Skip to content
Enforcement · NAIH (Hungary) ·NAIH-11443-3/2026 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

The DPA initiated an investigation into the GDPR compliance of an online store (the controller) processing the data of its customers (the data subjects) in April 2025

The processing activities in question included, inter alia, cookies, registration, billing, shipping, consumer complaint, and processing of orders.

€2,000,000 Fine
Hungary
Art. 12 GDPR Art. 13 GDPR
Summary

The privacy notice of the company operating the online store had been in force unchanged from May 2018 to May 2025, and the period under investigation extended from 1 January 2020 to 27 June 2025. Holding — The DPA held that the controller had violated Articles 12(1), 13(1)(c), (d) and (f), and 13(2)(a) GDPR and issued the controller a fine of HUF 2,000,000 (€5,500). In addition, the DPA ordered the controller to bring its data processing operations into compliance with the GDPR and to amend the content of its privacy notice. First, the DPA found an infringement of Article 12(1) GDPR: the structure of the privacy notice was confusing and difficult to follow. The privacy notice also contained incomplete, incorrect, and unnecessary information as well as repetitive details. Based on this, the DPA concluded that the controller had failed to provide data subjects with information regarding the processing of personal data that was sufficiently concise, transparent, intelligible and easily accessible. Second, the DPA held that the controller had also violated Articles 13(1)(c), (d) and (f) GDPR by failing to specify a legal basis for certain processing operations such as the use of cookies, not specifying its legitimate interests when relying on Article 6(1)(f) GDPR as a legal basis, and not providing detailed information regarding the safeguards ensuring the lawfulness of data transfers to the United States. Finally, the DPA found a violation of Article 13(2)(a) GDPR as the controller had also failed to provide the data subjects information on the period for which the personal data processed would be stored.

How it connects

64 of 74 paragraphs apply legislation or carry a topic — see them in the full text ↓

Full text 74 findings

Paragraphs carrying a topic or an applied provision show those connections inline Original at the source →
§

hu/adatkezelesi-tajekoztatok Falk Miksa utca 9-11. hu Case number: NAIH-11443-3/2026. NAIH-11591/2025. Administrator: […] Subject: decision in ex officio data protection procedure D E R O C T I O N The National Data Protection and Freedom of Information Authority (hereinafter: Authority) makes the following decision in ex officio data protection procedure to examine compliance with Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: General Data Protection Regulation or GDPR) against […]. (registered office:[…], acting attorney:[…]), represented by […] (registered office:[…]; hereinafter: Company), due to the data processing of the […] website (hereinafter: Website, Website or Homepage), regarding the […] website (hereinafter: Website, Website or Homepage), in connection with the data protection procedure initiated by the National Data Protection and Freedom of Information Authority (hereinafter: Authority) for the purpose of examining compliance with Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: General Data Protection Regulation or GDPR): 1.

§

The Authority finds that the Company negligently infringed - Article 12 of the General Data Protection Regulation. Article (1); - Article 13(1)(c), (d) and (f) of the General Data Protection Regulation; - Article 13(2)(a) of the General Data Protection Regulation. 2. The Authority, pursuant to Article 58(2)(d) of the General Data Protection Regulation, shall ex officio order the Company to bring its data processing operations into line with the provisions of the GDPR and to amend the content of its data processing information in accordance with the requirements set out in points (92)-(104) of this decision. 3. The Authority shall impose a data protection fine of HUF 2,000,000 on the Company for the infringements set out in point 1. * * The Company must confirm in writing to the Authority the measures prescribed in point 2 within 30 days of the date of this decision becoming final, together with the submission of supporting evidence.

§

The data protection fine must be paid within 30 days of the date of this decision becoming final to the Authority’s centralized revenue collection account (10032000- 01040425-00000000 Centralized collection account IBAN: HU83 1003 2000 0104 0425 0000 0000). When transferring the amount, reference must be made to the NAIH-11443/2026. BÍRS. number. If the Company fails to comply with the data protection fine payment obligation within the deadline, it shall pay a late payment surcharge to the above account number. The rate of the late payment surcharge is the statutory interest rate, which is the same as the central bank base interest rate valid on the first day of the calendar half-year affected by the delay. In the event of non-fulfilment of the obligations under point 2 and non-payment of the data protection fine and the late payment surcharge, the Authority shall order the enforcement of the decision.

§

There is no administrative remedy against this decision, but it may be challenged in an administrative lawsuit by filing a claim with the Metropolitan Court within 30 days of its notification. The claim must be submitted to the Authority electronically1, which shall forward it to the court together with the case documents. The request for a hearing must be indicated in the claim. For those not entitled to full personal exemption from fees, the administrative lawsuit fee is HUF 30,000, and the lawsuit is subject to the right to record the subject matter of the fee. Legal representation is mandatory in the proceedings before the Metropolitan Court. J U N T I O N I A T I O N I. 1. 2025, the Authority decided to launch an inspection, within the framework of which it inspected the data processing of the webshop operating on the […] domain with an official inspection, in accordance with the prior notification, regarding compliance with the General Data Protection Regulation, under number NAIH-9770/2025.

§

2025, the Authority conducted an inspection without prior notification, which consisted of viewing the Website and making backups. 2025. (3) After reviewing the Website, the Authority detected a suspicion of a violation regarding the validity of transparency, the adequacy of the information, and the information to be made available to the data subject. 2. 2025, NAIH-11591/2025. The Authority initiated a data protection authority procedure to examine the data management practices of the web store operating on the Website, including the prior information, in which it also used the data and documents of the previous official inspection and inspection. The procedure did not extend to the examination of other data protection requirements, nor to a complete overview of the Company's data management processes. (5) In the present procedure, the Authority examined compliance with the GDPR. 25. 25.

§

31. ) The form can be filled out using the general form filling program (ÁNYK program). e. the period after the initiation of the proceedings is not included. 01. 27. 1. 27, NAIH-11591-1/2025. In its order with file number , the Company was notified of the initiation of the data protection authority procedure and called upon to make a statement in order to clarify the facts, among other things, on the data processing related to consumer complaint handling and contact, the retention period of data processing related to the verification of consents, data processing for remarketing purposes, ensuring transparency, the structure of the information, and the possible use of automated decision-making. 2025 that the Company uses the “[…]” system operated by […]. The […] system helps webshop operators to create data management information and general terms and conditions using predefined legal texts.

§

This legaltech solution also takes into account the individual data management solutions of the webshop operators – in this context, the users of the […] system – and only provides users with texts that do not determine the conditions and content of data management. The system helps the user in creating the legal bases for data management, the conditions specified in the law, the rights of the data subject and the structure. In addition, the document itself is also displayed from the […] system, so the data management information seen on the Company’s website is displayed from the […] storage space, using the technical solution provided by it, and is embedded on the website with only one code. (10) The Company stated in relation to the operation of the […] system that the user fills in a predefined content with text and data. This means that the system includes data management functions related to typical webshops (for example, cookies, registration, billing, delivery, warranty and consumer complaints, prize games, remarketing, contact, order processing, newsletter sending, personalized advertising), which data management functions can be activated separately, and when activated, a sample text serving as an informational text appears, which the user can freely modify to specific his/her own data management.

