NAIH (Hungary) · NAIH-450-7-2026
The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025.
The period under review extended from January 2020 to November 2025. During this time, the company had multiple privacy notices in force, as well as other documents that contained relevant information on the processing of personal data. Holding — The DPA found the controller guilty of multiple GDPR violations and issued it a fine of HUF 15,000,000 (€41,500). In addition, it ordered the controller to bring its processing operations in compliance with the GDPR by amending the information system used on its website, in particular the data processing provisions of the general terms and conditions and the data processing notices related to prize contests. First, the DPA held that the controller had violated the principle of transparency laid down in Article 5(1)(a) GDPR: several separate documents contained partially conflicting, irrelevant, and incomplete information regarding the processing of personal data. The information was not organised within a uniform, transparent system. Second, the DPA determined that the controller had failed to provide concise, transparent, and intelligible information regarding the purposes and the legal basis for each processing activity and therefore infringed Article 12(1) GDPR. Finally, the DPA found infringements of Articles 13(1) and 13(2) GDPR – the controller had not provided the data subjects all information necessary when personal data is collected from data subjects. In particular, the controller had failed to adequately distinguish the purposes and the legal bases for each processing operation, recipients of personal data, and retention periods. The controller’s website also contained contradictory information on whether or not personal data was transferred to the United States.
How it connects
Related across sources
Full text 174 findings
: NAIH-450-7/2026. Background: NAIH- 15402/2025. NAIH-9728/2025. Case Officer: Subject: Decision in an ex officio data protection authority proceeding DECISION The National Authority for Data Protection and Freedom of Information (hereinafter: the Authority), with respect to the websites […] (hereinafter: the Website) and […] (hereinafter: the Blog), regarding the data processing practices of the online store operating on the Website, including, in particular, the provision of prior information, concerning […] (registered office: […]; company registration number: […]; tax ID: […]; hereinafter: “Company”), as the operator of the online store operating on the Website, regarding the protection of natural persons with respect to the processing of personal data and the free movement of such data, and repealing Directive 95/46/EC, Regulation (EU) 2016/679 (EU) (hereinafter: General Data Protection Regulation or GDPR) regarding the processing of personal data of natural persons and repealing Directive 95/46/EC.
1. The Authority finds that the Company negligently violated - Article 5(1)(a) of the General Data Protection Regulation; - Article 12(1) of the General Data Protection Regulation; - Article 13(1)(a), (c) through (f) of the General Data Protection Regulation; and - Article 13(2)(a) through (f) of the General Data Protection Regulation. 2. In light of the identified violations, the Authority—pursuant to Article 58(2)(d) of the GDPR— hereby orders the Company ex officio to amend the information system used on the Website under review—including, in particular, the Website Notice, the data processing provisions of the General Terms and Conditions, the data processing notices related to sweepstakes, and the Blog Notice—in order to remedy the deficiencies identified in this decision, and to ensure that the information complies with the GDPR and is provided in a concise, transparent, understandable, and easily accessible form, using clear and plain language, and aligned with the actual data processing operations; in this context, the Company is required to eliminate parallel, conflicting, or mutually incompatible information solutions, clearly define the relationship between individual documents, and remove outdated references to legislation and terminology not based on the GDPR framework; present information regarding data subjects’ rights and remedies accurately and in an easily understandable manner in accordance with the structure set forth in the Regulation; furthermore, clearly define for each data processing activity the categories of data processed, the purposes, the legal bases, recipients or categories of recipients, and retention periods—including data processing related to cookies—and to clarify the roles and responsibilities of data controllers in accordance with actual operations.
The Company is required to provide evidence of compliance by submitting the amended privacy notice to the Authority in such a way that the changes are clearly identifiable. hu 2 3. Due to the violations established in Section 1, the Authority has imposed a data protection fine of 15,000,000 Ft, that is, fifteen million forints . * * The Company must provide written confirmation to the Authority, together with supporting evidence, that it has taken the measures prescribed in Section 2 within 30 days of this decision becoming final. The data protection fine must be paid within 30 days of this decision becoming final to the Authority’s forint account for the collection of centralized revenues (10032000-01040425- 00000000 Centralized Collection Account, IBAN: HU83 1003 2000 0104 0425 0000 0000). When transferring the amount, please cite reference number NAIH-450/2026. FINE. If the Company fails to meet its obligation to pay the data protection fine by the deadline, it shall be required to pay a late payment penalty to the above account number.
The rate of the late payment penalty is the statutory interest rate, which corresponds to the central bank’s base rate in effect on the first day of the calendar half-year affected by the delay. In the event of failure to comply with the obligations set forth in Section 2, or failure to pay the data protection fine and the late payment penalty, the Authority shall order the enforcement of this decision. There is no right to an administrative appeal against this decision, but it may be challenged in administrative litigation by filing a complaint with the Budapest Metropolitan Court within 30 days of notification. The complaint must be submitted to the Authority electronically1, which will forward it to the court together with the case file. A request for a hearing must be included in the complaint. For those not eligible for full exemption from personal fees, the administrative litigation fee is 30,000 HUF; the case is subject to the right to charge a fee based on the subject matter.
Legal representation is mandatory in proceedings before the Budapest Metropolitan Court. R E A S O N I N G I. 1. The Administrative Inspection (1) On April 9, 2025, the Authority decided to initiate an administrative inspection regarding the data processing by the online store operating on the Website and the Blog, including preliminary notification, concerning compliance with the General Data Protection Regulation, under case number NAIH-9728/2025. (2) On November 4, 2025, the Authority conducted an unannounced inspection, which consisted of viewing the Website and making a backup copy. 1 The form designated NAIH_K01 is used to initiate administrative proceedings: NAIH_K01 form (September 16, 2019). The form can be completed using the General Form-Filling Program (ÁNYK program). hu/kozig-hatarozat-birosagi-felulvizsgalata 3 (3) After reviewing the Website and the Blog, the Authority identified a suspected violation regarding the adequacy of the preliminary data processing notice related to the operation of the online store.
2. Administrative Proceedings (4) The Authority concluded its official inspection and, pursuant to Section 60(1) of Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information (hereinafter: the Information Act), on November 12, 2025, under case number NAIH-15402/2025, an administrative data protection proceeding covering the Website’s data processing practices— specifically, the prior data processing notice—in which it also utilized the data and documents from the previous official inspection and review. The proceedings did not extend to an examination of other data protection requirements or to a comprehensive review of the Company’s data processing procedures. (5) The Authority may assess compliance with the provisions of the General Data Protection Regulation—applicable as of May 25, 2018. According to the Company’s statement, the online store began operations in 2020; therefore, the Authority refrained from examining the period prior to January 1, 2020.
(6) The period under review extended until the initiation of this proceeding; therefore, the period following the initiation of the proceeding is not included. (7) Based on the foregoing, the period examined by the Authority in this proceeding is: January 1, 2020 – November 12, 2025. 1. Clarification of the Facts (8) In its order dated November 12, 2025, file number NAIH-15402-1/2025, the Authority notified the Company of the initiation of the data protection authority proceeding and requested that it submit a statement to clarify the facts of the case. (9) In its response letter dated December 12, 2025, filed under reference number NAIH-15402- 7/2025, the Company stated that […] was registered on […] and began operating the […] online commerce platform in 2020. According to the Company, it entrusted […] with data protection duties as of July 13, 2022, and that entity also performed the duties of a data protection officer.
The Company further stated that concerns arose in 2024 regarding the external expert’s activities, which led to the termination of the engagement agreement. The Company emphasized that, in its view, it had no intention of engaging in unlawful data processing and acted in the belief that its data protection documents and processes complied with legal requirements. According to its statement, as a result of the present proceedings, it has begun reviewing its privacy notices and preparing amendments thereto. (10) To clarify the facts of the case, the Authority requested that the Company verify which data protection notices were available on the Website during the period under review, as well as to submit previous versions of the privacy notices and related documents, along with their effective dates, publication dates, and any amendments, and to confirm their publication. The Authority also requested that the Company use the form attached to the order for each document when responding.
” Among the documents attached to its statement, the Company identified the privacy notice, the privacy notice related to the sweepstakes, the cookie policy, and the sweepstakes rules, and confirmed their availability via links on the Website. 4 (11) In its statement, the Company argued that publishing the data protection provisions in several separate documents serves to uphold the principle of transparency. In its view, the Website’s privacy notice describes the general data processing activities carried out on the Website, while a separate privacy notice applies to data processing related to prize contests, so that data subjects can directly access information pertaining to that specific data processing. The Company further stated that information regarding the use of cookies is also contained in a separate cookie policy. According to its statement, this three-document structure—the Website’s privacy notice, the sweepstakes privacy notice, and the cookie notice—provides data subjects with clear and targeted information regarding the terms of each data processing activity.
The Company asserts that this approach is also in line with industry practice. (12) According to the Company’s statement, at the time the data processing notice was prepared, the property serving as the Company’s registered office could be identified by its cadastral number, as the property did not yet have a street address. The Company explained that in 2024, the local government reclassified the property, and its address was changed to […], which was updated in the company’s records; however, the privacy notice was not amended. According to the Company, it carries out procurement, central administrative, warehousing, and IT activities at its headquarters ([…]). Warehousing activities take place at its facilities ([…]; […]), while its branches ([…]; […]) handle financial, marketing, HR, customer service, IT development, and legal activities. 4 of the Privacy Notice effective as of July 2, 2025, was related to a previous function under which the product page displayed information about which person, by first name, from which municipality had most recently purchased the given product.
The Company stated that it discontinued this practice as of April 23, 2024, and currently only the name of the town is displayed. 8 of the Notice contain identical wording, which it claims is the result of an editorial inaccuracy. 8 concerns marketing communications directed at marketplace partners and suppliers. According to the Company, in practice, it sends marketing messages in both cases based on consent and does not engage in telemarketing activities. 17 of the Privacy Policy was related to the publication of user reviews regarding products and partners. It stated that since 2024, it has not engaged in this data processing in a manner where the user’s first name appears alongside the reviews; currently, reviews are published without the first name or only with the first name provided by the user. The Company indicated that it intends to correct the inaccuracies identified during the review of the Privacy Notice.
(14) In its statement, the Company explained that the phrasing “planned duration of data processing” in Section 2 of the Notice is inaccurate, as it could misleadingly suggest that the data retention periods specified there are merely planned periods. According to the Company, it has in fact applied and complied with the data retention periods specified in the Notice for each data processing activity. The Company further stated that it determined the data retention periods in accordance with the principle of limited storage and considers them binding upon itself. According to its statement, it will remove the term “planned” from the document during the review of the Privacy Notice. 2 of the Privacy Notice relates to the issuance and retention of invoices and other mandatory documents related to the fulfillment of purchases made through the online store. The Company 5 stated that it determined the data retention period based on Section 169(1)–(2) of Act C of 2000 on Accounting, which stipulates that accounting documents must be retained for at least 8 years.
Accordingly, the duration of data processing extends until the last business day of March following the expiration of the eighth year after the invoice was issued. It further stated that deletion is not currently carried out as part of an automated process; however, it considers the automation of this process to be a development priority. The Company also indicated that in certain cases—for example, in the event of a longer warranty period—the retention period for documents may be aligned with the duration of the warranty, which may exceed the 8-year period. (16) According to the Company, it has no direct information regarding the partners involved in data transfers as specified in Section 10 of the Prospectus—specifically […], […], ([…]), […], ([…]), […], […], […], […], […], and […]—the Company has no direct information regarding whether these service providers engage in profiling. The Company stated that, in accordance with industry practice, online advertising providers may use profiling methods to ensure effective advertising; however, the Company has not obtained direct information regarding this practice nor has it taken any specific measures in this regard.
According to its statement, data transfers to such providers are automated and typically occur through the placement of the providers’ cookies following the user’s consent; data transfers cease when the cookies are deleted or expire. (17) The Company stated that it does not use automated decision-making—whether based on profiling or otherwise—in the course of its operations, and currently has no plans to introduce such solutions. According to the Company, profiling is not necessary for the operation of the main service available on the Website, and therefore it refrains from using it. The Company further stated that the recommendations appearing on the Website—such as “People who bought this also bought,” “Top picks according to our customers,” “Most Popular Gift Items,” or “Newest Products in This Category”—are not based on user profiling but are displayed based on data from transactions conducted on the Website and other objective data.
(18) The Company stated that it cannot provide an explanation as to why the recipients of data transfers were not specifically named in Section 7 of the Privacy Notice, or why the individual recipients were not clearly assigned to the designated recipient categories. The Company further stated that it could not explain the criteria used to list the partners mentioned in Section 10 of the Notice, nor why they were listed in a separate section. According to its statement, the Company’s objective in revising the Privacy Notice is to provide data subjects with more comprehensive information regarding the recipients of data transfers or their categories, taking into account the considerations set forth in the judgment of the Court of Justice of the European Union in Case C- 154/21. (19) According to the Company, the inclusion of the term “Authority” in Section 7 of the Privacy Notice, in the context of information regarding data processors, is incorrect because, on the one hand, it has not been specified which body is meant by this term, and, second, in its view, given Article 4(9) of the GDPR, naming the authorities as recipients is not necessarily justified.
The Company further argued that the phrasing “Joint Data Controller: Marketplace Partners” is also inaccurate, as, according to the Company, there is no joint data processing between the Company and the marketplace partners. The partners act as independent data controllers with respect to the personal data provided during a purchase or inquiry. The Company indicated that these inaccuracies will be corrected during the review of the Privacy Notice. 2 of the Privacy Notice is inaccurate; however, it asserted that it did not intend to restrict data subjects’ right to access their personal data in practice. It stated that if a data subject were to request a copy of the camera recordings, the Company would fulfill the request in accordance with the relevant legal 6 . According to the Company, the camera system operates exclusively on the premises of the […] warehouse for property protection purposes; the recordings are retained for one month, and to date, a copy of the recordings has been provided to the police on only one occasion; no such request has been received from a private individual.
