NAIH (Hungary) - NAIH/962-10/2026

From GDPRhub
NAIH - NAIH/962-10/2026
Authority: NAIH (Hungary)
Jurisdiction: Hungary
Relevant Law: Article 6(1) GDPR
Article 6(1)(f) GDPR
Article 9(1) GDPR
Article 9(2) GDPR
Article 85 GDPR
Type: Investigation
Outcome: Violation Found
Started: 21.11.2025
Decided:
Published: 26.05.2026
Fine: 50,000,000 HUF
Parties: Mediaworks Hungary Zrt.
National Case Number/Name: NAIH/962-10/2026
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Hungarian
Original Source: NAIH (in HU)
Initial Contributor: ap

The DPA fined a media company HUF 50,000,000 (approximately €140,590) for publishing articles linking to an interactive map containing the personal data of data subjects affiliated to a political party. The map contained data subjects’ name, addresses, and contact information.

English Summary

Facts

Mediaworks Hungary Zrt. (the controller) is a Hungarian media company and publisher of several daily newspapers, magazines and websites. In November 2025, an unknown person published a website containing an interactive map. This map allowed persons to search through data of almost 200,000 data subjects associated with one of the political parties in Hungary, including their names, addresses, and contact information (email addresses and phone numbers). In addition, it was also possible to infer the data subjects’ political opinions. The controller published several articles on its websites, including a link to the map.

The DPA initiated an ex-officio investigation after receiving a large number of complaints from data subjects. During its investigations, the DPA found that the data from the map originated from a data breach of the Hungarian political party. The DPA had previously issued a statement emphasising that media providers must comply with the GDPR when reporting about the map and data breach. The DPA stated that it was unlawful to make the data from the map available to the public, even if this was done indirectly (e.g. by publishing a link to the map).

The controller argued that the processing was lawful on freedom of speech grounds, and that the press has a duty to draw the attention of the public to matters of public interest. In addition, the controller argued it had a legitimate interest in processing the data, and therefore the processing was lawful under Article 6(1)(f) GDPR.

Holding

The DPA first noted that under national law, the exercise of freedom of press should not (among others) infringe upon the personal rights of others. This includes the right to personal data protection. Processing of personal data for journalistic purposes is also regulated under Article 85 GDPR. However, the DPA stated that there are no specific national law provisions regarding data processing for journalistic purposes that would exempt the controller from its data obligations.[1] The DPA also clarified that the controller did not process personal data by publishing the articles, but by making the map available through the articles. The DPA stated that the controller could not justify the processing of names, addresses and contact information of data subjects in the map under public interest, and making the map available did not fall under the scope of exercising freedom of press.

The DPA found a violation of Article 6(1) GDPR, as the controller did not have a legal basis to process this data.[2] The DPA stated that the controller could not rely on Article 6(1)(f) GDPR to process the data. In addition to the lack of public interest, the controller acted against the DPA’s notice. The DPA noted that the controller could have reported the existence of the map without making the link accessible. Furthermore, the controller failed to take into account the vulnerable position of the affected data subjects, and miscategorised them as public figures. Since the controller did not have a legitimate interest to process the data, the DPA did not determine whether the data processing was necessary or proportionate.

In addition, the DPA found a violation of Article 9(1) GDPR, as the controller unlawfully processed special categories of personal data. The DPA clarified that the controller must have a lawful legal basis under Article 6(1) GDPR, and one of the exceptions under Article 9(2) GDPR must apply in order to process sensitive personal data lawfully. The controller did not have a legal basis under Article 6(1) GDPR, and could not rely on any of the exceptions under Article 9(2) GDPR. This is because the data subjects did not consent (Article 9(2)(a) GDPR), the data was not made manifestly public by the data subjects (Article 9(2)(e) GDPR), and the exception of substantial public interest did not apply (Article 9(2)(g) GDPR).

The DPA fined the controller HUF 50,000,000 (approximately €140,590). The DPA considered this a significant violation, especially as it involved processing of Article 9 GDPR data during a politically charged pre-election period. The DPA took into account the high number of affected data subjects and the controller’s previous data protection violations as aggravating factors, and the fact that the controller removed the link the same day as the articles were published as a mitigating factor. In addition, the DPA issued a reprimand for the violation of Article 9(1) GDPR, and prohibited the controller from publishing articles containing links to the map.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Hungarian original. Please refer to the Hungarian original for more details.

..............................................................................................................................................................................................................................................................................
1055 Budapest Tel.: +36 1 391-1400 naih.hu/adatkezelesi-tajekoztatok
Falk Miksa utca 9-11. KR ID: 429616918 ugyfelszolgalat@naih.hu
Case number: NAIH/962-10/2026 Subject: Decision establishing a violation of law in an ex officio data protection authority proceeding
Precedence: NAIH-16609/2025
NAIH-16611/2025
NAIH/16613/2025
NAIH-957/2026
NAIH-963/2026
D E R I S S O N C I O N
The National Data Protection and Freedom of Information Authority (hereinafter: Authority) with Mediaworks Hungary Zrt. (registered office: 1082 Budapest, Üllői út 48., company registration number: 01 10 047955; tax number: 24785725-2-44, hereinafter referred to as: Client)
in the data protection authority proceedings initiated ex officio against
the Authority, the following decisions are made.
I. The Authority, pursuant to Article 58(2)(b) of Regulation (EU) No 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Regulation 95/46/EC (General Data Protection Regulation) (hereinafter referred to as: General Data Protection Regulation), finds the Client guilty of intentionally infringing Article 6(1) of the General Data Protection Regulation by
a. in the article entitled “Tisza sympathizers are shown on an interactive map” (hereinafter: Article 1) published on the website www.origo.hu published by the Client on 7 November 2025 (hereinafter: Article 1), a link to the page […] (hereinafter: Map) created and made public by an unknown person was published, thus providing access to the name, address, telephone number, email address, and geolocation coordinates of the address of the data subject, as well as his/her political opinion; b. on the website www.magyarnemzet.hu published by the Client (hereinafter: Magyar Nemzet)
on November 7, 2025, in the article entitled “Everyone can find out who the Tiszás is on their street or in their village” (hereinafter: Article 2), it published a link to the Map – prepared and made public by the unknown person, and thus provided access to the names, addresses, telephone numbers, email addresses, geolocation coordinates and political opinions of the affected persons available through the Map;
c. in the article entitled “An amazing link is circulating on the world wide web: everyone can see the Tiszás nearby” (hereinafter referred to as Article 3) published on the website www.ripost.hu published by the Client on 7 November 2025, the image containing the name of the Map, made and made public by an unknown person, thus ensuring access to the data subjects’ name, address, telephone number, email address, and the geolocation coordinates of the address, as well as their political opinions, available through the Map; at the same time, it did not ensure the existence of any lawful case of data processing – pursuant to Article 6(1). 2 II. The Authority finds the Client guilty, pursuant to Article 58(2)(b) of the General Data Protection Regulation, of having intentionally infringed Article 9(1) in the context of the processing of special categories of personal data (hereinafter: special data) by publishing in Articles 1, 2 and 3 (hereinafter: Articles) the availability of the Map (the link to the Map and the image containing the name of the Map) created and made public by an unknown person, thereby providing access to the political opinion available through the Map, while failing to ensure that the processing was lawful under Article 9(2). III. Pursuant to Article 58(2)(f) of the General Data Protection Regulation, the Authority ex officio prohibits the repeated publication in Articles of the Map’s accessibility (the link to the Map or the image containing the Map’s name) – created and made public by an unknown person –, thereby providing access to personal and special data accessible through the Map.
IV. Due to the violations established in points I and II, the Authority ex officio obliges the Client to pay a data protection fine of HUF 50,000,000, i.e. fifty million forints, which he shall pay within 30 days of the date of the finalization of this decision.
V. The Authority shall, pursuant to Act CXII of 2011 on the right to informational self-determination and freedom of information, Act (hereinafter referred to as: Infotv.) Section 61 (2) a) and c) ex officio orders the publication of its final decision by publishing the Client's identification data on the Authority's website.
The fine shall be paid to the Authority's centralized revenue collection target settlement forint account (10032000-
01040425-00000000 Centralized collection account IBAN: HU83 1003 2000 0104 0425 0000 0000)
. When transferring the amount, reference must be made to the NAIH-962/2026. BÍRS. number.
If the Client fails to comply with his obligation to pay the fine within the deadline, he shall be obliged to pay a late payment surcharge. The rate of the late payment surcharge is the statutory interest, which is equal to the central bank base interest rate valid on the first day of the calendar half-year affected by the delay. In case of non-payment of the fine and the late payment surcharge, the Authority shall order the enforcement of the decision and the collection of the fine and the late payment surcharge as taxes. The collection of the fine and the late payment surcharge as taxes shall be carried out by the National Tax and Customs Office.
There is no right of administrative appeal against this decision, but it may be challenged in an administrative lawsuit by means of a statement of claim addressed to the Metropolitan Court within 30 days of its notification.1 The statement of claim shall be submitted to the Authority electronically, which shall forward it to the court together with the case documents. The request for a hearing shall be indicated in the statement of claim.
For those who do not benefit from full personal exemption from fees, the administrative lawsuit fee is HUF 30,000, and the lawsuit is subject to the right to record the subject-matter fee. Legal representation is mandatory in the proceedings before the Metropolitan Court. 1 The form NAIH_K01 is used to initiate the administrative lawsuit: NAIH_K01 form (2019.09.16) The form can be filled out using the general form-filling program (ÁNYK program). Further information: https://www.naih.hu/kozig-hatarozat-birosagi-felulvizsgalata 3 J U N D O C A T I O N I N G I. Facts I.1. Background
(1) On 7 November 2025, an unknown person made public a website via the URL […], on which anyone could search for data of data subjects linked to the Respect and Freedom Party (hereinafter: Tisza Party) using an interactive map.
As the Client also presented in the Articles2, the Map made it possible to find out the names, addresses, telephone numbers, email addresses and geolocation coordinates of the addresses of the data subjects. In addition, given that this data was made public in connection with a political party, it was possible to draw conclusions on the political opinions of the data subjects, as well as their special data, based on the Map.
(2) The fact that the data subjects could be linked to the Tisza Party was also acknowledged by the Client in the Articles3. The Authority also took into account that some of the data subjects who contacted the Authority attached a print screen from the Map to their submissions, showing their personal data accessible through the Map, and expressly stated that they had previously provided their personal data to the Tisza Party, either after downloading the application during registration, or before that, in connection with other data processing activities carried out by the Tisza Party. In addition, according to the statement published on the party's website on 7 November 2025 by the chairman of the Tisza Party, the data subjects appearing on the Map are supporters of the Tisza Party4. No information emerged during the procedure indicating that a database compiled from another source had been used to prepare the Map. In addition, based on the evidence generated in the ongoing data protection authority proceedings related to the Tisza Party data protection incident, the Authority also notes that the number of natural persons affected by the data protection incident is in the same order of magnitude as that published in Articles5 regarding the number of natural persons affected by the disclosure via the Map (nearly two hundred thousand persons). 2 Quote from Article1: “On the page [on the Map – Authority’s note], the leaked data can be browsed based on geographical coordinates, so Tisza Party sympathizers can be displayed even at street level.” Quote from Article 2: “On the page [on the Map – the Authority’s note], the people involved can be browsed based on geographical coordinates – so you can see who the Tisza sympathizers are in the area, even at street or house level. But you can also search for people’s names separately, and those interested can also find out who their acquaintances are Tisza supporters.” Quote from Article 3: “If we understand it correctly, the interactive map leaves it up to everyone to find the Tisza supporters near them by typing in the search data themselves. The application first offers a world map, and then various search options throughout the world, on all five continents.” "The site allows you to search for people based on geographical coordinates - so you can see who the Tisza sympathizers are in your area, even at street or house level, or even exactly how many registered users live in Australia and what their names are. In fact, the system works the other way around, so you can search by name or address, and the application will throw the person out if they are on the list, and will even provide their email address in addition to their name and address."
3 Quotes from Article 1: “Someone has already created an interactive map from the personal data leaked from the Tisza Világ application, on which the Tisza sympathizers can be seen by street and name (…)”. Quotes from Article 2: “The Tisza Party data scandal has taken a drastic turn.
Someone has put the leaked Tisza people on a map (…)”. “Now every Tisza person can experience firsthand what the Tisza data scandal really means, as an interactive map has been created from the data leaked from the Tisza mobile application.” Quote from Article 3: “After the personal data of around 200,000 users of the party’s app called TISZA VILÁG was made public in October, now someone – perhaps the Tisza Party itself – has decided to turn the disadvantage into an advantage and make the situation even more “user-friendly” by creating an interactive map.”
4 The statement by the Tisza Party president is available at: https://magyartisza.hu/hirek/tv/rendk%C3%ADv%C3%BCli-bejelent%C3%A9s-az-
ellopott-adatokr%C3%B3l-k%C3%A9sz%C3%ADtett-t%C3%A9rk%C3%A9p-kapcs%C3%A1n
5 Quote from Article 1: “(…) after the personal data of around 200,000 users was made public in October (…)”. Quote from Article 2: “(…)
where the approximately 200 thousand people whose data were made public (…) live”. Quote from Article 3: “After in October the personal data of approximately 200 thousand users of the party’s app called TISZA VILÁG was made public (…)”.
4
(3) The existence of the Map was first reported by the website www.index.hu published by INDEX.HU Zrt. (hereinafter referred to as Index) in its article titled “Interactive map showing Tisza sympathizers” published on November 7, 2025 at 3:26 p.m.