§

If the sample text is not modified, the system indicates this fact to the user when the document is published, thus encouraging and warning the user that the sample text is not necessarily true for the data management performed by him/her. As an illustration of the operation of the system, the Company has attached the screenshots of this. (11) In relation to the information on the activities related to handling consumer complaints and making contact, the Company stated that the information in fact did not contain any relevant information, which the Company has filled in. (12) In relation to the verifiability of consent, the Company stated that the data storage period detected during the official inspection was intended to refer to the general civil law limitation period, and therefore no special criteria were set for this point. In the information, the Company specified the data storage period with a clear reference.

§

(13) The Company indicated that the reason for including the information section on remarketing separately was to have a point in the data management information where this special data processing is separately explained to the data subjects. The […] system used by the Company added 4 additional pieces of information to the wording to clearly state whether the Company implements data management for remarketing purposes or not, as this information would be lost in the cookie information section. According to the Company, this point is worded more generally because the data management itself is implemented by separate cookies, therefore it is not possible to generally define a data management period and the scope of data managed. The Company stated that the purpose of referring to the […] and […] information is to enable data subjects to view the content of the data management at the service provider itself.

§

However, for the sake of easier understanding, the Company has modified and simplified the wording of the remarketing section. (14) Regarding the lack of numbering in the information, the Company stated that the […] system uses an HTML-based display, in which case there is no possibility of numbering in a clear way. The Company indicated that the HTML coding recognizes the numbering, but if it is followed by a content element, it restarts, therefore every part highlighted with numbering would receive the number 1, which is why the Company cannot use it. In order to delimit the content, the Company provided the individual chapter titles with a header and lower-level (h1-h4) code according to the generally accepted practice in HTML coding. The Company added that it uses a so-called widget display, which aims to help the reader to delimit the content elements by highlighting the chapter titles in the sidebar.

§

(15) The Company stated that it does not make automatic decisions, the wording was displayed as a template text provided by the […] system it used. The wording was deleted. (16) The Company's website was visited by 3,763,794 visitors – based on 2024 data. The Company stated that this number is distorted by robots viewing the website. According to the Company, the number of orders shows that the number of actual customers is lower in comparison, with a total of 119,380 orders recorded in its system. 25. 27. 2025) but not yet published. 2025. 2025 to its declaration no. NAIH-11591-4/2025 in PDF format. 24 (hereinafter: Information). 27 differ from a data protection perspective, the Company made the following statement. : it separately considers data processing carried out for the purpose of fulfilling the order 5, processing of the order, issuing an invoice, data processing related to the delivery of goods), - the designation of data processors has been clarified, - the rights of the data subject have been clarified.

§

24: - there is no substantive modification between the two notices, the reason for the new notice is that the notice was re-published in the […] system due to the modification of another document (presumably the GTC) and therefore generated (this is a technical feature and necessity of the […] system, that when the user modifies the document, it requests the publication of the document and in this case it manages the GTC and the data management notice at the same time, a new document is generated even if no modification has been made in the given document). (20) According to the Company's position, in the case of data management related to remarketing, automated decision-making and the verifiability of consent, the wording and its situation are a given from the […] system, and the Company had no influence on that. The Company highlighted that the missing text sections (regarding the handling of consumer complaints and contacting) are relevant to a significantly smaller number of data subjects compared to the actual number of users and customers, as not all customers fill out the contact form and the number of complaints is only a fraction of the number of customers (the number of complaints is typically low for low-value products).

§

Therefore, the number of data subjects is also significantly lower compared to the number of users and customers. According to the Company, the legal notice on automated decision-making did not infringe the rights and interests of the data subjects, the length of the text section itself did not disturb the reader, and did not impair the transparency of the notice. At the same time, it accepts that if there is no such type of data processing, the legal notice related to this is not of substantive relevance. (21) The Company has submitted to the NAIH-11591-4/2025. emphasized in its statement that the Authority may only examine the Company's data processing practices in accordance with the provisions of administrative procedural law. ” According to the Company, since the Authority acts in an administrative procedure pursuant to the Administrative Procedure Act, and the Information Act does not contain a limitation period different from the aforementioned rule, the Authority may not apply legal consequences even in the event of a potential infringement occurring more than three years earlier, the Company therefore raised the question of whether the Authority has the authority to examine this information.

§

2. 23 to May 2025, the Company stated that it had not identified any process change that would have required amendment. Despite the Authority's request, the Company was unable to prove the availability of the Policy on the Website, as the Company believes that the IT system it uses does not use such a level of logging that would record information related to the publication of the Data Management Policy. (23) In connection with the Data Processing Regulation, the Authority asked the Company to explain why several legal bases are listed at the same time for certain data processing, to which the Company responded that the reference to the relevant article of the GDPR in the wording is not appropriate, however, for the reader it is not the reference to the article that carries the information, the information, but the text, which clearly and correctly indicates the 6 legal bases of data processing.

§

Overall, therefore, according to the Company's position, although the legal technical solutions in the case of the data processing legal bases were not correct, the information contained the essential information necessary for providing the appropriate information. The textual indication of the legal basis in these cases was properly included in the information, the error in the precise indication of the legal position is purely a technical error, which cannot be attributed to the Company, and this error did not affect the decision-making ability of the data subject, the range of information available to him, or his ability to interpret it. (24) Regarding the duration of data processing for customer relations (in the case of claims, data processing lasts for 5 years after the contract), the Company stated that the customer relationship does not end with the performance, and that the designated data must be processed until the end of the limitation period in order to identify a given person, a given problem or a contract.

§

According to the Company, the content and rules of the limitation period have been presented in sufficient depth in a later subsection of the information notice, but related to this point, so that the customer, if he reads the information notice in full, can accurately identify why data processing for customer relations purposes is carried out for 5 years under this point. (25) When defining the chapter entitled “Online marketing services”, the Company considered that the name Online marketing services in itself provides a sufficiently accurate picture of the data processing. In its content, it intended to refer to the marketing activities carried out on social media under that point. , Article 6 (1) point a/, Section 13/A (3) of Act CVIII of 2001 on certain issues of electronic commerce services and services related to the information society), the Company stated that it cannot provide precise information due to the time horizon, but presumably due to an administrative error, it includes the reference to previous legal practice, such as the Infotv.

§

and the Electronic Commerce Act. (26) According to the Company, due to an administrative error, the fact that the Company did not process personal data using cookies may be included in point 6 of the Data Processing Regulations. The Company also refers to an administrative error in the official question as to why it did not provide information on the legal basis and duration of data processing in the case of “[…] conversion tracking” and “[…]” cookies. (27) In the case of “[…] tracking”, the Company referred to both the legitimate interest legal basis and the consent legal basis, in relation to which the Company submitted that the reference to legitimate interest was only indicated secondarily, the main legal basis for data processing being the consent of the data subject, to which the Company also intended to refer during the formulation (with the “also” in the case of the text referring to legitimate interest).

§

The last sentence of the information on the […] service contains information on the duration of data processing, which envisages data processing until the purpose is fulfilled. According to the Company, the general formulation of data transfer to a third country was unfortunately formulated in this form in the Regulations due to the limited information available on the […] service. According to the Company, data processing has taken place in the case of “[…] use of tracking”. (28) Regarding the exceptional cases in which the Company transferred personal data to the servers of […] in the USA in the case of the cookie called “[…] application” and on what legal basis it did so, the Company stated that due to the general wording of […], the Company could only formulate its statement in an uncertain manner. According to the Company, there could also be a fundamentally technical reason for the cross-border data transfer in the case of […].

