level, by the general meeting; - the implementation of the tasks was of a technical nature; - the purposes and direction of the data processing were not determined by natural persons, but by the Community body;
- the concept of data controller in the General Data Protection Regulation for natural persons is not applicable to the Community structure.
(44) According to Béla Miklós Berencsi, the activities he carried out were of a technical and administrative nature and did not constitute decision-making by a data controller within the meaning of the General Data Protection Regulation. In support of all this, he referred to the following documents of the present proceedings,
which confirm his submissions:
- minutes of the witness hearing (December 17, 2024);
- Resolution of the general meeting No. H/3/2020 (February 15, 2020);
- Resolution of the general meeting No. H/11/2020 (September 13, 2020).
I I I . ESTABLISHMENT OF THE FACT
I I I . 1. The organization and background of the MATT, the “Hungarian Republic” and its ideology
(45) Based on testimonies, public information available on the MATT website and police materials, MATT is an association of people who consider the current political and legal order illegitimate and are trying to remove themselves from its influence, building a kind of shadow state as state deniers. They consider themselves outside the law, and according to their idea, they are located outside the state as legally capable free people.
(46) They issue their own “documents” and “license plates” for identification and parking, and organize their own “police”. The members regularly refuse to prove themselves with real documents, instead presenting papers issued by themselves. They have their own “organizational system”, with “public administration bodies”, “ministries”. Their own “court” has “imposed” millions of fines on judges adjudicating parking cases.
9
(47) From the evidence at its disposal and presented in the following sections of this decision, the Authority has drawn the following conclusions regarding the ideology of MATT and the affiliated persons, in the context of the purpose of data processing.
(48) According to their theory, the “Hungarian State” can be acquired by original acquisition of ownership. Co-ownership claims can be submitted to the “Representation of the Hungarian Republic” (hereinafter: “Representation”), established on 1 September 2015, on the application form developed by the “Representation” and accepted by the first owner. This application form, available on the MATT website, is the “application form for submitting a claim for co-ownership over the Hungarian State” mentioned in paragraph (5) of the resolution.
(49) In their view, the de facto state called Hungary was established in 2011 by 262 members of the parliament in a coup d’état with the aim of withering away the “Republic of Hungary” by usurping the institutions of the “Hungarian State” and becoming a sole ruler in the country.
(50) With its activities, MATT aims to prepare and ensure the legal liberation from dictatorship and the possibility of self-determination for members of society. According to the ideology of MATT, the sovereign members of society have the opportunity to reclaim the occupied state institutions, their homeland, their human dignity, their freedom and rights, and at the same time reject the dictatorship, the parallel de facto state and the false democracy. (51) MATT creates the possibility of legal liberation from the dictatorship built by the parallel de facto state called Hungary through the legal act of “opting”, which is the declaration of belonging to the “de jure” “Hungarian State” that they recognize. Opting is done by making a declaration of citizenship in the presence of two witnesses. With the declaration of citizenship made during the opting, the member declares his will, according to which he wants to belong to the legal “Hungarian State”, and from the moment of joining, he exists not as a victim of the state, but as a legitimate beneficiary of the state. (52) The primary goal of opting is to free the individual from the dictatorial state system, and in the long term, Hungarian society can be made free and self-determined. The ultimate, more distant goal of MATT is that in a free and self-determined society, the members will determine by consensus and organize the political system of society in accordance with the common intention. (53) MATT set the fulfillment of the primary goal as its main task in the “Representation” intention unit, and all their activities are aimed at achieving the goal formulated therein, thus preparing the feasibility of the final goal. (54) According to MATT, the “Hungarian State” was not founded by Hungarian society. The actual “owner” or “owners” are unknown, therefore the “Hungarian State” without a known “owner” could be taken into ownership by declaring a claim to ownership. Since no one else did so, the first “owner” – Miklós Béla Berencsi – declared his claim to ownership and that he expected all members of Hungarian society to be full “owners”, so that the members of society would only have to declare their claim to this and they could all become “co-owners” of the state. (55) The “co-owners” could intervene in the operation of the “owned” state and override its legal provisions, which would allow them to restore the operation of the “Hungarian State” and take full control from the current usurpers. 10 (56) According to MATT, the institutions of the “Hungarian State” are currently under occupation, and therefore the exercise of ownership rights and interests still faces obstacles. Since the position of the occupiers (the current government bodies and offices) is currently still strong, this process is taking place gradually. (57) The main operating rules of MATT are as follows:
(58) The main decision-making body of MATT is the general meeting, in which the “owners” of the “Hungarian State” may participate. It makes its decisions in the form of resolutions.
(59) The preparation of the decisions of the general meeting (proposal, justification) and the implementation of the resolutions are carried out by the executive body. In principle, any “owner” can be a member of the executive body on a voluntary basis (in practice, this is often a matter of debate).
(60) In addition to the general meeting, there is a social oversight council (also known as the council of the wise), which can consist of at least five and at most twelve members. The first five members of the council are approved by the general meeting, and the additional members are elected by the members elected by the general meeting. The main task of the council is to perform supervisory activities and monitor the transformation of society. Its members have unlimited access to the affairs of “state institutions” and future institutions, they can submit motions to the general assembly through the executive body, they can instruct the executive body to convene a general assembly, or they can convene the general assembly directly, or they can give instructions to the “state institutions”. It determines its own operating rules.
(61) The process of legal regulation of the “Hungarian State”: the claim formulated at the individual level is presented to the general assembly, which either votes on or rejects the proposal. The voted proposals are recorded in a resolution of the general assembly.
I I I . 2 . The “public authorities” of the “Republic of Hungary”:
(62) According to the information available on the MATT website referred to in paragraph (46) of the decision – and the annex to the NAIH-5209-8/2025. note from the website, NAIH-9048-27/2025., containing a forensic backup – the “Hungarian
Republic” imagined by MATT has “administrative offices”, “courts”, “prosecutors”, and “police”.
The names, contact details, and leaders of these “organizations” are published on the MATT website.
(63) The “state bodies” of the “Republic of Hungary” during the period under review were the following:
- “Hungarian State Administrative Office State Records Management Services”: 12 records management services in large cities (Zalaegerszeg, Baja, Budapest, Debrecen, Győr, Karcag, Nagykanizsa, Miskolc, Nyíregyháza, Pécs, Szekszárd)
- “Local Service Centers of the Representation of the Republic of Hungary”: 12 service centers, also in the above cities
- “Hungarian State Administrative Office”
- “Departments of the Hungarian State Administrative Office” and authorities (3 departments, respectively
authorities)
- “Representation of the Republic of Hungary”
- “Supreme Court of the Hungarian State”
- “Hungarian State Tax and Customs Office”
- “Hungarian State Public Asset Management Office”
- “Hungarian State Police”
- “Hungarian State Prosecutor’s Office”
- “Government of the Republic of Hungary”, with 13 ministries
11
- “Hungarian State” itself.
(64) Among these “state bodies”, the “Representation” should be highlighted, the sole member of which is currently István Bende. According to its founding statement, the “Representation” was founded by three people
but one person left and left MATT, while the third founder is not
active.
(65) The annex to the memorandum No. NAIH-5209-10/2025 is the founding statement of the “Representation”
(hereinafter: the founding statement), which is also available on the “Representation”6 website. The founding declaration defines the overall purpose of data processing from a data protection perspective, as follows: (66) According to the founding declaration, the founders established that the “Republic of Hungary” was left without a president, government, parliament and executive bodies, therefore there is no one to represent it, and they also established that no one has undertaken to do so. According to the founding declaration, for this reason, the founders established the “Representation” replacing the president, government, parliament and executive bodies of the “Republic of Hungary”, which officially and exclusively represents the “Republic of Hungary”. Within the scope of this activity, it protects the legal order and laws of the “Republic of Hungary”, and represents the interests of Hungarian citizens. The “Representation” may issue identity documents, certificates and other official documents to the citizens of the “Republic of Hungary”. Citizens of the “Republic of Hungary” may turn to the “Representation of the Hungarian Republic” to protect their rights and interests.
(67) According to the founding declaration, the primary objective of the “Representation” is to restore the constitutional order, to organize the establishment of a provisional government with the authority of a significant part of the people to conduct the creation of a new constitution by the people, and at the same time to dismantle the occupied private state deceptively called Hungary.
(68) According to the founding declaration, the “Representation” will carry out its activities until the constitutional order and the functioning of the state are restored in the “Republic of Hungary” and a new elected government is established. The “Representation” is entitled to use the name “Representation of the Hungarian Republic” and the Hungarian national symbols. Its members independently represent the legal Hungarian state, the “Republic of Hungary”. Its operating rules are regulated by a separate document, including the expansion of the number of its members.
(69) Therefore, all further data processing and partial data processing is carried out in order to ensure that the
“Republic of Hungary” is operational.
(70) The annex to the memorandum No. NAIH-5209-8/2025, No. NAIH-9048-27/2025, containing a forensic backup, is the document entitled “Notification of the Hungarian State’s ownership claim” (hereinafter: ownership claim), which is available on the public website of the MATT. The document has a special role, because in it, as the first owner, Béla Miklós Berencsi, as stated in paragraph (54) of the resolution, declares his ownership claim to the “Hungarian State” and at the same time calls on all members of Hungarian society to become full co-owners, with the primary aim of jointly starting the operation of state institutions serving their self-determining society. According to the document, with this act, Béla Miklós Berencsi became the first owner of the “Hungarian State.” 6 https://magyar-allam.com/
12
(71) The reason for this action, according to the document, is that “Hungarian state institutions came under foreign occupation on 1 January 2012, and thus the Hungarian State was left alone, unmanaged and inoperative. Furthermore, due to its current inoperability, the Hungarian State is unable to serve Hungarian society as its beneficiary. Furthermore, Hungarian society is at the mercy of the occupiers, who systematically mislead, rob and exterminate society through the occupied state institutions, and this situation is simply intolerable. Furthermore, the Representation of the Republic of Hungary, established on 1 September 2015, internationally announced the fact of the occupation of the institutions of the Hungarian State, and since the announcement, no one has announced any objection or claim of ownership to the abandoned Hungarian State. claim.”
I I I . 3 . C a r t e s u s t a t i o n The Authority describes the forms used to apply for these and other rights below, indicating the personal data processed, which are typically personal identification and address data.
(74) The “Hungarian Republic Identification Card” presented by István Bende and another witness during the witness hearings – and recorded by the Authority – contains the person’s family name and first name, date of birth, facial image, citizenship, signature, validity period of the card, and legal relationship with the “Hungarian State” as the owner.
(75) The Authority is not aware of the exact data content of the cards entitling to unlimited public space use and free parking, i.e. the parking cards, and they were not presented to it or in its possession.
(76) MATT as an association, and the leaders representing MATT, on the one hand, by requesting these certificates and filling out other forms for the purpose described below, and on the other hand, in connection with belonging to the “Hungarian State”, Miklós Berencsi – as described in paragraphs (70)-(71) of the decision – collect, record and store personal data with the document used for the application for ownership. This can be established on the basis of the witnesses heard by the Authority and the information available on the websites of MATT. These forms are available on the website of MATT. (77) The Authority has access to the forensic record of the NAIH-5209-8/2025. on the rescue of the MATT website, also listed in paragraph (5) of the decision, as well as the NAIH-9048-27/2024. The relevant forms saved according to Annex No. are as follows:
1. “application form for submitting a co-ownership claim against the Hungarian State”;
2. “declaration of citizenship” (and its version on behalf of a minor child and on behalf of an incapacitated adult);
3. “application for a certificate entitling to unlimited public space use and free parking”;
4. “application for an identification card for the owner of the Hungarian State” (and its version for a minor child);
13
5. “declaration of nationality”;
6. “declaration for notification of change of address”;
7. “cooperation agreement for the provision of private student legal relationship, school”;
8. “cooperation agreement for the provision of private student legal relationship, family”;
9. “cooperation agreement for the provision of private student legal relationship, school and
student group”;
10. “enrolment form”;
11. “application for registration of private student status and verification of private student status”.
(78) 1. According to the document entitled “application form for submitting a co-ownership claim against the Hungarian State”,
the person concerned submits his co-ownership claim against the “Hungarian State” to the “Representation”, which is recognised as the official representation of the “Hungarian State”.
(79) Personal data to be provided on the document: “first name at birth, family name at birth, name used according to documents, mother’s name according to documents, place and time of birth (town, year, month, day), residential address according to documents, correspondence (residence address), document identifier, signature, e-mail address, telephone number”, and in the case of two witnesses, name, mother’s name, identification document number, residential address, signature.