case file number NAIH-962-1/2026, appendix number 10). Index explicitly emphasized that
it would not publish the availability of the Map in the article and asked readers not to try to search for it either. In its article, Index also explained at length what negative consequences the fact that their personal data is accessible through the Map may have for the data subjects (targeted harassment, intimidation, disadvantages at work or in society, danger to personal safety, impairment of free political expression).
The Index also quoted from the Authority's announcement published the previous day, on November 6, presenting the data protection requirements that the Authority has formulated in relation to media service providers.
(4) The Authority published a notice on the data protection requirements for the use of personal and sensitive data by media service providers made public from the databases of political parties on 6 November 2025, the day before the publication of the Map (hereinafter: Notice), which was published by the Hungarian Telegraph Office in the National Press on 6 November 2025 at 17:58. In the Notice, the Authority – taking into account the media service provider’s information activities related to the data protection incident affecting the data processing of the Tisza Party – formulated basic data protection requirements for media service providers. The Authority first of all stated that the actions of the unknown person who accessed, acquired or made public the personal and sensitive data processed by the Tisza Party – depending on the circumstances of the violation – may have committed a criminal offence. The Authority emphasized in its Communication that the vulnerability of an IT system used by a political party for its political activities may be considered a matter of public interest, but if media service providers report on this, they must comply with the provisions of the General Data Protection Regulation and the law enforcement practice determining the balance between freedom of the press and the right to the protection of personal data. The Authority stated in the Communication that in the case of the storage of personal data and its use in media content, the media service provider is independently responsible for its data processing activities. In this regard, the Authority emphasized in the Communication that the fact that the political party may have failed to take appropriate data security measures in violation of the applicable legal requirements, or that someone has already made the personal data public by exploiting a data security deficiency, does not play a legitimizing role in data processing. According to the Authority's position expressed in the Communication, it is contrary to data protection requirements if the personal and sensitive data of those affected by unlawful data processing are made available to the public in an article (even indirectly, i.e. by providing a link to the database or the website that makes the personal data public). In doing so, media service providers further increase the extent of the infringement and the negative impact on the privacy of the data subjects. On the other hand, media service providers must also take into account that the data subjects are in a vulnerable position, since it is not the data subjects who have made their personal and sensitive data public, but rather the infringer who exploits a potential data security flaw. The Authority also emphasized that, in relation to the use of personal data, data controllers must pay increased attention to the right of data subjects to respect for their private life, family life and home, and refrain from using personal data in a disturbing or harassing manner.
6 https://mti.hu/nemzeti-kozlemenytar/2025/11/06/politikai-partok-adatbazisaibol-nyilvanossagra-kerulo-szemelyes-es
5
I.2. Publication of the link to the Map via Article 1
(5) Article 1 was published on Origo, published by the Client, on 7 November 2025 at 16:47. The second paragraph of the article was as follows: “The Tisza Party data leak case continues with another scandal. According to the Index report, after the data of around 200,000 users from the party’s Tisza Világ application was made public in October, someone has now created a map visualization based on the database. The site allows users to browse the leaked data based on geographical coordinates, so Tisza Party supporters can be displayed even at street level. The interactive map is AVAILABLE HERE.” The latter sentence was in bold in the article. The text “AVAILABLE HERE” was a link to the Map, which readers could click on to go directly to the Map. In addition, “Index” was also a hyperlink in the paragraph, and clicking on it would bring up the Index article from November 7. In addition, Origo also wrote in Article 1 that “the NAIH specifically emphasized that media service providers may not refer to the leaked database and may not share a link that could lead to the data of the data subjects.” Article 1 also stated that “the appearance of the interactive map further increases the risk for the data subjects, since the data includes not only names, but also email addresses and exact residential addresses. This may provide an opportunity for harassment, intimidation or even physical abuse. The authority emphasized that the data subjects did not voluntarily disclose their personal data, but were put in a vulnerable position by an offender who exploited a data security flaw.” (6) Taking into account that the Authority received a large number of submissions regarding Article 1, the Authority initiated ex officio data protection proceedings against the Client under case number NAIH-16613/2025 on 21 November 2025 regarding the compliance of the data processing related to the publication of the link to the map in Article 1 with the General Data Protection Regulation. The Authority requested the Client to demonstrate the legitimate interest and the necessity-proportionality aspects of the data processing through several requests for statements, and the Authority requested the transmission of the original text of Article 1 (order number NAIH-16613-1/2025). (7) The Client responded to the Authority's questions in its statement dated 5 January 2026 (statement no. NAIH-962-1/2026). In response to the Authority's questions on what aspects it considered in connection with the publication of the link to the Map in Article 1 and how it took into account the specific circumstances when deciding on the publication of the link to the Map, the Client gave a general answer, expressly stating that it did not wish to make a statement in the Authority's questions. (8) Referring to Section 10 of the Smtv., the Client stated that “consistent case law and numerous decisions of the Constitutional Court consider the basic principle to be followed, according to which the task of the press is to draw the attention of the authorities and the public to matters of public interest.” In the statement, the Client referred to Section 2:44 of the Civil Code, according to which “the exercise of fundamental rights ensuring the free discussion of public affairs may restrict the protection of the personality rights of a public figure to a necessary and proportionate extent, without prejudice to human dignity.” The Client also referred to the practice of the Constitutional Court. On the one hand, it highlighted that according to Decision 13/2014. (IV. 18.) AB, “in assessing a public communication, it is first necessary to decide whether the given communication reflects a statement on public affairs or a position expressed in a public interest debate, i.e. whether it is related to the free discussion of public affairs.” On the other hand, Decision 7/2014. (III. 7.) AB
decision, in which the Constitutional Court stated with principled significance that
“the freedom to express an opinion related to public affairs belongs to the innermost circle of protection of freedom of speech and
6 the press. The focus of the expression of opinion in the context of the discussion of public affairs and the protection relating to it is not primarily on the status of the persons affected by the speech, but on the fact that the speaker expressed his views on a social or political issue.”