§

The legal basis for data processing was the consent given in the cookie cms system. (29) In the case of “Telephone recording”, the Company referred to legal grounds necessary for the fulfilment of both a legitimate interest and a legal obligation, in relation to which the Company stated that 7 the information referred to both the statutory requirement and the legitimate interest, since the rules of telephone recording in the Consumer Protection Act require the recording of voice calls at the telephone customer service in the case of certain service providers. However, the Company is not subject to this obligation, so in its case the legitimate interest legal basis provides the appropriate legal basis for data processing. In addition, although the Regulations include sections on automated decision-making and profiling, the Company has not carried out such data processing. According to the Company, the Regulations also included the relevant rights due to the need for full information on rights.

§

(30) The Company stated that the Company will only have visitor numbers explicitly available from 1 January 2022, which are as follows: 2022: 5,300,000 sessions; 2023: 5,300,000 sessions; 2024: 3,800,000 sessions. However, according to the Company, a session is not only a real user, but also multiple views made by robots and measured against a given user. (31) The number of actual orders of the Company: 2019: 149,054 pcs 2020: 135,577 pcs 2021: 141,997 pcs 2022: 152,694 pcs 2023: 159,956 pcs 2024: 135,234 pcs. The Company added that there may be identities between the customers and that these numbers also include the number of orders by legal entities. (32) In relation to the Regulations and the case, the Company submitted that the information has already been replaced by a more modern system that also facilitates the management of updates. The Company asked the Authority to take into account that its Website mainly offers low-value products with low basket values.

§

According to the Company, the data processing carried out by it is not unprecedented and blatant, the scope of data collected during the operation of the web stores is not excessive, they were used for a purpose-bound and lawful purpose. According to the Company, inaccuracies and shortcomings can indeed be found in the applied data processing regulations, however, these have no impact on the fact that the data processing itself was carried out within a viable, acceptable and lawful framework. 2025. , the Authority informed the Company that the evidentiary procedure had been completed and that it could examine the evidence uncovered during the clarification of the facts, taking into account the rules for access to documents, and could make further evidentiary motions. 2025. made a statement in the submission NAIH-11591-6/2025. No. on the day. The Company did not exercise its right of access to documents.

§

3. 1. Person of the data controller (34) The Company launched its webshop, […], in 2010 for the sale of various products. The Company, according to its Website2, currently serves its customers from a huge warehouse, “[…]”. Also according to the Website […]. (35) The Company identifies itself as the data processing service provider in the data processing information, and it can be concluded from its responses to the Authority that the purpose and means of data processing in connection with the processing of personal data are determined by the Company, and the Company is the operator and operator of the Website, and therefore qualifies as a data controller in connection with the data processing under examination pursuant to Article 4(7) of the GDPR. 2 […] 8 (36) The Authority emphasizes in relation to the […] system that the system only offered general data processing options related to webshops.

§

In addition, the Company could decide which of the listed text panels relating to data processing to activate, and could also modify the legal texts offered by the system (see point 13 of this decision). The Company could therefore decide for itself how to formulate its data management information, since the system did not define the conditions and content of its data management (see point 12 of this decision). The Authority emphasises that the data protection problems detected in the information were not incorrectly stated in the information because of the […] system used by the Company, since on the one hand the system offered data management options and the recommended wording could be modified. Therefore, the company providing the […] service does not have any responsibility as a data controller. (37) The Company’s net sales revenue in the 2024 business year was […] HUF. The average statistical number of employees was […] in 2024.

§

(38) Act XXXIV of 2004 on Small and Medium-sized Enterprises Within the meaning of Section 3(1)(a) of the Act, a small enterprise is an enterprise whose annual net turnover or balance sheet total does not exceed EUR 10 million and whose number of employees is less than 50. The Company had […] employees in 2024 and its annual net turnover was less than HUF 1 billion. (39) Based on all of this, the Company – in accordance with the applicable legal requirements – qualifies as a small enterprise. 2. Data processing information published on the Website (40) The Authority assessed the data processing information published on the Website in relation to the period under review. 2025 (annex to the note no. 2025, which does not result in any substantive changes, with minor, non-data protection-related corrections. 2025. II. Applicable legal provisions (42) Pursuant to Article 2(1) of the General Data Protection Regulation, the General Data Protection Regulation shall apply to the processing of personal data wholly or partly by automated means, and to the processing of personal data not by automated means which form part of a filing system or which are intended to form part of a filing system.

§

, the General Data Protection Regulation shall apply with the additions specified in the provisions specified therein. , the Authority shall be responsible for monitoring and promoting the protection of personal data, as well as the right to access data of public interest and made public in the public interest, and for promoting the free flow of personal data within the European Union. 9 (45) The Infotv. Pursuant to Section 38(2a) of the General Data Protection Regulation, the tasks and powers assigned to the supervisory authority in the General Data Protection Regulation shall be exercised by the Authority in respect of legal entities under the jurisdiction of Hungary, as specified in the General Data Protection Regulation and this Act. , within the scope of its tasks under Section 38(2) and (2a), it shall conduct data protection authority proceedings, in particular at the request of the data subject and ex officio, as specified in this Act.

§

(47) Pursuant to Section 60/A. , the administrative deadline in data protection authority proceedings shall be one hundred and fifty days. (48) According to Section 60(1), in order to ensure the right to the protection of personal data, the Authority shall initiate a data protection authority procedure at the request of the data subject and may initiate a data protection authority procedure ex officio. ), the Authority shall, within the scope of its competence, monitor compliance with the provisions of the law and the implementation of the provisions of the enforceable decision. (51) According to Ákr. In ex officio proceedings, pursuant to Section 103(1), the provisions of this Act relating to procedures initiated on request shall be applied, with the derogations set out in this Chapter. ” (55) According to Article 12(1)-(6) of the General Data Protection Regulation: "(1) The controller shall take appropriate measures to provide the data subject with all information relating to the processing of personal data referred to in Articles 13 and 14 and with all information referred to in Articles 15 to 22 and 34 in a concise, transparent, intelligible and easily accessible form, in clear and plain language, in particular for any information addressed to children.

§

The information shall be provided in writing or by any other means, including, where appropriate, by electronic means. At the request of the data subject, information may also be provided orally, provided that the identity of the data subject is otherwise verified. (2) The controller shall facilitate the exercise of the data subject's rights under Articles 15 to 22. In the cases referred to in Article 11(2), the controller shall not refuse to comply with a request by the data subject to exercise his or her rights under Articles 15 to 22 unless he or she demonstrates that the data subject cannot be identified. (3) The controller shall inform the data subject without undue delay and in any event not later than one month from the date of receipt of the request of the action taken on the request pursuant to Articles 15 to 22. Where necessary, taking into account the complexity of the request and the number of requests, this period may be extended by a further two months.

§

The controller shall inform the data subject of the extension of the period, stating the reasons for the delay, within one month from the date of receipt of the request. Where the data subject has submitted the request electronically, the information shall be provided electronically, unless the data subject otherwise requests it. (4) Where the controller does not take action on the data subject's request, it shall, without delay and at the latest within one month of receipt of the request, inform the data subject of the reasons for not taking action and of the right to lodge a complaint with a supervisory authority and to seek a judicial remedy. (5) The information referred to in Articles 13 and 14 and the information and action referred to in Articles 15 to 22 and 34 shall be provided free of charge. Where the request of the data subject is manifestly unfounded or excessive, in particular because of its repetitive nature, the controller may, taking into account the administrative costs involved in providing the requested information or communication or taking the requested action: (a) charge a reasonable fee, or (b) refuse to act on the request.

