Law note · Hungary

Infotorveny Sections 25/J-25/K, Breach Notification, Inserted by Act XXXVIII of 2018

cite 2011. evi CXII. torveny, 25/J-25/K. section, as inserted by 2018. evi XXXVIII. torveny 17. section stage In effect since 2019-04-26 reviewed 2026-08-24

Section 25/J(1), read verbatim from the Act's own footnoted text, confirms the General Data Protection Regulation (GDPR)-uniform 72-hour standard: a controller records specified data about a personal-data breach and reports it to NAIH without delay, but no later than 72 hours after becoming aware of it.

The Act's own footnotes show this subtitle was inserted by Act XXXVIII of 2018, Section 17, confirming on primary text the amending act commentary had previously dated only approximately (sectoral alignment completed by 26 April 2019). This restates rather than derogates from GDPR Articles 33-34; a separate commentary claim that controllers report through a dedicated Personal Data Breach Reporting System in the Hungarian language was not confirmed or contradicted by the text read.

What it asks of an app

  • Notify NAIH without delay, and no later than 72 hours after becoming aware of it, of a personal-data breach affecting a person in Hungary, per Infotorveny Section 25/J(1).

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, processes_biometrics

Primary source: njt.jog.gov.hu, Infotorveny sections 25/J-25/K (direct fetch, verbatim, with footnote confirming Act XXXVIII of 2018 sec. 17 as the inserting act)

← Back to the example  ·  Lint your app →