(9) The Client stated that, based on these legal provisions and case law, the internet portal [Origo] it operates qualifies as a press product, which has the broadest rights to exercise freedom of the press, which is part of freedom of opinion. The scandals related to the data processing of the Tisza Party are the subject of the most extensive public debate of recent times.
The participants in the public debate are also persons included in the TISZA Party database. The topic of the article
contributes to the above public debate. Since the topic of the article is related to a public debate, the purpose of the data processing in relation to all personal data is media service, informing the public through the press on a matter of public interest. Since the topic of the article is related to a public debate, the legal basis for the data processing – in relation to all personal data –
is legitimate interest in accordance with Article 6(1)(f) of the General Data Protection Regulation (freedom of the press, freedom of expression, information to the public).” The Client
also emphasized in the statement that he did not make the Map public, “it was accessible by anyone.”
(10) In response to the Authority’s request to forward the original text of Article 1, the Client stated that it “can no longer determine the original date of publication, and cannot forward the original text. The Client also informed the Authority that its system “[…]”. The Authority notes that during the data protection authority procedure, the Client was unable to state how long the link to the Map in Article 1 had been available. (11) During the data protection authority procedure initiated ex officio, the Authority noticed that at the time of the initiation of the procedure, Article 1 was available with content in which the sentence “The interactive map is AVAILABLE HERE” no longer appeared. The Client did not forward the original text of Article 1 upon the Authority’s request. In order to determine the original content of Article 1, the Authority conducted additional evidentiary proceedings. In doing so, the Authority used two services [the Wayback Machine service (https://web.archive.org/, hereinafter: Wayback Machine) operated by the Internet Archive non-profit organization, and the archive.today service (https://archive.ph/, hereinafter: archive.today)], the page backups of which make it possible to view the content of articles at an earlier time. The Authority determined the original content of Article 1 based on the page backup of Article 1 made by the archive.today service on November 7, 2025 at 4:50 p.m. (NAIH-
962-8/2026. file, Annex 1). (12) In addition, the Authority also conducted an evidentiary procedure to determine how long the sentence “The interactive map is AVAILABLE HERE” had been included in Article 1. In this regard, the Client stated in its statement dated 22 April 2026 that the link to the Map had been removed from Article 1 on the day of the publication of Article 1 (statement no. NAIH-962-5/2026). The Authority established, based on the page backup of Article 1 made by the Wayback Machine service on 7 November 2025 at 18:29, that the link to the Map had no longer been included in Article 1 at that time at the latest (case file no. NAIH-962-8/2026, Annex 2). On this basis, the Authority established that the link to the Map
was in Article 1 for a maximum of 1 hour and 42 minutes.
7
(13) The Client made a statement regarding the reading data of Article 1 that “it has no data on how many readers opened the Article between the time the Article was published and the time the Map
was unavailable” (statement number NAIH-962-1/2026). The Authority therefore requested a statement from the Client in a new order on how many people viewed Article 1 on 7 November 2025. The Authority based its decision on the data provided by Gemius SA (registered office: Domaniewska utca 48, Warsaw, Poland, Polish tax number: 527-22-41-358, hereinafter: Gemius) on the online service called “gemiusAudience” (website address: https://audience.gemius.com/en/, hereinafter: gemiusAudience service). According to the gemiusAudience service, on 7 November 2025, Origo had 1,648,890 page views and 725,066 visits. Based on these data, the Authority requested the Client to provide an estimate of how many unique visitors (Real users) could have read Article 1 on 7 November 2025, after Article 1 was made public, i.e. after 16:47 (Decision No. NAIH-962-2/2026). The Client stated in its statement dated 22 April 2026 that […] visitors viewed Article 1 on that day (Declaration No. NAIH-962-5/2026). The
Authority notes in this context that, given that the link to the Map
was in Article 1 for a maximum of 1 hour and 42 minutes, a portion of this number of visitors
could have read Article 1 before the link to the Map was removed from Article 1.
I.3. Publication of the link to the Map via Article 2
(14) Article 2 was published on Magyar Nemzet, published by the Client, on 7 November 2025 at 16:56. The introduction (or “lead” in journalistic terms) of Article 2 was as follows: “The Tisza Party data scandal has taken a serious turn. Someone has put the leaked Tiszas on a map, with the majority giving their addresses to Péter Magyar’s party, down to the street and house number. You can browse the map here!” The second paragraph of Article 2 was as follows: “Index came across the map, which makes the search for Tiszas more “user-friendly”. On the page, the people involved can be browsed based on geographical coordinates – so you can see who the Tisza sympathizers are in the area, even at street or house level. But you can also search for people’s names separately, and those interested can also find out who their acquaintances are Tiszas.” In the first
sentence, the word “map” was in a different color and was a link to the Map, which, when clicked, took readers directly to the Map. In addition, the word “Index” in the paragraph was also a hyperlink and by clicking on it, the November 7th article of the Index was published.
(15) On November 21, 2025, the Authority initiated an ex officio data protection authority procedure against the Client under the case number NAIH-16609/2025 regarding the compliance of the data processing related to the publication of the link to the Map in Article 2 with the General Data Protection Regulation. The Authority requested the Client to demonstrate the legitimate interest and the necessity-proportionality aspects related to the data processing through several requests for declarations, and the Authority requested the transmission of the original text of Article 2 (order number NAIH-16609-1/2025). (16) In the administrative procedure initiated in connection with Article 2, the Representative also acted as the Client's authorized representative. The Client responded to the Authority's questions in its statement dated 5 January 2026, which response was verbatim identical to its statement in connection with Article 1 (statement number NAIH-957-1/2026). In response to the Authority’s request to forward the original text of Article 2, the Client also stated that it “can no longer determine the original date of publication and cannot forward the original text.” The Client also informed the Authority that its system8 “[…]”. The Authority notes that during the data protection authority procedure, the Client was unable to state how long the link to the Map had been available in Article 2. (17) During the ex officio authority procedure, the Authority noticed that at the time of the initiation of the procedure, Article 2 was available with content in which the link to the Map no longer appeared. The Client did not forward the original text of Article 2 upon the Authority’s request. The Authority conducted further evidentiary proceedings in order to be able to determine the original content of Article 2. The Authority established the original content of Article 2 based on a page backup of Article 2 made by the archive.today service on 7 November 2025 at 17:46 (file number NAIH-962-8/2026, attachment number 3). (18) In addition, the Authority also conducted an evidentiary procedure to determine how long the link to the Map had been included in Article 2. In this regard, the Client stated in its statement dated 22 April 2026 that the link to the Map had been removed from Article 2 on the day Article 2 was published (statement number NAIH-957-5/2026). The Authority established, based on the page backup of Article 2 made by the Wayback Machine on 7 November 2025 at 18:09, that the link to the Map was no longer included in the article at that time. In this modified version of Article 2, the word “to the map” was no longer a hyperlink, so readers of Article 2 could no longer click on it (and thus access the Map) (case file no. NAIH-962-8/2026, Annex 4). On this basis, the Authority established that the link to the Map was included in Article 2 for a maximum of 1 hour and 13 minutes. (19) The Authority also records that a new version of Article 2 was subsequently published on 7 November 2025. Based on the page save made by the archive.today service on November 7, 2025 at 10:36 p.m.
of Article 2, it was determined that the text of the first sentence of the paragraph had been changed to the following text version: “the map, which according to the NAIH's position
we cannot publish, since that would make us data controllers, was discovered by Index” (case file number NAIH-962-
8/2026, appendix number 5). In this sentence, the phrase “which according to the NAIH's position
we cannot publish” is a link, by clicking on which the article published by the Client in Magyar Nemzet a day earlier can be accessed. In the article titled “Péter Magyar’s data scandal may constitute a criminal offence” published on 6 November 2025 at 9:33 p.m., Magyar Nemzet presented the Announcement in detail (case file number NAIH-962-8/2026, attachment number 6). (20) Regarding the reading data of Article 2, the Client made the following statement: “There is no data available regarding how many readers opened Article 2 between the time Article 2 was published and the time the Map became unavailable” (NAIH-957-1/2026.
statement no.). The Authority therefore requested a statement from the Client in a new order on how many people could have viewed Article 2 on 7 November 2025. In its order, the Authority based its order on the data from the “gemiusAudience” service, according to which on 7 November 2025, the page views (“Views”) for Magyar Nemzet were: 531,636, the number of visits (“Visits”): 277,745. Based on these data, the Authority requested the Client to provide an estimate of how many unique visitors (“Real users”)
could have read Article 2 on 7 November 2025 after the publication of Article 2, i.e. after 16:58 (order no. NAIH-957-2/2026). The Client stated in its statement dated 22 April 2026 that […] visitors viewed Article 3 on this date (statement number NAIH-957-5/2026). In this context, the Authority notes that, taking into account that the link to the Map was in Article 2-
9 for a maximum of 1 hour and 13 minutes, some of this number of visitors may have read Article 2 before the link to the Map was removed from Article 2.
I.4. Disclosure of the availability of the Map through the image in Article 3
(21) Article 3 was published on 7 November 2025 at 17:23 in the Ripost published by the Client.
The first two paragraphs of Article 3 introduce the operation of the Map, and then a screenshot of the Map
homepage is included in Article 3, the title of which is […],
i.e. the Map URL, thus ensuring that readers can access the Map.
In Article 3, Ripost refers to the November 7th article in Index,
emphasizing that the Map is “expressly dangerous for those affected”. In addition, Article 3 refers to the Communication, quoting several statements of the Authority from it: “The National Authority for Data Protection and Freedom of Information (NAIH) made it clear in its Thursday statement that although the vulnerability of a political party’s IT system may constitute a matter of public interest, this does not in itself create a legal basis for the person exploiting the data security deficiency to store and publish the personal and sensitive data of the data subjects in the database. Even if a political party has unlawfully failed to take adequate data security measures to protect the personal data stored electronically by it, and someone exploits this vulnerability to access and obtain this personal data, this act is also unlawful and, depending on the circumstances of the violation, may even constitute a criminal offence,” the authority emphasized. The NAIH also paid special attention to the liability of media service providers. The According to the position statement, although journalists may, in order to provide credible information, contact the data subjects to verify the authenticity of the leaked data or to ask for their opinion on a public matter, it is contrary to data protection requirements if an article ››makes the personal and sensitive data of those affected by the unlawful data processing accessible to the public – even indirectly, i.e. by providing a link to the database or the website that publishes the personal data‹‹.”
(22) On 21 November 2025, the Authority initiated ex officio data protection proceedings against the Client under case number NAIH-16611/2025 regarding the compliance of the data processing related to the publication of the link to the Map in Article 3 with the General Data Protection Regulation. The Authority requested the Client to demonstrate the legitimate interest and the necessity-proportionality aspects of the data processing through several requests for declarations, and the Authority requested the transmission of the original text of Article 3 (Order No. NAIH-16611-1/2025). (23) In the administrative procedure initiated in connection with Article 3, the Representative also acted as the Client's authorized representative. The Client also responded to the Authority's questions in its statement dated 5 January 2026, which response was verbatim identical to its statement in connection with Articles 1 and 2 (Declaration No. NAIH-963-1/2026). In response to the Authority's request to forward the original text of Article 3, the Client also stated that it was "no longer able to determine the original date of publication, and could not forward the original text." The Client also informed the Authority that its system was "[…]". The Authority notes that during the data protection authority procedure, the Client was unable to state how long Article 3 had been available with content such that the image in it contained the URL address [...]. (24) During the ex officio authority procedure, the Authority noticed that at the time of the initiation of the procedure, Article 3 was available with content such that the 10 images in it had been modified and the image no longer contained the URL address [...]. The Client did not forward the original text of Article 3 upon the Authority's request. In order to determine the original content of Article 3, the Authority conducted additional evidentiary proceedings. The Authority determined the original content of Article 3 based on a page backup of Article 3 made by the Wayback Machine service on 7 November 2025 at 17:54 (case file no. NAIH-962-8/2026, Annex 7). (25) In addition, the Authority also conducted evidentiary proceedings to determine how long the image had been included in Article 3 in such a way that the URL […] was visible on the image. In this regard, the Client stated in its statement dated 22 April 2026 that the link to the Map had been removed from Article 3 on the day Article 3 was published (statement no. NAIH-963-5/2026). The Authority notes that, based on the page backup of Article 3 made by the archive.today service on 7 November 2025 at 21:45, at that time, Article 3 still contained an image with the URL […] (case file number NAIH-962-8/2026, attachment number 8). The Authority highlights that neither service made a page backup of Article 3 on 8 November and 9 November 2025, and the closest page backup was made by the Wayback Machine service on 10 November 2025 at 13:33, when the image shown in Article 3 no longer contained the URL […] (case file number NAIH-962-
8/2026, attachment number 9). Considering that the web archiving services used by the Authority during the clarification of the facts did not make a page backup of Article 3 on November 8 and November 9, the Authority cannot therefore establish the content of the image in Article 3 on these days.
On November 10, an image was certainly included in Article 3 on which the […] URL address was not visible. The Authority therefore accepts the Client's statement that on the day of the publication of Article 3, but after 9:45 p.m., the image in Article 3 was modified so that the […] URL address was not visible. Based on this, the Authority established that an image on which the […] URL address was visible was included in Article 3 for at least 4 hours and 22 minutes.
(26) Regarding the reading data of Article 3 – similarly to Article 1 and Article 2
– the Client made the statement that “it has no data on how many readers opened the Article between the time of the Article’s publication and the time the Map became unavailable” (statement no. NAIH-963-1/2026). The Authority therefore requested a statement from the Client in a new order on how many people could view Article 3 on 7 November 2025. In its order, the Authority based its order on the data of the “gemiusAudience” service, according to which on 7 November 2025, the page opening data for Ripost (“Views”) was: 196,549, and the number of visits (“Visits”) was: 144,446. Based on these data, the Authority requested the Client to provide an estimate of how many unique visitors (‘Real users’) could have read Article 3 on 7 November 2025, after Article 3 was made public, i.e. after 17:23 (Decision No. NAIH-963-2/2026). The Client stated in its statement dated 22 April 2026 that […] visitors viewed Article 3 on that day (Declaration No. NAIH-963-5/2026). In this context, the Authority notes that, given that Article 3 contained an image showing the […] URL for at least 4 hours and 22 minutes, some of these visitors may have read Article 3 before the Client modified the image in Article 3.
I.5. Subject of the data protection authority procedure
(27) The subject of the present data protection authority procedure is the Client's data processing activity of publishing the link to the Map in Article 1 and Article 2, and of making the Map available through the 11 images published in Article 3, thereby providing access to the names, addresses, telephone numbers, email addresses and geolocation coordinates of nearly two hundred thousand data subjects.
(28) In the present data protection authority procedure, the Authority examined whether the Client had an appropriate legal basis pursuant to Article 6(1) of the General Data Protection Regulation for publishing the availability of the Map in Articles, and – given that the data processing activity also covered sensitive data in view of the political opinions and affiliations of the data subjects – whether the data processing activity involving the publication of sensitive data could be considered lawful pursuant to Article 9(2) of the General Data Protection Regulation.
I.6. Merger of cases and the Ákr. Call for a declaration pursuant to Section 76
(29) Considering that in the above data protection authority proceedings initiated ex officio under separate case numbers, both the person of the Client, the person of the representative authorized by the Client for legal representation, and the conduct of the data controller that is the subject of the authority case are essentially identical, and that the Client made a declaration that is substantively identical in all three proceedings, the Authority therefore ordered in its order dated 27 April 2026, case number NAIH-962-
7/2026, to merge the following authority cases under case number NAIH-
962/2026:
– NAIH-16613/2025. under case number (new case number in 2026: NAIH-962/2026.) in Article 1, the data protection authority procedure was initiated ex officio to examine the compliance of the data processing related to the publication of the link to the Map with the General Data Protection Regulation,