The Company further stated that only a small number of private individuals visit the warehouse premises, and the primary purpose of the camera surveillance is property protection. (21) According to the Company, […] was designated as the data protection officer in Section 1 of the Privacy Notice. The Company stated that […] will no longer perform these duties as of December 1, 2024, as the service agreement between the parties has been terminated. The Company further stated that, in its view, the conditions set forth in Article 37(1) of the GDPR are not met, and therefore it does not consider the appointment of a data protection officer necessary. According to its statement, the Company intends to review its data protection documents and processes with the involvement of an external expert in the future, and plans to take measures to strengthen data protection awareness and ensure the continuous performance of data protection tasks.
3 of the Prospectus, and does not intend to retain them during the review of the Prospectus. At the same time, it stated that, in its view, specifying the purpose of the restriction is significant for the data controller insofar as, based on the reason indicated by the data subject among the cases specified in Article 18(1)(a)–(d) of the GDPR, the reason specified by the data subject may clarify the basis for the restriction and the legal framework for the related data processing operations to the data controller. (23) According to the Company’s statement, it determines whether the partners listed in Section 10 of the Privacy Notice act as data controllers or data processors based on the contracts concluded with them and the terms and conditions they have published. According to the Company’s information, […] and […] ([…]) act as data processors, while […] ([…]), […], […], […], […], and […] are classified as data controllers.
The Company further indicated that it currently has no cooperation with […]. 1 of the Privacy Notice, it intended to provide information regarding the transfer of data to […] ([…]) and thereby comply with the relevant legal and contractual obligations. According to the Company’s statement, users’ personal data—specifically, the customer’s name, email address, billing and shipping addresses, and data related to the purchase—are transferred to […] during the payment process. The Company has stated that it does not intend to continue informing data subjects in this manner in the future and plans to place the notice regarding data transfer at the final step of the purchase process, prior to redirection to the payment page. (25) According to the Company, as part of its cooperation with […] (hereinafter: […]), following a purchase, it transmits the customer’s email address, as well as the name and identification number of the purchased product, to […].
According to the Company, the purpose of the data transfer is to enable […] to contact the customer regarding a purchase review, and based on the reviews collected in this manner, the […] online store may gain or lose its “trusted store” rating on the […] platform. According to the Company’s statement, to the best of its knowledge, […] does not use the personal data received in this manner for any purpose other than requesting feedback. The Company further indicated that it intends to review the terms of the cooperation again during the review of its data processing documents. (26) The Company stated that in 2022, […] offered to provide advertising services to the Company, and a testing process was initiated to evaluate the potential use of these services. According to the Company, the testing was unsuccessful; therefore, no service agreement was concluded between the parties, and […] did not actually perform any data control or data processing 7 activities for the Company.
The Company asserts that it is likely that […] was listed in the Prospectus even during the testing period, in preparation for potential future cooperation. The Company further indicated that it will remove references to […] during the review of the Prospectus. ” The Company acknowledged that the use of English-language abbreviations without explanation does not promote transparent disclosure, and further indicated that the references, in their current form, are not always well-founded. S. Data Privacy Framework. The Company indicated that, during the review of the Privacy Notice, it intends to amend the information regarding data transfers to third countries. ”) is intended to convey that if the data subject does not provide the necessary personal data, the specific purpose of data processing cannot be achieved. According to the Company, for example, in the absence of the data necessary for a purchase and related communication, it is not possible to complete the purchase, while in the case of certain services—such as sending newsletters—failure to provide the data will result in the inability to use the service in question.
According to the Company’s statement, it strives to require users to provide only the data necessary for the provision of the service on a mandatory basis. (29) In its statement, the Company explained that it had previously taken measures regarding the processing of data related to cookies used on the Website, about which it had informed the Authority in connection with the notice bearing case number NAIH/11301-2/2025. The Company noted that, according to the Authority’s notification dated November 26, 2025, it had taken the necessary measures and submitted the documents verifying their implementation to the Authority. According to the Company’s statement, it maintains the arguments presented in the previous case in the present proceedings as well, and requested that the Authority take into account the information provided and verified in that case in the present proceedings as well. (30) According to the Company’s statement, it has not been accepting incoming phone calls since March 2025; the customer service system directs interested parties to use the online contact form.
Prior to this, for incoming calls, a voice message played during the hold time informed the caller that the conversation was being recorded for quality assurance purposes and that a copy of the recording could be provided free of charge upon request; the message also stated that if the caller did not consent to the recording, an online contact option was available. The Company further stated that, by default, it retained recorded calls for 180 days. According to the Company, for outgoing calls, the operator provided information about the recording at the start of the conversation; however, it was also possible, at the caller’s request, to have the call returned via a line that was not recorded. (31) According to the Company, when drafting the Notice, it decided to present information regarding data subjects’ rights in a condensed form due to space constraints. The Company acknowledged that an adequate explanation of data subjects’ rights is a fundamental requirement of the GDPR; therefore, during the review of the Notice, it intends to ensure a more detailed presentation of these rights that meets the legal 8 requirements.
The Company further stated that the number of cases in which data subjects exercised their rights was low, and that it handled such requests in every instance in accordance with the data subjects’ needs. (32) The Company stated that the wording in Section 12 of the Privacy Notice is incorrect, as data subjects are entitled to information not only regarding the purpose and legal basis of data processing. The Company acknowledged that data subjects are entitled to access all information specified in Article 15 of the GDPR. 2 of the Privacy Notice is incorrect, and it does not intend to maintain it in the future. The Company stated that the conditions set forth in Article 12 of the GDPR , under which the data controller may charge a reasonable fee, taking into account the circumstances of the case, or may refuse to take action if the request is manifestly unfounded or—in particular due to its repetitive nature—excessive.
, the exercise of official authority. According to the Company, this legal basis is not applied; therefore, the relevant reference will be removed during the review of the Privacy Notice. (35) The Company indicated that the Prospectus’s current structure does not fully meet the transparency requirement, as while the information is included, it is not always presented in a way that is easily comprehensible and understandable to the relevant parties. The Company explained that its goal in revising the Privacy Notice is to create a document with a clearer, more logical structure and language that is easy to understand. It further stated that, in its view, the nature of its data processing activities is generally known to online shoppers; however, it strives to provide information in the future that presents its data processing practices in a way that is unambiguous to data subjects and reinforces their sense of security.
(36) The Company states that it cannot provide a substantive explanation for the large number of typos and confusing errors in the Privacy Notice, and believes that these can be attributed to a lack of due diligence in reviewing the document. The Company further indicated that it will immediately begin reviewing the Privacy Notice and, as part of that process, will correct the identified errors, omissions, and inaccuracies. (37) The Company explained that the phrase “by participating, you expressly accept” in the first sentence of the Privacy Notice dated September 1, 2023 […] regarding the sweepstakes conducted in cooperation with its Partners, as well as the phrase “gives their express consent,” reflect a previously applied practice whereby an interaction initiated by the user—such as clicking the “Enter” button—was interpreted by the service providers as acceptance of the terms of participation and consent to data processing.
The Company indicated that this approach is inadequate in its current form and plans to amend it during the review of the relevant documents to ensure that data processing is transparent and lawful. (38) The Company stated that the “Privacy Statement” referred to in Section 2 of the information notice regarding this sweepstakes is available on the […] page, where, in addition to the general data processing notice, the data processing notice for sweepstakes is also available. According to the Company, users can return to the prize contest data processing notice from the referenced page. The Company further explained that, in its view, all information related to the specific data processing purpose must be provided in one place, and cross-references or click-throughs do not promote transparent disclosure of information; therefore, 9 during the review of the relevant documents, it intends to amend the sweepstakes privacy notice accordingly.
(39) According to the Company’s report, the number of data subjects participating in the sweepstakes during the period under review was as follows: […] people in 2020, […] people in 2021, […] people in 2022, […] people in 2023, […] people in 2024, and […] people in 2025. (40) According to the Company, it publishes the winners of the sweepstakes on social media platforms ([…], […]), listing only the winner’s first name, in order to reinforce the credibility of the sweepstakes. According to the Company’s statement, no other personal data is disclosed. It further stated that, to its knowledge, no objections or requests for deletion were received from the winners either before or after the publication, and users did not question the credibility of the sweepstakes. (41) In order to clarify the facts of the case, the Authority requested that the Company verify the privacy notice used on the Blog during the period under review, as well as to submit previous versions of the Data Processing and Privacy Notice and the General Terms and Conditions, including their effective dates, publication dates, and any amendments, and to confirm their availability.
In its statement, the Company identified the Data Processing and Privacy Notice, which is currently available on the Blog and effective as of September 2, 2022, as well as the Blog Terms and Conditions of Use document, effective as of September 2, 2022, and confirmed their availability by providing web links. (42) The Company explained that, in order to enable users to post comments on the Blog, it requested that users provide their name and email address so that it could apply a minimal filter against anonymous comments. 1 of the Blog’s Data Processing and Privacy Notice—until the data subject withdraws their consent— means that comments and the personal data associated with them are retained for as long as the comment remains available on the website, and in the event of withdrawal of consent, they will be deleted along with the comment. 2 and plans to amend it during the review of the Blog’s Data Processing and Privacy Notice.
(43) The Company stated that it does not directly transfer personal data to a third country in the course of operating the Blog; however, it uses solutions provided by third-party service providers to improve the user experience and measure traffic. The Company explained that these service providers place cookies on users’ devices—with the exception of necessary cookies—based on the user’s consent, through which data processing may take place. The Company further indicated that its goal is the continuous development of its services and the improvement of the user experience. (44) The Company explained that, with regard to cookie management on the Blog, it has implemented the […] solution used on the Website. According to its statement, the cookie banner was last updated on November 26, 2025, at which time the Company changed the previously English-language information to Hungarian and began clarifying the related information and correcting the links.
The Company indicated that the development of information and settings related to cookie management is ongoing and is expected to be completed by December 31, 2025. 6 of the Blog’s Data Processing and Privacy Notice has not been applied in practice. The Company further indicated that, during the review of the Blog’s Data Processing and 10 Privacy Notice, it intends to amend this provision in accordance with the requirements set forth in Article 12 of the GDPR. ) . According to the Company, this is an incorrect approach, and it intends to correct it during the review of the Blog Data Processing and Privacy Notice by including a reference to the GDPR and explaining its provisions. 1 of the Blog Data Processing and Privacy Policy as reflecting a data controller’s perspective, according to which the data controller’s activities—within certain limits—may also be influenced by the decisions of the data protection authority.
At the same time, the Company pointed out that, in its view, the fact of cooperation between the data controller and the authority, as well as activities carried out to ensure the protection of fundamental rights, are not circumstances that would justify their inclusion in the Blog Data Processing and Privacy Policy; therefore, it plans to delete this provision during the review of the document. (48) According to the Company, the reason for providing information on data processing in two separate documents is to ensure that Blog visitors receive information exclusively about the data processing activities carried out on the Blog. It stated that, in its view, there is no justification for burdening Blog users with details of the data processing activities conducted on the Website, given the different functions of the two platforms, the different services they offer, and the partially different user bases.
According to the Company, given the limited nature of the data processing activities on the Blog, providing this information in a separate document ensures that data subjects receive a purpose-specific explanation of the relevant information. (49) The Company attached the following documents to its response: • Appendix 1: Personal Data Form; • Appendix No. zip compressed folder titled “Reference Documents” (Data Protection Documents, Contracts). (50) In its order dated January 12, 2026, case number NAIH-450-1/2026, the Authority requested the Company to submit a further statement in order to clarify the facts of the case. pdf” had been included twice among the attachments by mistake. The Company stated that, in addition, it had also submitted three data processing notices related to prize contests. According to the Company’s statement, it submitted a total of 21 version control forms as attachments to this statement—19 of which relate to the Website and 2 to the prize contests—and also attached the forms for those documents for which no new versions had been issued.
(52) The Company explained that data transfers related to the […] payment service are a necessary part of the transaction; data transfers under the […] “Trusted Store” program serve to collect customer reviews; and […] acts solely as a data processor for the purpose of sending newsletters. The Company stated that no cooperation was established with […], and therefore no data transfer took place. The Company further explained that the use of major technology platforms is intended to optimize advertisements, which 11 it considers necessary for the operation of the service and beneficial to users. According to its statement, it has sought to minimize the scope of data transfers and to ensure that data flow processes remain transparent and limited. The Company indicated that it continuously reviews its practices and documentation regarding data transfers. (53) The Company explained that, starting in April 2021, it has been using a cookie management solution provided by the […] service provider on its Website, which automatically manages and displays the type, purpose, duration, and owner of the cookies used.
It stated that the cookie panel allows users to accept, reject, or customize cookies, and that cookies requiring consent are placed only after the data subject has given their consent. According to the Company, […] prepares regular reports on the cookies used; based on these reports, the most recent change took place on December 3, 2025, when a feature was introduced that allows only essential cookies to be used. The Company further indicated that detailed information regarding cookie management is provided through the cookie panel, as well as the cookie notice and the privacy policy available on the Website, and that it uses […] to ensure that cookies requiring consent are used only with the user’s prior consent. (54) According to the Company’s report, the number of visitors to the Website during the period under review was as follows: […] in 2021, […] in 2022, […] in 2023, […] in 2024, and […] in 2025.