§

The burden of proof that the request is manifestly unfounded or excessive shall rest with the controller. ” (56) Article 13 of the GDPR states: “(1) Where personal data concerning the data subject are collected from the data subject, the controller shall, at the time of obtaining the personal data, provide the data subject with all of the following information: a) the identity and contact details of the controller and, where applicable, of the controller’s representative; b) the contact details of the data protection officer, where applicable; c) the purposes of the intended processing of the personal data and the legal basis for the processing; d) in the case of processing based on point (f) of Article 6(1), the legitimate interests of the controller or a third party; e) where applicable, the recipients or categories of recipients of the personal data, if any; f) where applicable, whether the controller intends to transfer the personal data to a third country or to an international organisation and whether or not the controller has obtained an adequacy decision or, in accordance with Article 46, the In the case of a transfer referred to in Article 47 or in the second subparagraph of Article 49(1), an indication of the appropriate and suitable safeguards and the means of obtaining a copy of them or their availability.

§

11 (2) In addition to the information referred to in paragraph 1, the controller shall, at the time of obtaining the personal data, provide the data subject with the following additional information in order to ensure fair and transparent processing: a) the period for which the personal data will be stored or, where that is not possible, the criteria for determining that period; b) the right of the data subject to obtain from the controller access to, rectification, erasure or restriction of processing of personal data concerning him or her and to object to the processing of such personal data, as well as the right to data portability; c) the information referred to in point (a) of Article 6(1) or in point (2) of Article 9(2) in the case of processing based on point (a), the right to withdraw consent at any time, without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal; d) the right to lodge a complaint with a supervisory authority; e) whether the provision of personal data is based on a legal or contractual obligation or is a prerequisite for entering into a contract, and whether the data subject is obliged to provide the personal data, and the possible consequences of not providing the data; f) the fact of automated decision-making referred to in Article 22(1) and (4), including profiling, and at least in those cases, intelligible information on the logic involved and the significance and foreseeable consequences of such processing for the data subject.

§

(3) Where the controller intends to further process personal data for purposes other than those for which they were collected, the further processing shall be prohibited. shall inform the data subject in advance of this different purpose and of any relevant additional information referred to in paragraph (2). ” 12 (58) According to Article 83(2) and (5) of the GDPR: “[…] (2) Administrative fines shall be imposed in addition to or instead of the measures referred to in points (a) to (h) and (j) of Article 58(2) depending on the circumstances of the case. When deciding whether to impose an administrative fine and when setting the amount of the administrative fine in each case, due regard shall be had to: a) the nature, gravity and duration of the infringement, taking into account the nature, scope or purposes of the processing in question, the number of data subjects affected by the infringement and the extent of the damage suffered by them; b) whether the infringement was intentional or negligent; c) any measures taken by the controller or processor to mitigate the damage suffered by data subjects; d) whether the controller or processor the level of responsibility of the data controller, taking into account the technical and organisational measures taken by the controller or processor pursuant to Articles 25 and 32; e) any relevant infringements previously committed by the controller or processor; f) the level of cooperation with the supervisory authority in order to remedy the infringement and mitigate its potential negative effects; g) the categories of personal data affected by the infringement; h) the manner in which the supervisory authority became aware of the infringement, in particular whether the controller or processor reported the infringement, and, if so, in what detail; i) if the controller or processor concerned has previously been subject to one of the measures referred to in Article 58(2) in relation to the same subject matter, the compliance with those measures; j) whether the controller or processor has acted in accordance with the approved codes of conduct in accordance with Article 40 or approved certification mechanisms in accordance with Article 42; and (k) other aggravating or mitigating factors relevant to the circumstances of the case, such as financial gain gained or loss avoided as a direct or indirect consequence of the infringement.

§

[…] (5) Infringements of the following provisions shall be punishable by administrative fines of up to EUR 20 000 000 or, in the case of undertakings, up to 4 % of the total annual worldwide turnover of the preceding financial year, whichever is the higher: (a) the principles of data processing, including the conditions for consent, in accordance with Articles 5, 6, 7 and 9; (b) the rights of data subjects in accordance with Articles 12 to 22; (c) the processing of personal data by third parties to a recipient in a Member State or to an international organisation in accordance with Articles 44 to 49; (d) obligations under Member State law adopted pursuant to Chapter IX; (e) failure to comply with an order of the supervisory authority pursuant to Article 58(2) or to temporarily or permanently restrict processing or to suspend data flows, or failure to provide access in breach of Article 58(1).

§

[…]” III. 1. The requirement for adequate information on data processing 13 (59) The data subject must be able to monitor and control the way and circumstances of data processing. e. the General Data Protection Regulation, ensures this in several ways and regulates the right to information. These rights enable data subjects to review the data processing before it begins, to actually check it in its entirety, and to exercise any additional rights they may have or to seek legal remedies. (60) The system of adequate information in the General Data Protection Regulation serves to ensure that the data subject is aware of which personal data will be processed by which controller, for what purpose, on what legal basis and for how long. This is essential to be in a position to be able to exercise their rights as data subjects in a meaningful way. (61) Article 12 of the General Data Protection Regulation (1) The controller shall take appropriate measures to provide the data subject with all the information referred to in Articles 13 and 14 and with all the information referred to in Articles 15 to 22 and 34 concerning the processing of personal data in a concise, transparent, intelligible and easily accessible form, in clear and plain language.

§

Incomplete or unclear information, in particular but not limited to the purpose and legal basis, may directly affect the exercise of the data subject's rights. (62) The requirements for information, its content and specific rules are laid down in Articles 13 and 14 of the General Data Protection Regulation, in two aspects. On the one hand, Article 13 regulates information when personal data are collected from the data subject by the data controller, and on the other hand, Article 14 contains the rules when personal data are not obtained from the data subject by the data controller. (63) With regard to the processing of data by online stores, since personal data are collected from data subjects, the central element of the obligation to provide information is Article 13(1)-(2) of the General Data Protection Regulation, which lists the essential data processing circumstances on which the controller must provide information.

§

(64) In the context of prior information, the controller must strive to provide data subjects with the most complete and accurate picture possible of the processing of their personal data, since this is the only way to assess the impact of a given data processing on them. Article 13(1)-(2) of the General Data Protection Regulation contain the minimum data processing circumstances that data controllers must inform data subjects about, but this does not limit the controller from providing more detailed information. 2. ) - Customer relations - Data processors used - Cookie management - Use of […] conversion tracking - Use of […] tracking 14 - Application of […] - Bank card payment-Simplepay - […] - Newsletter, DM activity - Complaints handling - Telephone voice recording - Social media - Customer relations and other data processing - Rights of the data subjects - Action deadline - Informing the data subject about the data protection incident - Reporting a data protection incident to the authority - Possibility of filing a complaint - Conclusion (66) The Company provided partially adequate information to the customers and interested parties about the above, however, the information was not appropriate or acceptable in several respects as follows: (67) The Company indicated several legal bases in parallel for certain data processing: • for data processing related to registration, the Company referred to the data subject's consent and the contractual legal basis (Page 4, Section 7 of the Regulations); • for “Data processing related to the operation of the Web Store”, the Company referred to Article 6(1)(b) and (c) of the GDPR, as well as to Section 13/A.