(80) According to the above document, the recipient is the “Representation”. The “application form” contains the restrictions on the ownership right over the “Hungarian
State”, and the conditions under which people can be considered members of Hungarian society. The document does not contain any data management information.
(81) 2. According to the text of the “citizenship declaration”, the data subject declares that he/she has Hungarian citizenship in the “Republic of Hungary” with the data relating to him/her.
(82) These data to be provided by the data subject are the following: “surname, first name(s), family name at birth, name(s) given at birth, mother’s family name at birth, mother’s name(s) given at birth, place of birth (country, settlement), time, unique identifier, place of residence (country, postal code, settlement, public area name, number), I have additional citizenship in these
states, documents confirming the data.”
(83) This declaration must be signed by two witnesses, stating their full name, mother's birth name, address and personal identifying information. According to the declaration, the recipient is the
"Representation".
(84) The “citizenship declaration” contains the following information: “Recognizing that the state called Hungary is not legally continuous with the Republic of Hungary, and therefore was not established instead of it, but alongside it, exercising the right of option recognized in international practice, I declare my express will that I do not wish to renounce my Hungarian citizenship in the Republic of Hungary. I have not claimed or consented to the citizenship of any other state other than the Republic of Hungary and the state(s) specified above, and I expressly object to any other state treating me as its own citizen or as a legal subject of its own legal system under any other title, and to any data relating to me and things in my possession being registered as falling under its scope under any title. I acknowledge that as long as the Republic of Hungary is territorially and financially under foreign occupation, I can count on no or only limited state services from the Republic of Hungary.”
14
(85) There is no data processing information on the declaration.
(86) In the case of a minor, the “citizenship declaration” is different in that it is necessary to provide the minor’s unique identifier, and the information on citizenship is also tailored to minors, in all other respects there is no difference between the declarations.
The declaration has the same content in the case of an incapacitated adult.
(87) 3. According to the document entitled “Request for a certificate of unlimited public space use and free parking”, the data subject requests the “Representation” that the general meeting of the owners of the “Hungarian State” issue to him, as a co-owner of the “Hungarian State”, a certificate of unlimited public space use (plastic card) and a certificate of unlimited and free parking (plastic card).
(88) Personal data to be provided on the document: “birth surname and first name(s),
civil surname and first name(s), place and time of birth, mother’s birth surname and
first name(s), serial number of the property registration, mailing (postal) address, notification e-mail address,
telephone number.”
(89) The document contains information on the method of submission, as well as an acknowledgement and statement that the person concerned has received information on the use of certificates and the method of handling any
legal disputes, and undertakes to cooperate as described therein. The document does not contain information on data processing.
(90) 4. According to the document entitled “Application for an identification card for the owner of the Hungarian State”, the data subject, referring to the declaration of citizenship made under the given reference number, requests the “Public Administration Office of the Hungarian State” to issue him/her an identification card corresponding to his/her ownership relationship with the “Hungarian State”, bearing the current name of the “Hungarian State”, i.e. “Republic of Hungary”.
(91) The following personal data must be provided on the document: the data subject’s
portrait, signature, family name, first name(s), family name at birth, first name(s),
place of birth (country, settlement), date of birth, mother’s family name at birth, mother’s
first name at birth, ownership registration number, reason for the application.
(92) The document does not contain any information on data processing.
(93) In the case of a minor, the document entitled “Application for an identification card for the owner of the Hungarian State” is different in that there is no signature, and in all other respects there is no difference between the declarations. The declaration in the case of an incapacitated adult is also of the same content.
(94) 5. Based on the “declaration of nationality”, the owner of the vehicle requests the existing Hungarian nationality of the vehicle registered in the Republic of Hungary, and requests the registration of the vehicle in the public vehicle register of the “Republic of Hungary”.
(95) The data to be provided in the declaration are: name, address, vehicle make, type, model, vehicle chassis number, vehicle engine number/code, vehicle registration number (if any), vehicle registration certificate number (if any), other document identifier (if any), date of registration of citizenship, attached documents proving the data (registration certificate / registration certificate / other document).
(96) The declaration must be signed by two witnesses, providing their name and address.
15
(97) There is no data processing information on the “citizenship declaration”.
(98) 6. The following personal data must be provided on the document entitled “declaration of change of address”: the declarant’s family and first name/name, the declarant’s birth name, the declarant’s place and date of birth, the declarant’s mother’s name, the declarant’s citizenship (with the name of the state), the declarant’s previous (ceasing) address (country (if abroad) postal code, settlement, residential address), the declarant’s new address (country (if abroad) postal code, settlement, residential address), the number of children affected by the change (persons), a list of the children’s details (name, place and date of birth, mother’s name).
(99) The document does not contain any information on data processing.
(100) 7. The document entitled “Cooperation Agreement for the Provision of Private Student Legal Status, School” is concluded between the “Education Department of the Hungarian State Administrative Office” and the commissioned service provider.
(101) The personal data to be provided on the document are as follows: school representative,
date of birth, place of birth (country, settlement), state of birth, mother’s maiden name, permanent address, state of permanent address, qualifications, contact details (e-mail, telephone).
(102) The document contains the tasks of the service provider and the “Education Department of the Hungarian State Administrative Office”, the type of agreement, the conditions for termination and
termination of the agreement.
(103) The document does not contain any data management information, however, the website contains a guide to establishing a private student relationship with the “Hungarian State”, which includes a data management information sheet that also refers to this cooperation agreement among the data processed, as follows: “Data provided on the forms “Cooperation Agreement for the Provision of Private Student Relationship”, “Enrollment Form” and “Application for Registration of Private Student Relationship and Proof of Private Student Relationship”.”
(104) The above data management information sheet includes:
- the name of the data controller: “Education Department of the Hungarian State Public Administration Office”;
- the scope of data subjects: service providers that have concluded a cooperation agreement with the “Education Department of the Hungarian State Public Administration Office”; applicants for private student status: parent/guardian and child;
- the scope of the processed data: data provided on the forms “Cooperation Agreement for the provision of private student status”, “Enrolment Form” and “Application for registration of private student status and verification of private student status”;
- the legal basis for data processing: the consent of the data subject pursuant to Article 6(1)(a) of the General Data Protection Regulation;
- information on the storage of data: paper-based data is stored separately from other documents, and electronic data is stored in a code-protected storage location. The data is processed within the “Hungarian State Public Administration Office”, the data is not disclosed to third parties;
- the rights of the data subject: the data subject has the right
• to request information about their data stored by the data controller;
• request the correction of the stored data if they are incorrect or incomplete;
16
• request the deletion of the stored data;
• object to the processing of your data;
• request the restriction of the use of your data.
(105) 8. The document entitled “Cooperation Agreement for the Provision of Private Student Legal Relationship,
Family” is concluded between the “Education Department of the Hungarian State Administrative Office” and the service provider.
(106) The personal data to be provided on the document are as follows: name as shown on the identification document, date of birth, place of birth (country, settlement), state of birth, mother’s maiden name, permanent address, state of permanent address. In addition, the addresses and signatures of two witnesses must be provided.
(107) The document contains the tasks of the service provider and the “Education Department of the Hungarian State Administrative Office”, the type of agreement, the conditions for termination and termination of the agreement.
(108) The document does not contain data management information, however, the above-mentioned guide on the establishment of a private student relationship with the “Hungarian State” on the website is the data management information, which, as stated in paragraph (103) of the resolution, also refers to this document among the processed data.
(109) 9. The document entitled “Cooperation Agreement on the Provision of Private Student Relationships, School and Study Group” is concluded between the “Education Department of the Hungarian State Administrative Office” and the service provider.
(110) The personal data to be provided on the document are as follows: name as shown on the identification document, date of birth, place of birth (country, settlement), state of birth, mother's maiden name, permanent address, state of permanent address, qualifications, contact details (e-mail, telephone). In addition, the addresses and signatures of two witnesses must be provided.
(111) The document contains the tasks of the service provider and the "Education Department of the Hungarian State Administrative Office", the type of agreement, the conditions for termination or termination of the agreement.
(112) The document does not contain data management information, however, the above-mentioned guide on establishing a private student relationship with the "Hungarian State" on the website is the data management information, which, as stated in paragraph (103) of the resolution, also refers to this document.
(113) 10. The data to be provided on the document called “enrolment form” are: the name of the child
(student) and the parent/guardian, their date of birth, place of birth (country,
town), state of birth, mother’s maiden name, permanent address,
state of permanent address. In the case of a child, their residential address, state of residential address, special education, and health need(s). In the case of a parent/guardian, their mailing address and other contact information (e-mail,
telephone). In addition, the residential addresses and signatures of two witnesses must be provided.
(114) The document also contains the data of the service provider, data relating to the start of studies, and the parent/guardian’s declaration that he/she entrusts the service provider with the upbringing and education of his/her child in accordance with the terms of the cooperation agreement concluded with the “Education Department of the Hungarian State Administrative Office”. The mandate is valid until revoked or until the end of the school year in which the child turns 16 or 17. The document also contains the service provider’s declaration that he/she undertakes the upbringing and education of the child in accordance with the terms of the cooperation agreement concluded with the “Education Department of the Hungarian State Administrative Office”.
(115) The document does not contain any data management information, however, the above-mentioned guide on the establishment of a private student relationship with the “Hungarian State” on the website is part of the data management information, which, as stated in paragraph (103) of the resolution, also refers to this document.
(116) 11. The data to be provided on the document entitled “Application for registration of private student relationship and verification of private student relationship” are: the name of the child
(student) and the parent/guardian, their date of birth, place of birth (country, settlement), state of birth, mother’s maiden name, permanent address, state of permanent address. In the case of a child, their residence
address, state of residence
address, educational identification number in the state called Hungary, and the number of the identification card issued by the “Republic of Hungary”. In the case of a parent/guardian, the identification card number issued by the “Republic of Hungary”, their mailing address, and other contact information (e-mail, telephone). In addition, the residential addresses and signatures of two witnesses must also be provided. (117) The document also contains the place of the child's (student's) previous studies in the state of Hungary, the justification for the application, and a statement regarding the continuation of studies, according to which "my child continues his/her private student status in the following institution - family / school / regional or local student group / school operated by foundations, churches or other non-state maintainers - accredited by the "Hungarian State" and having concluded a cooperation agreement with the "State" - providing public education services (hereinafter: Provider)". (118) The document contains information that the "Republic of Hungary" provides the legal basis for the private student status, however, the exercise of the right is the responsibility of the parents. “During the transition period, there may be difficulties in validating the benefits of the student ID card and in receiving the family allowance. Please only choose this option if you feel prepared for this. In case of legal difficulties, you can seek help at jogsegely@egysegbe.hu.” (119) It also contains a declaration that the person making the declaration declares that he/she has read the information on the private student legal relationship, understood its contents, and that the information provided by him/her is true. Being aware of his/her criminal liability, he/she declares that a) he/she exercises the right of custody of the child jointly with the other parent and submits the application with the express consent of his/her co-parent; b) the consent of the other parent could not be obtained because the other parent is in an unknown location; c) he/she is actually prevented from exercising his/her rights; d) exercises parental custody rights alone.
He further declares that he has read and accepts the contents of the data processing information.
(120) According to the text of the document, “the data processing information forms an annex to the form and can be found in the guide to establishing a private student relationship with the Hungarian State as part 1.1 of the document.” This is manifested in practice as the fact that, as stated in paragraph (103) of the resolution, the data processing information refers to this document among the processed data.
18
I I I . 4 . F o r t h e r e s t e r s , e v i d e n t i o n s (121) Of the blank, unfilled form samples listed above, downloaded from the website, the following four filled-in document types containing personal data can be found in the documents sent by the […] Police Headquarters, supporting that the forms are actually used in practice, and that the information specified in III.3. above is included. As presented in point 
, personal data can be found:
- “application form for submitting a claim for co-ownership over the Hungarian State” 15
pieces,
- “declaration of citizenship” 22 pieces, of which 4 relate to minors,
- “application for an identification card for the owner of the Hungarian State” 22 pieces, of which 4 relate to minors,
- “application for a certificate entitling to unlimited use of public space and free parking” 6
pieces.
(122) The document entitled “application form for submitting a claim for co-ownership over the Hungarian State”
also bears the stamp of the “Local Service Center of the Hungarian Representation” and the signature of the person who received the document.
(123) The “declaration of citizenship” also bears the stamp of the “Public Administration Office of the Hungarian State”
and the signature of the person who received the declaration.
(124) The document entitled “Application for an identification card for the owner of the Hungarian State” also bears the stamp of the “Hungarian State Public Administration Office” and the signature of the person who received the document.
(125) The document entitled “Application for a certificate of unlimited use of public areas and free parking” bears the stamp of the “Local Service Center of the Hungarian Representation” and the signature of the person who received the document.