(55) In response to the Authority’s request, the Company stated that the content of the Blog’s Data Processing and Privacy Notice has not changed since the site’s launch on September 2, 2022. According to the Company, a review of this document has begun and is currently underway as part of this proceeding. In light of this, the Company attached a version control form pertaining to the referenced document. (56) The Company stated that it did not use the […] service, while the use of […] began following the website’s launch on September 2, 2022. The Company explained that, prior to the entry into force of the Data Privacy Framework, data transfers to the United States were based on the Standard Contractual Clauses adopted by the European Commission and used by […], which it considered to be an appropriate safeguard under Article 46 of the GDPR. It stated that, following the determination of […]’s adequacy under the Data Privacy Framework, the legal basis for data transfers changed to Article 45(1) of the GDPR.
According to the Company, data subjects were informed in advance via the cookie panel and the Blog’s Data Processing and Privacy Notice. (57) The Company stated that, as of September 2, 2022, it has been using the […] system to operate the Blog, within which it utilized the […] plugin to manage cookies. According to the Company, this solution provided users with information about the types and functions of the cookies used and allowed them to accept or reject them. The Company indicated that it had made a separate document available regarding its cookie management practices prior to November 26, 2025, but does not have any more detailed information than that. As of November 26, 2025, the Blog also uses the […] service, which provides standardized information regarding the types, purposes, duration, and management of cookies, as well as the option for users to grant, reject, or adjust their consent.
According to the Company, its cookie management practices have not changed since then, and information is provided to users via the cookie panel. 12 (58) According to the Company, the number of visitors to the Blog during the period under review was as follows: […] in 2022, […] in 2023, […] in 2024, and […] in 2025. (59) The Company emphasized that the data processing procedures and practices it has established were developed in connection with the operation of the online store and marketplace, and any changes made to them were also aligned with these operations. The Company also indicated that it has begun reviewing its data processing documents in order to provide more accurate and transparent information to data subjects. The Company also pointed out that the number of requests from data subjects for data erasure has been low in recent years, which, in its view, indicates the satisfaction of data subjects.
The Company further requested that the Authority take into account, during the proceedings, its efforts to improve data protection documents and ensure lawful data processing. ” (61) In its order dated March 13, 2026, case no. NAIH-450-4/2026, the Authority requested the Company to submit a further statement in order to clarify the facts of the case. pdf” was submitted with an incorrect filename. According to its statement, the document in question was in fact in effect between June 9, 2020, and October 20, 2020, which corresponds to the validity period of the other document previously submitted, and this was correctly indicated on the version verification form sent later. The Company also attached the privacy notice in effect between October 21, 2020, and November 9, 2020, which it made available to the Authority as an annex to this statement. pdf” was incorrect due to an administrative error.
According to its statement, the document was actually in effect between November 10, 2020, and July 14, 2021, a period that was correctly indicated on the submitted version verification form. The Company also indicated that it does not have a separate privacy policy in effect as of January 22, 2021; however, it attached the document used during that period as an appendix to this statement. (64) According to the Company’s statement, the privacy notice related to the sweepstakes dated May 16, 2022, was in effect until August 30, 2023, after which it was replaced, effective September 1, 2023, by the privacy notice currently in use for prize draws organized in cooperation with […] and its partners. The Company further stated that no further amendments were made to this document, and no new version was created. (65) According to the Company’s statement, with regard to the Blog Data Processing and Privacy Notice and the Blog General Terms and Conditions, only the documents currently available on the website have been prepared and published; no earlier versions of these were created.
(66) In its statement, the Company explained that it verifies the requested CMS-based version history using database extracts and screenshots from its proprietary system, which record the creation date, validity 13 period, and version history of each document. Furthermore, regarding the privacy notices related to the sweepstakes, the Company intended to substantiate the dates of storage and publication of the documents with data derived from the server-side file structure. Regarding the Blog, the Company stated that the publication date displayed on the […] administrative interface (October 1, 2021) does not reflect the actual publication date, but rather the date the system was installed, while the Blog actually launched on June 28, 2022, when the privacy notice was also published; however, the system did not record this date. The Company further indicated that user activity related to the Blog was low.
png (68) In its order No. NAIH-450-6/2026 dated April 9, 2026, the Authority informed the Company that the evidentiary proceedings had been concluded and that, subject to the rules governing access to documents, the Company may review the evidence uncovered during the clarification of the facts and may submit further motions for evidence. (69) The Company did not state whether it intended to exercise its right to inspect the documents, nor did it submit any further motions for evidence. 2. 1. Identity of the Data Controller (70) The Company is the operator of the Website and the domain user. In the Privacy Notice, it identifies itself as the data controller, while it indicates that it acts as a joint data controller with respect to certain partners. ” (72) Pursuant to Section 3 of Act XXXIV of 2004 on Small and Medium-Sized Enterprises and the Support of Their Development, a medium-sized enterprise is defined as an enterprise with a total workforce of fewer than 250 employees and annual net sales revenue not exceeding the forint equivalent of 50 million euros, or a balance sheet total not exceeding the forint equivalent of 43 million euros.
According to the Company’s annual report, in 2024 it employed […] people and had annual net sales of […] HUF, based on which—according to the available data—it qualifies as a medium-sized enterprise. 2. The Website’s Data Processing Documents (73) With regard to the period under review, the Authority examined the Privacy Notice published on the Website and effective as of July 2, 2025, as well as the documents submitted by the Company (previous versions of the Website Privacy Statement, information related to the Sweepstakes, the Blog Data Processing and Privacy Notice, and the Blog Terms and Conditions of Use) as well as the documents generated during the on-site inspection and included in Record No. NAIH-9706-2/2025. 14 (74) The Authority identified three main versions of the Website Notices submitted by the Company for the period under review; within these versions, additional variants—which were not considered separate versions but rather modifications to the given version—could also be distinguished, and the Authority also examined the changes in their content: - The first version is the Privacy Policy in effect from May 24, 2018, through January 31, 2020 (hereinafter: Notice No.
1). 1. 2. 3. 4. 5. 6. 7. Notice). - The second version is the Privacy Policy effective from July 15, 2021, through April 6, 2022 (hereinafter: Notice No. 1. 2. 3. 4. 5. Notice). - The third version is the Data Processing Notice effective from May 24, 2023, through September 8, 2024 (hereinafter: Notice No. 2). II. Applicable Legal Provisions (75) Pursuant to Article 2(1) of the General Data Protection Regulation, the General Data Protection Regulation applies to the processing of personal data, whether fully or partially automated, as well as to the non-automated processing of personal data that forms part of a filing system or is intended to form part of a filing system. (76) Pursuant to Section 2(2) of the Information Act, the General Data Protection Regulation shall apply, subject to the additions specified in the provisions cited therein. 15 (77) Pursuant to Section 38(2) of the Information Act, the Authority is responsible for monitoring and promoting the protection of personal data, as well as the right of access to data of public interest and data made public in the public interest, and for facilitating the free flow of personal data within the European Union.
(78) Pursuant to Section 38(2a) of the Information Act, the Authority exercises the tasks and powers established for the supervisory authority in the General Data Protection Regulation with respect to legal entities subject to Hungarian jurisdiction, as specified in the General Data Protection Regulation and this Act. (79) Pursuant to Section 38(3)(b) of the Information Act, within the scope of its responsibilities under Sections 38(2) and (2a), the Authority shall, in particular, conduct data protection proceedings at the request of the data subject or on its own initiative, as specified in this Act. (80) Pursuant to Section 60/A(1) of the Information Act, the administrative deadline for data protection authority proceedings is one hundred fifty days. (81) Pursuant to Section 60(1) of the Information Act, in order to ensure the enforcement of the right to the protection of personal data, the Authority shall initiate a data protection proceeding upon the data subject’s request to that effect and may initiate such a proceeding ex officio.
) , the Authority—within the scope of its jurisdiction—monitors compliance with the provisions set forth in the law, as well as the fulfillment of the terms of enforceable decisions. , in ex officio proceedings, the provisions of this Act applicable to proceedings initiated upon request shall apply, subject to the exceptions set forth in this chapter. ” (90) According to Article 6(1) of the General Data Protection Regulation: “The processing of personal data is lawful only if and to the extent that at least one of the following applies: a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes; b) the processing is necessary for the performance of a contract to which the data subject is a party, or for taking steps at the request of the data subject prior to entering into a contract; c) the processing is necessary for compliance with a legal obligation to which the controller is subject; d) the processing is necessary to protect the vital interests of the data subject or of another natural person; e) the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller; f) the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject that require the protection of personal data, in particular where the data subject is a child.
” (91) According to Article 7(3) of the General Data Protection Regulation: “The data subject has the right to withdraw consent at any time. Withdrawal of consent shall not affect the lawfulness of processing based on consent prior to its withdrawal. The data subject must be informed of this before consent is given. ” (92) Pursuant to Article 12(1)–(6) of the General Data Protection Regulation: “(1) The controller shall take appropriate measures to ensure that the data subject is provided with all information regarding the processing of personal data referred to in Articles 13 and 14, as well as all information referred to in Articles 15–22 and 34, in a concise, transparent, intelligible, and easily accessible form, using clear and plain language, particularly in the case of any information addressed to children. The information must be provided in writing or by other means, including, where appropriate, by electronic means.
” (93) According to Article 13 of the General Data Protection Regulation: “(1) Where personal data relating to a data subject are collected from the data subject, the controller shall, at the time of collection, provide the data subject with all of the following information: a) the identity and contact details of the controller and, where applicable, the controller’s representative; b) the contact details of the data protection officer, if any; c) the purposes of the intended processing of personal data and the legal basis for the processing; d) in the case of processing based on Article 6(1)(f), the legitimate interests of the data controller or a third party; e) where applicable, the recipients of the personal data or categories of recipients, if any; f) where applicable, the fact that the controller intends to transfer personal data to a third country or to an international organization, as well as the existence or absence of an adequacy decision by the Commission, or, in the case of data transfers referred to in Article 46, Article 47, or the second subparagraph of Article 49(1), the 17 appropriate and suitable safeguards, as well as a reference to the means of obtaining copies of them or to their availability.
(2) In addition to the information referred to in paragraph (1), the data controller shall, at the time the personal data are collected, in order to ensure fair and transparent processing, provide the data subject with the following additional information: a) the period for which the personal data will be stored, or, if that is not possible, the criteria used to determine that period; b) the data subject’s right to request from the controller access to and rectification or erasure of personal data concerning him or her, or restriction of processing, and to object to the processing of such personal data, as well as the data subject’s right to data portability; c) in the case of data processing based on Article 6(1)(a) or Article 9(2)(a), the right to withdraw consent at any time, which does not affect the lawfulness of the data processing carried out on the basis of consent prior to withdrawal; d) the right to lodge a complaint with a supervisory authority; e) whether the provision of personal data is required by law or a contractual obligation, or is a prerequisite for entering into a contract, whether the data subject is required to provide the personal data, and the possible consequences of failing to provide such data; f) the fact of automated decision-making referred to in Article 22(1) and (4), including profiling, as well as, at least in these cases, the logic applied and comprehensible information regarding the significance of such processing and the expected consequences for the data subject.
(3) If the controller intends to carry out further processing of personal data for a purpose other than that for which the data were collected, the controller must inform the data subject of that different purpose and of all relevant additional information referred to in paragraph (2) prior to such further processing. ” (94) According to Article 14 of the General Data Protection Regulation: “(1) Where personal data have not been obtained from the data subject, the controller shall provide the data subject with the following information: a) the identity and contact details of the controller and, where applicable, the controller’s representative; b) the contact details of the data protection officer, if any; c) the purpose of the intended processing of the personal data and the legal basis for the processing; d) the categories of personal data concerning the data subject; e) the recipients of the personal data or, where applicable, the categories of recipients; f) where applicable, the fact that the controller intends to transfer the personal data to a recipient in a third country or to an international organization, as well as the existence or absence of an adequacy decision by the Commission, or, in the case of a transfer referred to in Article 46, Article 47, or the second subparagraph of Article 49(1), as well as a reference to the means of obtaining copies of such safeguards or to their availability.
(2) In addition to the information referred to in paragraph (1), the data controller shall provide the data subject with the following supplementary information necessary to ensure fair and transparent data processing with respect to the data subject: a) the period for which the personal data will be stored, or, if that is not possible, the criteria used to determine that period; b) if the processing is based on Article 6(1)(f), the legitimate interests of the controller or a third party; c) the data subject’s right to request from the controller access to and rectification or erasure of personal data concerning him or her, or restriction of processing, and to object to the processing of personal data, as well as the data subject’s right to data portability; 18 d) in the case of data processing based on Article 6(1)(a) or Article 9(2)(a), the right to withdraw consent at any time, which does not affect the lawfulness of the data processing carried out on the basis of consent prior to withdrawal; e) the right to lodge a complaint with a supervisory authority; f) the source of the personal data and, where applicable, whether the data is derived from publicly available sources; and g) the fact of automated decision-making, including profiling, referred to in Article 22(1) and (4), and, at least in those cases, the logic applied and meaningful information regarding the significance of such processing and the expected consequences for the data subject.
(3) The data controller shall provide the information referred to in paragraphs (1) and (2) as follows: a) taking into account the specific circumstances of the processing of personal data, within a reasonable period of time from the collection of the personal data, but no later than one month; b) if the personal data are used for the purpose of contacting the data subject, at least at the time of the first contact with the data subject; or c) if the data is expected to be disclosed to other recipients, no later than the first time the personal data is disclosed. (4) If the data controller intends to carry out further processing of personal data for a purpose other than that for which the data were collected, the data controller must inform the data subject of this different purpose and of all relevant additional information referred to in paragraph (2) prior to such further processing.