§

1) • In the chapter entitled “[…] use of tracking” (Page 22 of the Regulation), the Company referred to both the legitimate interest legal basis and the consent legal basis. (68) Among the several legal bases specified in the Regulations for the data processing operations “Data processing related to the operation of the web store”, “Customer relations” and “Telephone voice recording”, the Company has specified the limitation rules pursuant to Section 6:22 of Act V of 2013 on the Civil Code as Article 6(1)(c) of the GDPR. Reference to the limitation of civil law and the enforcement of a claim cannot be accepted as a legal basis for the fulfillment of a legal obligation. If the Company bases the data processing on Article 6(1)(c) of the GDPR, it is obliged to specify the specific, applicable legal provision and cannot refer in general to the limitation rules of civil law. (69) The Company has provided information about the purposes of its data processing in a similar way: it has indicated different purposes for each data processing operation.

§

In the case of “Data processing related to the operation of the Web Store” (pages 4 and 5 of the Regulation), not all of the specified purposes (contacting, invoicing, creating a contract, enabling home delivery, managing order and delivery-related information) were related to the aforementioned data processing activity, they were related to other data processing operations. As in the case of data processing related to customer relations (page 8 of the Regulation), different purposes were specified (maintaining contact, identification, performance of contracts, business purpose). g. Article 6 (1) (b) and (c) of the GDPR – are incomprehensible to each other, since maintaining contact, identification or business interests do not fit into Article 6 (1) (c) of the GDPR. The Authority notes that the term “Data processing related to the operation of the Web Store” is such a general term that it can include all data processing by the Company, and therefore there is no adequate, clear information about the specific, detailed data processing purposes.

§

(70) The Authority points out that according to the General Data Protection Regulation, each data processing must be linked to a specific, specified purpose and a clearly identifiable legal basis must be assigned to it. It is not in accordance with the Regulation if the data controller designates several legal bases in parallel for the same data processing purpose assigned to the same data processing activity. If the Company intends to use the data of the data subjects for different purposes, it must primarily determine the individual data processing purposes and designate each data processing in accordance with the given purpose, and it must designate the appropriate legal basis for each data processing separately. (71) Furthermore, the Company did not provide any information at all on the legal basis for the use of […] conversion tracking and […] cookies (Pages 20, 21 and 23 of the Regulation).

§

(72) The Authority found that the Company did not provide clear information in the Regulation on the legal basis for the data processing relating to registration, webshop operation, contact, customer relations, newsletter sending, telephone voice recording and […] tracking cookies, and on the purposes of the data processing relating to the operation of the webshop and customer relations. Furthermore, the Company did not provide any information at all on the legal basis for the cookies specified in the above paragraph. Therefore, the Company violated Article 13(1)(c) and (d) of the General Data Protection Regulation. (73) Furthermore, the Authority found that the term “Data processing related to the operation of the Web Store” indicated on page 4 of the Regulation is a general and insufficiently specific purpose designation that does not ensure the requirement under Article 12 of the GDPR that information must be provided in a clear, transparent and intelligible manner.

§

(74) In addition, in the data processing activities “Request for a callback” (page 7 of the Regulation) and “Telephone Audio Recording” (page 26 of the Regulation), the Company indicated the legitimate interest legal basis, but without indicating/explaining its legitimate interest. In the absence of this, it is not clear to the data subject why the Company’s legitimate interest takes precedence over the interests of the data subject during data processing. Therefore, the Company violated Article 13(1)(d) of the General Data Protection Regulation. (75) The Company did not clearly indicate or did not indicate the information regarding the duration of data processing at several points. In the chapter entitled “Data processing related to the operation of the web store”, it indicated a contradictory data processing duration, in the chapter entitled “Community pages”, it did not provide information in the case of […] tracking, […] conversion tracking and […] cookies, and in the case of data processing related to customer relations and telephone voice recording, the Company did not provide adequate information regarding the duration of data processing.

§

16 (76) In the chapter entitled “Data processing related to the operation of the web store”, the Company indicated a contradictory data processing duration. While the Regulation, page 5, paragraph 3. 4. of page 6 of the Regulations, the Company states 5 years in accordance with Section 6:21 of Act V of 2013 on the Civil Code. Due to the use of conflicting periods, the data management period has not been clearly defined. The Company states that the data management period for “Community Pages” (Page 27, Section 4 of the Regulations) is that since the data management is carried out on the community pages, the data management period is subject to the regulations of the given community page. In the case of the […] tracking cookie (Page 22 of the Regulations), it refers to the data management information of the service provider. The Authority notes that, under the General Data Protection Regulation, the controller is obliged to inform the data subject in a clear and understandable manner about the duration of the data processing or the aspects of its determination.

§

According to the Authority, by determining the duration of the data processing by referring to the information of another data controller, the Company does not provide direct and clear information to the data subject and does not comply with its obligation to provide information. The Company did not provide any further information about the duration of the data processing in the case of […] conversion tracking and […] cookies (pages 20, 21 and 23 of the Regulation). (77) In relation to the data processing relating to the customer relationship, the Company also referred to Article 6(1)(b) and (c) of the GDPR (page 9 of the Regulation), specifying the duration of the data processing as the period until the termination of the legal relationship between the controller and the data subject, or in the case of claims, a period of 5 years following the contract. However, given that the Company has also indicated Article 6(1)(c) of the GDPR as the legal basis for data processing, the indicated data processing period cannot be considered appropriate in this form, since in the case of data processing based on a legal obligation, the retention period must always be adjusted to the relevant legal provisions and must be clearly defined accordingly.

§

), while the criteria for the duration of data processing are the same as for customer relationship data processing. If the Company's data processing is based on a legal obligation or legitimate interest, then the retention period that lasts until the termination of the legal relationship or 5 years in the case of claims is not appropriate, since, as the Authority has also established in the case of data processing related to customer relations, in the case of a legal obligation, the duration of data processing must be adjusted to the relevant legal provisions, while in the case of legitimate interest, data processing may only last as long as the legitimate interest of the data controller exists. (78) Based on the above, it can be concluded that the Company did not provide adequate, accurate information on the duration of each of its data processing operations, and therefore the Company violated Article 13(2)(a) of the General Data Protection Regulation.

§

] USA server. Given that the Company transferred personal data outside the European Union or the European Economic Area, it should have provided more detailed information on the guarantees ensuring the lawfulness of the data transfer. In this context, it should have provided information on the appropriate guarantees (such as contractual or other legal safeguards) under which the data transfer was carried out, and also on the manner and contact details through which data subjects can request or obtain a copy of these guarantees. The Company therefore infringed Article 13(1)(f) of the General Data Protection Regulation. (80) The clarity of the Policy is significantly impaired by the fact that the numbering of paragraphs under each heading restarts from the first point, and the lack of page numbering makes the structure of the document difficult to follow and unclear. The Regulation also contained information that was not necessary for the information of the data subjects, which impaired the clarity and comprehensibility of the document.

§

In the introductory part, the Company explained in detail why it did not appoint a data protection officer, introduced several basic concepts of the GDPR, the principles of data management, the security of data management on page 30, and on pages 30 and 31, the Company informed the data subject about the data protection incident and the data controller's obligations. Although these provisions presented general requirements for the operation of the data controller, they did not provide information on the specific processing of the personal data of the data subjects, so they were not relevant for the information on data management pursuant to Article 13 of the GDPR and were merely repetitions of statutory provisions. (81) The “Data subject rights” section of the Policy (Page 29 of the Policy) describes the data subject’s right to object to automated decision-making and the data subject’s right to object to profiling.