(126) In addition to the documents sent by the […] Police Department, the documents received from the [police] also contain – among others – a list of MATT members using public parking cards in the II., VI., IX., XIII. and XIV.
districts of Budapest (33 people). They used fake parking cards issued by MATT, containing real personal data, after filling out a document called “Request for a certificate of entitlement to unlimited public space use and free parking” in order to avoid paying the mandatory parking fee. The documents include the following copies of the cards containing the personal data of real people, as well as copies of forms in use, also filled out with the personal data of real people:
- 6 parking cards entitled “certificate of entitlement to unlimited and free parking”;
- 4 cards entitled “certificate of entitlement to unlimited public space use”;
- 4 “Identification Card of the Republic of Hungary”;
- 13 “declarations of citizenship”.
(127) The […] Police Department also sent four DVDs in connection with the investigation conducted at a MATT branch. The police letter itself is annexed to NAIH-5209-
8/2025. NAIH-9048-44/2024. The document annexed to NAIH-5209-
11/2025. contains which relevant copies of documents containing personal data were stored on the DVDs.
The discs contain tens of thousands of word files, PDF documents, and video files, including the above-mentioned forms with the personal data of real people.
19
(128) NAIH-5209-11/2025. According to the records in the record no. 
, the following electronic documents can be found among the disks,
including the completed version containing personal data. Due to the tens of thousands of files, which are often duplicated, the Authority has carried out a summary by name. Based on this, the following figures can be established:
- “declaration of citizenship”7 (and its version on behalf of a minor child and on behalf of an incapacitated adult) affecting approximately 40 people;
- application form for submitting a claim for co-ownership over the Hungarian State”8
involving approximately 50 people
- “application for a certificate entitling to unlimited use of public space and free parking”9
involving approximately 20 people;
- “application for an identification card for the owner of the Hungarian State” (and its version for a minor child)10, affecting approximately 30 people.
(129) In addition, an extract from the “Public Data and Address Register of the Hungarian Republic”11 issued by the “Hungarian State Central Registry Office” – affecting approximately 110 people in terms of repetitions – and an extract from the “Public Data and Address Register of the Hungarian Republic”12 issued by the “Hungarian State Central Registry Office” – affecting approximately 10 people in terms of repetitions – can also be found on the disks.
(130) The data content of the extract from the “Public Data and Address Register of the Hungarian Republic” is as follows:
- date of data query;
- title of query;
- administrator name;
- query result:
- birth name;
- used name;
7 For example:
- citizenship_statement_of_S202200430012_20220115000002.pdf
- citizenship_statement_of_S20200196.pdf
- citizenship_statement_of_S202100370003_20211006125752.tif
8 For example:
- img_2544x3508x24_00802782.jpg
- img_1272x1754x24_00801444.jpg
- img_1272x1754x24_00804107.jpg
9 For example:
- img_1272x1754x24_00802642.jpg
- img_1272x1754x24_00804104.jpg
- img_1272x1754x24_00796178.jpg
10 For example:
- idcard_request_for_2-660810-7272.pdf
- 00803900.pdf
- 00801456.pdf
11 For example:
- 00810582.pdf
- 01589027.pdf
- 01676433.pdf
12 For example:
- 01034589.pdf
- 01890618.pdf
- astra95.Id_b8000000070f8ef.pdf
20
- place and time of birth;
- mother's name;
- address;
- state of residence;
- place of residence;
- state of residence;
- citizenship;
- beginning of Hungarian citizenship;
- beginning of “Republic of Hungary” citizenship;
- confirmation of “Republic of Hungary” citizenship;
- additional citizenships;
- legal relationship with the “Hungarian State”;
- declaration of citizenship;
- identification card (document identifier);
- valid.
(131) The data content of the extract from the “Public Vehicle Register of the Republic of Hungary” issued by the “Hungarian State Central Registry Office” is as follows:
- date of data retrieval
- title of query
- name of administrator
- result of query
- nationality of vehicle
- name of vehicle owner
- address of vehicle owner
- name of vehicle operator
- address of vehicle operator
(132) In addition, the extract from the “Public Vehicle Register of the Republic of Hungary” contains the technical data of the
vehicle.
(133) At the bottom of both records, it is stated that “the document is authentic when displayed on screen by the person concerned on the website magyar-allam-tajladonasai.com or officially on the website magyar-allam.org, and when printed only when signed and stamped by the Hungarian State Central Registry Office, the Hungarian State Administrative Office, or the Representation of the Republic of Hungary, in all other cases together with a copy of the Declaration of Citizenship.”

(134) Furthermore, on the 2nd DVD there is a video file13 – the viewing of which is documented in NAIH-5209-9/2025.

record number was made – can be found from a MATT online forum held on October 17, 2021, in which István Bende, using a webcam, sitting in front of his computer and logging in with his username, broadcasts or demonstrates to the other online attendees, also directing the camera’s angle to his monitor, how an authorized user can record new “ownership claims” on the https://magyar-allam-tajladonasai.com/sidlo page, how to manage already recorded “ownership claims” in the electronic register, how to modify, delete, and search the stored data in the register. During the broadcast, he demonstrates step by step which personal data from the paper-based forms should be recorded in which field on the electronic interface, i.e. what data management operations can be performed in the system. 13 File named “GMT20211017-165134_Recording_1920x1080.mp4”
21
(135) In the video, István Bende also demonstrates, similarly to the above, how the authorized user – specifically István Bende – can issue, modify, and revoke “new documents” – “Hungarian Republic Identification Card”, “residence certificate”, “certificate of unlimited public space use and free parking”, “vehicle registration certificate” – on the https://magyar-
allam.org/offices page, how to manage data already recorded from applications for document issuance in electronic registers, how to modify, delete stored data, and conduct searches in registers, i.e. in this case, he demonstrates certain data management operations.
(136) According to the recording, in the case of both “ownership claims” and “documents”, the underlying application forms are also available in scanned form and are also recorded in the systems.
(137) The electronic storage of the application forms – together with the personal data recorded in them – and István Bende’s data processing activities are also supported by the part of the recording that shows István Bende’s user account, with the following folders:
“identity_id_ids”, “ids_kpi”, “ids_tul”, “irattar”; and two “.tif” files,
which show how he issues a parking card to a specific data subject and how he records him as the owner.
(138) In addition to the above, based on the summary of the testimonies, it can also be stated that
István Bende represents the “Representation” as its sole representative, which, for example,
stores the citizenship declarations. Béla Miklós Berencsi is the first owner,
he himself stated during his testimony that he started the operation of MATT. Several of the people interviewed, as well as himself, consider him to be a data controller, since as the first
owner, he registers the personal data of the additional owners who have concluded contracts with him on a contractual basis, and stores the contracts.
(139) Several people also stated that they had to fill out forms at a MATT office,
with which they could initiate the issuance of the “Hungarian Republic Identification Card” and
parking cards. (Testimony records no. NAIH-5209-49/2024., NAIH-5209-50/2024. and NAIH-5209-
51/2024.)
(140) According to one of the witnesses, István Bende, Béla Miklós Berencsi and two other office managers make decisions regarding the processing of personal data. According to his knowledge, the main decision-makers in MATT are István Bende and Béla Miklós Berencsi. He also stated – using his own phone – that he can access the MATT website with a password and query his own personal data even now, although he has not paid a membership fee for some time. Regarding the storage of personal data, he claimed that there could be a central registry where the documents to which the office manager has access, according to his knowledge. Regarding the “Identification Card of the Hungarian Republic” and the cards entitling to unlimited public space use and free parking, he stated that the “Identification Card of the Hungarian Republic” is the basis, while the parking-related cards can be purchased separately, and the three cards cost a total of 5-6 thousand forints. The office manager handles the cards, but he has no knowledge of how. (Testimony record no. NAIH-9048-49/2024) (141) The other witness stated that he provided the data on his identity card by filling out a form, but he does not know what was done with the form after the data was collected. According to his knowledge, Béla Berencsi had access to it, he took ownership of the country, and the other members, like him, joined him as co-owners. According to his knowledge, Béla Berencsi makes decisions regarding the processing of personal data. (Testimony record no. NAIH-9048-50/2024) 22 (142) The additional witness joined MATT because of the parking card, i.e. the “certificate of unlimited public space use and free parking”, in the hope that by acquiring it he would not have to pay parking fees. He filled out the application form for the card in a Budapest office. He had to provide the data on his ID card (natural ID data and address) and a photo of his ID. He does not know where the data is stored, in his opinion the management has access to it, but he did not meet any of the managers in person, he only heard the name of István Bende. He stated that he certainly did not receive a separate consent statement, a sheet containing it, because the form to be filled out consisted of one sheet, with two pages. He did not receive information about the processing of his personal data, he would remember this. (Testimony record no. NAIH-9048-51/2024). (143) The next witness stated in relation to the place of data processing that Miklós Béla Berencsi has information about ownership, as he has a copy of the contract as a contracting party, while the “Hungarian State Public Administration System” can provide information about ID cards and confirmation of citizenship. He can access his own data on the MATT website. (Testimony record no. NAIH-9048-54/2024)
(144) The other witness stated in relation to the electronic records of MATT, the “Hungarian State”, that he had no information about this, but that Miklós Béla Berencsi should be asked, since he is the data controller, he collects all the contracts and other documents containing personal data.
He also stated that everyone has access to their own documents on cloud storage. (Testimony record no. NAIH-
9048-73/2024)
(145) István Bende stated that MATT is a collective name, not an organization, it cannot handle data, it cannot be joined, it has no founding document, organizational and operational regulations and a manager. It is not MATT that operates, but the “Hungarian State”. MATT is the collective name of the owners of the “Hungarian State”. The “Representation” has been entrusted with receiving the new owner’s claims. The original claim is a contractual offer, as a result of which the submitter accepts the basic terms and conditions, and thus a contract is created between the first owner – Miklós Béla Berencsi – and the new owner. Miklós Béla Berencsi is the data controller in this respect, but at the same time he entrusts the “Representation” with the management of the contracts. There is also a contract between the “Representation” and Miklós Béla Berencsi, the original claim itself. The “Representation” accepted its contents, thus creating the contract. What the “Representation” qualifies as under the General Data Protection Regulation is not addressed, because the “Representation” does not belong to the state and is not subject to the General Data Protection Regulation. The “Representation” is not an institution of a state or a member state, but is outside the state, which is why it was able to receive co-ownership claims. In connection with compliance with data protection requirements, it stated that there is data autonomy, which means that every owner can query his or her own registered data in the form of a document, together with the declaration of citizenship, which, when signed, is an authentic document. The person can modify his or her email address and telephone number, as well as delete it. However, the “Hungarian State” is not subject to the General Data Protection Regulation, since as long as they cannot enforce their rights, their obligations cannot be held accountable. They keep two types of registers: one is the register of owners, which is not within the “Hungarian State”. The other is kept by the “Hungarian State”. In this case, the “Hungarian State” processes the data of those who have confirmed their citizenship of the “Republic of Hungary”. The source of data processing is the declaration of citizenship. It also stated that, despite the fact that it does not apply to them, they are aware of the General Data Protection Regulation and try to act in accordance with it. Article 6(1)(f) of the General Data Protection Regulation is the basis for the processing of proprietary data. The “Hungarian State” is the legal entity that is responsible for the processing of proprietary data.(1) c) and e) of Article 1, and, where applicable, a)). The purpose of data processing is, for example, to know who owns the ID card,
23 to be able to prove citizenship. It did not state the place of data processing, databases, and access to the data. The data required for new identification cards issued by the “Republic of Hungary” are stored in the central registry for as long as the card is valid, and also afterwards for possible legal disputes. The “Administrative Office of the Hungarian State” issues the card. The same data is processed for the issuance of the certificate authorizing the use of unlimited public spaces, the certificate authorizing unlimited and free parking, and the registration permit, as stated in the declaration, and no additional data is requested. The place of storage of personal data is the internal affairs of the “Hungarian State”. (Testimony record no. NAIH-9048-52/2024) (146) In relation to his duties arising from his position as owner, Miklós Berencsi Béla stated that if someone wants to be an owner, a contract must be concluded with him, as stated in the instructions for completing the application form. Regarding the storage of contracts, he stated that he would not answer the questions on this because there is another contracting party, this is a private contract. The other contracting party also receives a copy of the contract, and he also has a copy. He did not answer the place of storage, but according to his statement, these important documents are in a very good place. In relation to compliance with data protection requirements, he stated that the “Hungarian State” has laws, which describe how data management works. The effective status of the “Hungarian State” is 17 April 2011, as there has been no parliament since then. According to his position, his data processing is not carried out in accordance with the legal order represented by the Authority’s staff. Incidentally, Article 6 (1) b) of the General Data Protection Regulation states that data processing is lawful in the event of a contract. Point f) refers to legitimate interest. He is not familiar with these laws, but in his position, his data processing is correct and complies with these two points. With regard to the individual data processing, he stated that he and the parties who have contracted with him are the data controllers. The contract also mentions maintaining contact, and in this regard he is also the data controller. So, based on the contract, he sends the general meeting invitations and resolution proposals to the owners. (Report of testimony No. NAIH-9048-80/2024)
(147) In addition to the above, István Bende and Béla Miklós Berencsi submitted the following to the Authority's clarification orders issued in the administrative procedure:
(148) They submitted that the Authority does not have jurisdiction to conduct the administrative procedure.