(5) Paragraphs (1) through (4) do not apply if and to the extent that: a) the data subject already has the information; b) the provision of the information in question proves impossible or would involve a disproportionate effort, in particular for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes; in the case of data processing carried out in accordance with the conditions and safeguards set forth in Article 89(1), or where the obligation referred to in paragraph (1) of this Article would be likely to render impossible or seriously jeopardize the achievement of the purposes of such data processing. ” (95) According to Article 15 of the General Data Protection Regulation: (1) The data subject has the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where such processing is taking place, the right to access the personal data and the following information: a) the purposes of the processing; b) the categories of personal data concerning the data subject; c) the recipients or categories of recipients to whom the personal data have been or will be disclosed, including, in particular, recipients in third countries or international organizations; d) where applicable, the envisaged period for which the personal data will be stored, or, if that is not possible, the criteria used to determine that period; e) the data subject’s right to request from the controller the rectification, erasure, or restriction of processing of personal data concerning him or her, and to object to the processing of such personal data; f) the right to lodge a complaint with a supervisory authority; g) if the data were not collected from the data subject, any available information regarding their source; 19 h) the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4), and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.
(2) Where personal data are transferred to a third country or to an international organization, the data subject has the right to be informed of the appropriate safeguards pursuant to Article 46 regarding the transfer. (3) The data controller shall provide the data subject with a copy of the personal data undergoing processing. For any additional copies requested by the data subject, the data controller may charge a reasonable fee based on administrative costs. If the data subject submitted the request electronically, the information must be provided in a commonly used electronic format, unless the data subject requests otherwise. ” (96) According to Article 18 of the General Data Protection Regulation: “(1) The data subject has the right to obtain from the controller restriction of processing upon request if any of the following applies: a) the data subject contests the accuracy of the personal data; in this case, the restriction shall apply for a period enabling the controller to verify the accuracy of the personal data; b) the processing is unlawful, and the data subject opposes the erasure of the data and requests the restriction of its use instead; c) the data controller no longer needs the personal data for the purposes of processing, but the data subject requires it to establish, exercise, or defend legal claims; or d) the data subject has objected to the processing pursuant to Article 21(1); in this case, the restriction applies for as long as it remains to be determined whether the controller’s legitimate grounds override those of the data subject.
(2) If the processing is restricted pursuant to paragraph (1), such personal data may be processed—with the exception of storage—only with the data subject’s consent, or for the establishment, exercise, or defense of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of an important public interest of the Union or of a Member State. ” (97) Pursuant to Article 22 of the General Data Protection Regulation: “(1) The data subject shall have the right not to be subject to a decision based solely on automated processing—including profiling—that produces legal effects concerning him or her or similarly significantly affects him or her. (2) Paragraph (1) shall not apply if the decision: a) is necessary for the conclusion or performance of a contract between the data subject and the data controller; b) is permitted by Union or Member State law applicable to the data controller, which also provides for appropriate measures to safeguard the data subject’s rights, freedoms, and legitimate interests; or c) is based on the data subject’s explicit consent.
(3) In the cases referred to in points (a) and (c) of paragraph (2), the controller shall take appropriate measures to safeguard the data subject’s rights, freedoms, and legitimate interests, including at least the right of the data subject to request human intervention by the controller, to express his or her point of view, and to contest the decision. ” 20 (98) Pursuant to Article 26(2) of the General Data Protection Regulation: “(2) The agreement referred to in paragraph (1) shall set out the roles of the joint controllers in relation to data subjects and their relationship with them. ” (99) According to Article 37 of the General Data Protection Regulation: “(1) The controller and the processor shall designate a data protection officer in any case where: a) data processing is carried out by public authorities or other bodies performing public tasks, with the exception of courts acting in their judicial capacity; b) the core activities of the data controller or data processor involve data processing operations which, by virtue of their nature, scope, and/or purposes, require the regular and systematic monitoring of data subjects on a large scale; c) the core activities of the controller or processor involve the processing of special categories of personal data as defined in Article 9 and data relating to criminal convictions and offenses referred to in Article 10 on a large scale.
(2) The group of companies may also designate a single data protection officer if that officer is easily accessible from all locations where the group operates. (3) If the data controller or data processor is a public authority or another body performing public functions, a joint data protection officer may be appointed for several such bodies, taking into account the organizational structure and size of the bodies in question. (4) In cases other than those set forth in paragraph (1), the data controller or data processor, or associations and other organizations representing categories of data controllers or data processors, may appoint a data protection officer, or, if required by Union or Member State law, are required to appoint one. The data protection officer may act on behalf of such associations and other organizations representing data controllers or data processors. (5) The data protection officer shall be designated on the basis of professional competence and, in particular, expert-level knowledge of data protection law and practice, as well as suitability to perform the tasks referred to in Article 39.
(6) The data protection officer may be an employee of the data controller or the data processor, or may perform his or her duties under a service contract. ” (100) According to Article 45 of the General Data Protection Regulation: “(1) Personal data may be transferred to a third country or to an international organization if the Commission has determined that the third country, a territory or one or more specified sectors within that third country, or the international organization in question ensures an adequate level of protection. No specific authorization is required for such data transfers. (2) In assessing the adequacy of the level of protection, the Commission shall take into account, in particular, the following factors: a) the rule of law, respect for human rights and fundamental freedoms, relevant general and sector-specific legislation, including provisions on public security, defense, and national security, as well as criminal law provisions; provisions governing public authorities’ access to personal data; and the enforcement of such legislation; data protection rules, professional rules, and security measures, including rules governing the onward transfer of personal data to another third country or international organization that must be complied with within that country or international organization; case law, as well as whether the data subjects whose personal data are being transferred have effectively enforceable rights, including effective administrative and judicial remedies; b) whether there is one or more independent and effective supervisory authorities in the third country in question—and whether the international organization in question is subject to the supervision of such an authority—that is responsible for ensuring compliance with data protection rules 21 and enforcement, possesses, among other things, appropriate enforcement powers, and is responsible for providing assistance and advice to data subjects regarding the exercise of their rights, as well as for cooperating with the supervisory authorities of the Member States; furthermore, c) the international obligations of the third country or international organization in question, or its obligations arising from other legally binding agreements or legal instruments, as well as from its participation in multilateral or regional systems—in particular those relating to the protection of personal data.
(3) Following an assessment of the adequacy of the level of protection, the Commission may, by means of implementing acts, determine that a third country, a territory of a third country, or one or more specified sectors thereof, or an international organization, ensures an adequate level of protection within the meaning of paragraph (2). The implementing act shall provide for a mechanism for periodic review, to be carried out at least every four years, taking into account all relevant developments in the third country or international organization concerned. The implementing act shall specify its territorial and sectoral scope of application and, where applicable, designate the supervisory authority or authorities referred to in paragraph 2(b). The implementing act shall be adopted in accordance with the examination procedure referred to in Article 93(2). (4) The Commission shall keep under review developments in third countries and international organizations that may affect the implementation of paragraph 3 of this Article and of decisions adopted pursuant to Article 25(6) of Directive 95/46/EC.
(5) The Commission shall determine, on the basis of the available information, in particular the review referred to in paragraph 3 of this Article, whether a third country, a territory, or a specific sector of a third country, or an international organization no longer ensures an adequate level of protection within the meaning of paragraph 2 of this Article, and, to the extent necessary, repeal, amend, or suspend the previous decision referred to in paragraph 3 of this Article by means of an implementing act, without retroactive effect. Such implementing acts shall be adopted in accordance with the examination procedure referred to in Article 93(2). In duly justified cases of extreme urgency, the Commission shall adopt immediately applicable implementing acts in accordance with the procedure referred to in Article 93(3). (6) The Commission shall initiate consultations with the third country or international organization regarding the resolution of the situation leading to the decision referred to in paragraph (5).
(7) A decision pursuant to paragraph (5) shall not affect the transfer of personal data to the third country, a territory within a third country, or one or more specified sectors thereof, or to the international organization in question, pursuant to Articles 46–49. (8) The Commission shall publish in the Official Journal of the European Union and on its website a list of third countries, territories within third countries, and specific sectors, as well as international organizations, for which it has determined that they do or no longer ensure an adequate level of protection. ” (101) According to Article 46 of the General Data Protection Regulation: “(1) In the absence of a decision pursuant to Article 45(3), the controller or processor may transfer personal data to a third country or an international organization only if the controller or processor has provided appropriate safeguards, and only on condition that enforceable rights and effective legal remedies are available to data subjects.
(2) Without specific authorization from the supervisory authority, the appropriate safeguards referred to in paragraph (1) may consist of the following: 22 a) a legally binding and enforceable legal instrument between public authorities or other bodies performing public functions; b) binding corporate rules pursuant to Article 47; c) general data protection clauses adopted by the Commission in accordance with the examination procedure referred to in Article 93(2); d) standard data protection clauses adopted by a supervisory authority and approved by the Commission in accordance with the examination procedure referred to in Article 93(2); e) an approved code of conduct pursuant to Article 40, together with a binding and enforceable commitment by the data controller or data processor in a third country to apply appropriate safeguards, including those relating to the rights of data subjects; or f) an approved certification mechanism pursuant to Article 42, together with a binding and enforceable commitment by the data controller or data processor in a third country to apply appropriate safeguards, including with respect to the rights of data subjects.
(3) With the authorization of the competent supervisory authority, the following, in particular, may serve as appropriate safeguards referred to in paragraph (1): a) contractual provisions between the controller or processor and the controller, processor, or recipient of personal data in the third country or within the international organization; or b) provisions to be incorporated into an administrative agreement between public authorities or other bodies performing public tasks, including provisions regarding the enforceable and effective rights of data subjects. (4) In the cases referred to in paragraph 3 of this Article, the supervisory authority shall apply the consistency mechanism referred to in Article 63. (5) Authorizations issued by a Member State or a supervisory authority pursuant to Article 26(2) of Directive 95/46/EC shall remain in force until, where necessary, the supervisory authority amends, replaces, or revokes them.
” (103) Pursuant to Article 83(2) and (5) of the General Data Protection Regulation: “[…] (2) Administrative fines shall be imposed, in addition to or in lieu of the measures referred to in points (a) through (h) and (j) of Article 58(2), depending on the circumstances of the case. When determining whether an administrative fine is necessary, or when 23 determining the amount of the administrative fine, due consideration must be given in each individual case to the following: a) the nature, severity, and duration of the violation, taking into account the nature, scope, or purpose of the data processing in question, as well as the number of data subjects affected by the violation and the extent of the harm they have suffered; b) whether the violation was intentional or negligent; c) any measures taken by the data controller or data processor to mitigate the damage suffered by the data subjects; d) the extent of the data controller’s or data processor’s liability, taking into account the provisions of Articles 25 and 32; e) any relevant prior infringements committed by the controller or the processor; f) the extent of cooperation with the supervisory authority to remedy the infringement and mitigate any negative effects of the infringement; g) the categories of personal data affected by the breach; h) the manner in which the supervisory authority became aware of the infringement, with particular regard to whether the controller or processor reported the infringement and, if so, in what detail; i) if any of the measures referred to in Article 58(2) had previously been imposed on the data controller or data processor in question—in the same matter—compliance with those measures; j) whether the data controller or data processor has complied with approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42; and k) other aggravating or mitigating factors relevant to the circumstances of the case, such as financial gain or avoided loss resulting directly or indirectly from the infringement.
[…] (5) Violations of the following provisions shall be subject—in accordance with paragraph (2)—to an administrative fine of up to EUR 20,000,000 or, in the case of undertakings, up to 4% of their total worldwide annual turnover in the preceding financial year, whichever of the two amounts is higher: a) the principles of data processing—including the conditions for consent—in accordance with Articles 5, 6, 7, and 9; b) the rights of data subjects in accordance with Articles 12–22; c) the transfer of personal data to a recipient in a third country or to an international organization in accordance with Articles 44–49; d) the obligations under Member State law adopted pursuant to Chapter IX; e) failure to comply with an instruction from the supervisory authority pursuant to Article 58(2), or with a request to temporarily or permanently restrict data processing or suspend data flows, or failure to grant access in violation of Article 58(1).
[…]” (104) Pursuant to Article 5(3) of Directive 2002/58/EC of the European Parliament and of the Council of July 12, 2002, concerning the processing of personal data and the protection of privacy in the electronic communications sector (“Electronic Communications Privacy Directive”): “Member States shall ensure that the storage of data in a subscriber’s or user’s terminal equipment, or access to data stored therein, is permitted only on condition that the subscriber or user concerned has given his or her prior consent on the basis of clear and comprehensive information provided in accordance with Directive 95/46/EC, including information on the purposes of the data processing. ” 24 III. 1. The Requirement for Prior Notice of Data Processing (105) The purpose of the information obligations set forth in Articles 12–14 of the General Data Protection Regulation (GDPR) is to ensure that the data subject can learn in advance about the manner and circumstances of the processing of their personal data and can monitor the processing throughout its entire duration.
The GDPR ensures this in several ways and regulates the right to information. These rights enable data subjects to review data processing even before it begins, to effectively monitor it throughout its entire duration, and to exercise any additional rights they may have or seek legal remedies. (106) The system of appropriate information provided for in the General Data Protection Regulation serves to ensure that the data subject is aware of which of their personal data will be processed, by which data controller, for what purpose, on what legal basis, and for how long. This is essential for the data subject to be in a position to effectively exercise their rights. (107) Pursuant to Article 12(1) of the General Data Protection Regulation, the data controller shall take appropriate measures to provide the data subject with all information regarding the processing of personal data referred to in Articles 13 and 14, as well as all information required under Articles 15–22 and 34, in a concise, transparent, understandable, and easily accessible form, expressed clearly and in plain language.
