Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
cite 2011. evi CXII. torveny, 25/J-25/K. section, as inserted by 2018. evi XXXVIII. torveny 17. section
stage In effect
since 2019-04-26
source njt.jog.gov.hu, Infotorveny sections 25/J-25/K (direct fetch, verbatim, with footnote confirming Act XXXVIII of 2018 sec. 17 as the inserting act)
Section 25/J(1), read verbatim from the Act's own footnoted text, confirms the General Data Protection Regulation (GDPR)-uniform 72-hour standard: a controller records specified data about a personal-data breach and reports it to NAIH without delay, but no later than 72 hours after becoming aware of it.
The Act's own footnotes show this subtitle was inserted by Act XXXVIII of 2018, Section 17, confirming on primary text the amending act commentary had previously dated only approximately (sectoral alignment completed by 26 April 2019). This restates rather than derogates from GDPR Articles 33-34; a separate commentary claim that controllers report through a dedicated Personal Data Breach Reporting System in the Hungarian language was not confirmed or contradicted by the text read.
What it asks of an app →
Comprehensive regime
cite 2011. evi CXII. torveny az informacios onrendelkezesi jogrol es az informacioszabadsagrol
stage In effect
since 2012-01-01
source njt.jog.gov.hu, Infotorveny (direct fetch, Hungarian text, 283,570 chars, footnote 1 and sec. 73(1)-(2), verbatim)
Hungary's data-protection act predates the General Data Protection Regulation (GDPR) by roughly seven years and, unusually, originally combined data protection and freedom-of-information law in one statute; the freedom-of-information half was never split into a separate act and remains bundled alongside the data-protection half.
A direct crawler-based read of the Act's own Hungarian text supplies primary-sourced dates: footnote 1 states the Act was adopted by the National Assembly on 11 July 2011 and promulgated on 26 July 2011, and Section 73(1) reads that the Act enters into force the day after promulgation with exceptions in paragraphs (2) and (3); paragraph (2) puts most substantive sections, including the sections numbered 1 through 37, in force 1 January 2012, which is the date recorded here.
Rather than repeal the Infotorveny when the GDPR became directly applicable, Hungary amended it (sectoral alignment completed by 26 April 2019, per commentary) so it now operates as a supplementary, mainly procedural statute alongside the Regulation.
What it asks of an app →
Cross border transfer
cite Regulation (EU) 2016/679, Arts. 44-49, 83(5)(c)
stage In effect
since 2018-05-25
source GDPR Arts. 44-49, 83(5)(c)
A transfer of personal data outside the EEA requires an adequacy decision, appropriate safeguards, or a narrow Article 49 derogation, backed by the Article 83(5)(c) top fine tier. CMS commentary states explicitly there are no derogations from the General Data Protection Regulation (GDPR) for cross-border transfer in Hungary.
What it asks of an app →
Data subject rights
cite Regulation (EU) 2016/679, Arts. 12-22
stage In effect
since 2018-05-25
source GDPR Arts. 12-22
General Data Protection Regulation (GDPR) Articles 12-22 apply directly. No Hungary-specific derogation was found in commentary; this session's own primary-text read confirmed the Infotorveny's definitions and its Section 24 remedy but did not separately check for a data-subject-rights derogation beyond what commentary reported.
What it asks of an app →
Enforcement supervision
cite Regulation (EU) 2016/679, Art. 82; 2011. evi CXII. torveny, 24. section
stage In effect
since 2018-05-25
source njt.jog.gov.hu, Infotorveny sec. 24 (direct fetch, verbatim)
Nemzeti Adatvedelmi es Informacioszabadsag Hatosag (NAIH), the National Authority for Data Protection and Freedom of Information, is Hungary's supervisory authority, with General Data Protection Regulation (GDPR) Article 83 fines.
Section 24(2) of the Infotorveny, read verbatim, confirms a genuine Hungarian civil-law addition layered on GDPR Article 82: a person whose personality right has been infringed may claim serelemdij (compensation for infringement of a personality right) from the controller or processor, and Section 24(5) makes joint controllers and their processors jointly and severally liable for both ordinary damages and serelemdij. Section 24(3)-(4) give a force-majeure-style exemption for an unavoidable cause outside the scope of the processing.
What it asks of an app →
Sensitive categories
cite 2011. evi CXII. torveny, point 3 and point 3b ("kulonleges adat" and "biometrikus adat")
stage In effect
since 2018-05-25
source njt.jog.gov.hu, Infotorveny definitions section (direct fetch, verbatim)
The Infotorveny's own definitions list biometric data alongside racial or ethnic origin, political opinion, religious belief, trade-union membership, genetic data, health data, and sex-life or orientation data as a special category, matching General Data Protection Regulation (GDPR) Article 9(1) exactly.
Its biometric definition, read verbatim from the Act's own text, is a near-verbatim restatement of GDPR Article 4(14): "biometrikus adat: egy termeszetes szemely fizikai, fiziologiai vagy viselkedesi jellemzoire vonatkozo olyan, sajatos technikai eljarasokkal nyert szemelyes adat, amely lehetove teszi vagy megerositi a termeszetes szemely egyedi azonositasat, mint peldaul az arckep vagy a daktiloszkopiai adat" (English: biometric data means personal data obtained through specific technical procedures relating to the physical, physiological, or behavioural characteristics of a natural person, which enables or confirms the unique identification of that natural person, such as the facial image or dactyloscopic fingerprint data), naming the same two examples GDPR names and no others, including no audio analogue.
A reported employment-biometric derogation, permitting biometric access control to prevent unauthorized access to classified or hazardous information, comes from one commentary source only (CMS) and could not be verified against this primary text in this pass; it is not asserted here.
What it asks of an app →