They also explained the differences between the "Hungarian State" and Hungary, and that MATT is not a natural person, but an association of people. They submitted that the EU regulation has no legal effect with regard to MATT, given that MATT is not an EU member state and is not part of any EU member state, and consequently there can be no violation of the EU regulation. In this regard, they also submitted that, in their view, the EU regulation does not apply to the Authority either, given that the state called Hungary – in which the Authority operates – is not a member of the European Union, and consequently the Authority cannot lawfully act in reference to the EU regulation. In addition, the EU regulation does not apply to them either, given that István Bende and Miklós Béla Berencsi are members of Hungarian society, “co-owners” of the Hungarian State in a private and unlimited capacity, and are not an EU Member State or part of an EU Member State. Consequently, there can be no infringement of the EU regulation on their part. (149) In view of this, they did not answer the Authority’s questions regarding data processing, did not make any further statements, or will not make any, and they submitted that when they answered as witnesses during the official inspection, they did not make any statements either. If
the Authority nevertheless assessed what they said as statements, they requested that
they be disregarded.
24
I I I . 5 . B r i c h s u m a t i o n of the facts
(150) The Authority, based on the information obtained during the official inspection, the statements made by the witnesses heard –
including István Bende and Béla Miklós Berencsi –, the contents forensically saved from the MATT websites, and the review of the documents sent by the police
, started from the following facts:
(151) MATT is an association of private individuals without legal personality.
(152) The goal and ideology of MATT is the withdrawal of the fictitious state they invented, the “Republic of Hungary”, from the legal system of Hungary and the establishment of a new state system, considering that in their opinion the Fundamental Law adopted in 2011 is invalid due to public law invalidity, thus the current state power acquired its mandate illegitimately, and therefore the state organization it established and the laws it created are invalid. (153) In this resolution, the term MATT also refers to the people associated with MATT, the “owners”, and the persons representing them and MATT, since MATT is a loose community of people. (154) From a data protection perspective, it can be stated that in this fictitious state, the associated persons are registered, i.e. their personal data is processed. According to the information available to the Authority, one of the registers is the “Public Data and Address Register of the Republic of Hungary”, while the other registers the vehicle owners. Its name is the “Public Vehicle Register of the Republic of Hungary”.
(155) Despite being aware of it, they do not consider the General Data Protection Regulation to be mandatory for them – since they do not recognise the jurisdiction and legal system of Hungary as valid – but they take into account some of its parts, such as the provisions on legal bases – according to their own ideas. This is contradicted by the statement made by István Bende on 11 September 2025, according to which he himself recognises the General Data Protection Regulation, but not the jurisdiction of the Authority.
(156) The decision III.3. The data subjects are entered into the given register using the forms described in point III.3., data collection is carried out through these data sheets, and the “Hungarian Republic Identification Card” and “parking cards” are issued to the applicants based on the relevant application forms.
(157) Websites belonging to MATT: https://magyar-allam-tuljanodosai.com, https://optalas.hu.
No data management information or other data protection regulations can be found on these websites, and MATT or its managers do not provide any data management information on these pages, except for a guide described in point III.3.
(158) Among the documents on the DVDs received from the […] Police Department is NAIH-5209-11/2025. According to the 
note number, the minutes of the executive board meeting on the 2nd DVD14, however
14 MATT Executive Board regular meeting minutes 84th Online meeting (2021. 10. 20. 84th ÜT Minutes.pdf)
MATT Executive Board regular meeting minutes 85th Online meeting (2021. 10. 27. 85th ÜT Minutes.pdf)
MATT Executive Board regular meeting minutes 86th Online meeting (2021. 11. 03. 86th ÜT Minutes.pdf)
MATT Executive Board regular meeting minutes 87th Online meeting (2021. 11. 10. 87th ÜT Minutes.pdf)
MATT Executive Board regular meeting minutes 89th Online meeting (2021. 12. 01. 90. Minutes of the regular meeting of the MATT Executive Board 92. Online meeting (2021. 12. 15. 92. Minutes of the regular meeting of the MATT Executive Board.pdf)
25
The task of preparing a “Uniform Data Management Regulation” by the “Legal Group”
by October 27, 2021, and then sending it to the “offices” by November 3, 2021, was recorded as a task, however,
apart from the task designations, no further information on this is available to the Authority.

(159) However, on DVD 4, there was an unpublished data protection and data security regulation with document number AVABSZ-1/10/2021 and registration number MK-1-
10-2021/000003, issued by the “Hungarian State Administrative Office” on 1 February 2021, with the following characteristics:
(160) This regulation refers to the General Data Protection Regulation. The regulation contains the following data as the data controller: its name “Hungarian State Administrative Office”, its seat ([…]), its professional manager ([…]), its activity (performance of a public task). Therefore, this regulation specifically applies to the “Hungarian State Administrative Office”. However, no more information can be established about the role of the data controller.
(161) The regulation defines concepts and contains general rules. For example: “The controller shall process data exclusively in accordance with the provisions of the applicable laws. The controller shall only process data in a manner that is consistent with the purpose at all stages. In all cases, the controller shall inform the data subject of the purpose of the processing, the legal basis for the processing, and the facts relating to the processing. The controller shall ensure that the data are not accessed by unauthorized persons using organizational, physical, IT and authorization management tools.” (162) The regulation also states in general terms regarding the legal basis for data processing: “the Office shall determine the legal basis for data processing for each data processing process. The Office shall design its data processing system in such a way that it can prove for each personal data when, in what form the personal data was collected and what information the data subject received when the personal data was collected. Before collecting the data, the Data Controller shall in all cases inform the data subject of the purpose of the data processing and the legal basis for the data processing. The possible legal bases for data processing in the case of personal data are: the consent of the data subject; the data subject may expressly give his or her consent in writing in a demonstrable manner.” (163) The regulation lists the rights of data subjects and describes the principles of data processing in general.
(164) The policy also includes the procedure to be applied in the event of a data protection incident, data security rules, and provisions on training.
(165) A further annex to the policy is a consent declaration, which must state the name, birth name, address, mother’s name, ID card number of the data subject, and the names, addresses, and ID cards of two witnesses. In addition, the declaration must be filled in by hand with the following information: “the purpose and conditions of data processing”, “accessibility of the data”, “the person of the data controller” and “the duration of data processing”. This declaration does not contain anything else. Confidentiality and data protection declarations are also part of the policy, however, these cannot be considered as data processing notices, they only state that the data subject has become familiar with “the concept of personal data according to the GDPR” and the confidentiality rules.
MATT Legal Board regular meeting minutes 93. Online meeting (2021. 12. 22. 93. ÜT Minutes.pdf)
26
I V . A p p l e c t i o n l a g e r s u r e (168) According to Article 7 of Act CL of 2016 on General Administrative Procedure (hereinafter referred to as the Act), the provisions of the Act shall apply to the data protection authority procedure. In accordance with Article 103(1) of the Act, the provisions of the Act relating to procedures initiated upon request shall apply in the official procedure initiated ex officio, with the derogations set out in Articles 103 and 104 of the Act. (169) Pursuant to Article 4(1) of the General Data Protection Regulation: “personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, a number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.”
(170) According to Article 4(2) of the GDPR: “processing” means any operation or set of operations which is performed upon personal data or upon sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.”
(171) According to Article 4(7) of the GDPR: “controller” means the natural or legal person, public authority, agency or any other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of processing are determined by Union or Member State law, the controller or the specific aspects relating to the designation of the controller may also be determined by Union or Member State law.”
(172) According to Article 5(1)(a) and (b) of the General Data Protection Regulation: Personal data:
a) shall be processed lawfully and fairly and in a manner transparent to the data subject (‘lawfulness, fairness and transparency’);
b) personal data shall be collected: only for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes; in accordance with Article 89(1), further processing for archiving purposes in the public interest, scientific and historical research purposes or statistical purposes (‘purpose limitation’) shall not be considered incompatible with the initial purpose.
(173) According to Article 6(1) of the GDPR: “The processing of personal data shall be lawful only if and to the extent that at least one of the following is met:
a) the data subject has given his consent to the processing of his personal data for one or more specific purposes;
27
b) the processing is necessary for the performance of a contract to which the data subject is a party, or in order to take steps at the request of the data subject prior to entering into a contract;
c) the processing is necessary for compliance with a legal obligation to which the controller is subject;
d) the processing is necessary to protect the vital interests of the data subject or of another natural person;
e) the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
f) the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which personal data protection is necessary, in particular when the person concerned is a child.”

(174) According to Article 13 of the GDPR: “(1) Where personal data concerning the data subject are collected from the data subject, the controller shall, at the time of obtaining the personal data, provide the data subject with all of the following information:
a) the identity and contact details of the controller and, where applicable, of the controller’s representative;
b) the contact details of the data protection officer, where applicable;
c) the purposes of the intended processing of the personal data and the legal basis for the processing;
d) in the case of processing based on point (f) of Article 6(1), the legitimate interests of the controller or a third party;
e) where applicable, the recipients or categories of recipients of the personal data, if any;
f) where applicable, whether the controller intends to transfer the personal data to a third country or to an international organisation and whether or not the controller has obtained an adequacy decision or, in accordance with Article 46, the In the case of a transfer referred to in Article 47 or in the second subparagraph of Article 49(1), an indication of the appropriate and suitable safeguards and the means by which a copy of the data can be obtained or a reference to their availability. (2) In addition to the information referred to in paragraph 1, the controller shall, at the time of obtaining the personal data, provide the data subject with the following additional information in order to ensure fair and transparent processing: (a) the period for which the personal data will be stored or, where that is not possible, the criteria for determining that period; (b) the right of the data subject to obtain from the controller access to, rectification, erasure or restriction of processing of personal data concerning him or her and to object to the processing of such personal data, as well as the right of the data subject to data portability; (c) the information referred to in point (a) of Article 6(1) or point (a) of Article 9(2) in the case of data processing based on point 1, the right to withdraw consent at any time, which shall not affect the lawfulness of the processing carried out on the basis of consent before its withdrawal; d) the right to lodge a complaint with a supervisory authority; e) whether the provision of personal data is based on a legal or contractual obligation or is a prerequisite for entering into a contract, and whether the data subject is obliged to provide the personal data, and the possible consequences of not providing the data; f) the fact of automated decision-making referred to in Article 22(1) and (4), including profiling, and at least in such cases, intelligible information on the logic involved and the significance of such processing and the foreseeable consequences for the data subject. (3) Where the controller intends to further process personal data for purposes other than those for which they were collected, prior to further processing shall inform the data subject of this different purpose and of any relevant additional information referred to in paragraph (2). (4) Paragraphs (1), (2) and (3) shall not apply if and to the extent that the data subject already has the information.” (175) According to Article 58(2) of the General Data Protection Regulation, the supervisory authority may, in the exercise of its corrective powers, for example: (b) order the controller or processor where its processing activities infringe the provisions of this Regulation; (c) order the controller or processor to comply with the data subject’s request to exercise his or her rights under this Regulation; (d) order the controller or processor to bring its processing operations into compliance with the provisions of this Regulation, in a specific manner and within a specific period. (176) The Infotv. According to Section 61(2): “The Authority may order the publication of its decision – by publishing the identification data of the data controller or the data processor – if the decision affects a wide range of persons, if it was made in connection with the activities of a body performing a public task, or if the gravity of the infringement of rights justifies the publication.
(177) Pursuant to Section 71(1) and (2) of the Infotv.: “(1) During the proceedings of the Authority – to the extent and for the period necessary for the conduct thereof – it may process all personal data, as well as data classified as secrets protected by law and secrets related to the practice of a profession, which are related to the proceedings or the processing of which is necessary for the effective conduct of the proceedings.
(2) The Authority may use documents, data or other means of evidence lawfully obtained during its proceedings in other proceedings may use it.”