Incomplete or ambiguous information—particularly, but not exclusively, regarding the purpose and legal basis—may directly affect the data subject’s ability to exercise their rights. (108) Articles 13 and 14 of the General Data Protection Regulation set forth the requirements, content, and specific rules regarding information, based on two perspectives. On the one hand, Article 13 governs the information provided when personal data is collected from the data subject by data controllers, while Article 14 sets forth the rules for situations where personal data is not obtained from the data subject by data controllers. (109) With regard to data processing by online stores, since personal data is collected directly from data subjects, the central element of the obligation to provide information is Article 13(1)–(2) of the General Data Protection Regulation, which lists the essential circumstances of data processing about which the data controller must provide information.
(110) As part of this prior notification, the data controller must strive to ensure that data subjects receive as complete and accurate a picture as possible of the processing of their personal data, as this is the only way for them to assess how a given data processing operation affects them. Article 13(1)–(2) of the General Data Protection Regulation specifies the minimum circumstances of data processing about which data controllers must inform data subjects; however, this does not preclude the data controller from providing more detailed information. 2. 1. The Data Processing Notice System (111) The Authority first determined that the Company’s data processing notice practices during the period under review were not implemented within a uniform, transparent system. Information regarding data processing appeared in several separate documents and on different interfaces, including in the notices related to the Website, in documents related to prize contests, in the data processing notice related to the Blog, and in the data protection provisions of the General Terms and Conditions (GTC) applicable to the Blog.
The Authority 25 considers that it is not objectionable in and of itself for a data controller to use multiple notices tailored to different data processing situations; however, this is subject to the condition that it be clear to the data subject which document applies to which data processing activity and which platform, and that the documents be consistent with one another and their relationship to each other be clearly traceable. The Company’s information system did not meet these requirements. It was not possible to clearly determine from the documents reviewed exactly which data processing activities and which platforms each notice covered. In particular, there was overlap between the privacy notices related to the Website, the Blog Data Processing and Privacy Notice, and the data protection provisions of the Blog’s Terms of Use, while these documents did not form a coherent information system built upon one another.
(112) The Authority emphasizes that the requirement of transparency does not merely mean the formal provision of information, but rather that the data subject must actually be able to understand the essential circumstances of the data processing based on the information provided, specifically the purpose, legal basis, and conditions of data processing, the parties involved in data processing, and the options for exercising their rights. In the Authority’s view, the information system under review did not meet this requirement, as the information regarding data processing appeared in multiple separate documents that followed partially divergent logics. (113) The documents did not refer to one another or did not do so appropriately, and they failed to clarify which information the data subject should consider authoritative in the given data processing situation. In the Authority’s assessment, the overlaps were not merely formal in nature.
Discrepancies were evident among the documents, particularly with regard to the legal bases for data processing, the scope of recipients and data processors, and the description of data transfers. For example, data processing related to the Blog was not governed exclusively by the Blog’s Data Processing and Privacy Notice; the Website’s Notice also included a data processing purpose related to blog registration, and the General Terms and Conditions (GTC) applicable to the Blog also contained privacy provisions. However, these documents did not present the legal basis, recipients, and conditions of data processing according to the same logic, nor did they always present the same content. The Authority further found that the terminology and structure of the documents were inconsistent and, in several cases, did not align with the framework of the GDPR but instead partially reflected the logic of the previous data protection regulations.
In this regard, the Authority specifically noted that, during the period under review, the Company’s privacy notices also referred to data processing based on the exercise of public authority, even though the Company, as an online store engaged in commercial activities, did not actually carry out such data processing. The Company itself stated that it would remove this reference from the privacy notice. (114) The Authority also took into account that the Privacy Notice related to the Website included data processing activities that were not directly related to services provided to Website visitors or online store customers, but rather, for example, to camera surveillance carried out in warehouse, security, or workplace environments. The inclusion of these data processing activities in the Website’s general information further complicated understanding of exactly which group of data subjects and which data processing situations the document applied to.
(115) The Authority also took into account the Company’s statements made during these proceedings, which confirmed the identified shortcomings on several points. ” The Company was also unable to provide a clear explanation 26 regarding the logic behind the structure of the notice and the listing of the various parties involved. (116) In the Authority’s view, the information system structured in this manner did not enable data subjects to easily and effectively understand for what purposes, on what legal basis, with the involvement of which recipients, and under what conditions their personal data were processed when using the given platform or service. The problem, therefore, was not merely that the information appeared in multiple documents, but that these documents could not be properly linked to one another, their content partly overlapped and partly differed, and they did not provide a consistent, transparent picture of the Company’s data processing practices.
(117) In light of all this, the Company violated the principle of transparency set forth in Article 5(1)(a) of the GDPR. 2. 1. Information Notice No. 1, effective as of May 24, 2018 (118) The Authority found that Privacy Notice No. 1, effective as of May 24, 2018, Notice, effective as of May 24, 2018, did not comply with the requirements set forth in Article 12(1) of the GDPR, according to which the data controller is required to provide the data subject with the information specified in Articles 13 and 14 in a concise, transparent, intelligible, and easily accessible form, using clear and plain language. (119) In this regard, the Authority notes that, overall, the structure, language, and conceptual framework of Information Notice No. 1 did not enable the data subject to obtain a clear, internally consistent, and easily understandable picture of the data processing. (120) Already in its introductory section, Notice No.
” In contrast, later sections of the document cited not only consent but also the performance of a contract, a legal obligation, and a legitimate interest as possible legal bases. Thus, even in its basic structure, Information Notice No. 1 did not clearly distinguish between the various data processing situations and gave the impression that the use of the website, as such, constituted general consent to all data processing. (121) The Authority further found that Notice No. 1 did not contain a clear, separate description for each data processing activity from which the data subject could have determined exactly for what purpose, within the framework of what data processing operation, on what legal basis, and for how long the Company processes their specific personal data. The relevant information was scattered throughout Chapters I, III, IV, V, and VI, appearing in some cases repetitively and in others inconsistently.
For example, the document did not clearly state that the customer’s name and address are processed in connection with invoicing and the retention of accounting records, for the purpose of complying with a legal obligation, subject to a specified retention period. Instead, Information Notice No. 1 was based on a general consent framework, while in other sections it also referred to contract performance, legal obligations, and legitimate interests. 6 of Notice No. ” In its 27 ruling, the Authority held that this wording erroneously presented the acknowledgment of the data processing notice as a binding legal acceptance and further reinforced the misleading impression that the use of the service or the conclusion of a contract could be interpreted as general consent to data processing. (123) The conceptual framework of Notice No. 1 also failed to meet the requirement for clear and comprehensible information.
” and subsequently outlined the terminology used in the Info Act. In addition, Chapter I included the following: “Data Processing Registration Number: […]; […]” was also included. In the Authority’s view, given that the Act’s entry into force was contingent upon the GDPR becoming applicable, the conceptual framework based on the Info Act and the emphasis on the previous registration numbers did not convey an information system that was clear, up-to-date, and actually helpful to data subjects in accordance with the GDPR. (124) The Authority notes that, among the data used to identify the data controller, the data controller listed a data processing registration number that no longer exists under current regulations and has no legal significance. Given that the legal institution of the data protection registry maintained by the Authority ceased to exist as of May 25, 2018, the continued use of the registration number is misleading to data subjects, creating the impression that the data processing is listed in some official registry or has undergone official approval.
The Authority notes that even prior to May 25, 2018, the data processing registration number did not certify the lawfulness of data processing; it merely served to identify the data processing in order to facilitate data subjects’ understanding of the matter. Any information in the notice that does not correspond to reality or that relates to a situation that does not correspond to reality must be omitted. For example, information regarding data processing operations that were not actually carried out, legal bases and data subject rights that are not applicable to the data processing in question, and—among other things—information concerning a data protection register that has already been discontinued is unnecessary and misleading and must therefore be deleted in all cases. (125) The Authority also notes that the wording of Information Notice No. 1 was linguistically incorrect, editorially disjointed, repetitive, or incomplete in numerous places.
An example of this is several sections of Chapter X, where the rules regarding the Information Act, the GDPR, the rights of data subjects, and the data controller’s procedures are presented consecutively but not in a consistent logical order. Equally confusing is Section 3 of Chapter XVIII, which incorporates the rule on keeping records of data processing activities in accordance with Article 30 of the GDPR into the text of the privacy notice intended for data subjects without clarifying what function this serves from the data subject’s perspective. (126) In several places, Information Notice No. 1 used legal references and terminology that do not align with the GDPR framework. For example, when describing data security requirements, the notice did not base its information on the system of technical and organizational measures set forth in Article 32 of the GDPR; instead, it referred to the Information Act and described the data security provisions in general terms that were difficult for data subjects to follow.
This further reinforced the conclusion that Notice No. 1 did not follow the modern and clear information structure required by the GDPR. (127) Based on the foregoing, the Authority determined that, due to the overall structure, language, legal reasoning, and, in several instances, contradictory or ambiguous wording of Notice No. 1, the Company had violated Article 12(1) of the GDPR. (128) The Authority found that Notice No. 1 did not provide clear, specific, and identifiable information regarding the legal basis for each data processing activity. 28 (129) According to Section 2 of Chapter III of Privacy Notice No. ” (130) Section 1 of Chapter IV of the 1st Privacy Notice generally provided that data processing related to the operation and services of the Website is based on the data subject’s voluntary consent, while Section 7 of the same chapter already stipulated that the collected personal data may be processed without further separate consent for the purpose of fulfilling the Service Provider’s legal obligations, or to pursue its own or a third party’s legitimate interests, without requiring further separate consent, and even after the user has withdrawn their consent.
In the Authority’s view, these provisions presented the legal basis for data processing in a manner that was inconsistent with one another and were likely to mislead data subjects as to whether the processing of their data was in fact based on consent, the performance of a contract, a legal obligation, or a legitimate interest. (131) In the Authority’s view, these provisions do not make it clear to the data subject which specific data processing activities are based on which specific legal grounds. Information Notice No. 1 lists the legal grounds side by side but does not assign them to specific data processing operations. For example, it is not clear whether consent, performance of a contract, a legal obligation, or a legitimate interest is the actual legal basis for online purchases, invoicing, data transfers to courier services, customer service interactions, reviews, marketing communications, or sweepstakes.
In the absence of this information, the data subject is unable to assess the legal basis on which their personal data is being processed, and consequently, the conditions for exercising their individual rights are not transparent to them. (132) For example, Section 3 of Chapter V defines the scope of data processed during a purchase as follows: “Purchase: Data processed during an online purchase: name, email address, phone number, address … list of purchased products”; however, Privacy Notice No. 1 does not clearly specify the legal basis for this. Similarly, Section VI, Point 4 provides for the transfer of data to […], but it does not clarify the specific legal basis for such data transfer to the data subject. Section V, Paragraph 5, regarding marketing communications, and Section VI, Paragraph 3, already suggest a consent-based approach, but these are not separated from the data processing necessary for the purchase.
(133) Based on the foregoing, the Authority determined that the Company violated its obligation under Article 13 (1)(c) of the GDPR. (134) The Authority found that Information Notice No. 1 did not provide accurate, coherent information regarding the recipients of data transfers or the categories of recipients that was clearly linked to the specific data processing activities. (135) Section 2 of Chapter I of Information Notice No. ” 29 At the same time, Sections 2–3 of Chapter I designate […] as data processors, along with […], […], […], […], and […]. Sections 1–4 of Chapter VIII, however, describe data transfers partly to partners and partly to other recipients, but do not clarify the exact capacity in which each party acts, nor do they specify which specific data processing purposes each data transfer relates to. (136) It is particularly problematic that Section 4 of Chapter VIII of Information Notice No.
1 refers to data transfers to “joint controllers and/or data processors,” while other parts of the document do not identify with sufficient precision who qualifies as a joint controller or whether such a capacity actually exists, nor do they clearly distinguish between the roles of data controller and data processor. (137) The Authority emphasizes that the legal significance of identifying recipients or categories of recipients is not merely a matter of form. Pursuant to Article 13(1)(e) of the GDPR, the data subject must be informed of the recipients or categories of recipients to whom their personal data may be disclosed. This information only fulfills its purpose if it allows the data subject to determine, at a minimum, the purpose of the data processing associated with the specific recipient or category of recipients and the role they play in the data processing. Notice No. 1 did not meet this requirement, as it merely listed several parties but did not clarify for what purpose, with respect to which categories of data, and in what capacity they would be subject to data transfer or data processing.
(138) In the Authority’s view, the document also failed to describe the roles of external service providers—particularly social media and advertising providers—in sufficient detail to allow the data subject to clearly determine whether a given service provider was acting as a data processor, an independent data controller, or in some other data processing capacity. (139) The Authority therefore determined that the Company had violated the requirement set forth in Article 13(1) (e). (140) The Authority found that Notice No. 1 did not provide the detailed and unambiguous information required by Article 13 of the GDPR regarding data processing related to the cookies used on the Website. (141) Chapter XV of Notice No. 1 merely states in general terms that “The Service Provider … uses ‘cookies’ …” and identifies the purposes of cookies as providing “a more comprehensive service” and “convenience features,” but it does not clearly describe the specific data processing purposes, legal bases, scope of data processed, data retention period, or recipients associated with each cookie.