– NAIH-16609/2025. under case number (new case number in 2026: NAIH-957/2026.) in Article 2, the data protection authority procedure was initiated ex officio to examine the compliance of the data processing related to the publication of the link to the Map with the General Data Protection Regulation,

– NAIH-16611/2025. under case number (new case number in 2026: NAIH-963/2026.) a data protection authority procedure initiated ex officio to examine the compliance of data processing related to the publication of the image containing the name of the Map in Article 3 with the General Data Protection Regulation.
(30) In its order No. NAIH-962-9/2026 dated 28 April 2026, the Authority notified the Client, pursuant to Section 76 of Act CL of 2016 on General Administrative Procedure (hereinafter: Ákr.), that it may make a statement and further motions for evidence, in light of the evidence contained in the note with case number NAIH/962-8/2026.
prepared by the Authority on the procedural act conducted in order to clarify the facts, sent as an annex to the order. The Client did not make a statement based on this invitation from the Authority.
II. Applicable legislation
(31) According to recital (4) of the General Data Protection Regulation, the right to the protection of personal data is not an absolute right, but must be considered in accordance with the principle of proportionality, in relation to its role in society, and in balance with other fundamental rights. This Regulation respects all fundamental rights and observes the freedoms and principles recognised in the Charter and enshrined in the Treaties, in particular the right to respect for private and family life, home and correspondence and the protection of personal data, the freedom of thought, conscience and religion, the freedom of expression and information, the freedom to conduct a business, the right to an effective remedy and to a fair trial, and the right to cultural, religious and linguistic diversity.
(32) According to Article 2(1) of the GDPR, this Regulation shall apply to the processing of personal data wholly or partly by automated means and to the processing other than by automated means of personal data which are part of a filing system or which are intended to be part of a filing system. (33) According to Article 4(1) of the GDPR, personal data means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, a number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. (34) According to Article 4(2) of the GDPR, processing means any operation or set of operations which is performed upon personal data or upon sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. (35) According to Article 4(7) of the GDPR, the natural or legal person, public authority, agency or any other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of the processing are determined by Union or Member State law, the controller or the specific criteria for the designation of the controller may also be determined by Union or Member State law. (36) According to Article 5(2) of the GDPR, the controller shall be responsible for compliance with paragraph (1) and shall be able to demonstrate such compliance (‘accountability’).

(37) Article 6(1)(f) of the GDPR states that the processing of personal data shall be lawful only if and to the extent that at least one of the following is met: (…) the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, unless such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

(38) Pursuant to Article 9(1) of the GDPR, the processing of personal data relating to political opinions shall be prohibited.

