Law / Hungary

Hungary

privacy

Hungary's data-protection act, the Infotorveny (Act CXII of 2011), predates the General Data Protection Regulation (GDPR) by roughly five years and originally combined data protection with freedom-of-information law in one statute; it was amended rather than replaced when the GDPR became directly applicable.

A crawler-based read of the Act's own Hungarian text confirms its biometric definition restates GDPR Article 4(14) without narrowing it, that Act XXXVIII of 2018 inserted the 72-hour breach-notification duty at Sections 25/J-25/K, and that Section 24 arms a data subject with a distinct serelemdij (personality-rights compensation) remedy, joint and several among controllers and processors, layered on GDPR Article 82.

A commentary-sourced first pass reported an employment-biometric derogation that this session could not locate or verify in the Act's own text; it remains unverified and is not asserted as fact.

16 instruments named 6 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

Infotorveny Sections 25/J-25/K, Breach Notification, Inserted by Act XXXVIII of 2018

cite 2011. evi CXII. torveny, 25/J-25/K. section, as inserted by 2018. evi XXXVIII. torveny 17. section stage In effect since 2019-04-26 source njt.jog.gov.hu, Infotorveny sections 25/J-25/K (direct fetch, verbatim, with footnote confirming Act XXXVIII of 2018 sec. 17 as the inserting act)

Section 25/J(1), read verbatim from the Act's own footnoted text, confirms the General Data Protection Regulation (GDPR)-uniform 72-hour standard: a controller records specified data about a personal-data breach and reports it to NAIH without delay, but no later than 72 hours after becoming aware of it.

The Act's own footnotes show this subtitle was inserted by Act XXXVIII of 2018, Section 17, confirming on primary text the amending act commentary had previously dated only approximately (sectoral alignment completed by 26 April 2019). This restates rather than derogates from GDPR Articles 33-34; a separate commentary claim that controllers report through a dedicated Personal Data Breach Reporting System in the Hungarian language was not confirmed or contradicted by the text read.

What it asks of an app

Comprehensive regime

Infotorveny (Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information)

cite 2011. evi CXII. torveny az informacios onrendelkezesi jogrol es az informacioszabadsagrol stage In effect since 2012-01-01 source njt.jog.gov.hu, Infotorveny (direct fetch, Hungarian text, 283,570 chars, footnote 1 and sec. 73(1)-(2), verbatim)

Hungary's data-protection act predates the General Data Protection Regulation (GDPR) by roughly seven years and, unusually, originally combined data protection and freedom-of-information law in one statute; the freedom-of-information half was never split into a separate act and remains bundled alongside the data-protection half.

A direct crawler-based read of the Act's own Hungarian text supplies primary-sourced dates: footnote 1 states the Act was adopted by the National Assembly on 11 July 2011 and promulgated on 26 July 2011, and Section 73(1) reads that the Act enters into force the day after promulgation with exceptions in paragraphs (2) and (3); paragraph (2) puts most substantive sections, including the sections numbered 1 through 37, in force 1 January 2012, which is the date recorded here.

Rather than repeal the Infotorveny when the GDPR became directly applicable, Hungary amended it (sectoral alignment completed by 26 April 2019, per commentary) so it now operates as a supplementary, mainly procedural statute alongside the Regulation.

What it asks of an app

Cross border transfer

GDPR Chapter V, Cross-Border Transfer Restrictions

cite Regulation (EU) 2016/679, Arts. 44-49, 83(5)(c) stage In effect since 2018-05-25 source GDPR Arts. 44-49, 83(5)(c)

A transfer of personal data outside the EEA requires an adequacy decision, appropriate safeguards, or a narrow Article 49 derogation, backed by the Article 83(5)(c) top fine tier. CMS commentary states explicitly there are no derogations from the General Data Protection Regulation (GDPR) for cross-border transfer in Hungary.

What it asks of an app

Data subject rights

GDPR Articles 12-22, Data-Subject Rights

cite Regulation (EU) 2016/679, Arts. 12-22 stage In effect since 2018-05-25 source GDPR Arts. 12-22

General Data Protection Regulation (GDPR) Articles 12-22 apply directly. No Hungary-specific derogation was found in commentary; this session's own primary-text read confirmed the Infotorveny's definitions and its Section 24 remedy but did not separately check for a data-subject-rights derogation beyond what commentary reported.

What it asks of an app

Enforcement supervision

NAIH Enforcement, GDPR Article 82, and Infotorveny Section 24 Serelemdij

cite Regulation (EU) 2016/679, Art. 82; 2011. evi CXII. torveny, 24. section stage In effect since 2018-05-25 source njt.jog.gov.hu, Infotorveny sec. 24 (direct fetch, verbatim)

Nemzeti Adatvedelmi es Informacioszabadsag Hatosag (NAIH), the National Authority for Data Protection and Freedom of Information, is Hungary's supervisory authority, with General Data Protection Regulation (GDPR) Article 83 fines.

Section 24(2) of the Infotorveny, read verbatim, confirms a genuine Hungarian civil-law addition layered on GDPR Article 82: a person whose personality right has been infringed may claim serelemdij (compensation for infringement of a personality right) from the controller or processor, and Section 24(5) makes joint controllers and their processors jointly and severally liable for both ordinary damages and serelemdij. Section 24(3)-(4) give a force-majeure-style exemption for an unavoidable cause outside the scope of the processing.

What it asks of an app

Sensitive categories

Infotorveny Definitions, Biometric and Special-Category Data

cite 2011. evi CXII. torveny, point 3 and point 3b ("kulonleges adat" and "biometrikus adat") stage In effect since 2018-05-25 source njt.jog.gov.hu, Infotorveny definitions section (direct fetch, verbatim)

The Infotorveny's own definitions list biometric data alongside racial or ethnic origin, political opinion, religious belief, trade-union membership, genetic data, health data, and sex-life or orientation data as a special category, matching General Data Protection Regulation (GDPR) Article 9(1) exactly.

Its biometric definition, read verbatim from the Act's own text, is a near-verbatim restatement of GDPR Article 4(14): "biometrikus adat: egy termeszetes szemely fizikai, fiziologiai vagy viselkedesi jellemzoire vonatkozo olyan, sajatos technikai eljarasokkal nyert szemelyes adat, amely lehetove teszi vagy megerositi a termeszetes szemely egyedi azonositasat, mint peldaul az arckep vagy a daktiloszkopiai adat" (English: biometric data means personal data obtained through specific technical procedures relating to the physical, physiological, or behavioural characteristics of a natural person, which enables or confirms the unique identification of that natural person, such as the facial image or dactyloscopic fingerprint data), naming the same two examples GDPR names and no others, including no audio analogue.

A reported employment-biometric derogation, permitting biometric access control to prevent unauthorized access to classified or hazardous information, comes from one commentary source only (CMS) and could not be verified against this primary text in this pass; it is not asserted here.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.