(142) Notice No. 1 also fails to distinguish between cookies necessary for the website’s operation and those requiring consent, and does not provide clear information regarding the legal basis for the use of each type of cookie. (143) The Company itself stated in these proceedings that it only later modified its information practices regarding cookie management on the Website and, beginning in April 2021, has been using the cookie panel provided by the […] service provider, which displays information on the type, function, and duration of cookies. The Company further stated that the information regarding cookie management was developed in greater detail within the framework of this system. (144) Based on the foregoing, the Authority determined that the Company violated Article 13 (1)(c) and (e), as well as Article 13(2)(a). 30 (145) The Authority found that Privacy Notice No. 1 provided contradictory and incomplete information regarding data transfers to third countries.
(146) According to Section 5 of Chapter VIII of Notice No. ” (147) In the Authority’s view, the two provisions clearly contradict each other. On the one hand, Privacy Notice No. 1 generally excludes data transfers outside the EU; on the other hand, it itself states that, within the framework of […]’s services, data is stored in the United States. It is not clear to the data subject from this whether data is transferred to a third country. (148) Furthermore, Information Notice No. 1 does not adequately describe the safeguards applicable to such data transfers. Section 5 of Chapter VIII merely states that data transfers take place “with safeguards in accordance with the provisions of the GDPR,” but does not describe the content, nature, or availability of these safeguards, nor does it explain how data subjects can access them. (149) Inaccurate disclosure of recipients and data transfers is particularly significant in the context of data transfers to third countries, since if the recipient is an organization outside the EEA, the data subject must be informed, pursuant to Article 13(1)(f) of the GDPR, of the fact of the data transfer, the existence or absence of an adequacy decision, and the appropriate or suitable safeguards and how to access them.
Notice No. 1 did not provide specific and verifiable information of this nature in this regard. (150) Based on the foregoing, the Authority determined that the Company violated Article 13 (1)(f) of the GDPR. (151) The Authority found that the First Privacy Notice did not provide adequate, accurate, and unambiguous information regarding the duration of data retention and the criteria for determining it, covering all data processing activities. (152) Although the table in Chapter VI lists retention periods for several data processing purposes, these are not always clear, nor do they always correspond unambiguously to the legal basis and nature of the specified data processing. For example, in the case of “Newsletter Distribution” and “Sending telephone messages,” Privacy Notice No. ”) does not clearly refer to communications for purely marketing purposes. As a result, it is not clear to the data subject what different data retention rules apply to communications related to the purchase versus marketing communications.
(153) Similarly, in the case of “Package Delivery,” the phrase “Until withdrawal” is used, which clearly does not provide adequate information about data processing related to the fulfillment of a purchase, the actual duration of which is not determined by the withdrawal of consent. In the case of “Writing a Review” data processing, Notice No. 1 states that reviews are “stored and made available on an ongoing basis,” from which the data subject cannot determine what specific duration this entails or under what conditions the data processing will cease. 31 (154) Section 4 of Chapter IX further increases the uncertainty by providing the following summary: “The duration of data processing extends until the time periods specified in the data processing purposes, but as a general rule, until the purpose of data processing is fulfilled … and finally, until the data subject withdraws their consent …” This wording does not make it clear exactly according to what logic each specific data processing operation is terminated.
Consequently, the data subject cannot determine how long their personal data will actually be retained. (155) The Authority therefore found that the Company had violated Article 13(2) (a). (156) The Authority found that Notice No. 1 provided information on the data subject’s rights in an inappropriate structure, with insufficient clarity, and with content that was, in part, inaccurate. (157) Chapter X of Notice No. 1 and, in part, its subsequent sections provide information on data subjects’ rights that is extensive but structurally disjointed and mixed in content. The text simultaneously refers to the Information Act and the GDPR, describes certain rights multiple times in varying formats, and in several instances it is unclear which rule applies to the exercise of a given data subject right. , while other sections of the First Notice also refer to the GDPR. ”, rather than primarily the right of access under Article 15 of the GDPR.
Section 16 of Chapter X also describes cases where information provided to data subjects may be omitted or restricted, mixing references to the Information Act and the GDPR in a way that is difficult for data subjects to follow. (159) Particularly problematic is Section X, Paragraph 23, which states that in the event of a violation of their rights, data subjects “may exercise their rights before the arbitration tribunal designated in the Data Controller’s generally applicable and currently valid general terms and conditions” and may also turn to the NAIH. In the Authority’s view, such a provision is misleading in the context of data subjects’ enforcement of their rights and is likely to present the data subject’s remedies in an ambiguous manner. (160) Based on the foregoing, the Authority determined that the Company violated Article 13 (2)(b) of the GDPR. (161) The Authority found that Notice No.
1 did not provide sufficiently differentiated and clear information regarding the right to withdraw consent. (162) Privacy Notice No. 1 generally applies the logic of consent to the Website’s entire data processing system. This includes the introductory provision stating that by using the Website, the user consents to the processing of their data, as well as Sections 1–2 of Chapter IV, which generally attribute data processing related to the Website’s operation to consent. In contrast, other sections of Privacy Notice No. 1 also mention data processing based on contractual obligations, legal obligations, and legitimate interests. (163) The Authority finds the general wording in Notice No. 1 particularly concerning, as it states that the Company may be entitled to continue processing the data subject’s personal data even after consent is withdrawn, based on a legal obligation or legitimate interest.
It is not in itself impossible that the processing of certain personal data may continue to be necessary after the withdrawal of consent on the basis of another, independent legal basis; however, the data controller must set forth the conditions for this in advance and unambiguously, linking them to a specific purpose of data processing and a specific legal basis. In contrast, Information Notice No. 1 formulated the continued processing of data as a general, undifferentiated possibility, from which the data subject could not determine 32 which data processing activities would cease as a result of the withdrawal of consent, and which data processing activities could continue on a different legal basis. (164) Under this structure, it is not clear to the data subject to which data processing activities the right to withdraw consent actually applies. Although Section 3 of Chapter X provides detailed provisions on the withdrawal of consent given for marketing-related communications, it is not clearly evident from the document as a whole which data processing activities—such as those related to purchases, customer service, delivery, or other operations—are actually based on consent as a legal basis.
Consequently, it is not clear to the data subject in which cases of data processing they may exercise their right to withdraw consent and in which cases they may not. (165) The Authority therefore determined that the Company violated Article 13(2) (c) of the GDPR, as it failed to provide clear information—specific to each data processing activity— regarding the right to withdraw consent and its actual consequences. (166) The Authority found that Information Notice No. 1 did not provide information regarding the right to lodge a complaint with the supervisory authority in a sufficiently clear and appropriate context as required by the GDPR. (167) Although Section XII, Point 1 states that the data subject “may initiate an investigation with the National Authority for Data Protection and Freedom of Information,” the information regarding the enforcement of rights is inconsistent, because Section 23 of Chapter X simultaneously identifies arbitration as a forum for enforcing rights.
In the Authority’s view, including arbitration in this manner among the remedies available in the event of a violation of the data subject’s rights is misleading and does not provide the data subject with a clear picture of their actual right to lodge a complaint and the system of legal remedies. (168) The Authority emphasizes that the right to lodge a complaint with a supervisory authority is one of the fundamental safeguards of the GDPR, intended to provide the data subject with a clear and direct avenue for redress. The uncoordinated and, in part, misleading presentation of the remedies in Information Notice No. 1 is likely to cause uncertainty for the data subject and effectively hinder the effective exercise of their rights. (169) Based on the foregoing, the Authority determined that the Company violated Article 13 (2)(d). 2. Amendments to Prospectus No. 1, effective as of February 1, 2020, did not substantially remedy the previously existing disclosure deficiencies; it largely retained the same content, and the amendments introduced did not constitute a separate, new violation of the law, nor did they remedy the previously existing violation.
1, the inclusion of a separate section detailing data transfers related to the payment service provider. 2, and the phrase “I acknowledge” presented the legal basis for data transfer in a misleading manner. The amendment therefore did not substantially remedy the previously existing shortcomings. 3, effective as of March 26, 2020, is the version that took effect on the 23rd day of March 2020, immediately preceding the one effective as of March 26, 2020 March 23, 2020, which was in effect as of March 23, 2020, regarding the transfer of data to […], but it did not remedy the ambiguous presentation of the legal basis for the data transfer—which was based on the phrase “I acknowledge”—nor did it sufficiently clarify the roles of the recipients. The amendment therefore did not give rise to a new violation, but it did maintain the previously identified violation. 4, effective as of May 19, 2020, introduced a new data processing element compared to the previous version regarding the […]-related customer satisfaction survey and the transfer of email addresses for this purpose.
4 does not provide clear and comprehensive information in this regard, as it defines the legal basis for data processing in a contradictory and insufficiently precise manner, fails to clarify the role and status of […] as a recipient, and does not contain adequate information regarding the duration of data processing. 4 of the Privacy Notice not only resulted in the persistence of the previous deficiencies but, in connection with the introduction of a new data processing activity, the Company violated Article 13(1)(c) and (e) and Article 13(2)(a) of the GDPR. 5, effective as of June 9, 2020, substantially amended the information regarding the identity and contact details of the data protection officer compared to the previous version. The Authority determined that this change, in and of itself, did not constitute a new, separate violation; however, the amendment did not remedy the previously identified deficiencies regarding legal bases, data transfers, retention periods, and transparent information, and thus the prior state of non-compliance remained unchanged.
6, effective as of October 21, 2020, was substantially amended from the previous version in that Chapter VIII was supplemented with a new Section 8, which provides for the transfer of data to […]. According to this amendment, the data transfer covers cookies and browsing data stored during the customer’s browsing session, as well as the email address, billing, and shipping information in the event of a purchase. 6 remain substantively unchanged. (177) In the Authority’s assessment, this amendment does not result in a new violation of the law; however, it maintains the previously identified deficiencies in their original form and extends them to an additional recipient. 6 still fails to provide clear and comprehensive information regarding data transfers as required by Article 13(1)(e) of the GDPR, particularly with respect to the precise definition of the purposes of data processing, the legal bases, and the roles of the recipients.
6 regarding the description of data processors and the physical environment of data processing. While the previous version identified […] as the organization assisting in providing the IT infrastructure, the newer Notice named […] in this role and also modified the description of the location and circumstances of data processing. (179) Notice No. 7 did not substantially remedy the previously existing deficiencies in the information provided; it largely retained the same content, and the amendments introduced did not constitute a separate, new violation of the law, nor did they remedy the previously existing state of noncompliance. 3. Prospectus No. 2, effective as of July 15, 2021 34 (180) The Authority found that Information Notice No. 2 contained not merely formal changes compared to the previous version, but had also undergone substantial changes in its structure and level of detail.
The individual data processing operations—in particular those related to orders, marketing, online payments, complaint handling, reviews, sweepstakes, customer service, and “data processing related to the last order”—were presented in separate chapters, and data processors and their roles were also covered in a separate chapter. (181) The Authority found that, taken as a whole, the Privacy Notice does not present a unified, coherent data processing system, but rather consists of elements that are partly contradictory and not adequately coordinated. (182) At the same time, the Authority notes that this structural and substantive revision did not, in and of itself, result in the cessation of the previously existing violation. The second Privacy Notice continued to retain the substantive shortcomings of the earlier versions, specifically the inconsistent and intermingled presentation of legal bases, the unjustified overemphasis on consent, the mixed description of data subjects’ rights—partly following the logic of the GDPR and partly that of the Information Act—and the opaque description of data processing related to cookies and web analytics tools.
All of this confirms that the amendments did not give rise to a new violation but rather resulted in the continuation of the previous state of non-compliance. (183) The Authority emphasizes that Notice No. 2 underwent such extensive structural and substantive changes compared to the previous version that it should be considered a separate, new data processing notice. Accordingly, the Authority assessed the information gaps contained therein independently, regardless of whether they had also appeared in part in the previous versions. (184) In the Authority’s view, Notice No. 2 not only retained the previous deficiencies but also constituted separate violations with respect to the newly introduced or modified data processing activities. (185) The Authority therefore assessed the amendments to the Second Privacy Notice on a case-by-case basis: on the one hand, it noted the persistence of the previously existing deficiencies, and on the other hand, it examined any new violations related to newly introduced or substantially modified data processing activities.
(186) The Authority found that, in the new version, regarding certain data processing activities—in particular “Data Processing Related to the Last Order,” as well as the more detailed marketing and behavioral data processing operations—Privacy Notice No. 2 did not provide specific and unambiguous information tailored to the specific characteristics of the respective data processing operations. The shortcomings identified in this regard relate in particular to the determination of legal bases, data transfers, and the description of how each data processing operation functions. (187) In the Authority’s view, if the Second Notice fails to provide the specific and transparent information required by Article 13 of the GDPR with respect to newly introduced or substantially modified data processing operations, this should be assessed not merely as a continuation of the previous deficiency, but as a new, separate violation.
In the present case, the Authority determined that the deficiencies related to certain data processing operations within the new structure constitute such a separate violation. (188) The Authority found that, despite the structural reorganization, the Second Privacy Notice continued to retain the substantive deficiencies of previous versions in several respects; in particular, the legal bases were still presented in a way that conflated them and failed to differentiate them by data processing activity—especially through the use of consent as a general, quasi-“default” legal basis—the description of data subjects’ rights was inconsistent, following partly the logic of the GDPR and partly 35 the logic of the Information Act, which did not ensure a clear and precise understanding of how to exercise those rights; the scope of data transfers and recipients associated with each data processing operation was not consistently presented in relation to the specific purpose of the data processing; retention periods were in many cases still defined in general, imprecise, or conditional terms (“until withdrawal,” “until the purpose ceases to exist”), and the descriptions of data processing activities related to cookies, web analytics, and advertising services remained fragmented and difficult to follow.