(39) Article 9(2) of the GDPR states that paragraph 1 shall not apply where: (a) the data subject has given explicit consent to the processing of those personal data for one or more specific purposes; (…) (e) the processing relates to personal data which the data subject has explicitly made public; (…) (g) the processing is necessary for reasons of substantial public interest, is based on Union or Member State law, is proportionate to the aim pursued, respects the essence of the right to the protection of personal data and provides for suitable and specific measures to safeguard the fundamental rights and interests of the data subject; (…)”.
(40) Pursuant to Article 58(2)(b) of the GDPR, the supervisory authority shall, acting in its corrective powers, take action against the controller or processor where the processing activity has infringed the provisions of this Regulation.
(41) Pursuant to Article 58(2)(f) of the GDPR, the supervisory authority shall, acting in its corrective powers, temporarily or permanently restrict the processing, including the prohibition of processing.
(42) Article 85(1) of the GDPR states that Member States shall reconcile the right to the protection of personal data under this Regulation with the right to freedom of expression and information, including the processing of personal data for journalistic purposes or for scientific, artistic or literary expression.
(43) Article 85(2) of the GDPR Pursuant to Article 85(3) of the GDPR, Member States shall provide for exceptions or derogations from Chapter II (principles), Chapter III (rights of the data subject), Chapter IV (controller and processor), Chapter V (transfer of personal data to third countries or international organisations), Chapter VI (independent supervisory authorities), Chapter VII (cooperation and consistency) and Chapter IX (specific cases of processing) in respect of the processing of personal data for journalistic purposes or for the purposes of scientific, artistic or literary expression, where such exceptions or derogations are necessary to reconcile the right to the protection of personal data with the right to freedom of expression and information. (44) Pursuant to Article 85(3) of the GDPR, Member States shall notify the Commission of the legal provisions they have adopted pursuant to paragraph 2 and shall notify the Commission thereof without delay. on subsequent amending legislation or amendments to the aforementioned legal provisions.
(45) According to recital (153) of the General Data Protection Regulation, the law of the Member States should reconcile the rules on freedom of expression and information, including journalistic, scientific, artistic and literary expression, with the right to the protection of personal data under this Regulation.
(46) According to Section 4(3) of Act CIV of 2010 on Freedom of the Press and Fundamental Rules for Media Content (hereinafter: Smtv.), the exercise of freedom of the press may not constitute a criminal offence or an incitement to commit a criminal offence, may not offend public morality or may not infringe the personality rights of others.
(47) According to Section 2:43(e) of Act V of 2013 on the Civil Code (hereinafter: Ptk.),
(47) Pursuant to Section 10 of the Smtv., everyone has the right to be adequately informed about local, national and European public affairs and about events of importance to the citizens of Hungary and the members of the Hungarian nation. The media system as a whole has the task of providing reliable, rapid and accurate information about these matters and events.
III. Decision
III.1. Preliminary findings
III.1.1. Definition of the data processing activity and determination of the object scope of the General Data Protection Regulation
(48) The Authority examined the Client's data processing activity by publishing the availability of the Map in the Articles and thereby providing access to the names, addresses, telephone numbers, email addresses and geolocation coordinates of the addresses of the data subjects, and - as already stated in The Authority has established in Section I.1 of this decision that the Client's data processing activities also covered special data pursuant to Article 9(1) of the General Data Protection Regulation, as personal data from the data processing of a political party, the Tisza Party, were used to prepare the Map, and thus, based on the Map, a conclusion could be drawn as to the political opinion of the data subjects. (49) Based on the definition in Article 4(2) of the General Data Protection Regulation, any operation performed on personal data results in data processing. As the Client emphasized in his statement, he did not make the Map public, so the Client's data processing activities did not constitute a data processing operation of publication. However, according to the above definition of the General Data Protection Regulation, "making personal data otherwise accessible" also qualifies as a data processing operation. The Authority has established that the Client’s publication of the availability of the Map in the Articles constitutes a data processing operation of “making it accessible in another way”. (50) In this context, the Authority also notes that the Client did not carry out the data processing by publishing the Articles, but by publishing the availability of the Map in the Articles (and thereby providing access to the personal and special data of nearly two hundred thousand data subjects). (51) The number of natural persons affected by the Client’s data processing activities is the same as the number of data subjects whose personal and special data were made public through the Map. As the Authority has established in Sections I.1. – I.2. of this decision – and other media service providers have also reported this in their media content – nearly two hundred thousand persons were affected by the publication through the Map.
(52) The Authority further states that the Client's publication of the availability of the Map in the Articles (and thereby providing access to the personal and sensitive data of nearly two hundred thousand data subjects) falls within the scope of Article 2(1) of the General Data Protection Regulation, as this data processing activity of the Client constitutes the automated processing of personal data. Therefore, the provisions of the General Data Protection Regulation apply to the data processing in this administrative procedure.
III.1.2. Determination of the capacity of data controller
15
(53) The imprint of the online press products lists the Client as the publisher, and the data protection notices on the websites of these press products, which were in force at the time of the initiation of the procedure, list the Client as the data controller with regard to the data processing associated with the use of the websites, including editorial content. The Client is also listed as the publisher of the press products in the public register of the National Media and Communications Authority7 on internet press products and news portals.
(54) Furthermore, in its statements to the Authority, the Client stated in relation to Origo, Magyar Nemzet and Ripost that they are internet portals operated by it. With this wording, the Client also acknowledged its capacity as a data controller in relation to the data processing activities carried out through Origo, Magyar Nemzet and Ripost, which are the subject of the present official procedure.
(55) Based on the above, the Authority concludes that the Client, as the publisher of the internet press products, qualifies as a data controller in relation to the data processing activities examined pursuant to Article 4(7) of the General Data Protection Regulation.
III.1.3. Article 85 of the GDPR and the Client's data processing activities
(56) According to recital 4 of the GDPR - which is also referred to in the client's declaration - the right to the protection of personal data is not an absolute right, but must be taken into account in accordance with the principle of proportionality, in relation to the role it plays in society, and in balance with other fundamental rights. The EU legislator has highlighted, among others, the freedom of expression and freedom of information as fundamental rights that must be balanced against the right to the protection of personal data.
(57) In accordance with recital 4 of the GDPR, Article 85(1) requires Member States to reconcile the rules on the freedom of expression and information (including journalistic activities) with the right to the protection of personal data. Article 85(2) of the GDPR expressly provides for the possibility for Member State legislators to provide for exceptions or derogations for processing for journalistic purposes, insofar as they are necessary to reconcile the freedom of expression and the right to information with the right to the protection of personal data. (58) The Curia has addressed the role of Article 85(2) of the GDPR in several decisions in relation to the information activities of the press. The Curia has considered the role of Article 85(2) of the GDPR in relation to the information activities of the press in its decision No. 37.978/2021/10. In its judgment no. 101/2009, the Court stated in principle in this regard that
“no exceptions or derogations have been defined by the Member States for journalistic purposes.
Consequently, according to the legislator, exceptions or derogations are not necessary in order to reconcile the right to the protection of personal data with the right to freedom of expression and information. (…) No specific legislation has been enacted for specific data processing operations by the press, and no amendment has been made to the Smtv. in this regard”.8
7 https://sajtopub.nmhh.hu/sajto_kozzetetel/app/index.jsp, date of query: 2026.04.16.
8 Kfv.37.978/2021/10. Judgment No. [134], paragraph 16
(59) It follows from the above that there are no special Hungarian legal provisions regarding data processing for journalistic purposes that would exempt the Client from certain data controller obligations set out in the General Data Protection Regulation.
Therefore, the Client must carry out its data processing activities in accordance with the rules of the General Data Protection Regulation, while at the same time taking into account the legal provisions on the exercise of press freedom and the practice of law enforcement in relation to the reconciliation of the freedom of expression and the right to information with the right to the protection of personal data.
III.1.4. Specific features of the present case compared to the Authority's practice related to the information activities of media service providers
(60) The Authority has previously conducted numerous data protection authority proceedings against media service providers regarding their articles containing personal data. In these procedures, the data subjects submitted a request for an official procedure, complaining that the data controller had infringed the General Data Protection Regulation by including some of their personal data in the given article. During the procedure, the Authority usually primarily examined the lawfulness of the data processing in relation to one (or at most: a few) data subjects, thus basically examining whether the data controller was able to prove the existence of legitimate interest, necessity and proportionality in the case of its data processing of the data subject(s). In doing so, the Authority took into account the relevant court and constitutional court practice, which was also based on the fact that a natural person had initiated a personal rights lawsuit against a media service provider due to a communication appearing in its media content. The practice of law enforcement has determined the examination of a complex system of aspects in relation to public communication9, and has classified the communication published in the press into two types: value judgment or statement of fact. The Authority has also taken these aspects into account in the data protection authority proceedings against media service providers.
(61) In the present data protection case, however, two significant differences can be stated compared to the cases that have arisen in the Authority's practice so far. On the one hand, in the present case, the data processing carried out by the Client does not cover one or a few identified persons, but nearly two hundred thousand persons. The Client's statements and arguments regarding the legal basis must be appropriate not only for one data subject, but for all data subjects.
On the other hand, the Client does not express the opinion or statement of fact expressed in the Articles regarding individual data subjects, but rather the access granted to their personal and special data, which has been made public through the Map. In other words, the subject of the procedure is not a public communication concerning a data subject (as has been the subject of official and judicial law enforcement up to now), but a “new” type of media service provider information and data processing activity: providing access to personal and sensitive data. As a result of these two differences, the constitutional standards, official law enforcement and judicial case law that have been developed in relation to communications concerning a person (i.e. the processing of their personal data) are of limited validity in the current data protection official procedure against the Client. III.2. The legal basis for publishing the availability of the Map in the Articles (and thereby providing access to the personal and sensitive data of nearly two hundred thousand data subjects) 9 For example, the 13/2014. (IV. 18.) AB Resolution [39] states that “when assessing a public communication, it is first necessary to decide whether the given communication reflects a statement on public affairs or a position expressed in a public interest debate, i.e. whether it is related to the free discussion of public affairs. In order to assess this, it is necessary to primarily take into account the manner and circumstances of the communication, the subject and context of the opinion. Thus, the type of medium, the event giving rise to the communication, the reactions to it and the role played by the given communication in this process must be examined. As a further aspect, it is necessary to assess the content, style, and the topicality and purpose of the statement.”
17
III.2.1. Legal basis for data processing
(62) The fundamental requirement of lawful data processing is that the data controller has an appropriate legal basis for the processing of personal data. Article 6(1) of the General Data Protection Regulation defines the possible legal bases for data processing. In the context of the processing of sensitive data, the Authority states that in these cases it is also necessary for the controller to have a legal basis in accordance with Article 6(1) of the General Data Protection Regulation, and the General Data Protection Regulation defines as a conjunctive condition that in the case of the processing of sensitive data, one of the cases in Article 9(2) must also be met. The Authority will examine this latter circumstance in this decision separately from the legal basis for data processing, in point III.3 of the decision. (63) According to the Client’s statement, the processing of data “with regard to all personal data”, i.e. name, address, telephone number, email address, geolocation coordinates of the address, and also in the case of political opinions that are considered special data, was based on the legitimate interest of the Client, in accordance with Article 6(1)(f) of the General Data Protection Regulation. (64) In order to apply the legitimate interest legal basis, three combined conditions must be met: first, the legitimate interest of the controller or a third party must be pursued, second, the processing of the personal data must be necessary for the pursuit of a legitimate interest, and third, the interests or fundamental rights and freedoms of the data subject must not be overridden by the legitimate interest of the controller or a third party.10 Pursuant to Article 5(2) of the General Data Protection Regulation, the controller must be able to demonstrate that these three conditions are met in relation to the processing of its data. Based on the consistent practice of the Authority
and the courts11, data controllers can fulfil this obligation by carrying out a so-called balancing test prior to data processing.
(65) As regards the first condition of Article 6(1)(f) of the GDPR, namely legitimate interests, the case-law states that the concept of legitimate interest “is not limited to interests recognised and defined by law, but requires that the alleged legitimate interest be legitimate”12. In addition, the case-law states that “where a legitimate interest exists, it must be substantiated by precise and reasoned justification by the controller”13 and that the legitimate interest “must exist and be actual at the time of the processing”14.
(66) The Authority further highlights that the legitimate interest plays a prominent role in the case of the legal basis under Article 6(1)(f) of the GDPR, as the other two conditions are linked to it. The necessity condition can be examined if there is a legitimate interest, on the basis of which it can be considered whether the data processing is necessary for the exercise of this legitimate interest. Also, if there is a legitimate interest, the third condition, the issue of proportionality, can be examined, since in the case of a non-legitimate legitimate interest, the processing of personal data cannot be proportionate. 10 Judgment of the Court of Justice of the European Union in case C-621/22. 11 For example, Kfv.37.978/2021/10. [162]: “the controller must be able to justify the carrying out of a balancing of interests, which follows from the principle of accountability [Article 5(2) GDPR]. In that case, the controller must carry out a balancing of interests, demonstrating why the legitimate interests of the controller override the rights of the data subjects.”
12 Judgment of the Court of Justice of the European Union in Case C-621/22 Koninklijke Nederlandse Lawn Tennisbond v Autoriteit Persoonsgegevens, paragraphs 40 and 57
13 Judgment of the Court of Justice of the European Union in Case C-708/18 TK v Asociaţia de Proprietari bloc M5A-ScaraA, paragraph 44
18
management. Therefore, as a first step in the legal basis, it is necessary to decide whether the interest indicated by the data controller is legitimate before the other two conditions are assessed. (67) The Authority also notes that in the case of media service providers, the determination of the legitimate interest even before data processing (and the subsequent balancing of interests) cannot be considered an obligation under data protection law. The responsibility of media service providers to exercise “prudent procedure” prior to publication has appeared in several Constitutional Court decisions.15 In the context of freedom of the press, the Constitutional Court has formulated the constitutional requirement that the freedom of the press to provide information is not unlimited, but is burdened with obligations in order to ensure the enforcement of other fundamental rights or constitutional values.16 With regard to Section 4(3) of the Smtv. and Section 2:43 of the Civil Code. § e), such a limitation can be identified as the right to the protection of personal data. In the Authority's opinion, it may not only constitute a violation of the provisions of the General Data Protection Regulation, but also a violation of § 4. (3) of the Smtv. if, prior to the publication of the media content, the media service providers are not required to consider whether the disclosure of personal data in the media content intended to be published (or: providing access to it) violates the right to the protection of personal data.
III.2.2. Examination of legitimate interest in relation to the publication of the availability of the Map in the Articles
(68) As the Authority has previously established, the Client did not implement data processing by publishing the Articles, but by publishing the availability of the Map in the Articles and thereby providing access to the personal and special data of the data subjects. For this reason, the legitimate interest should not be related to the publication of the Articles, but rather – in accordance with court practice17 – should be identified as a legitimate interest in ensuring that the personal data and political opinions of nearly two hundred thousand data subjects were made known by publishing the availability of the Map. (69) The Authority notes that the Client did not attach a balancing test during the present data protection authority procedure. In its response dated 5 January 2026, the Client indicated the freedom of the press, freedom of expression and information of the public as legitimate interests – in relation to all personal data. In the identification of the legitimate interest, the Client’s right to freedom of expression and information of the public, in accordance with the Smtv, may be taken into account. 10. § that “the consistent case law and the numerous decisions of the Constitutional Court consider the basic principle to be followed, according to which the task of the press is to attract the attention of the authorities and the public in matters of public interest.” The Client further stated that “the most extensive public debate of the past period is related to the scandals related to the data processing of the Tisza Party. The participants in the public debate are also persons included in the TISZA Party database. The topic of the article contributes to the above public debate. (…)” In this statement, the Client also informed the Authority that the Map was not made public by him, “it was accessible to anyone.”
15 For example, in 3051/2022. (II. 11.) AB Resolution [57] or 3038/2024. (II. 9.) AB Resolution AB Resolution [56]

