Law note · Hungary
Infotorveny Sections 25/J-25/K, Breach Notification, Inserted by Act XXXVIII of 2018
Section 25/J(1), read verbatim from the Act's own footnoted text, confirms the General Data Protection Regulation (GDPR)-uniform 72-hour standard: a controller records specified data about a personal-data breach and reports it to NAIH without delay, but no later than 72 hours after becoming aware of it.
The Act's own footnotes show this subtitle was inserted by Act XXXVIII of 2018, Section 17, confirming on primary text the amending act commentary had previously dated only approximately (sectoral alignment completed by 26 April 2019). This restates rather than derogates from GDPR Articles 33-34; a separate commentary claim that controllers report through a dedicated Personal Data Breach Reporting System in the Hungarian language was not confirmed or contradicted by the text read.
What it asks of an app
- Notify NAIH without delay, and no later than 72 hours after becoming aware of it, of a personal-data breach affecting a person in Hungary, per Infotorveny Section 25/J(1).
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot, processes_biometrics