Despite the revised structure, the above shortcomings meant that Notice No. 2 did not provide clear, transparent, and distinct information regarding the individual data processing activities, which continued to result in a violation of the requirements set forth in Article 12(1) of the GDPR. 6 generally link the processing of personal data to the data subject’s consent or to the acceptance of the Privacy Notice, while Chapters IV–XI assign different legal bases for specific data processing operations, in accordance with Article 6(1) of the GDPR. This contradiction fails to make it clear to data subjects on what legal basis each specific data processing activity actually takes place, which resulted in a violation of the requirements set forth in Article 12(1) of the GDPR. (190) The Authority further found that, in several instances, the scope of the personal data processed as indicated in the summary table in Chapter XIII of the Privacy Notice does not correspond to the detailed descriptions of the individual data processing operations provided in Chapters IV–XI.
In particular, with regard to data processing related to online payments, the detailed description lists the username, last name, first name, address, phone number, email address, and bank account number as processed data, while the summary table lists a narrower scope of data for the same data processing activity. Such a discrepancy renders the information inconsistent and does not meet the requirement for clear and transparent information set forth in Article 12(1) of the GDPR. (191) The Authority found that, with regard to certain data processing activities introduced in the new version or substantially modified, Notice No. 2 contains deficiencies that can be considered separate violations of the law. (192) Regarding the introduction of “Data Processing Related to the Last Order” as a separate data processing activity, Notice No. 2 does not define the actual content and operation of the data processing with sufficient specificity.
, personalized interface, recommendations, identification of returning users). Notice No. 2 also fails to explain the logic behind the data processing, what events trigger it, or how it relates to the user’s previous activity. , via a separate checkbox, setting, or pop-up window), at what time, under what conditions, or to which data processing operations it applies. As a result, it is not clearly established for data subjects for what purpose and on what legal basis their personal data are processed in this context, and consequently, the Company has violated Article 13(1) (c). (193) With regard to marketing and behavior-based data processing, the Privacy Notice in Section 2 of the Privacy Notice does indicate that the data controller analyzes users’ “purchasing habits” and “user behavior,” but in this context, it does not provide clear and explicit information as to whether the data processing involves profiling within the meaning of Article 4(4) of the GDPR.
Notice No. , personalized offers, display of different content, targeted advertising). In this context, the 2nd Privacy Notice also states in another section that the data controller’s activities constitute “regular and systematic, large-scale monitoring of data subjects”; however, the substantive basis for this classification—the specific data processing operations on which it is based, as well as a description of the associated data processing logic and consequences—is entirely absent. The reference to “large-scale monitoring” is thus not linked to specific data processing practices and does not make it clear to data subjects exactly what kind of monitoring is taking place, based on which data categories, and how this affects them. Due to these shortcomings in Notice No. 2, data subjects are not provided with adequate information regarding the essential characteristics, significance, and expected consequences of automated data processing and profiling, as a result of which the Company has violated Article 13(2)(f) of the GDPR.
(194) The legal bases for each of the re-regulated data processing activities are set forth in Section 2 of the Information Notice—with simultaneous, undifferentiated references to Article 6(1)(a), (b), (c), and (f) of the GDPR—without clearly specifying which legal basis actually applies to the specific data processing purpose in question. In several places, Notice No. 2 states that the data controller processes data “pursuant to Article 6(1) of the GDPR” and then lists the possible legal bases one after another; however, it is not clear, for example, on which legal basis a specific data processing activity related to marketing, customer service, or behavioral analysis is actually carried out. Furthermore, the legal basis of consent is in several instances linked to data processing activities that, by their nature, are more closely associated with the performance of a contract or a legitimate interest; moreover, the specific method and timing of obtaining consent are not described.
When relying on the legal basis of legitimate interests, Notice No. 2 does not describe the specific legitimate interest of the data controller or a third party, does not refer to the essential aspects of the balancing of interests, and does not make it possible to understand what justifies the data processing in relation to the data subject’s interests. As a result, it is not clearly established for data subjects on what legal basis their personal data is being processed, and consequently, the Company has violated Article 13(1)(c) and (d) of the GDPR. (195) With regard to the newly identified data processors and recipients, while the Second Notice lists several organizations, it does not clearly link their roles to the specific purposes of data processing. The list of recipients is disconnected from the description of the data processing operations, so it is not clear, for example, exactly which data is transferred for marketing purposes, web analytics services, customer service communications, or online payments, for what purpose, and to which specific organizations.
In several instances, Privacy Notice No. 2 contains only general categories or lists, without presenting the actual operation and scope of data transfers as they relate to the specific data processing activity. As a result, the system of data transfers is not transparent to data subjects, and the Company has therefore violated Article 13(1)(e) of the GDPR. (196) The Authority further found that, in several instances, the scope of the personal data processed as indicated in the summary table in Chapter XIII of the Privacy Notice does not correspond to the detailed descriptions of the individual data processing operations provided in Chapters IV–XI. In particular, with regard to data processing related to online payments, the detailed description lists the username, last name, first name, address, phone number, email address, and bank account number as the data being processed, while the summary table lists a narrower scope of data for the same data processing activity.
Such a discrepancy renders the information inconsistent and fails to meet the requirement for clear and transparent information set forth in Article 12(1) of the GDPR. 37 (197) Furthermore, Notice No. 2 addresses the issue of data transfers to third countries in a contradictory manner. On the one hand, it explicitly states that the data controller does not transfer personal data outside the European Union; at the same time, however, it refers to the use of several services—in particular web analytics and advertising providers—whose operations may in fact result in the transfer of data to a third country, specifically the United States. In this regard, Notice No. 2 does not provide clear information on whether such data transfers take place and, if so, under what safeguards—such as an adequacy decision, general terms and conditions, or other safeguards—and how these are accessible to data subjects.
With this contradictory and incomplete information, the Company has violated Article 13(1)(f) of the GDPR. The Authority finds that such contradictory information does not allow data subjects to verify the actual circumstances of the data transfer. (198) Finally, in several cases, the retention periods associated with newly introduced or substantially modified data processing operations continue to be defined in general and conditional terms, such as “until consent is withdrawn,” “until the purpose ceases to exist,” or “until the legal relationship terminates,” without Information Notice No. 2 specifying a concrete, objective, and predictable duration or clear criteria on the basis of which the data subject could actually assess the duration of the data processing. Such phrasing does not allow for a prior and clear understanding of the temporal scope of data processing, as a result of which the Company violated Article 13(2)(a) of the GDPR.
(199) The Authority further found that, in the case of certain data processing activities, the Privacy Notice applies an 8-year retention period to certain categories of data by referring to Section 169(2) of Act C of 2000 on Accounting, even though the retention of such data cannot be derived from the cited legislation. In particular, with regard to data processing related to online payments—such as usernames, phone numbers, and email addresses—as well as the retention of product images and videos in the context of complaint handling and warranties, the Privacy Notice generally links these retention requirements to accounting obligations. This information is inaccurate and does not allow data subjects to clearly ascertain the duration of data processing, which reinforces the violation of Article 13(2)(a) of the GDPR. III. 4. 1, effective as of April 7, 2022, did not introduce a completely new information system compared to the previous version; however, it modified the content of certain sections on data processing, particularly regarding data processors and data transfers related to data processing for marketing purposes.
1 Privacy Notice explicitly named […] and […], and defined in greater detail the scope of data transferred to these organizations and their roles in data processing for marketing purposes. In addition, the list of data processors in Chapter I was revised, as some of the organizations previously listed there were replaced by others. (201) At the same time, the Authority notes that the vast majority of these amendments did not result in the creation of a new violation of the law, but rather confirm the persistence of previously identified deficiencies in the information provided and their continuation in a new structure. 1 of the Privacy Notice continued to contain the substantive errors of previous versions, including, in particular, the inconsistent and confusingly intertwined presentation of legal bases, the unjustified overemphasis on consent, the mixed description of data subjects’ rights—which followed a logic based partly on the GDPR and partly on the Information Act—as well as the fragmented and difficult-to-understand description of data processing activities related to cookies, web analytics tools, and data processing for marketing purposes.
38 (202) The Authority emphasizes that the mere fact that certain parties and data categories related to marketing data processing have been listed in greater detail does not constitute a new violation if the substance of the deficiencies in the information provided remains unchanged. 1 provides a more detailed list of the data processed in the context of data processing for marketing purposes or lists the data processors in a new structure, provided that it remains unclear to the data subjects how the individual data processing operations actually function, on what legal basis they are carried out, and exactly which organizations play what roles in them. 1 of the Notice identifies the individual data processors and the scope of the data they process in greater detail than the previous version. 1 now specifically defines the types of data transferred and the individual elements of data processing.
However, this level of detail does not amount to a substantive clarification of the information provided, as it remains unclear which organization acts in what capacity and in connection with which specific data processing purpose during each data processing operation, and what logic governs the data transfers. (204) The Authority notes that this deficiency cannot be considered a new violation, as the structural lack of transparency regarding information related to recipients and data processors was also present in the previous Notice No. 2, effective as of July 15, 2021. The current version does not introduce any new deficiencies in this regard, but rather contains a more detailed—though still unclear—presentation of the previous, inadequate information practices, which confirms the continuation of the prior non-compliance. 1 continues to address the issue of data transfers to third countries in a contradictory manner in the current version.
Although, on the one hand, it excludes data transfers outside the European Union, on the other hand, it specifically names a service provider based in a third country ([…]) to which personal data is or may be transferred. However, this circumstance also cannot be assessed as a new violation, but rather as an extension of the incomplete and contradictory information regarding data transfers to third countries that already existed in the previous Privacy Notice, which confirms the continued breach of the obligations under Article 13(1)(e) and (f) of the GDPR. 2 Privacy Notice, both among the data processors used and in the section concerning external web analytics and ad-serving companies. According to the amended text, […] places tracking cookies on users’ devices for remarketing purposes and monitors visitors’ online behavior. (207) The Authority notes that this amendment did not result in the elimination of the previously existing information gaps, but rather involved the insertion of a new entity—related to behavioral tracking and remarketing—into an information system that was already inadequate to begin with.
2 of the Privacy Notice names the […] service, it does not make clear exactly in what capacity this party participates in the data processing, which specific personal data of data subjects are processed, the exact legal basis for the data processing, the duration of the processing, or to which recipients the data are transferred and along what data transfer chain. 2 of the Notice also fails to provide clear and comprehensive information tailored to the specific characteristics of the data processing in question regarding the operation of remarketing and the tracking of users’ online behavior, 39 its logic, and its impact on data subjects. 2 of the Notice does not adequately address the legal basis, does not clearly link the recipients to the purpose of data processing, and does not contain sufficiently specific information regarding the duration of data processing either. (209) The Authority found that the amendment effective as of April 25, 2022, did not remedy the previously identified deficiencies in the information provided; thus, the infringing situation persisted.
2 of the Privacy Notice still does not contain the information required under Article 13(1)(c) of the GDPR regarding the legal basis for data processing, clear and comprehensive information regarding the recipients under Article 13(1)(e), and the retention period under Article 13(2)(a). In this regard, the amendment does not establish a new category of violation but constitutes a further manifestation of the previously established violation. 3, effective as of May 18, 2022, contained substantive changes compared to the previous version regarding provisions related to product reviews and data processing for marketing purposes. On the one hand, the amendment stipulated that personal data included in product reviews would also be used for marketing purposes; on the other hand, it allowed for the uploading of photographs associated with reviews and, in this context, the processing and publication of images.
In the Authority’s view, these amendments do not merely represent the persistence of previous deficiencies in the information provision but introduce new elements of data processing that must be assessed independently. 3 does not provide sufficiently specific and clear information regarding the purpose of data processing, its legal basis, the recipients, and the duration of data processing; thus, data subjects are unable to fully understand the essential circumstances of the processing of their personal data. 3 of the Notice does not provide sufficiently specific and unambiguous information regarding the use of personal data contained in product reviews for marketing purposes. 3 of the Notice does not specify exactly which personal data this covers, within the framework of which specific marketing activities, through which data processing operations, and in what context this takes place.
Nor is it clear whether the public publication of the review and the use of the personal data contained therein for marketing purposes constitute separate data processing operations, and to what extent, at what time, and through what specific statement consent is obtained in this regard. For these reasons, it is unclear to the data subjects for what exact purpose and on what legal basis their personal data are being processed in this context, as a result of which the Company violated Article 13(1)(c) of the GDPR. (212) The Authority further found that the uploading of photographs in connection with reviews and the personal data appearing therein—in particular, the information regarding the processing of images—also do not fully comply with the requirements of the GDPR. 3 of the Privacy Notice states that users have the option to upload a photograph and that, if their personal data appears in it, the data controller will process it based on consent, it does not specify with sufficient detail exactly on which platform, in what format, to which audience, and for how long the photograph will be made available, nor does it describe the technical and content-related parameters under which the publication will take place.
3 of the Notice alone, but must rely on a combined interpretation with another document. This approach continues to fragment the information provided and does not ensure that the data subject can understand, based on a single, clear, and comprehensive set of information, to which recipients, in what manner, and 40 for what data processing purposes their image is made available; as a result, the Company violated Article 13(1)(e) of the GDPR. (213) In the Authority’s view, the information regarding the duration of data processing related to the photograph and likeness is also not sufficiently clear. 3 of the Privacy Notice defines the duration of data processing related to the review as lasting until the data subject withdraws their consent, it does not provide adequate information on how the publicly published photograph or any copies or shares thereof, as well as the technical and practical consequences of removing the publication, will be handled following the withdrawal of consent.