V . D ecision
V.1. Legal assessment of the MATT and its ideas as a preliminary issue for establishing the responsibility of the data controller and the purpose of data processing
(178) Anti-state tendencies exist in many countries around the world, characterized by the fact that they do not recognize the jurisdiction of the state in which they live, and they express this by various – radical or less radical – means.
(179) MATT is a continuously organized political community of ideas based on state and constitutional denial.
(180) According to online press articles15 and the literature dealing with fake news, disinformation, and conspiracy theories16, it can be said to be a global trend that disinformation is gaining an increasing role, and the distinction between facts and opinions is becoming blurred.
15 For example: https://telex.hu/techtud/2024/11/12/alhir-osszeeskuves-elmelet-allamtagadas-dezinformació-szuveren-
allampolgar
16 For example:
- Péter Krekó (2023). Mass Paranoia 2.0 - Conspiracy theories, fake news, and disinformation. Budapest:
Athenaeum Kiadó Kft.
29
In every
country, there are widely spread theories and fake news of unknown origin,
which, to some extent, express the thinking, fears and problems of a community. The alternative reality, the world created with the help of conspiracy theories,
is more attractive and beautiful than reality, and represents an escape from the hopelessness and the problems that loom over our heads. Believing in such theories does not necessarily mean being stupid or some kind of extremism, often they are composed of logical information and elements of reality to create a completely new, different kind of narrative. The constructed pseudo-reality is often more attractive and pleasant than objectivity, and it is easier for us to believe what we want to believe.
(181) According to the aforementioned literature and experts on the subject, MATT and similar movements can be considered a kind of counter-reaction to the difficulties that are oppressing people, for example, the financial impossibility due to the “foreign exchange loan crisis”. Individuals often start to think in such theories when they feel that they are not the masters of their own destiny. The various theories can be linked to new age, esoteric, science-rejecting thinking, for example, anti-vaccination. (182) Based on what is written in the referenced article and according to the literature, getting to know the state-denying and constitutional-denying ideologies, it can be seen that they simplify the excessive complexity of the world, and thus do not have to face reality, and by offering a simple solution, “a new life can be started”, or at least hope for this. In such cases, wishful thinking is typical: group members believe in the theory because they would like it to be true.
(183) According to the cited articles, citizens active in such organizations can experience the process as very democratic, since by building from the bottom up, they can quasi-destroy the existing power and come up with new plans. Behind these movements lies a political strategy aimed at redistributing power and material resources - the exploited people break the rule of the elite.
(184) Belonging to the “new state” and the related shared knowledge strengthen group cohesion and internal solidarity, while the feeling of initiation strengthens commitment.
(185) The Authority concluded from the witness hearings that the representatives of the MATT ideas often seem to argue for their beliefs very logically and convincingly, trying to support them with legal and constitutional knowledge. Derived by legal reasoning, as “amateur constitutional lawyers”, they affirm the existence of their state with conviction and enthusiasm, often with a messianic sense of mission. (186) The Authority further sees that from a data protection perspective, the validity of the requirement of voluntariness and information in relation to consent as a legal basis, and therefore the possibility of free choice, is relativized, and believers in the above ideas, the data subjects, almost blindly, grant all kinds of authorization to the controllers of their data. - Nóra Falyuna (2024): Online disinformation and its effects - An introduction to the development of disinformation networks through the relationship between scientific disinformation and state denial conspiracy theories, https://inmediasresfolyoirat.hu/imr/article/view/294/567, downloaded on: 25 August 2025.
30
V.2. Scope of the General Data Protection Regulation, jurisdiction, other objections
(187) Based on the available documents and statements, MATT's ideology regarding data protection is contradictory: on the one hand, they do not consider the General Data Protection Regulation to be a legal regulation applicable to them and do not accept the Authority's jurisdiction, while at the same time they refer to the General Data Protection Regulation and data protection rules in some of their documents. Such a document is, for example, the "Confidentiality and Data Protection Statement", which refers to the concept of personal data according to the General Data Protection Regulation. In addition, István Bende stated during his testimony and statement that although they are not bound by the General Data Protection Regulation, they try to act in accordance with it, and he acknowledges this. Béla Miklós Berencsi stated that his data processing is not carried out in accordance with the legal order represented by the Authority's staff. He is aware of the contractual and legitimate interest legal bases under Article 6(1)(b) and (f) of the General Data Protection Regulation, but is otherwise unaware of the General Data Protection Regulation. (188) However, contrary to their position, the data processing operations examined in the present case fall within the scope of the General Data Protection Regulation, and the Authority has jurisdiction, tasks and powers to examine them. (189) Article 2 of the General Data Protection Regulation provides for its material scope, while Article 3 provides for its territorial scope. Article 2(2) contains the exemption rules in which
the processing does not fall within the scope of the GDPR,
so the regulation does not apply, while the rules on territorial scope clarify the issues of
jurisdiction.
(190) These rules do not include cases on the basis of which the Authority would not have
jurisdiction. The processing of data by controllers established in the European Union, in this case Hungary, in this case MATT, or persons linked to it, in the context of the activities of István Bende and Miklós Béla Berencsi, is subject to the scope of the GDPR.
(191) There is no exception rule based on which the General Data Protection Regulation would not be applicable to the data processing examined in the present case because - according to the position of István Bende and Miklós Béla Berencsi - the General Data Protection Regulation does not apply to the “Hungarian State”, since as long as it cannot enforce its rights, its obligations cannot be held accountable, or because the “Hungarian State” processes data in accordance with the laws and data protection requirements in force on 17 April 2011, since there has been no parliament in the legal system of the “Hungarian State”. There is also no reason to refer to the exemption from its scope as being that Hungary, its Fundamental Law and all legislation enacted following its adoption are invalid under public law, Hungary does not exist, and instead the “Republic of Hungary” or the “Hungarian State” and its rules are valid and applicable. (192) Furthermore, the Authority shall decide on the clarification of the facts, in what manner and with what means, based on the provisions of the Code of Civil Procedure. On this basis, the Authority did not consider the appointment of an expert to be justified, given that no professional issue arose in the proceedings that would require special expertise, in particular to decide on issues of jurisdiction, since the Authority has jurisdiction as stated above, and therefore there is no need to suspend the proceedings, despite the objection raised by István Bende in his letter dated 11 September 2025 (registered under number NAIH-5209-16/2025). (193) In connection with István Bende's further objections, the Authority draws attention to the following: 31 (194) In connection with the use of police documents, the Authority The Authority shall not be subject to the Be. The Authority may, on the basis of the rules on requests pursuant to Section 25(1)(b) of the Act, contact another body if another body possesses the data or documents necessary for the procedure. (195) The legal basis for data processing in this case is Article 6(1)(e) of the General Data Protection Regulation, according to which the processing of personal data is lawful if the processing is in the public interest or is necessary for the performance of a task carried out in the exercise of official authority vested in the controller. (196) Article 6(3) of the General Data Protection Regulation further provides that the legal basis for data processing pursuant to Article 6(1)(e) shall be established by Union law or Member State law. (197) The Infotv. According to Section 5(3) of the General Data Protection Regulation, in the case of data processing as defined in Article 6(1)(e) of the General Data Protection Regulation, the types of data to be processed, the purpose and conditions of data processing, the accessibility of the data, the person of the data controller, as well as the duration of data processing or the periodic review of its necessity shall be determined by the law or local government decree ordering the data processing. If the legislation prescribing data processing does not fully comply with Section 5(3) of the Infotv. and does not include the circumstances of data processing, the data controller shall implement the principles and guarantees of the general rules governing the processing of personal data, which the legislator has failed to provide for. (198) The Infotv. Pursuant to Section 71(1), the Authority may process, during its proceedings, to the extent and for the period necessary for the conduct of the proceedings, all personal data, as well as data classified as secrets protected by law and secrets related to the practice of a profession, which are related to the proceedings and whose processing is necessary for the effective conduct of the proceedings. (199) An additional legal basis is Article 58(1)(e) of the General Data Protection Regulation, according to which the supervisory authority, acting within its investigative powers, shall have access to all personal data and all information from the controller or processor necessary for the performance of its tasks.
(200) Based on these legal provisions, the Authority, as a body exercising public authority, is entitled to process personal data in connection with its tasks performed within the framework of the exercise of this authority without sectoral legislation. That is, the Authority may access any personal data related to the procedure and necessary for the conduct of the procedure in the given
procedure, including the documents seized by the police in the present case.
(201) Furthermore, the Authority carried out website backups in the case based on the rules of the Ákr. on inspections. The legal basis for data processing is Article 6(1)(e) of the General Data Protection Regulation referred to above, due to the obligation to clarify the facts necessary for the conduct of the present procedure. The relevant right may be exercised by the given data subject, if the conditions are met.
(202) The information on the right to appeal is contained in the operative part of the Authority, while the postal service provider provides information on the delivery of the document sent by István Bende.
(203) In connection with István Bende's objection to the processing of his personal data, the Authority also provides him with information under a different case number.
32
(204) Regarding the objection of Miklós Béla Berencsi that neither he nor the KNYH are data controllers under the General Data Protection Regulation, the Authority explains its position in Chapter V.4 of the decision.
V . 3 . M A T T - CONNECTION DATA MANAGEMENT
(205) MATT, and its “organizations”, managers – István Bende and Béla Miklós Berencsi – store and keep the forms and data sheets filled out by the
connectors, i.e. the “owners”,
and they issue various documents and certificates, i.e. they manage and register the personal
data indicated on them, and use the personal data collected with the forms.
(206) These “organizations”, individuals issue such documents and certificates, which
are similar in terms of their content and external appearance to identity cards, parking cards, and grant “citizenship”
not only to Hungarian but also to foreign nationals, including minors.
These cards are the “Identification Card of the Republic of Hungary” and the parking cards. The Authority describes the personal data contained in the “Identification Card of the Republic of Hungary”,
and the forms used for this, as well as for applying for parking and other rights
in Section III.3, indicating the personal data processed,
which are typically personal identification and address data.
(207) As stated in paragraphs (128)-(133) of the decision, based on the DVDs received from the […] Police Department, MATT has two electronic registers, i.e. the data is arranged in a database. One is the “Public Data and Address Register of the Republic of Hungary”, the other is the “Public Vehicle Register of the Republic of Hungary”.
(208) According to witnesses, including István Bende, the “owners” can access their personal data via the MATT website with a password. István Bende and Miklós Béla Berencsi, who were heard as witnesses in the official inspection, considered the electronic registry and data security measures to be an “internal matter”, so the Authority has no more information regarding the electronic registry. (209) The organization has also started issuing personal identification cards that are similar to the real ones in terms of both content and appearance, after filling out the form called “Application for an identification card for the owner of the Hungarian State”, these are the “Identification Cards of the Hungarian Republic”. According to the document sent by [the police], the police cannot initiate criminal proceedings against those presenting such fictitious ID cards for the use of a false public document, since plastic cards are not public documents, nor are they forged public documents, but fictitious cards filled in with unverifiable data with an untrue legal background, the use of which may constitute fraud. The card, called the “Identification Card of the Republic of Hungary”, has the same format and contains the same type of data as the official identity card. (210) After the personal data has been recorded, the cards providing unlimited and free parking are also issued, after filling in the form described in point III.3 of the decision. The Authority has not come into possession of such ID cards, so the exact data content of these cards is not known to the Authority. (211) According to the Authority, the possession of self-made, officially non-existent cards is not a criminal offence in itself, unless they are misused. However, since their appearance and inscriptions resemble an official document, they are susceptible to deception, their data are not authentic, and the private individuals who make or have them made can enter anyone's data on them.
33
V . 4 . P r o s t o f d a t e r s t r a c t i o n s V.4.1 Data controller status (212) Based on the definitions of the General Data Protection Regulation, a data controller is a natural or legal person, public authority, agency or any other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
(213) The central element of the definition of the data controller is the taking of a substantive decision on data processing, which basically concerns the following data processing circumstances:
- determination of the purpose of data processing;
- determination of the scope of data processed;
- decision on the legal basis for data processing;
- decision on the duration of data processing;
- establishment of the method of data processing, implementation of data processing;
- access to personal data;
- decision on data transfer;
- use of personal data for other data processing purposes, in the course of other activities;
- ensuring and implementing the rights of data subjects, including the requirement of prior information
- decision on using a data processor;
- decision on taking basic data security measures.
(214) These data processing circumstances are the cornerstones through which it can be identified
who (or who) can be considered as a data controller.
(215) The definition of controller also refers to the frequent possibility that a controller makes substantive decisions concerning data processing together with others. In this case, the controllers will be joint controllers. The GDPR requires that in the case of joint data processing, the controllers must enter into an agreement with each other, specifying how they will fulfil their obligations under the GDPR (for example, on what legal basis, what personal data, for how long the controllers will process them, or how they will act in relation to prior information of the data subjects). (216) In the present procedure, these aspects need to be taken into account in determining who or who can be considered as controllers and in what respect in the processing of personal data related to MATT, which is not a legal person, and the ideology behind it. (217) In connection with the identification of the data controller, the Authority established the following:
(218) As already stated above, MATT is a community of ideas, an association of people.