§

The Company acknowledged that it does not carry out such data processing, but the Policy only included the relevant rights due to the need for full information. The Company also refers to data transfer (Pages 20 and 21 of the Policy) in the case of […] tracking and in the case of […] (Page 22 of the Data Processing Policy). However, the Company later explains that this was formulated in this way in the Policy due to the limited information available from the service providers ([…] and […]), since data processing was actually carried out in the case of the two cookies. In addition, on page 26 of the Regulations, the Company explained that the recordings can only be listened to in person, and later on, in the data processing, it states the right of the data subject to data portability. However, the two statements are contradictory, since the possibility of only personal listening limits the release of data in other forms, while the right to data portability ensures that the data subject can also receive the recordings in electronic, portable form.

§

According to the Authority, any information that does not correspond to reality or that does not relate to a situation that does not correspond to reality should be omitted from the information. Information provided about data processing operations that have not actually been carried out and about data subject rights that cannot be applied in relation to the given data processing is unnecessary and misleading, as such information may lead to the deception of the data subjects. Therefore, the indication of data transfer in the Information in the case of automated decision-making, profiling, […] and […] tracking cookies was not justified, since such data processing did not take place on the Website, therefore the information in this regard was incorrect. (82) The Policy also contained repetitive details for all data processing, which were unjustified from the perspective of the data subjects.

§

In the case of data processing, the Company indicated which employee of the data controller could have learned the data (for example, point 4 of the Policy, “Data processing related to the operation of the Web store” on page 4 of the Policy), and where the data subject’s rights can be exercised (for example, point 6 of the Policy, “Data processing related to the operation of the Web store” on page 4 of the Policy). The Regulations contained repetitions in several places, for example, the data controller's contact information was indicated on page 1 of the Regulations and in point 6 of the chapter entitled "Data processing related to the operation of the Web store", and the General Data Protection Regulation was listed as the legal regulation applied by the Company on pages 1 and 32 of the Regulations. Such repetitions and information that was not relevant to the data subjects unreasonably increased the scope of the information, thereby reducing its clarity.

§

g. a list of legal grounds). For this reason, it is not clear whether the given description describes the role of data processors or the data processing practices of the Company. Information such as the fact of data processing, the scope of personal data processed or the duration of data processing is also included in this section, as these are related to the data processing activity and cannot be interpreted in the data processing context, therefore their inclusion is incorrect. However, based on the information described, it is in several cases doubtful whether the actors designated as data processors should indeed be considered data processors or data controllers. e. the Company. The linking of data subject rights to data processors is misleading and is likely to prevent data subjects from addressing their requests to the appropriate addressee. (85) The Authority further notes that the Company was wrong when it stated in the “Cookies” section (page 20 of the Regulations) that “[…]”.

§

In contrast, the Company itself indicated the purpose of data processing as the identification of users, the registration of the “shopping cart” and the tracking of visitors (page 19 of the Regulations). Pursuant to Article 4(1) of the GDPR, personal data is any information relating to an identified or identifiable natural person. The unique identification numbers stored in cookies enable users to be distinguished, identified and their activities to be tracked - as the Company indicated as the purpose of data processing - and thus qualify as personal data. The table on cookies in the same chapter (pages 19 and 20 of the Regulations) does not clearly state what data, including personal data, the customer collects when using cookies, for example, in the case of the designation “Webshop statistics (anonymized)”, it is not clear exactly what it covers and what personal data it is subject to.

§

e. whether they participated in the data management as a recipient, data controller or data processor. (86) The Company included the right to automated decision-making and profiling among the data subject rights (page 29 of the Regulation), however, none of the data processing activities listed in the information referred to the application of such data processing. This indication of the rights in this way, which is not in accordance with the legal basis, further increased the inaccuracy of the information. Furthermore, the Company regulated the data subject rights not only by data processing, but also in a separate chapter (pages 28 and 29 of the Regulation, chapter entitled “Data subject rights”). The published information did not make it transparent how the individual rights were related to the specific data processing operations of the Company, so the relevant chapter did not enable the data subject to exercise their rights effectively, meaningfully and predictably.

§

19 (87) In several cases, the Company did not mention the GDPR, but only used the word “article”, from which it could only be concluded that the text referred to the GDPR. For example, on page 18 of the Regulations, the following was stated: “ […] (…)”. However, without mentioning the GDPR, it is not clear to the data subject that it is referring to Article 6 of the General Data Protection Regulation and not Infotv. In the Regulations, the term “user” appears in several places in different (lowercase and uppercase) forms, however, the Company did not define their meaning or clarify exactly which group of persons it understood under the term “user”. (88) The Authority notes, without finding any infringement, that the Company has indicated in the Regulations the old seat and mailing address of the Authority (Page 29 of the Regulations) (89) Based on the above, it can be concluded that the Company has not provided data subjects with sufficiently concise, accurate, clear, transparent and intelligible information on the processing of personal data, thereby violating the requirements set out in Article 12(1) of the GDPR.

§

3. Compliance of the Notice with data protection requirements (90) The Notice follows the following structure: - Name and contact details of the data controller - Name and contact details of the hosting provider - Description of data processing carried out during the operation of the webshop - Information on the use of cookies - Data processed for the purpose of concluding and fulfilling the contract - Registration on the website - Order processing - Issuance of the invoice - Data processing related to the delivery of goods - Data processed in connection with the verification of consent - Data processing for marketing purposes - Data processing related to sending newsletters - Remarketing - Further data processing - Recipients of personal data - Data processing for the storage of personal data - Data processing activities related to sending newsletters - Data processing related to accounting - Data processing related to invoicing - Data processing related to the operation of the CRM system - Your rights during data processing - Logging into the data protection register - Data security measures - Legal remedies - Amendment of the data processing information - Delivery to be left at the post office and at the post office (91) The Company provided adequate information to the customers and interested parties on the above, but the information was not correct or acceptable in several respects, as follows: (92) The Company did not properly define or clearly indicate the duration of data processing on several points.

§

In the sections “Remarketing” and “Information on the use of cookies”, no information was provided at all about the duration of data processing for the cookies named “[…] cookie”, “[…] cookie” and “[…] ([…] cookie)”, and in the section on the verifiability of consent20, the aspect of determining the duration was not understandable due to the following: (93) The Information provides information on cookie data processing in two paragraphs: in the “Remarketing” data processing (page 6 of the Information), and in the paragraph “Information on the use of cookies” of the Information (pages 1-3 of the Information). In the paragraph “Information on the use of cookies”, the Company also indicates the operation of the cookies available on its Website and in several cases their duration (pages 1-3 of the Information). However, the Company does not indicate the duration in any paragraph of the Notice for the cookies named “[…] cookie”, “[…] cookie” and “[…] ([…] cookie)”, but refers to the […] general cookie notice, […] notice and […] data processing policy (see the Notice on pages 2, 3 and 6).

§

Referring back to paragraph 76 of this decision, the Authority reiterates that under the General Data Protection Regulation, the controller is obliged to clearly and intelligibly inform the data subject about the duration of the data processing or the criteria for determining it. According to the Authority, by determining the duration of the data processing by referring to the notice of another data controller, the Company does not provide direct and clear information to the data subject and does not comply with its obligation to provide information. g. registration, newsletter subscription), the Company stores the consent of the data subject for the purpose of later proof. ” (Information Notice page 5). According to its statement, the Company intended to refer to the general five-year limitation period under civil law (see paragraph 12 of this resolution), however, this five-year period is not disclosed in the Information Notice, so for those data subjects who are not aware of the general limitation period, it is not clear how long the Company processes their personal data.