16 3203/2025. (VI. 23.) AB Resolution AB Resolution [53]
17 Kfv.37.978/2021/10. [163] paragraph of judgment no.: “the Curia emphasizes that the legitimate interest must always be examined in relation to the specific situation and activity (…)”
19
(70) In the present proceedings, the Authority must decide the legal question of whether the exercise of freedom of the press and freedom of expression can be used as a legitimate legitimate interest in the case of the Client’s examined data processing activity (publishing the availability of the Map in the Articles and thus providing access to the personal and special data of nearly two hundred thousand data subjects). According to the Authority, it is not sufficient for the Client to invoke freedom of the press and freedom of expression as a legitimate interest, but it is also necessary for appropriate arguments to support the fact that the Client's data processing is based on the exercise of freedom of the press as a legitimate interest, as the case law requires the data controller to be able to substantiate its actual legitimate interest in a precise and justified manner. (71) In its statement based on Section 10 of the Smtv., the Client did not present any argument as to why providing access to the names, addresses, telephone numbers, email addresses, and geolocation coordinates of the addresses and political opinions of nearly two hundred thousand people through the publication of the availability of the Map would fall under the heading of "national public affairs" or "significant event". The Client has demonstrated in its statement that the Articles were created in a matter of public interest, and that the topic of the Articles contributes to the public debate. The Authority emphasizes that even if the Articles present a matter of public interest, this in itself is not sufficient for the exercise of freedom of the press to constitute a legitimate interest of the Client in data processing, since it did not implement data processing by publishing the availability of the Map in the Articles, but by publishing it in them. According to the Authority, providing access to the name, address, telephone number, email address and geolocation coordinates of the address of the supporters of a political party cannot be considered an event of public interest. In the Authority's opinion, publishing the availability of the Map in the Articles goes beyond the scope of reporting on a public matter. The Authority has established that the publication of the availability of the Map cannot be considered as the exercise of freedom of the press pursuant to Section 10 of the Smtv. (72) According to the Authority, in determining the legitimacy of the legitimate interest, the Client should have first of all taken into account that the Authority stated in the Notice that, in the Authority's opinion, it is contrary to data protection requirements if the personal and sensitive data of those affected by unlawful data processing become available to the public in an article (even indirectly, i.e. by providing a link to the database or the website that makes the personal data public). This requirement was known to the Client before the Articles were published, as Article 1 expressly stated that “the NAIH specifically highlighted: media service providers may not refer to the leaked database and may not share a link that could lead to the data of the data subjects.” In the case of Magyar Nemzet, the day before the publication of Article 2, on November 6, 2025, it wrote about this requirement18, so it was known before the publication of Article 2 what requirement the Authority had formulated in this context. In the case of Article 3, the Authority also included this requirement: “the NAIH paid particular attention to the responsibility of media service providers. According to the position statement (…) it is contrary to data protection requirements if in an article the personal and special data of those affected by the unlawful data processing become available to the public – even indirectly, i.e. by providing a link to the database or the website that makes the personal data public.” 18 Quoted from an article published in Magyar Nemzet on November 6, 2025: “The NAIH emphasized that in addition to the personal data made public by the affected person – such as political opinion – the dissemination of certain additional personal data – address, telephone number, etc. – by media service providers is already considered unlawful.” 20
(73) When assessing the legitimate interest, the Client should have taken into account the vulnerable position of the data subjects arising from the fact that both the acquisition of their personal and special data, the publication of these data in a database and the use of these data for the preparation of a Map (and the publication of the Map) may constitute a criminal offence, since these infringements clearly go far beyond the fact that one (or more) unknown data controllers have infringed the requirements of the General Data Protection Regulation on data controllers. The Client should have taken these circumstances into account when assessing the legitimacy of the legitimate interest, if only because Article 1 expressly stated that “the data subjects did not voluntarily disclose their personal data, but were put in a vulnerable position by an offender exploiting a data security vulnerability.” In the case of Article 2, it was also aware of this requirement, as the article in Magyar Nemzet, published a day earlier, on November 6, 2025, presenting the Authority's Announcement, stated that "in addition, media service providers must be aware that the data subjects are in a vulnerable position, since it was not they who made their data public, but the person who violated the law by exploiting the data security deficiency." Furthermore, in the case of Article 3, it was also aware of this requirement, since although - unlike Article 1 and Article 2 - no similar text appeared in Article 3 itself, Article 3 refers to the Announcement19 and quotes several passages from it, thus the data protection requirements contained in the Announcement were known to the Client even before the publication of Article 3.
(74) Contrary to the Client's statement, the Authority considers that "the persons included in the Tisza Party database" cannot be considered "participants in the public debate related to the scandals related to the Tisza Party's data management", or "public figures" with reference to Section 2:44 of the Civil Code, but rather the data subjects are victims of this potential crime. The Authority points out in this context that the Client incorrectly drew the conclusion that the data subjects became active public figures simply because they were affected by the data leak related to the Tisza Party's data management. The personal and special data of the data subjects appearing on the Map were not made public through their voluntary consent, so they did not become the shapers of the public debate by their own decision, but the negative consequence of the data leak affecting the data management of the Tisza Party was that anyone could get to know their data through the Map. The Client did not prove in its statement that each of the data subjects had previously made their political opinions public. However, according to the Authority's position, even if a data subject who could be considered a public figure were included in the database in a way that can be verified by the Client, the disclosure of their personal data (address, telephone number, e-mail address) relating to the private sphere, in addition to their previously made public political opinions, is already contrary to the requirements of the General Data Protection Regulation. (75) Another important aspect in determining the legitimate interest is that the disclosure of personal and sensitive data – by an unknown person – through the Map may have a significant negative impact not only on the data protection rights of the data subjects, but also on their right to respect for their private life, family life and home, as this makes their name, address and telephone number easily accessible to anyone, making it easy to contact them – in a potentially disturbing, harassing or otherwise offensive manner. The Customer should have taken into account the data subject’s right to access the Map when making a decision on whether to disclose it. 19 Quoted from Article 3: “the National Data Protection and Freedom of Information Authority (NAIH) made it clear in its position statement on Thursday (…)”. 21
The Authority considers that the Client should have considered whether, at the time of the publication of the Articles, it could be excluded that the right to respect for private life, family life and home would not be infringed, in respect of all (almost) two hundred thousand data subjects whose personal data and political opinions relating to the private sphere had become known. According to the Authority, it is not reasonably possible to completely exclude in advance the potential negative effects of data processing activities on a large number of data subjects.
(76) The Authority also highlights in this context that this circumstance was known to the Client, as Article 1 expressly contained this requirement20 and Magyar Nemzet also referred to this circumstance in its article of 6 November21. The Client was also aware of this requirement in the case of Article 3, given that Article 3 quotes several passages from the Authority's Notice, which shows that the content of the Notice was known to the Client even before the publication of Article 3. (77) In addition, in terms of determining the legitimate legitimate interest, the Client should have been aware that Index, which was the first to report on the existence of the Map, expressly did not wish to publish the availability of the Map in the article and asked its readers not to try to find the Map. The Client was aware of the Index article, since it linked to the article previously published on Index in Articles 1 and 2, while in Article 3 it referred to this Index article. Since the Client and the publisher of the Index perform the same media service activity (operating an internet news portal) and the topic of the Articles and the article published on the Index is the same (informing about the existence of the Map), the Client should have taken into account, when assessing the existence of a legitimate interest, that a publisher of the Index considered the disclosure of the availability of the Map in a previously published article to be unlawful. (78) However, according to the Authority, the fact that the Map was not made public by the Client and was available to anyone has no role at all in determining the legitimate interest. As the Authority has previously highlighted, the disclosure of the Map may constitute a criminal offence. The fact that the Client has not committed a crime in the case of a completely different data processing activity has no impact on whether the Client has a legitimate interest in ensuring access to personal and sensitive data attributable to its independent data processing activity through the publication of the availability of the Map in the Articles. According to the Authority, the above data protection requirements cannot be neglected in relation to the Client's independent data processing activity, citing the circumstance that the Map, which is reasonably suspected of being generated by committing a crime, is accessible to anyone, since, despite this, there is a direct risk of harm to the vulnerable situation of the data subjects and their right to respect for their private life, family life and home, which undermines the existence of a legitimate interest. (79) According to the Authority, based on the assessment of all these circumstances, the Client should have recognized that it has no legitimate interest in providing access to the personal and sensitive data of nearly two hundred thousand data subjects by publishing the availability of the Map, thus taking into account – in accordance with Section 4(3) of the Smtv. – the freedom of the press
20 Quoted from Article 1: “the appearance of the interactive map further increases the risk for data subjects, since the data includes not only names,
but also e-mail addresses and precise residential addresses. This may provide an opportunity for harassment, intimidation or even physical abuse.”
21 Quoted from an article published in Magyar Nemzet on November 6, 2025: “in connection with the use of personal data, data controllers must pay particular attention to the right of data subjects to respect for their private life, family life and home, refraining from using personal data in a disturbing or harassing manner.”
22
The exercise of freedom of expression and freedom of expression cannot serve as a legitimate interest in this data processing activity.
(80) In view of the above, the Authority found that the Client could not substantiate in a precise and justified manner that it had an actual, legitimate legitimate interest at the time of the commencement of data processing – i.e. at the time of the publication of the Articles.
(81) Based on all of this, the Authority concluded that the Client did not have a legitimate interest to publish the availability of the Map in the Articles and thus provide access to the personal and sensitive data of the data subjects. (82) As the Authority previously stated, in the absence of a legitimate interest, it is not possible to assess whether the Client's data processing was necessary for the exercise of the legitimate interest or whether the data processing carried out by it can be considered proportionate in relation to the legitimate interest. For example, Decision 13/2014. (IV. 18.) AB and Decision 7/2014. (III. 7.) AB indicated in the client's statement could be relevant in the event that a legitimate interest exists and therefore further examination of whether access to personal and sensitive data is necessary for the presentation of an event of public interest is justified. Also on the basis of the legitimate legitimate interest, the Authority could examine the proportionality between the disclosure of the availability of the Map and the severity of the infringement of fundamental rights caused in this regard. Since the Authority established a lack of legitimate interest in accordance with the above, the Authority was not able to examine the necessity and proportionality of the data processing. (83) Finally, the Authority notes that the lack of legitimate interest does not mean that the Client could not have informed its readers about this topic of paramount public interest by exercising freedom of the press. According to the Authority, it could have reported on the existence of the Map without publishing the availability of the Map. (84) On the basis of all this, the Authority finds ex officio that the Client, by publishing the link to the Map in Article 1 and
Article 2, and by publishing the image containing the name of the Map in Article 3, provided access to the name, address, telephone number, email address and the geolocation coordinates of the address of the data subject without appropriate legal basis, and thus infringed Article 6(1) of the General Data Protection Regulation.
(85) The Authority also took into account the fact that the Client amended the content of all three articles within a few
hours and, by expressly acknowledging in Article 2 that data protection legal considerations may override the exercise of freedom of the press and freedom of expression22. According to the Authority, the Client's actions show that
the Client recognized that the data processing carried out by publishing the availability of the Map is in violation of the General Data Protection Regulation and does not have an appropriate legal basis for it.
III.3. Assessment of the lawfulness of data processing activities involving sensitive data