(219) Based on the testimony of all witnesses, István Bende and Béla Miklós Berencsi have a prominent and decisive role in the establishment and operation of MATT, which they themselves acknowledged. The hearing of István Bende as a witness is included in Annex NAIH-9048-52/2024 to the NAIH-5209-
8/2025. 
and the hearing of Béla Miklós Berencsi is also included in Annex NAIH-9048-80/2024 to the NAIH-5209-
8/2025. 
. The hearing of additional witnesses is also included in Annexes NAIH-9048-49/2024., NAIH-9048-50/2024., NAIH-9048-51/2024.,
34
NAIH-9048-54/2024., NAIH-9048-72/2024., NAIH-9048-73/2024.
to the memorandum no. (220) Based on the documents downloaded by the Authority from the MATT website – and also publicly available – and also
received from the police, István Bende, as the current sole member of the “Representation”,
“Prime Minister”, is the signatory of several MATT documents and letters, for example letters addressed to official state bodies,
courts, local governments, and foreign missions, and is
one of the leading persons.
(221) Miklós Béla Berencsi is also a leading person, the first “owner”, according to his testimony,
he started the operation of MATT. He is mentioned by several interviewed persons (testimony record no. NAIH-9048-49/2024, page 4, testimony record no. NAIH-9048-50/2024, page 3, testimony record no. NAIH-9048-54/2024, page 5 and testimony record no. NAIH-9048-73/2024, page 4), as well as István Bende (testimony record no. NAIH-9048-52/2024, page 4), and Béla Miklós Berencsi himself considers himself a data controller (testimony record no. NAIH-9048-80/2024, pages 4-5): as the first “owner”, he registers the further data subjects who have entered into a contract with him on a contractual basis. “owners” personal data, stores the contracts. According to what was presented in his submission registered under number NAIH-5209-28/2025.
, however, he only performed tasks of a technical and
administrative nature, including, among others, the preparation of documents, IT support, and the operation of social communication tools. In the Authority’s opinion, these tasks did not constitute a definition of the purpose or means of data processing within the meaning of the definition of data controller in the General Data Protection Regulation. In the Authority’s opinion, the ones presented by Miklós Béla Berencsi are general objections that do not cast doubt on the fact that the data subjects wishing to become owners conclude a contract with him as the first
“owner”.
(222) The “Representation” has the right to a contract with him as the first
“owner” as described in paragraphs (65)-(69) of the decision, as set out in NAIH-5209-10/2025.
According to the founding declaration, which is an annex to the memorandum no. 1 In this context, the “Representation” issues personal documents, certificates, parking cards and other official documents to the citizens of the “Republic of Hungary”, and therefore processes personal data in this context. In addition, a contract is concluded with Miklós Béla Berencsi as the first “owner”, at which point someone also becomes an “owner” of the “Hungarian State” and becomes part of the regime in which the “Representation” and other “state” bodies operate, as if copying the current official administrative, judicial, prosecutorial and police organizational system.
(223) Based on the publicly available list of civil society organizations and the statements made by István Bende (testimony record no. NAIH-9048-
52/2024, page 4) and Béla Miklós Berencsi (testimony record no. NAIH-9048-
80/2024, page 3), neither the “Hungarian
Republic”, nor the “Representation”, nor the “state bodies” officially exist, are not registered in any state register as legal or non-legal entities, nor is MATT. The Authority does not know all the people who accept this ideology, or who exactly among them are those who
35
actively participate in the life of the system, but according to the documents received from the [police], the number is between 2-3 thousand people. MATT is not a legal entity, it is not registered in the state register, but a loose association of people. Based on the concept of data controller in the General Data Protection Regulation, it can be considered a data controller based on the definition of “other body”. It has internal operating rules and an organizational system, but it is designed to bypass the existing state organizational system, and there are no clear personal responsibility relationships, there is no leading person or management.
(224) In paragraphs (58)-(61) of the decision, based on the [police], NAIH-5209-
11/2025. According to document number NAIH-9048-19/2025, which is an annex to the memorandum, one of the bodies of MATT is the general meeting, which is convened from time to time and is usually held online. Decisions are made at the general meeting, and decisions may in principle be related to data management, but the Authority is not aware of any decision that would have been made in a data protection matter or would have an impact on data management. The Authority is not aware of the participants in the general meetings, the decision makers and the decisions, but based on the available documents, there is information about the agenda of some general meetings. Therefore, the role of the general meeting as a data controller cannot be established at present. (225) Among the electronic documents on the DVDs received from the […] Police Department, NAIH-
5209-11/2025. The minutes of the executive board meeting, which are attached to the memorandum no. 158 – as stated in paragraph (158) of the resolution – however, set as a task the preparation of a “Uniform Data Processing Regulation” by the “Legal Group” by 27 October 2021, and its dispatch to the “offices” by 3 November 2021, however, apart from the task descriptions, no further information on this is available to the Authority. (226) The data protection and data security regulations, described in paragraphs (159)-(165) of the decision, with document number AVABSZ-1/10/2021 and registration number MK-1-10-2021/000003, issued by the “Hungarian State Administrative Office” on 1 February 2021, are only general in nature, in several cases they repeat the provisions of the General Data Protection Regulation, but do not contain any specific information regarding either the MATT or the “Hungarian State Administrative Office” on the exact purpose of data processing and on what specific conditions. The scope of these regulations may specifically extend to the “Hungarian State Administrative Office” based on the information available to the Authority, which the Authority does not examine separately beyond the above. (227) Another annex to the regulations is the consent declaration described above, which must include the name, birth name, address, mother's name, ID card number of the data subject, as well as the names, addresses, and ID cards of two witnesses. In addition, the following must be filled in by hand on the declaration: "purpose and conditions of data processing", "accessibility of the data", "person of the data controller" and "duration of data processing". This declaration does not contain anything else. Confidentiality and data protection declarations are also part of the regulations, however, these cannot be considered as data processing information, they only contain that the data subject has become acquainted with "the concept of personal data according to the GDPR" and the confidentiality rules are displayed. These annexes do not qualify as data processing notices, do not provide any specific information on any data processing, and based on the above, their scope may also extend to the “Hungarian State Public Administration Office” based on the information available to the Authority. (228) The possible role of the “bodies” of the MATT, the “Hungarian State”, such as the general assembly, “record management services”, “ministries” as data controllers should also be examined. However, no information has emerged on the basis of which these “bodies” or their managers would make a decision or determine a data processing purpose, but rather they only have an executive function, regardless of the fact that the “Hungarian State Public Administration Office” is named as a data controller in the data protection and data security regulations described above. Therefore, these “bodies” are currently not considered data controllers, but at most data processors. The same is true of the objection raised by Béla Miklós Berencsi that the general meeting is the decision-maker, but he did not elaborate on this claim, nor did he substantiate that the general meeting would decide on the purpose of data processing. (229) However, as already detailed above, there are two individuals whose role should be highlighted within the MATT organization: István Bende and Béla Miklós Berencsi. They are both the intellectual leaders, founders, and leading figures of MATT. The establishment of MATT and the launch of the entire organization are linked to them, and they made and continue to make the most important decisions regarding its operation, including the processes related to the processing of personal data: registering “owners” and issuing documents. They have authorized themselves to represent the state they have invented. (230) Miklós Béla Berencsi is the “first owner” in the “new state”, the new owners join and contract with him, and he also entrusted the “Representation” to receive the ownership claims. Miklós Béla Berencsi is the leading person as the first “owner”, he started the operation of MATT. Several people heard as witnesses, as well as himself, consider him to be the data controller, since as the first “owner”, the subsequent persons wishing to become owners conclude contracts with him. Thus, he records the personal data of the subsequent “owners” who conclude contracts with him on a contractual basis, and he also stores the contracts themselves. He did not refute these facts in his objections. (231) According to the text of the application presented in paragraphs (70)-(71) of the resolution, Miklós Béla Berencsi approves the previous activity of the “Representation” as an agent and consents to the continuation of its activities in this direction;
instructs the “Representation” to publish the announcement of its ownership claim on both the Hungarian and international levels, and to develop and publish the method of receiving applications for co-ownership, as well as the methods necessary for the enforcement of the will of the future “co-owners” in relation to the operation of the state. He also orders that until the restoration of state institutions, all measures shall be taken using the methods of enforcement of will developed by the “Representation”, expressly in the interests of society. According to the document, “the state shall be obliged to make good the damage and injury it has caused to people and society without delay”.
(232) In all of this, i.e. in relation to the ownership claim, Miklós Béla Berencsi
determined the purpose of data processing, the method and circumstances of data processing, he concludes the
contracts to be stored by him, which include, in accordance with the provisions of point III.3. subparagraph 1
of the resolution
the following personal data of the data subjects: “first name at birth, family name at birth, name used according to documents, mother’s name according to documents, place and time of birth (town, year, month, day), address according to documents, correspondence (residence address),
document identifier, signature, e-mail address, telephone number”, and in the case of two witnesses, name, mother’s name, identification document number, address, signature.
(233) Based on these, Miklós Béla Berencsi is therefore considered a data controller pursuant to Article 4, point 7
of the General Data Protection Regulation.
(234) István Bende heads the “Representation”, which issues documents issued by István Bende as the decision-maker. According to paragraph (64) of the resolution, the “Representation” was founded by three people, one of whom is István Bende. Based on the information available, it can be established that he is a “Member of the Representation”, Prime Minister, a signatory of several MATT letters, such as letters addressed to official state bodies, courts, local governments, foreign missions, one of the creators of the MATT ideology, and the leader of the association. Currently, István Bende represents the “Representation” alone, as the other two members are absent or inactive. He personally embodies the “Representation”, and makes decisions on issues concerning the processing of citizenship declarations and the personal data contained in them. István Bende stores – on the basis of the testimonies – the declarations of citizenship. István Bende stores in his user account the scanned versions of the applications for “ownership claims”, “identification certificates”, “address certificates”, “certificates for unlimited public space use and free parking”, “vehicle licenses”, with the personal data of the affected persons. (235) According to the text of the extracts from the “Public Data and Address Register of the Hungarian Republic” and the “Public Vehicle Register of the Hungarian Republic”, the extract is authentic if – among other things – it is also signed and stamped by the “Representation”, so the influence of the “Representation”, or István Bende representing it, can be established on these registers, and he performs data processing operations in relation to them as well. (236) As the founder, István Bende himself defined the purpose of the “Representation” in his founding declaration, which is also the purpose of data management: the restoration of constitutional order, the creation of a new constitution by the people, the establishment of a provisional government and, at the same time, the dismantling of the occupied private state called Hungary. The “Representation” issues personal documents, certificates and other official documents and extracts from registers to the citizens of the “Republic of Hungary” in connection with the restoration of constitutional order mentioned in the founding declaration. In all these respects, as the sole representative of the “Representation of the Hungarian Republic” – and also its founder – István Bende determines the purpose, method and circumstances of data processing, and as the sole representative of the “Representation”, he stores the documents containing personal data, therefore, in this respect, he qualifies as a data controller pursuant to Article 4(7) of the General Data Protection Regulation.
(237) At the same time, the Authority also established that the data processing is carried out in the name of MATT, in connection with its name, and in its interest, and its aim is to restore the constitutional order of the “Hungarian
Republic”, and to this end, to process the personal data of the data subjects and members. Accordingly, the form templates analyzed in Section III.3 of the decision in relation to the data processing, as well as all information related to MATT, are available on the MATT
website. Consequently, the Authority considers MATT as an association of natural persons as a data controller in this respect, but in practice, it cannot be held liable for data controller responsibility. This is supported by the fact that István Bende and Miklós Béla Berencsi referred to it as a mere association of people, without any kind of organizational form and without the number or identity of MATT members being known.