§

Furthermore, this information from the Company is incorrect because in the case of consent, the existence of the legal basis must be proven as long as the data processing is in progress for the given data processing purpose. If the purpose or data processing ceases or the consent is withdrawn, then in order to justify the existence of the previous consent, another legal basis must be ensured for the preservation of the consent, which is typically legitimate interest. The consideration of legitimate interest also includes the consideration of the retention period. In the consideration of the retention period and its aspects, and in the information to be provided on this, the civil law limitation period has no role, and it is incorrect to refer to a legal concept – limitation – that is not relevant. (95) Based on the above, it can be concluded that during the period under review, the Company did not provide adequate and accurate information to the data subjects about the duration of certain data processing operations, and therefore the Company violated Article 13(2)(a) of the General Data Protection Regulation.

§

(96) According to the section entitled “Issuance of the invoice” on page 4 of the Information Notice, the Company processes personal data for 8 years on the legal basis of fulfilling a legal obligation, which is not an element of the invoice (email address, telephone number), thus this legal basis is also incorrectly indicated in relation to data for which it is not relevant in the absence of the relevant legal regulation. (97) Furthermore, the Information Notice is a text without numbering or other section designations, therefore it is not entirely clear which are the chapter headings and which are the subheadings, and the font size and bolding of the headings do not help to separate them (the list in paragraph 90 of this resolution is therefore not necessarily accurate). The Information Notice is therefore not easy to understand, and it is not easy to find certain information in it. 21 (98) The structure and composition of the Information Notice are not logical, not well thought out, but rather disorganized and inconsistent.

§

For example, at the beginning of the Notice, the hosting provider is described (Page 1 of the Notice), although this is not really relevant for the data subjects, and in addition, the same company is also described as a data processor on pages 6 and 7 of the Notice. Shortly after this, also at the beginning of the Notice (Pages 1-3 of the Notice), the information on cookies is explained at length, while the section entitled “Remarketing” also refers to the use of cookies (Page 6 of the Notice). It also shows the lack of thought and clarity that there is no content behind the heading “Recipients of personal data” (Page 6 of the Information), or for example, a sentence after the heading “Further data processing” talks about conditional data processing, according to which if the data controller will carry out further data processing, it will provide information about the circumstances of this (Page 6 of the Information), so this wording is irrelevant, unnecessary and does not provide any substantive information.

§

(99) The section “Your rights in the course of data processing” of the Information (Page 7 of the Information) describes the rights of the data subject against automated decision-making, and the paragraph under the sub-heading “Right to portability” (Page 11 of the Information) also refers to possible automated data processing. The Company acknowledged that it does not carry out such data processing, the wording appears as a template text provided by the […] system it uses. As the Authority explained, any information in the information that does not correspond to reality or that does not relate to a situation that does not correspond to reality should be omitted. Information about data processing operations that are not actually carried out and about data subject rights that are not applicable in relation to the given data processing is unnecessary and misleading, as such information leads to the deception of data subjects.

§

Therefore, the indication of automated decision-making in the Information was not justified, since such data processing did not take place on the Website, therefore the information was incorrect in this regard. (100) The chapter entitled “Your rights during data processing” is disproportionately long, unnecessarily detailed and circumstantial (Information 7-10 pages). The Information Notice, in the paragraph “Description of data processing carried out during the operation of the webshop”, also includes the Infotv. (Page 1 of the Information Notice), as the legislation containing all relevant data processing information in relation to the operation of the webshop. At the same time, the Company’s data processing is subject to the GDPR. , should be taken into account as relevant data processing information in relation to the operation of the Website. Furthermore, this title and the content below are not consistent, but rather have different contents, since the description of data processing and the applied legislation are two different topics.

§

(101) Furthermore, the Notice was incomplete: the Website includes a “Contact” tab, where you must provide your name, email address, phone number and message, as well as a checkbox for consent to data processing and acceptance of the Notice, but the Notice does not provide information about this data processing. The Company also sells industrial goods to consumers as a retail webshop, and in this context also carries out data processing activities related to warranty and guarantee claims, but it did not publish data processing information regarding this activity. The Company acknowledged that it did not have any relevant information regarding both data processing activities, which filled the gap. 22 (102) In several cases, the Notice does not make it clear what kind of personal data of the data subjects the Company processes using cookie technology, for example, on page 2 of the Notice, in the case of […], only an illustrative list of the collected data was included, in the case of […], “a report is prepared on conversions”, “the page owner receives detailed analysis data on the use of the visited website”, so it is not entirely clear exactly what kind of personal data the Company stored using cookie technology.

§

The Notice also did not state whether the companies providing the cookie service are data controllers during data processing or not. It cannot be established from the Notice what kind of data the Company collected about the visitors/customers of the Website via cookies, nor did it state whether the visitors or customers were profiled. For this reason, the Authority establishes that the Company did not provide clear information in its data management information about exactly what personal data it obtains within the framework of cookie technologies, what is the purpose of the data management, what the status of the cookie service providers is, whether any personal data is received by them. (103) In the case of the data management activity “Remarketing” on page 6 of the Information, the content of this data management activity is not precisely defined, it can only be concluded that the Company means the cookies on pages 1-3 of the Information by this data management activity.

§

In the same data management, it was not clearly indicated what personal data the Company processed, but only indicated: “[…]”. e. the […] system. e. for the Company to check the data management information generated in this way before its application to the data subjects, in order to ensure that all the information requirements of the GDPR are met. 2025 because, due to the technical characteristics of the […] system, a new information is generated in every case when the Company modifies not only the data management information, but also any other document managed in the system. The Authority notes that multiple data management notices with different dates – even if they are identical in content – make the transparency of data management more difficult for data subjects and consumers. This can be particularly problematic in cases where the data management and the relationship with the data subject are continuous, for example in the case of regular customers.

§

Based on points (96) – (104), it can be established that during the period under review the Company did not provide adequate and accurate information to the data subjects, thereby violating Article 12(1) of the General Data Protection Regulation. (105) Regarding the Company’s position on the Authority’s competence, the Authority notes that Section 5(4) of the Sanctions Act — according to which an administrative sanction cannot be applied if three years have passed since the commission of the offence — is not relevant if the unlawful situation has existed continuously. For the statute of limitations of infringements to expire, it is essential that the limitation period commences, and the starting date of the limitation period can only be calculated from the date on which the unlawful state ceases. Since the Regulation has been in force for more than 7 years, the data protection problems identified have been continuously implemented before the publication of the Information Notice.

§

(106) Furthermore, according to the Authority’s position, the Sanctions Act should be interpreted in accordance with the GDPR, but the GDPR does not specify a limitation period, conditions or time limit for the data processing that can be examined, therefore the above provision of the Sanctions Act is not applicable by the Authority in any case. 4. e. the changes to the Information Notice following the notification of the procedure. (108) The Company presented the amendments made based on the Authority's observations and its efforts in the field of data protection. (109) The Authority takes the above amendments and measures into account as a manifestation of cooperation with the Authority as mitigating circumstances. I V . L e g a l c o n s i o n s (110) The Authority finds, pursuant to Article 58(2)(b) of the General Data Protection Regulation, that the Company has infringed Article 12(1), Article 13(1)(c), (d) and (f) and Article 13(2)(a) of the General Data Protection Regulation.