22 Quoted from the amended text of Article 2: “The map, which according to the NAIH's position we cannot publish, since that would make us data controllers, was discovered by Index.” In this sentence, the text “which according to the NAIH's position we cannot publish” was a link, which, when clicked on, would access an article in Magyar Nemzet a day earlier, in which Magyar Nemzet presented the Announcement in detail.
23
(86) One of the categories of sensitive data pursuant to Article 9(1) of the General Data Protection Regulation is political opinion. As the Authority has explained in Section I.1 of this Decision, since the Map contains personal data of data subjects related to the Tisza Party, it was possible to draw conclusions on the political opinion of the data subject based on the Map. By publishing the availability of the Map in the Articles, the Client also provided access to the political opinion of the data subjects.
(87) By their nature, the processing of sensitive data may entail significant risks for the data subject, since the processing of data falling into this category may have a serious impact on the fundamental rights and freedoms of the data subject. Consequently, the General Data Protection Regulation allows the processing of sensitive data in certain cases, subject to stricter rules. The starting point of the GDPR is that the processing of special data is prohibited [Article 9(1) of the GDPR], and then Article 9(2) of the GDPR defines the situations in which the processing of special data may be lawful. (88) However, as the Authority has already referred to in Section III.2 of this Decision, it is not sufficient for the lawfulness of data processing that the circumstances of Article 9(2) of the GDPR are met in the case of the given data processing: the controller must also have a legal basis in accordance with Article 6(1) of the GDPR. Article 9(2) of the General Data Protection Regulation does not constitute an exemption from the requirements of Article 6(1) but – due to the special protection of sensitive data – these cases must be applied as additional requirements in relation to the specific data processing activity. Consequently, the above requirements of Article 6(1)(f) of the General Data Protection Regulation must be applied to the processing of sensitive data, among others. (89) Based on all of this, the Authority states that in order to process sensitive data, the controller must, on the one hand, have a legal basis in accordance with Article 6(1) of the General Data Protection Regulation and, on the other hand, as a conjunctive condition, one of the cases of Article 9(2) of the General Data Protection Regulation must also be met. In the event that the controllers are unable to demonstrate that the processing falls within the scope of Article 9(2) of the GDPR, the prohibition under Article 9(1) will apply (i.e. the processing of sensitive data is prohibited) and the controller will also infringe this provision in relation to the processing of sensitive data. (90) Considering that in point III.2 of the reasoning of this decision, the Authority found that the Client did not have a legal basis in accordance with Article 6(1) of the GDPR for the publication of the availability of the Map in the Articles, therefore this conjunctive condition for the processing of sensitive data was not met. (91) The Authority notes, however, that none of the cases of Article 9(2) of the GDPR can be applied to the processing of data by the Client by publishing the availability of the Map in the Articles and thereby providing access to the political opinions of nearly two hundred thousand data subjects. According to the Authority, the Client clearly did not have the express consent of all data subjects for this data processing activity [case under Article 9(2)(a)], and the Client in its declaration indicated legitimate interest and not consent as the legal basis for its data processing. The case under Article 9(2)(e) of the GDPR cannot apply to the processing of data by the Client, since recital 24 of this decision I.1. Based on the facts presented in point 1 and the outstanding number of requests and submissions received by the Authority, it is clear that it was not the data subjects who made their political opinions known through the Map public, but the unknown data controller who prepared the Map. In the context of the case under Article 9(2)(g) of the General Data Protection Regulation, the exercise of freedom of the press and freedom of expression may arise as significant public interests that could potentially justify the data processing examined by the Client, provided that this is proportionate to the aim sought to be achieved and respects the essential content of the right to the protection of personal data. Reasons for this decision III.2. However, due to the arguments set out in point 1, the exercise of freedom of the press and freedom of expression do not constitute a legitimate interest in the case of the data processing activity under review, so it is obvious that the exercise of freedom of the press or freedom of expression cannot be considered as a significant public interest in the case of the Client's data processing under review. The Authority notes that the other cases of Article 9(2) of the General Data Protection Regulation cannot be interpreted at all in relation to the Client's data processing under review. (92) Based on the above, it can be concluded that none of the cases of Article 9(2) of the General Data Protection Regulation would be applicable to the Client's provision of access to the political opinions of the data subjects through the publication of the availability of the Map in the Articles. (93) On the basis of all this, the Authority found that, with regard to the processing of sensitive data, the Client infringed Article 9(1) of the General Data Protection Regulation by providing access to the political opinions of the data subjects through the publication of the availability of the Map in the Articles, while failing to ensure the existence of any legitimate grounds for processing pursuant to Article 9(2). IV. Legal Consequences IV.1. Legal consequences applied due to the infringements established by the Authority
(94) The Authority condemns the
Client on the basis of Article 58(2)(b) of the General Data Protection Regulation for having published the availability of the Map in the Articles and thereby provided access to the names, addresses, telephone numbers,
email addresses, and the geolocation coordinates of the addresses, as well as the political
opinions of nearly two hundred thousand data subjects, in violation of Article 6(1) of the General Data Protection Regulation.
In addition, given that it did not ensure the existence of any legitimate case for the
processing of data – pursuant to Article 9(2) of the General Data Protection Regulation – with regard to the political opinion, the
Client therefore violated Article 9(1) of the General Data Protection Regulation.
(95) The Authority prohibits the Client from repeatedly publishing the Map’s availability (the link to the Map or the image containing the Map’s name) in the Articles pursuant to Article 58(2)(f) of the General Data Protection Regulation.
(96) If the Authority establishes a breach of law in the data protection authority procedure, it may apply the legal consequences specified in the General Data Protection Regulation and the Infotv.
These include data protection fines, which the Authority shall decide on ex officio, independently or in addition to other legal consequences, based on its free discretion provided for in the General Data Protection Regulation.
25
(97) The Authority has examined whether it is justified to impose a data protection fine on the Client.
The Authority has considered the necessity of imposing a fine in accordance with Article 83(2) of the General Data Protection Regulation and the Infotv. 75/A. considered all the circumstances of the case and, taking into account Section 61. (1) a) of the Infotv., decided to impose a fine on the basis of Article 58. (2) i) of the General Data Protection Regulation.
IV.2. Determination of the data protection fine
IV.2.1. Determination of the Client’s conduct that can be sanctioned by a fine
(98) Taking into account the European Data Protection Board’s Guidelines No. 4/2022 on the calculation of administrative fines under the General Data Protection Regulation (hereinafter: the “Fine Guidelines”), the Authority first determined the Client’s conduct that can be sanctioned by a fine when imposing a fine.
(99) In this context, the Authority found that the Client carried out three data processing activities, as Article 1 was published on Origo on 7 November 2025 at 16:47, Article 2 was published on Magyar Nemzet on 7 November 2025 at 16:56, while Article 3 was published on Ripost on 7 November 2025 at 17:23. However, the Client's data processing activities that were the subject of this data protection authority procedure were identical: it published the availability of the Map in the Articles and thus provided access to the personal and sensitive data of the data subjects. Furthermore, the Authority found the same infringement in respect of all three Articles: the Client, by unlawfully processing, infringed two different provisions of the GDPR, Article 6(1) by providing access to the names, addresses, telephone numbers, email addresses and the geolocation coordinates of the addresses of the data subjects and to political opinions, and Article 9(1) in respect of political opinions. (100) The Authority assessed that the processing activities carried out by the Client were closely linked in context and constituted a coherent conduct. Therefore, the processing activities carried out in connection with the publication of the availability of the Map in the Articles were to be considered as “linked” and constituted the same conduct. Although the Client's conduct violates several provisions of the General Data Protection Regulation, the applicability of one provision does not exclude or override the applicability of another provision. Consequently, the Authority assesses the infringements and their severity due to the Client's unlawful processing of data, covering all Articles, together.
IV.2.2. Circumstances justifying the imposition of a data protection fine
(101) The Authority has established that the Client has violated one of its fundamental obligations as a data controller, with intentional conduct, and based on the assessment of the circumstances detailed below, the Authority has assessed the violations as being of high gravity, therefore the imposition of a data protection fine against the Client is justified.
(102) The Authority has assessed the nature of the violation as being that the Client has violated one of its fundamental obligations as a data controller; it did not have an adequate legal basis for the data processing. The Authority has set out in Sections III.2 and III.3 of this decision established that the Client did not have any appropriate legal basis, either in relation to personal data or sensitive data, to provide access to the data of the data subjects by publishing the availability of the Map in the Articles [Article 83(2)(a) of the General Data Protection Regulation].
(103) The Authority also established that the Client committed high-severity infringements. As the Authority established in Sections I.1. and III.1.1. of this decision, the number of persons affected by the Client’s unlawful data processing activities is significant, as it covered the personal and sensitive data of nearly two hundred thousand data subjects [Article 83(2)(a) of the General Data Protection Regulation].
(104) According to the Authority’s assessment, the high seriousness of the infringements is also supported by the fact that – as the Authority established in Section I.1. of this decision and III.1.1. – the breaches covered the personal data of the data subjects relating to their private sphere (name, e-mail address, telephone number, address, geolocation coordinates of the address) and their sensitive data indicating political opinions [Article 83(2)(g) of the General Data Protection Regulation]. The latter data is considered sensitive personal data pursuant to Article 9(1) of the General Data Protection Regulation, therefore its processing involves a higher risk for the data subjects. Taking into account the strong political polarization existing at the time of publication of the Articles – five months before the national parliamentary elections – the dissemination of the data relating to the private sphere of the data subjects, in particular their residential address and the location data relating to their residential address – and their data indicating their political opinions may have a number of potential negative consequences for the data subjects (targeted harassment, social stigmatization, discrimination, intimidation, conflicts at work or in the family, disadvantages, threat to personal safety, impairment of free political expression), the Authority therefore assessed that the unlawful disclosure of the personal data of the data subjects supporting the party – in addition to the fact that it concerned sensitive personal data pursuant to Article 9(1) – constitutes a highly serious infringement, also because it occurred in a politically heightened, pre-election period. (105) The Authority also took into account the high seriousness of the infringement, that the Client’s infringement was intentional [Article 83(2)(b) of the General Data Protection Regulation]. As the Authority has shown in Section III.2.2 of this decision, the Client was firstly aware of the content of the Notice, and Articles 1 and 3 contained several passages of text that the Client had taken from the Notice. The Magyar Nemzet also published an article on the content of the Notice on 6 November 2025, the day before the publication of Article 2. The Authority
emphasizes that Articles 1 and 3 expressly stated that it is contrary to the
General Data Protection Regulation if personal and sensitive data of data subjects become available to the public through a media content
(even indirectly, for example by providing a link to a website that makes personal data public).
In addition, the Client was also aware of the Index article that first reported on the Map,
in which Index expressly stated that it did not wish to publish the availability of the Map in the article, and asked its readers not to try to search for the Map either. The Index also listed additional arguments based on the Communication as to why the Map can be considered to be contrary to data protection requirements. The Client was therefore clearly aware of the data protection requirement that it could be a violation of the law to provide access – even indirectly – to personal and sensitive data that had been unlawfully made public (through the Map). The Client nevertheless decided to publish the availability of the Map in the Articles. Based on all of this, the Authority considered that the Client’s conduct exceeded the standard of negligence and assessed the Client’s infringement as intentional. 27 (106) Another circumstance taken into account in the context of the high seriousness of the infringements was that by publishing the availability of the Map, the Client made the personal and sensitive data of data subjects in a vulnerable position accessible to readers [nature of data processing – Article 83(2)(a) of the General Data Protection Regulation]. Since the Articles were published in an online press product and did not restrict access to them23, the Client essentially provided all internet users with the opportunity to read the Articles and to learn about the personal and sensitive data disclosed via the Map via the link and contact details published in the Articles. The Authority also took into account that Origo, based on the data from the “gemiusAudience” service, was among the five most read news portals on 7 November 2025 in terms of both “Views” and “Visits”, while Magyar Nemzet was the eleventh most read news portal based on the same criteria during this period. Although these figures are lower in the case of Ripost compared to the other two news portals, the Authority took into account that “Ripost” is a nationally known brand, as it was published as a widely known printed daily newspaper until February 2021 and then as a weekly newspaper until June 2022. [scope of data processing – Article 83(2)(a) of the General Data Protection Regulation] The Authority also assessed that the information activity – within the framework of which the unlawful data processing took place – can be considered the Client’s main activity, so it is even more expected that it be aware of and appropriately apply the data protection requirements [purpose of data processing – Article 83(2)(a) of the General Data Protection Regulation].