(238) In the Authority's opinion, however, it is not possible to carry out data processing on the basis of an organisation or association of people that does not actually officially exist, in such a way that the actual data processing is concealed and that the personal relationships are unclear and there is no real person who takes responsibility for the data processing. In the Authority's opinion, it is inadmissible for data processors to be exempted from data controller responsibility in this way and to irresponsibly collect and use personal data without consequences. (239) Furthermore, the fact that MATT is referred to and viewed as an "association of people" does not mean that liability can be avoided due to the indefinability of the participants, and that MATT's liability as an association and its compliance with the law can be disregarded. 38
(240) Based on the above, the Authority considers both MATT and István Bende and Miklós Béla Berencsi to be data controllers. The Authority also examined whether they qualify as joint data controllers or parallel data controllers in accordance with Article 26 of the General Data Protection Regulation. As a result of this examination, the Authority concluded that MATT and István Bende and Miklós Béla Berencsi qualify as joint data controllers because there are no separate data processing operations or separate data processing purposes in relation to the data processing operations examined, but rather the data controller qualities and responsibilities exist in an atypical manner, yet in the data controller construction examined in the present case they are inseparably linked in the interest of a single common purpose, the establishment of the state organization of the “Republic of Hungary” operating in parallel. The data controller roles of the three data controllers cannot be separated more precisely than those set out in this decision, given the lack of cooperation, as the Authority did not receive a response to several of its questions aimed at clarifying the circumstances of the data processing, with reference to “internal affairs”. Thus, the Authority made its findings on the basis of the evidence it had obtained in a wide range. (241) Accordingly, the Authority considered MATT, István Bende and Béla Miklós Berencsi to be joint data controllers and on this basis established the liability of all three, but only applied legal consequences to István Bende and Béla Miklós Berencsi. V . 5 . P r o u s t , f r e c e t i o n a n d l a b a t i o n o f d a t i o n (242) The fulfilment of the principle of purpose-bound data processing supports predictable data processing, helps data subjects in the enforcement of their rights, while at the same time providing a flexible framework along the interests arising from the data controller. (243) The principle of purpose-bound data processing can be assessed as the most important doctrine among the basic principles in terms of its content, “first among equals”. It is a prerequisite for the validity of the other basic principles and the commencement of data processing. It accompanies the entire life cycle of data processing, its fulfilment can and should be examined in all its phases. A closer connection can be seen with the principles of fair procedure and transparency, and the principles of data economy and limited storage also follow from it. (244) In order to comply with the principle of purpose limitation, the data controller also assesses the position of the data subject while taking into account his own interests. He plans the data processing process, determines the purpose or purposes of data processing, assesses the scope of data necessary for this, these and the effects of data processing on the data subject. (245) In simple terms, the principle of purpose limitation means the prohibition of data processing without a purpose, of data collection for stockpiling. It follows from purpose limitation that “the collection and storage of data without a specific purpose, for an unspecified future use, is unconstitutional”. (246) Before starting his data processing activity, the data controller must take into account what he wants to achieve, whether the processing of personal data is necessary at all to achieve his purpose, and if so, how the processing of the data serves the achievement of the purpose. The controller must focus on defining a range of data that is aligned with the purpose and compatible with it. The purpose must be clearly, obviously, and in an understandable language so that data subjects are aware of all the essential circumstances of the data processing, the specific purposes and the range of data aligned with them. (247) The fulfilment of the principle must be examined not only in the case of voluntary, but also in the case of contractual and mandatory data processing, since no legal basis can exempt from the application of the principle of purpose limitation. (39) (248) The appropriate choice, specification and communication of the purpose presupposes a good faith procedure and mutual cooperation between the controller and the legal subjects. The purpose can only be lawful. Consequently, it is clearly not permissible to continue data processing that is in violation of the law or serves to support activities sanctioned by criminal law. (249) Summarizing the essential content of the purpose limitation principle, it has two main, mutually reinforcing
building blocks:
- the choice of a clear and legitimate purpose;
- subsequently, the processing of personal data in a manner that is compatible with the purpose or purposes.
(250) The expectations arising from these are summarized as follows:
- a specifically defined purpose, declared before the start of data processing;
- legitimate purpose or purposes in accordance with the legal bases and in connection with the data processing;
- understandable communication towards the target group, not ambiguous or misleading;
- in the case of additional purpose or purposes, interpretation in accordance with the compatibility test, which generally assumes a congruence of interests or a high degree of similarity
between the earlier and later arising purpose or purposes.
(251) Based on the above, it can be stated that MATT, István Bende and Béla Miklós Berencsi as data controllers decided on the principles related to MATT, its objectives, and also on the data management and their objectives. These objectives, as can be read from the founding declaration of the “Representation” and from Béla Miklós Berencsi’s ownership application, are the change of the constitutional order, the establishment of a provisional government, the dissolution of Hungary as a state, the operation of a new state, and for this purpose the processing of the personal data of the data subjects by filling out the forms described in point III.3 of the decision, the registration of the data subjects, and the issuance of ID cards to them. It is necessary to analyze to what extent these objectives, or the main objective, the parallel “operation of a new statehood” alongside the official, existing one, correspond to the principle of purpose-bound data management. (252) According to the available information, the individuals associated with MATT, as well as Miklós Béla Berencsi and István Bende, refrain from carrying out violent activities. One of the articles cited above17 states: “The situation in Hungary is not yet where it is, say, in America, although the authorities already know about domestic state denialists. The expert put it this way: Hungarian state denialist groups have not yet committed any violent acts, but there are those who are linked to state denialist groups. There are already organizations in Hungary that, following the ideas of state denial, are setting up their own police and gendarmerie, from which a violent outbreak may not be too far away. On the one hand, the authorities currently encounter state denialists mostly during background checks, on the other hand, […] one of the biggest weapons of state denialists in Hungary is paper terrorism. The essence of this is that they bombard offices, authorities, courts, or anyone they come across with letters full of pseudo-legal slurs and often referring to the UCC. […]. This is extraordinary. It is a burden on the bureaucracy, and according to Falyuna, such cases are the reason
for example, that a state denialist's court case can drag on for months instead of a few days or weeks, because the courts are paralyzed with all kinds of documents and submissions. It is not that a professional would not notice that the many, often hundred-page
17 Source: https://telex.hu/techtud/2024/11/12/alhir-osszeeskuves-elmelet-allamtagadas-dezinformació-szuveren-
allampolgar
40
documents do not make any sense, but that they are forced to read them and have to respond to them in some form. Which takes a lot of time.
“So that is why they call this paper terrorism, because it is not only about filling up the mailbox of an
official body, but also about dealing with them, interpreting them,
just like other submissions,” the expert explained.
This is also dangerous because if someone is convinced by this pseudo-legalism that the
state denier understands what he is talking about, he may receive legal advice from him that
has nothing to do with reality.”

(253) Translated into MATT, this means – based on the documents related to parking cases in the file number NAIH-9048-19/2024, which is also from the [police] and forms an annex to the note number NAIH-5209-11/2025.
– that the followers of MATT,
including István Bende and Miklós Béla Berencsi,
also follow paper terrorism
by explaining the basis for the existence of the state system they imagine in their letters sent to official state bodies
by using lengthy deductions that appear to be legal texts,
establishing the invalidity of the current legal system. As the document received from the [police] also proves, this pseudo-legalism has convinced many that they understand what they are talking about,
and that the “Hungarian Republic” exists solely and independently, and that
the You can live according to “local” rules, escaping the jurisdiction of official state bodies and all obligations towards Hungary.
(254) Furthermore, according to the document filed under number NAIH-9048-19/2024, sent by [the police] and also annexed to the memorandum number NAIH-5209-11/2025, MATT and Miklós Béla Berencsi and István Bende also caused financial damage to those who joined them and accepted the MATT ideology. They were questioned as suspects in several cases on suspicion of committing crimes. using the “documents” they created, the “Hungarian
Republic Identification Card”, and the cards entitling them to unlimited public space use and free parking. By using the plastic card that appeared to be a parking card made by MATT and the two data controllers, the affected persons did not pay the parking fee, and therefore incurred a surcharge debt, which in many cases turned into a large debt and was collected in the framework of enforcement proceedings. (255) On the DVDs sent by the […] Police Department (note no. NAIH-5209-11/2025), there are also Excel spreadsheets in which the persons with a parking debt are recorded. For them – NAIH-9048-19/2024, which is an annex to note no. NAIH-5209-8/2025, received from the [police]. According to document no. 1 They write letters to official state bodies to hand over the buildings under their control, and they also write letters to foreign states about the formation of the new “Hungarian Republic”.
(257) They issue “identification cards” that “replace” identification cards, parking cards, and register members in the “Public Data and Address Register of the Hungarian Republic” and the “Public Vehicle Register of the Hungarian Republic” by filling out the forms specified in Section III.3 of the resolution.
41
Furthermore, they “grant citizenship” not only to Hungarian but also to foreign citizens, including minors. In order to operate all of this, and to ensure the operation of the “Hungarian Republic”, they collect, use and store the personal data to be provided on the forms specified in Section III.3 of the resolution.
(258) The Authority has compiled the forms among the documents received from the police agencies, based on which the following number can be established, taking into account the persons concerned, taking into account that the electronic files can also be found in duplicate on the DVDs:
- “Citizenship declaration”: concerning 75 persons;
- “Citizenship declaration made on behalf of a minor child”: concerning 4 persons;
- “Application form for submitting a co-ownership claim to the Hungarian State”: concerning 15 persons;
- “Application for an identification card for the owner of the Hungarian State”: concerning 56 persons;
- “Application for a certificate entitling to unlimited public space use and free parking”: concerning 36 persons;
- an extract from the “Public Data and Address Register of the Republic of Hungary” issued by the “Hungarian Central State Registry Office”: 110 pieces concerning 10 persons;
- an extract from the “Public Vehicle Register of the Republic of Hungary” issued by the “Hungarian Central State Registry Office”: 10 persons.
(259) The requirement for purpose-bound data processing is, among other things, that the purpose be clear
and at the same time lawful and legitimate. The dismantling and replacement of an existing state with an “other
state” together with the entire state organization cannot be a lawful purpose, even if
the Fundamental Law of Hungary and Hungarian criminal law only prohibit the violent
acquisition of power.
(260) The ideology and idea itself, for the sake of which data processing is carried out, cannot be accepted as an appropriate data processing purpose; the data processing purpose is unlawful because it is not lawful, unconstitutional, or real. It is misleading because it creates the impression that one can simply leave the existing social order and legal system without any consequences, that one can abandon all obligations imposed by the state and those towards it, and that one can start a “new life” in a new system of relations. (261) Of course, in a state governed by the rule of law, one is free to believe in any ideology, follow any system of ideas, and exercise the right to express one’s opinion, but in connection with these, the processing of personal data entails the responsibility of the data controller. This means that if any body or person processes data or performs a data processing operation, the data protection regulations apply to this and the data protection requirements must be complied with. Within the data protection regulations, there is a great emphasis on the basic principles, such as the requirement of purpose limitation. (262) The establishment and operation of a new, parallel state alongside the existing, official state organizational system, with explicit disregard for the existing regulatory system and encouragement of this, as a data processing purpose is unlawful, and for this purpose, the collection of data for “ownership claims”, as well as the issuance of “ownership registers”, “documents” and all other related activities, including data processing via the various forms presented in Section III.3. of the Decision, cannot be accepted as specific physical data processing operations. Moreover, these data processing operations (data collection, data use) are carried out in a deceptive manner, so that they give the appearance of officiality, and the documents, ID cards, and letters used can be confused with the documents, procedures, and data processing operations of official state bodies.
42
(263) Therefore, data processing cannot be lawfully linked to an illegal, untrue, or unlawful purpose, and personal data cannot be processed for unlawful purposes.
(264) Consequently, the Authority condemns István Bende and Miklós Béla Berencsi,
because they are carrying out data processing for unlawful purposes, thus violating the principle of purpose-bound data processing as set out in Article 5(1)(b) of the General Data Protection Regulation.
(265) The Authority also condemns MATT, as it also processes data for unlawful purposes, thus violating the principle of purpose-bound data processing pursuant to Article 5(1)(b) of the General Data Protection Regulation.
(266) Lawful data processing requires, in addition to compliance with the law and the existence of a lawful purpose for data processing, a moral and ethical attitude. For this reason, the fairness of data processing is also one of the conditions for lawfulness. The principle of fair data processing primarily applies to the legal relationship between the data controller and the data subject. The fairness of data processing is closely related to the protection of human dignity, and unfair data processing behavior can seriously harm data subjects not only in their right to their personal data, but also in their human dignity.
(267) The principle of fairness is violated by the data processing carried out by MATT, namely István Bendei and Miklós Béla Berencsi, which creates the deceptive impression that as a result of the data processing, the data subject becomes a citizen of an imaginary, non-existent state and is exempted from his obligations towards the real, official state by using plastic cards that give the appearance of various ID cards providing benefits, citing that the official state or state body has no jurisdiction over him. In fact, the data subjects also suffer damage with this conduct, since, for example, the “free parking card” does not actually provide free parking, and the data subject has an obligation to pay for unpaid parking fees, despite the fact that MATT encourages card users to ignore the measures of the state body enforcing the fee payment obligation, citing a lack of jurisdiction.