§

The Company committed the infringements negligently, intent has not been proven. (111) Due to the established infringements, the Authority ex officio orders the Company, pursuant to Article 58(2)(d) of the General Data Protection Regulation, to amend the content of its data processing notice in accordance with the requirements set out in the justification for this decision and to provide the Authority with proof thereof. (112) The Authority has examined whether it is justified to impose a data protection fine on the Company, and in this regard the Authority has considered all the circumstances of the case on the basis of Article 83(2) of the General Data Protection Regulation. According to the Authority, due to the established infringements, the long-standing incorrect practice in this regard, and for the reasons of special and general prevention, a warning is not a proportionate sanction, therefore a fine should be imposed.

§

(113) When determining the amount of the fine, the Authority took into account that the infringements committed by the Company are classified as infringements falling within the higher maximum fine category pursuant to Article 83(5) of the GDPR. (114) When determining the amount of the fine, the Authority took into account the provisions of the European Data Protection Board's Guideline No. 4/20223 (hereinafter referred to as the "Guidelines"), which sets out the criteria for calculating administrative fines under the GDPR. e. […] forints. (115) When determining the amount of the fine, the Authority took into account the sales revenue of the last closed year (2024). pdf 24 (116) Pursuant to Article 83(5) of the General Data Protection Regulation, the Company shall be subject to administrative fines of up to EUR 20,000,000 [static maximum fine] or, in the case of undertakings, up to 4% of its total annual worldwide turnover in the preceding financial year [dynamic maximum fine], whichever is the higher.

§

e. e. an amount equivalent to EUR 20,000,000. Since the fine must be calculated on the basis of the higher category of the static and dynamic amounts that can be imposed in a given case and proportionate to it, the Company may be imposed an administrative fine of up to EUR 20,000,000 in the present case. (118) According to the Guidelines, in the case of infringements falling within the fine category referred to in Article 83(5) of the GDPR, to which the static maximum fine of EUR 20,000,000 applies, the net turnover of the undertaking taken into account in determining the fine amount and the gravity of the infringement committed shall be subject to further examination. e. […] forints, which, at the current HUF/EUR exchange rate, falls into the category of undertakings with a turnover of up to EUR 2 million and up to EUR 10 million as specified by the Guidelines in relation to the consideration of the business data of the undertakings.

§

(120) When determining the amount of the data protection fine, the Authority took into account as aggravating circumstances that - the number of data subjects was large, according to the Company’s statement, the number of visitors to the webshop in 2024 was 3,763,794, and the number of buyers was 119,380 [Article 83(2)(a) of the General Data Protection Regulation]; - the infringements lasted for a long time [Article 83(2)(a) of the General Data Protection Regulation]. ; - the Company has not yet been convicted of a violation of the General Data Protection Regulation [Article 83(2)(e) of the General Data Protection Regulation]; - the Company has amended its data processing information during the Authority's procedure [Article 83(2)(f) of the General Data Protection Regulation]. (122) In determining the data protection fine imposed on the Company, the Authority did not consider the circumstances referred to in Article 83(2)(h), (i), (j) of the General Data Protection Regulation to be relevant, as they cannot be interpreted in the context of the specific case.

§

(123) The Authority considered the infringements committed in the present case to be of medium gravity, based on the infringements committed, the facts revealed and the aggravating and mitigating circumstances relating to the given case. 25 (124) According to the Guidelines, if the net turnover of the undertaking in the previous year is between EUR 2 million and EUR 10 million, the maximum amount of the fine that can be imposed is reduced to EUR 80,000 in the case of infringements of medium gravity. (125) The amount of the fine was determined by the Authority acting in accordance with its statutory discretion. (126) The fine imposed is proportionate to the gravity of the infringement, it cannot be considered excessive, and is a low amount compared to the net sales of the Company. (127) Based on the above, the Authority has decided as set out in the operative part. V. Other issues (128) The Authority’s competence is determined by Section 38 (2) and (2a) of the Information Act, and its jurisdiction extends to the entire territory of the country.

§

(129) The Authority’s present decision is based on Sections 80-81 of the Information Act and Section 61 (1) of the Information Act. The decision becomes final upon its publication pursuant to Section 82 (1) of the Information Act. The Information Act Pursuant to Section 112, and Section 116, Paragraphs (1) and (4) d), and Section 114, Paragraph (1), the decision may be appealed against through administrative proceedings. * * (130) Pursuant to Section 135 of the Civil Code, the debtor shall pay a late payment surcharge in the amount equivalent to the statutory interest if he fails to meet his payment obligation within the deadline. (131) Pursuant to Section 6:48, Paragraph (1) of Act V of 2013 on the Civil Code, in the event of a financial debt, the debtor shall pay default interest in the amount equivalent to the central bank base rate valid on the first day of the calendar half-year affected by the delay, starting from the date of default.

§

(132) The rules of administrative litigation are determined by Act I of 2017 on the Code of Administrative Procedure (hereinafter referred to as the Code). Pursuant to Section 12 (1) of the Code, administrative litigation against the decision of the Authority falls within the jurisdiction of the courts, and the Metropolitan Court has exclusive jurisdiction over the litigation pursuant to Section 13 (3) a) sub-paragraph aa) of the Code. Pursuant to Section 27 (1) b) of the Code, legal representation is mandatory in a dispute in which the court has exclusive jurisdiction. Pursuant to Section 39 (6) of the Code, the filing of a claim does not have a suspensive effect on the entry into force of the administrative act. (133) The Code Section 29 (1) and, in view of this, Section 604 of Act CXXX of 2016 on the Code of Civil Procedure, Section 19 (1) b) of Act CIII of 2023 on the Digital State and Certain Rules for the Provision of Digital Services, the legal representative of the client is obliged to maintain electronic communication.

§

(134) The time and place of filing the statement of claim is determined by Section 39 (1) of the Civil Procedure Code. The information on the possibility of requesting a hearing is based on Section 77 (1)-(2) of the Civil Procedure Code. 26 (135) The amount of the administrative litigation fee is determined by Section 45/A. (1) of Act XCIII of 1990 on Fees (hereinafter: the Civil Procedure Code). Section 59 (1) and Section 62 (1) h) of the IT Act exempt the party initiating the procedure from the advance payment of the fee. (136) If the Company fails to provide adequate proof of the fulfillment of the prescribed obligations, the Authority shall consider that the obligation has not been fulfilled within the deadline. , if the Company has not fulfilled the obligations set out in the final decision of the Authority, it shall be enforceable. The Authority's decision shall become final upon its notification, in accordance with Section 82 (1) of the Ákr.

§

, enforcement shall be ordered by the authority that made the decision, unless otherwise provided by law or government decree. According to Section 133 of the Ákr. Pursuant to Section 134, the enforcement shall be carried out by the state tax authority - unless otherwise provided by law, government decree or, in the case of a local government authority, by a local government decree. Pursuant to Section 61 (7) of the Information Act, the enforcement of the decision shall be carried out by the Authority in respect of the obligation to perform a specific act, to behave in a specific manner, to tolerate or to cease performing a specific act. Dated: Budapest, according to the electronic signature and time stamp. Dr. habil. Péterfalvi Attila, President, University Professor