IV.2.3. Aggravating circumstances taken into account when imposing the fine
(107) The Authority also considered as an aggravating circumstance that, prior to the adoption of this decision, the Authority had convicted the Client for relevant infringements committed by it in the past and had imposed data protection fines on it on several occasions [Article 83(2)(e) of the General Data Protection Regulation]. The Authority took into account in particular as an aggravating circumstance that the Authority had imposed administrative fines on the Client for unlawful data processing on a total of […]
occasion, the highest of which was […]
and that the infringements sanctioned by the fines concerned the processing of sensitive data in three cases.
(108) The Authority assessed as an aggravating circumstance the exceptionally high number of requests from data subjects to initiate the Authority’s proceedings in relation to Article 1: the Authority received more than three hundred requests for data protection authority proceedings from data subjects because the Client had published the availability of the Map in Article 1, thereby providing access to their personal data and political opinions. [Article 83(2)(h) of the GDPR].
IV.2.4. Mitigating circumstances taken into account when imposing the fine
(109) The Authority took into account the duration of the infringements as a mitigating circumstance [Article 83(2)(a) of the GDPR]. In determining the duration of data processing, the Authority took as a basis the fact that the Client did not implement data processing by publishing the Articles, but by publishing the availability of the Map in the Articles. Therefore, the data processing activities that are the subject of the present authority procedure could have been the application of a paywall, known among media service providers, by which certain content is only available to users against a subscription. The duration of the limitation is adjusted to the length of time the availability of the Map was included in the Articles and not to the fact that the Articles are currently available on the given internet news portal. As the Authority has presented in points I.2-I.4., the Authority established during the evidentiary procedure conducted in this legal issue that the Client removed the availability of the Map from the Articles on the day the Articles were published. Therefore, the Authority took into account as a mitigating circumstance that the Client:
– in the case of Article 1, no later than 1 hour 42 minutes after the publication of Article 1
– removed the link to the Map from the text of Article 1
– in the case of Article 2, no later than 1 hour 13 minutes after the publication of Article 2
– and in the case of Article 3, that on November 7 (after 9:45 p.m., but at an unspecified time) the Client modified the image in Article 3
so that it did not include the URL […].
(110) In parallel, the Authority also assessed as a mitigating circumstance the number of unique visitors who, according to the Client's statement, could have read the Article on 7 November 2025: […] in the case of Article 1, […] in the case of Article 2, and […] visitors in the case of Article 3. The Authority also took into account that since the link was removed from Article 1 no later than 1 hour 42 minutes after the publication of Article 1, and from Article 2 no later than 1 hour 13 minutes after the publication of Article 2, and in the case of Article 3, the image in Article 3 was modified on the same day so that it did not include the […] URL address, some of the unique visitors were still able to read the Articles with the Map's availability.
(111) The Authority also took into account as a mitigating circumstance in the case of the Articles that, according to publicly available IT expert findings24, the Map became globally inaccessible on the morning of 9 November 2025 (and the Map has not been accessible since then). This circumstance reduces the severity of the consequence of the Client's infringement, as readers who became aware of the Map's availability through the Client's unlawful data processing activity could no longer access the Map containing personal and sensitive data after two days.
IV.2.5. Other circumstances pursuant to Article 83(2) of the General Data Protection Regulation
(112) The Authority assessed as a neutral circumstance that the Client cooperated with the Authority in clarifying the facts, as this cooperation did not exceed its obligations under the legislation [Article 83(2)(f) of the General Data Protection Regulation].
(113) The Authority considered the extent of the damage suffered to be neutral, as the Authority did not receive any notification or declaration in which any data subject would have been demonstrably harmed as a result of the infringements [Article 83(2)(a) of the General Data Protection Regulation].
(114) In addition to the above, the Authority did not take into account other aggravating or mitigating factors relevant to the circumstances of the infringements when determining the amount of the fine [Article 83(2)(k) of the General Data Protection Regulation].
24 https://www.cyberthreat.report/p/a-tisza-vilag-doxxing-infrastrukturajanak
29
(115) The Authority did not consider the circumstances referred to in Article 83(2)(c), (d), (i) and (j) of the General Data Protection Regulation to be relevant, as they cannot be interpreted in the context of the specific case.
IV.2.6. Determination of the amount of the administrative fine
(116) The Authority notes that, in view of what is explained in point IV.1.1 of this decision, it took into account Article 83(3) of the General Data Protection Regulation when determining the amount of the fine. According to this provision, the total amount of the fine may not exceed the amount determined in the case of the most serious infringement.
(117) The infringements committed by the Client constitute a breach of the provisions on the lawfulness of data processing and the processing of special categories of personal data, which constitute a more serious infringement falling within the higher fine category pursuant to Article 83(5)(a) of the GDPR. In the event of such infringements, the maximum fine shall be EUR 20 million or 4% of the annual turnover of the undertaking, whichever is higher. The Authority, in accordance with the Fines Guidelines25, has taken into account the profit and loss account of the Client as set out in its latest publicly available consolidated annual accounts for the year 202426. Based on this, 
4% of the Client's net sales revenue in 2024 (HUF 70,279,652,000) is HUF 2,811,186,080,
which corresponds to EUR 7,853,13327, i.e. it does not reach the static maximum fine of EUR 20,000,000 as defined in Article 83(5) of the GDPR. Therefore, in the present case,
taking into account Article 83(3) of the GDPR, the Client may be fined a maximum of EUR 20,000,000.
(118) Taking into account the above, the Authority has decided, in its discretion regarding the determination of the amount of the fine, to impose a fine of HUF 50,000,000 (EUR 139,677) in respect of these infringements, as set out in the operative part. The fine imposed is 0.07% of the annual net turnover, which is lower than the maximum fine of EUR 20,000,000 pursuant to Article 83(5) of the GDPR. Consequently, the amount of the fine imposed does not constitute a disproportionate burden for the Client, and at the same time, the fine imposed is proportionate to the gravity of the infringements and has a dissuasive effect, taking into account the amount of administrative fines imposed on the Client prior to the adoption of this decision. The fine imposed also has an incentive to pay increased attention to its data processing activities in the future, to carry them out in accordance with the provisions of the General Data Protection Regulation and to refrain from similar infringements in the future. (119) In view of Article 83(1) of the General Data Protection Regulation, the Authority also took into account the amount of fines previously imposed on data controllers performing media service activities similar to the Client, in the context of the proportionality of the fine. The Authority finds that in the present case, given the high gravity of the infringement and the aggravating circumstances – and taking into account the mitigating circumstances – the fine of fifty million forints cannot be considered outrageous or excessive compared to the fines imposed in its previous decisions (25 Fine Guidelines, points 129-130). 26 https://e-beszamolo.im.gov.hu/oldal/beszamolo_megjelenites, download date: 15 May 2026. 27 According to the central exchange rate of the Hungarian National Bank valid on 14 May 2026, 1 EUR = 357.97 HUF, source: https://www.mnb.hu/arfolyam-
tablazat?deviza=rbCurrencySelect&devizaSelected=EUR&datefrom=2026.05.14.&datetill=2026.05.14.&order=1, download date:
May 15, 2025
30
The Authority has imposed fines of ten million forints on media service providers […] on several occasions).
IV.3. Publication of the Decision
(120) Pursuant to Section 61(2)(a) of the Infotv., the Authority may order the publication of its decision by publishing the identification data of the data controller if the decision affects a wide range of persons, while pursuant to point c) of the same section, in the event that the gravity of the infringement of rights that has occurred justifies the publication.
(121) As the Authority has established in this decision, the number of individuals affected by unlawful data processing is significant, and by publishing the availability of the Map in the Articles, the Client has provided access to their personal and sensitive data for nearly two hundred thousand data subjects. As the Authority has established in point IV.2.2. of this decision, the infringement committed by the Client can be considered to be of high gravity. In addition, the Authority, taking into account both general and special prevention, wishes to emphatically draw attention to the obligations of media service providers regarding the processing of personal data, and also uses the public sphere to point out the special importance of the increased and expected protection of personal data. (122) In view of all this, the Authority has Based on Section 61 (2) a) and c),
the Authority has ex officio ordered the publication of its final decision on its own website, including the publication of the Client’s identification data.
V. Other issues
(123) The Authority’s competence is determined by Section 38 (2) and (2a) of the Information Act, and its competence
extends to the entire territory of the country.
(124) The Authority has not exceeded the administrative deadline set out in Section 60/A. (1) of the Information Act.
(125) The Authority’s present decision is based on Sections 80-81 of the Information Act and Section 61 (1) of the Information Act.
The decision shall become final upon its publication pursuant to Section 82 (1) of the Information Act. The Information Act Pursuant to Section 112, Section 114 (1) and Section 116 (1), the decision may be appealed through an administrative lawsuit.
(126) The rules of administrative lawsuits are determined by Act I of 2017 on the Code of Administrative Procedure (hereinafter: the Code). Pursuant to Section 12 (1) of the Code, administrative lawsuits against the decision of the Authority fall within the jurisdiction of the courts, and the Metropolitan Court has exclusive jurisdiction over the lawsuit pursuant to Section 13 (3) (a) (aa) of the Code. Pursuant to Section 27 (1) (b) of the Code, legal representation is mandatory in a dispute in which the court has exclusive jurisdiction. The Code According to Section 39(6), the filing of a claim does not have a suspensive effect on the entry into force of the administrative act.
(127) Pursuant to Section 29(1) of the Civil Procedure Code and, in view of this, Section 604 of Act CXXX of 2016 on the Code of Civil Procedure, and pursuant to Section 19(1)(b) of Act CIII of 2023 on the Digital State and Certain Rules for the Provision of Digital Services (Dáptv.), the legal representative of the client is obliged to maintain electronic contact.
(128) The time and place of filing a claim against the decision of the Authority are determined by Section 39(1)
of the Civil Procedure Code. The information on the possibility of requesting a hearing is based on Section 77(1)-(2)
of the Civil Procedure Code.
31 The amount of the administrative litigation fee is determined by Section 45/A. (1) of Act XCIII of 1990 on Fees (hereinafter: Itv.). The party initiating the procedure is exempted from the advance payment of the fee by Section 59. (1) and Section 62. (1) h) of the Itv. (129) If the Client fails to adequately prove the fulfillment of the prescribed obligation, the Authority shall deem it to have failed to fulfill the obligation within the deadline. According to Section 132 of the Ákr., if the 
obligor has not fulfilled the obligation set out in the final decision of the authority, it may be enforced. According to Section 133. (1) of the Ákr., the enforcement shall be ordered by the authority that made the decision, unless otherwise provided by law or government decree. According to Section 134 of the Ákr. Pursuant to Section 134 (1), the execution shall be carried out by the state tax authority – unless otherwise provided by law, government decree or, in the case of a local government authority, by a local government decree. Pursuant to Section 61 (7) of the Information Act, the execution of the Authority’s decision shall be carried out by the Authority in relation to the obligation to perform a specific act, to behave in a specific manner, to tolerate or to cease to act contained in the decision. Dated: Budapest, according to the electronic signature and time stamp Dr. habil. Attila Péterfalvi Chairman c. university professor
  1. See also case No. Kfv. 37.978/2021/10 from the Hungarian Supreme Court
  2. The DPA took into consideration national case law on privacy related lawsuits against media service providers, which make a distinction between value judgments and factual statements. In this case, however, the DPA stated that this case does not concern a value judgment or factual statement, but rather a “new” type of processing activity (providing access to personal data through the link to the map). Therefore, constitutional standards and judicial precedents apply to a limited extent to this case. The DPA also took into consideration its past cases where media service providers published data subjects’ data, where the DPA assessed whether the provider in question could demonstrate a legitimate interest to publish this data. However, the DPA stated that this case was different, as it concerned almost 200,000 data subjects. Therefore, the controller’s arguments regarding legitimate interest must be appropriate for all affected data subjects.