(268) The Authority finds István Bende and Miklós Berencsi Béla guilty of unfair processing, as they have infringed the principle of fair processing pursuant to Article 5(1)(a) of the GDPR.
(269) The Authority further finds MATT guilty of also infringing the principle of fair processing pursuant to Article 5(1)(a) of the GDPR.
(270) A further requirement for the lawfulness of data processing is that the processing can be carried out on a legal basis pursuant to Article 6(1) of the GDPR.
(271) Although István Bende and Béla Miklós Berencsi stated during their hearing as witnesses that the General Data Protection Regulation does not apply to them – or to MATT – they did, on the other hand, indicate some of the legal bases of the General Data Protection Regulation (Article 6(1)(c) and (e) of the General Data Protection Regulation, where applicable, points a) or f), or point b) in the case of ownership claims, such as the conclusion of a contract with Béla Miklós Berencsi). However, despite the fact that they indicated these legal bases, these are merely the most likely legal bases in their opinion, which are not applicable in the present case, and on the other hand, none of the legal bases can provide exemption from the application of the principles of purpose limitation and fairness. Data processing carried out for an unlawful purpose and unfairly is in any case unlawful, as the principles themselves must be effective, and in some cases the existence of consent or other legal basis is not sufficient to qualify the data processing as lawful, especially - as in the present case - if the legal bases cited are not applicable.
(272) Consequently, the Authority condemns István Bende and Miklós Béla Berencsi,
because they process the personal data of the data subjects without legal grounds, in violation
of Article 6 of the General Data Protection Regulation.
(273) The Authority also condemns MATT,
because they also process the personal data of the data subjects without legal grounds, in violation
of Article 6 of the General Data Protection Regulation.
V . 6 . I nformation on the processing of data
(274) In order for the processing of data to be lawful, it is a further condition that the controller
provides appropriate information.
(275) In the context of prior information, the controller must strive to provide the data subject with the most complete and comprehensive picture possible of the processing of his or her personal data, as this is the only way for the data subject to assess the impact of a given data processing on his or her privacy. Article 13(1)-(2) of the General Data Protection Regulation stipulates that data controllers must at least provide data subjects with information on the circumstances of data processing, but this does not prevent the data controller from providing more precise information. (276) The Authority found only one document in relation to the information on data processing, which qualifies as a data processing notice. (277) This is the case for III.3. described in point 1. (278) In addition, the Authority does not have any documents that would qualify as independent data processing information, the forms do not contain such, they only refer to the information in the guide related to the establishment of a private student relationship with the “Hungarian State”, and the witnesses did not mention that they had received such a document, and neither István Bende nor Béla Miklós Berencsi provided any information in this regard. They both informed the Authority that they would tell the participants how to access their own data in the electronic register available on the MATT website. The data protection and data security regulations issued by the “Hungarian State Administrative Office” are not information for data subjects, but internal regulations, but do not contain any specific information about the data processing of either MATT, the “Hungarian State Administrative Office”, István Bende, or Miklós Béla Berencsi. 44 (279) When submitting ownership claims and when filling out and submitting applications for the issuance of documents, the data subjects do not receive information about the data processing(s). The data processing information related to the private student legal relationship does not cover these data processing activities. Although there is a data processing information regarding the private student legal relationship with the “Hungarian State”, it only covers this narrow area and provides information on this. The way in which the personal data of the data subjects are processed by
MATT, István Bende, Béla Miklós Berencsi, or, where applicable, the “Republic of Hungary”,
or its “bodies” in relation to the additional forms is not provided by
MATT, István Bende, Béla Miklós Berencsi.
(280) Consequently, the Authority finds that István Bende and Béla Miklós Berencsi have not provided information on the data processing, in breach of Article 13(1)-(2) of the General Data Protection Regulation.
(281) The Authority further finds that MATT has not provided information on the data processing, in breach of Article 13(1)-(2) of the General Data Protection Regulation.
V I . L e a g i c a l i c a l i s t i o n (2) (b) of the General Data Protection Regulation, the Authority establishes that MATT, István Bende and Miklós Béla Berencsi have violated Article 5(1)(a) and (b) of the General Data Protection Regulation, Article 6 of the General Data Protection Regulation and Article 13(1)-(2) of the General Data Protection Regulation by processing data for unlawful purposes, unfairly, in the absence of a legal basis, without adequate information and by failing to provide information about them. (283) In the data protection authority procedure initiated ex officio, the Authority prohibits István Bende and Béla Berencsi from processing data for an unlawful purpose, without a legal basis and without appropriate information, pursuant to Article 58(2)(g) of the General Data Protection Regulation, and obliges them to delete personal data.
(284) Data deletion may also take place by destroying the documents listed in the operative part.
(285) The Authority further obliges István Bende and Béla Berencsi to delete the personal data stored in the “Public Data and Address Register of the Hungarian Republic” and the “Public Vehicle Register of the Hungarian Republic”.
(286) The Authority examined whether it was justified to impose a data protection fine on István Bende and Miklós Béla Berencsi.
(287) In this regard, the Authority considered all the circumstances of the case on the basis of Article 83(2) of the General Data Protection Regulation and Section 75/A of the Infotv.
and concluded that in the case of the infringements revealed in the course of the present proceedings, a warning is neither proportionate nor a dissuasive sanction, therefore a fine should be imposed.
(288) In its order No. NAIH-5209-1/2025, the Authority called on István Bende, NAIH-5209-
2/2025. In its order no. 111111, the Authority may impose a data protection fine ex officio in the event of a breach of law during the data protection authority procedure, to present all relevant facts and circumstances that may be of significance in the eventual imposition of a fine. 45 (289) However, neither István Bende nor Béla Berencsi responded to this call from the Authority. (290) Thus, when determining the amount of the fine, the Authority first of all took into account that the breaches committed by István Bende and Béla Berencsi were considered to be breaches falling under the higher fine category pursuant to Article 83(5)(b) of the General Data Protection Regulation. (291) When determining the amount of the data protection fine, the Authority took into account the following as aggravating circumstances in relation to both István Bende and Béla Miklós Berencsi:
- The data processing is continuous, according to the period considered from 25 May 2018 until the initiation of the present proceedings [Article 83(2)(a) of the General Data Protection Regulation];
- According to the figures summarized in paragraph (258) of the decision, the number of data subjects is: 110 people are registered in the “Public Data and Address Register of the Republic of Hungary”, and 75 people are registered in a declaration of citizenship. (These figures were compiled by the Authority and derived from documents found in the documents received from police agencies, and from house searches.) Furthermore, the number of people affected by data processing and information, and those related to the MATT ideology, is approximately 2-3 thousand people [General Data Protection Regulation, Article 83 (2) a)]; - According to the document filed under the number NAIH-9048-19/2024 sent by the [police], forming an annex to the note no. NAIH-5209-8/2025, proceedings were initiated against 33 people in the districts of Budapest due to illegal parking, with payment obligations, so these people actually suffered material damage. The Authority does not have any further statistical data on how many such cases have occurred in other administrative units of Hungary [General Data Protection Regulation, Article 83(2)(a)];
- Data controllers encourage data subjects to take action through various procedures to be exempted from parking fee payment obligations, but in reality, due to this intervention, the financial damage of data subjects does not cease, but rather increases, and higher fines are incurred, which the data subjects have to pay [General Data Protection Regulation, Article 83(2)(c)];
- Data controllers have in several cases refused to answer the Authority's questions, citing that the given issue is an internal matter of MATT, thus making it difficult to clarify the facts and to learn about the circumstances of data processing [General Data Protection Regulation, Article 83(2)(f)];
- The data processing also affects minors, which is confirmed by the fact that separate forms were prepared for them, and the Authority also found specific forms with the data of minors (factually concerning 4 persons) among the documents at its disposal [General Data Protection Regulation, Article 83(2)(k)].
(292) When determining the amount of the data protection fine, the Authority took into account as mitigating circumstances that
- the Authority had not previously established a violation of the law against István Bende and Miklós Béla Berencsi [General Data Protection Regulation, Article 83(2)(e)],
- the Authority exceeded the administrative time [General Data Protection Regulation, Article 83(2)(k)],
- special categories of personal data were not processed [General Data Protection Regulation, Article 83(2)(g)].
46
(293) When determining the data protection fine imposed on István Bende and Béla Miklós Berencsi, the Authority did not consider the circumstances referred to in Article 83(2)(b), (d), (h), (i) and (j) of the General Data Protection Regulation to be relevant, as they cannot be interpreted in the light of the specific case.
(294) The Authority considered the criteria for imposing the fine to be the same for both István Bende and Béla Miklós Berencsi because their involvement in the data processing is approximately the same, they are both managers of MATT, the purpose of the data processing is the same, and the nature of the data processing carried out by them is the same.
(295) The imposition of the fine is necessary based on the above in relation to both István Bende and Béla Miklós Berencsi, and when determining the amount of the fine imposed, the Authority, in addition to the special preventive purpose, also took into account the general preventive purpose sought to be achieved with the fine, with which the Authority – in addition to deterring István Bende and Béla Miklós Berencsi from further infringements – intends to ensure the enforcement of the right to the protection of personal data and to ensure that personal data cannot be processed for unlawful purposes.
(296) The publication of the decision on the Authority’s website with the identification data (name) of the clients serves the same general preventive purpose.
(297) Based on all of this, the Authority has decided as set out in the operative part.
V I I . O ther m a y is s u p p e r s 
(298) The Authority’s competence is determined by Section 38 (2) and (2a) of the Information Act, and its competence extends to the entire territory of the country.
(299) The Authority’s present decision is based on Sections 80-81 of the Information Act and Section 61 (1) of the Information Act. The decision becomes final upon its publication pursuant to Section 82 (1) of the Information Act. Pursuant to Section 112, and Section 116 (1) and (4) d) of the Information Act, and Section 114 (1) of the Information Act, the decision may be appealed against through administrative proceedings.
* * *
(300) The Information Act According to Section 135 of the Civil Code, the debtor is obliged to pay a late payment surcharge in the amount equivalent to the statutory interest if he fails to meet his payment obligation within the deadline.
(301) Pursuant to Section 6:48. (1) of Act V of 2013 on the Civil Code, in the event of a financial debt, the debtor is obliged to pay default interest in the amount equivalent to the central bank base rate valid on the first day of the calendar half-year affected by the delay, starting from the date of default.
(302) The rules of administrative litigation are determined by Act I of 2017 on the Code of Administrative Procedure (hereinafter: the Code).
(303) Pursuant to Section 12. (1) of the Code, administrative litigation against the decision of the Authority falls within the jurisdiction of the courts, and the lawsuit is subject to the jurisdiction of the Code. Pursuant to Section 13(3)(a)(aa)
of the Budapest Metropolitan Court, the court has exclusive jurisdiction.
47
(304) Legal representation is mandatory in administrative proceedings falling within the competence of the court pursuant to Section 27(1)(b) of the Civil Procedure Code. Pursuant to Section 39(6) of the Civil Procedure Code, the filing of a claim does not have a suspensive effect on the entry into force of the administrative act.
(305) Pursuant to Section 29(1) of the Civil Procedure Code and, in view of this, Section 604 of Act CXXX of 2016 on the Code of Civil Procedure, and Section 19(1)(b) of Act CIII of 2023 on the Digital State and Certain Rules for the Provision of Digital Services, the client's legal representative is obliged to maintain electronic communication.
(306) The time and place of filing the claim is determined by Section 39 (1) of the Administrative Procedure Act. The information on the possibility of requesting a hearing is based on Section 77 (1)-(2) of the Administrative Procedure Act.
(307) The amount of the administrative litigation fee is determined by Section 45/A. (1) of Act XCIII of 1990 on Fees
(hereinafter: the Administrative Procedure Act). The party initiating the proceedings is exempted from the advance payment of the fee by Section 59 (1) and Section 62 (1) h) of the Administrative Procedure Act.
(308) According to Section 132 of the Administrative Procedure Act, if the client has not fulfilled the obligation set out in the final decision of the Authority, it is enforceable. The Authority’s decision is subject to the Administrative Procedure Act. According to Section 82 (1), it becomes final upon notification. Pursuant to Section 133 of the Tax Code, enforcement shall be ordered by the authority that made the decision, unless otherwise provided by law or government decree. Pursuant to Section 134 of the Tax Code, enforcement shall be carried out by the state tax authority, unless otherwise provided by law, government decree or, in the case of a local government, a local government decree. Pursuant to Section 61 (7) of the Information Act, the Authority shall implement the decision in respect of the obligation to perform a specific act, to behave in a specific manner, to tolerate or to cease. Budapest, 2 December 2025. Dr. habil. Attila Péterfalvi, President, University Professor