It is therefore unclear to the data subject how long the content containing their image will actually remain accessible and what effect the withdrawal will have on content that has already been published. In light of this, the Company has also violated Article 13 (2)(a) of the GDPR in this regard. 4, effective as of August 31, 2022, substantially modified the rules governing data processing related to online payments compared to the previous version. While the earlier version treated online payments as a single data processing category, the new version has broken it down into “Advance Transfer” and “Payment by Credit Card and Card Storage,” and in this context has introduced, as new content, descriptions of data processing related to card storage and the “OneClick” payment method. 3 of the Privacy Notice; thus, the violation persisted even after the amendment. (215) The Authority notes that this amendment did not merely involve a structural reorganization of the previous information but also entailed the introduction of a new data processing element in the context of online payments.
4 of the Privacy Notice no longer merely states that the customer’s data is transferred to […] for the purpose of processing online payments, but also specifies that credit card data is recorded and stored on […]’s platform, and that by using the “OneClick” payment method, the User can take advantage of a solution designed to simplify future payments. The Authority finds that the introduction of these new data processing elements would have provided even greater justification for presenting the information provided to data subjects in a clear and comprehensive manner. 4 does not specify the specific legal basis for the data processing with sufficient clarity. 4 of the Notice does not clarify whether card storage constitutes data processing necessary for the performance of the contract or is based on some other legal basis, even though this issue is essential for the data subject to assess the lawfulness of the data processing.
In light of the foregoing, the Company has violated Article 13 (1)(c). 4 of the Privacy Notice does not provide sufficiently transparent and, in and of itself, comprehensive information regarding the transfer of data related to credit card payments and the identification of the parties involved in data processing. Although the document describes the scope of data transferred to […], and notes that the nature and purpose of the data processing activities carried out by the data processor are available in […]’s data processing notice, the Authority notes that a reference to the data processor’s own notice does not exempt the data controller from its obligation to provide information under Article 13 of the GDPR. 4 does not state clearly and in a manner that is understandable to the data subject on its own exactly which data processing operations the data transfer relates to, for what purpose, and in what capacity; furthermore, it does not consistently clarify the relationship between the data controller and the data processor.
3 of the Privacy Notice and were not remedied by the current amendment; thus, the infringing situation remains unchanged. In light of all this, the Company has violated Article 13(1)(a) and (e) of the GDPR. 4 does not provide adequate information—directly accessible to the data subject—regarding the duration of data processing related to card storage. While the document specifies an 8-year retention period for “Advance Transfer” data processing in accordance with accounting obligations, it does not clearly state—particularly with regard to credit card payments and, more specifically, card storage—how long the data processed in this context, or the information related to solutions facilitating subsequent payments, remains in the system, under what conditions it may be deleted, or how the data subject may request its deletion. (220) The Authority notes that the possible inclusion of information regarding the duration of data processing in other, external privacy notices does not compensate for the deficiency in the data controller’s own notice.
4 thus does not enable the data subject to obtain clear, advance knowledge of the time frame of data processing, as a result of which the Company violated Article 13(2)(a) of the GDPR. 5, effective as of October 28, 2022, primarily amended, compared to the previous version, the name of the data controller ([…]), information regarding its registered office and business premises, as well as the identity of the data protection officer and the identification of certain external service providers. However, these changes are typically of a formal nature and have not resulted in a substantive remedy for the previously identified deficiencies in the information provided. The boilerplate and vague presentation of the legal bases, the failure to specify the data subjects and data processors in relation to the purposes of data processing, and the opaque description of data processing related to cookies, remarketing, and web analytics remain unchanged; furthermore, with regard to data processing related to online payments, a reference to the data processor’s privacy notice does not satisfy the data controller’s own obligation to provide comprehensive and direct information.
5. Privacy Notice No. 3, effective as of May 24, 2023 (222) The Authority notes that Information Notice No. 3, effective as of May 24, 2023, cannot be considered a structural continuation of Information Notices No. 1 and No. 2, but rather a document prepared with a new structure, broken down by data processing purposes. In light of this, the Authority assessed Notice No. 3 independently and examined whether the information contained therein complies with the requirements set forth in Articles 12 and 13 of the GDPR. (223) The Authority found that the scope of Notice No. 3 is not sufficiently clear. The document refers generally to the “website” and to data processing activities managed by the Company; however, it does not clearly specify exactly which online platforms the Notice covers, particularly the […] online store, the […] website, or both. 10 of the Notice covers data processing related to blog registration, separate data processing and usage documents were also associated with the blog.
As a result, it is not clear to the data subject which notice applies in a given data processing situation. This system of information provision violates the requirement for clear, transparent, and easily accessible information set forth in Article 12(1) of the GDPR. 42 (224) In the Authority’s view, Notice No. 3 does not specify with sufficient precision the legal provision serving as the legal basis for data processing in the case of several data processing purposes. 2 refers to Article 6(1)(c) of the GDPR in connection with data processing related to invoicing and mandatory documentation, but fails to specify the specific sector-specific legal provision that establishes the data processing obligation. 15. A mere reference to Article 6(1)(c) of the GDPR does not, in and of itself, make it clear to the data subject exactly which legal obligation applies to the data controller. The Company thereby violated Article 13(1)(c) of the GDPR.
2 of the Privacy Notice—in the context of data processing related to invoicing—also lists certain categories of data, specifically including email addresses. The Privacy Notice lists data categories—including, in particular, email addresses, the contact person’s name, and job title—in the context of data processing related to invoicing, for which the Privacy Notice fails to explain why their processing is necessary to fulfill invoicing and accounting obligations. Consequently, the Notice does not provide sufficiently precise information, tailored to the purpose of data processing, regarding the purpose, legal basis, and scope of the data processed in this context. 5 of Notice No. 3 stipulates that, in the case of data processing related to the advance payment service, the user name, last name, first name, address, phone number, email address, bank account number, and order number are retained for 8 years following the purchase; however, it does not explain what specific legal or data processing need justifies retaining this full set of data for eight years.
Merely citing the legal basis of “performance of a contract” does not, in and of itself, make it clear why it is necessary to retain the entire set of data for such a period following the purchase. The Company thereby violated Article 13(2)(a) of the GDPR. 8 of the 3rd Privacy Notice identifies the data controller’s legitimate interest as the legal basis for data processing in the context of advertising services, providing information, sending newsletters, email marketing (eDM), and telephone solicitations, and defines this legitimate interest as direct marketing. However, the Notice does not specify the exact channels through which such marketing-related data processing takes place, the specific group of data subjects involved, or the conditions under which it occurs; furthermore, it does not clarify how the consent requirements for electronic marketing communications are enforced. Consequently, it is not clearly established for the data subject on what legal basis the data processing for marketing purposes takes place, thereby constituting a violation by the Company of Article 13(1)(c) of the GDPR.
2 of the 3rd Privacy Notice do not describe the conditions under which the data subject may exercise their rights in accordance with the requirements of the GDPR. According to the document, the data controller charges an administrative fee if the data subject requests information regarding the same data a second time within one month, and may refuse to comply if the data subject exercises the same right a third time within one month. This wording in Information Notice No. 3 gives the impression that a repeated request by the data subject alone can justify the imposition of a fee or the refusal to comply with the request, whereas the exercise of a data subject’s rights may only be restricted in this manner if the data controller demonstrates that the request is manifestly unfounded or excessive. In the Authority’s view, such information is likely to deter the data subject from exercising their rights or to create uncertainty regarding such exercise.
Consequently, the Company violated Article 12(1) of the GDPR and Article 13(2)(b) of the GDPR. 21 of the 3rd Privacy Notice, the information regarding the retention period does not comply with the requirements of the GDPR. In this regard, the document states that the planned duration of data processing is “indefinite,” meaning that it essentially provides for retention for an unlimited period of time with respect to data subject requests, incidents, and their documentation 43 data. The Privacy Notice does not specify a specific time period or provide clear, objective criteria that would allow the data subject to determine how long the data controller will retain the personal data processed in this context. The phrase “not to be discarded” leaves the time frame for data processing completely open-ended; therefore, the Company has violated Article 13(2)(a) of the GDPR in this regard. 23 of Privacy Notice No.
3, the Privacy Notice does not provide sufficiently specific and unambiguous information. According to the document, “all categories of digital data collected or processed by the Organization” may be processed for this purpose; however, this definition is so general and unrestricted that the data subject cannot determine exactly which personal data fall within this scope, what data processing operations are involved, or what specific purpose they serve. Furthermore, the retention period is not sufficiently clear, as Privacy Notice No. 3 uses the phrasing “for a maximum of 8 years, or until the data subject’s objection is deemed valid, provided that this is technically feasible,” which does not establish a clear, foreseeable time frame. In light of the foregoing, the Company has violated Article 13(1)(c) and Article 13(2)(a) of the GDPR. (231) The Authority further found that Sections 7, 10, and 11 of the 3rd Privacy Notice do not provide clear and coherent information regarding the description of data processors, recipients, and data transfers to third countries.
Section 7 presents the categories and specific entities of recipients and data processors in an extremely broad and heterogeneous list—including, among others, suppliers and partners outside EEA member states, operators of social media sites and websites, […] and […] […]—without clearly assigning them to specific data processing purposes and data categories. Although Section 10 describes certain data transfers in greater detail, this does not provide a clear overview of the purpose, legal basis, and role of all recipients, data processors, and data transfers listed in Section 7. Section 11 provides safeguards regarding data transfers to third countries exclusively with respect to […], while other parts of the Notice indicate that additional entities outside the EEA may also be involved. As a result, it is not clearly established for the data subject which of their personal data are transferred to which specific recipients, for what data processing purposes, in what capacity, or exactly which data transfers to third countries take place and what safeguards are associated with them.
The Company has thereby violated Article 13(1)(e) and (f) of the GDPR. (232) The Authority further notes that Privacy Notice No. 3 does not consistently describe the data processing roles of marketplace partners. According to Section 1 of Privacy Notice No. ” However, during the clarification of the facts, the Company stated that there is no joint data processing with marketplace partners and that the reference to joint data processing will be removed from the Privacy Notice. The Authority therefore did not find a violation of Article 26 of the GDPR in this case; however, it assessed the contradictory provisions of the Notice in light of the obligation to provide information to data subjects and parties involved in data processing. Due to these internal contradictions in Notice No. 3, it was not clear to data subjects in what capacity the marketplace partners were involved in the processing of their personal data.
The Company thereby violated Article 13(1)(e) of the GDPR. 20—that are not exclusively related to visitors or customers of the […] online store. The inclusion of these data processing activities is not unlawful in and of itself; however, combined with the imprecise definition of the Privacy Notice’s scope, it further increases uncertainty as to exactly which group of data subjects 44 , which platforms, and which data processing situations it applies to. The Authority assessed this Article 12(1). 6. Amendments to the 3rd Privacy Notice (234) The Authority found that Notice No. 1, effective as of September 9, 2024, was supplemented with substantially new data transfer elements compared to the previous version. New content elements included descriptions of data transfers to […], […], […], and […], which are related to measuring the effectiveness of […]’s advertisements and to web traffic analytics purposes, and in this context, also cover the—in certain cases.
The Authority notes, however, that these amendments did not remedy the previously identified deficiencies in the information provided; in particular, the retention periods remained insufficiently specific, the presentation of recipients and data processors remained fragmented and difficult to follow, and the wording regarding data subjects’ rights remained imprecise and, in some cases, restrictive. 8 do not merely constitute a clarification of the previous information but involve the introduction of new data processing operations and new categories of recipients. 1 does not assign a specific legal basis to these operations that is independent, clear, and directly recognizable to the data subject, but merely describes them in a descriptive manner in the section on data transfers. 1 of the Notice does not clarify whether these organizations participate in data processing as data processors, independent data controllers, or in some other capacity.
Based on the foregoing, the Company has violated its obligation to provide information under Article 13(1) (c) and subparagraph (e). 1 of the Privacy Notice does not provide adequate information regarding the retention periods associated with the newly disclosed data transfers or the timeframes for data processing. It is not clear for how long the data transferred to […], […], […], or […]—whether hashed or otherwise technically transformed—may be used, for what period they may be linked to ad views or purchases, or when they will be deleted. The Authority notes that a hashed or encrypted format does not, in and of itself, render clear information regarding the duration of data processing unnecessary. Therefore, the Company violated Article 13(2)(a) of the GDPR. (237) In the Authority’s view, the new amendment also failed to clarify the information regarding data transfers to third countries.
1. Privacy Notice continues to contain a reference to safeguards exclusively in relation to […], while other parts of the document continue to mention the Israeli […], and, as new data transfer elements introduced by this amendment, additional data processing activities for analytical and marketing purposes involving the use of data subjects’ personal data have been introduced. 1. became even more apparent, and they do not make it clear to data subjects in which cases, to which recipients, and under what safeguards their personal data is transferred outside the European Economic Area. Shortcomings in the information regarding data transfers to third countries were present in earlier versions as well, and this amendment has not remedied them. With the introduction of new data transfer operations, these shortcomings have become even more apparent; however, the Authority does not find a new, separate violation in this regard.
1. 0. In the Authority’s view, this editorial and temporal inconsistency creates uncertainty for the data subject as to the effective date of the new data processing rules. 1. Information Notice. Although the amendment resolved the previous inconsistency between the document’s date, version number, and effective date, it did not remedy the previously identified shortcomings regarding the content of data processing activities and the information provided to data subjects. 9. 2 specifies the scope of the data processed and the general purpose of the data transfer; however, it does not make it clear to which specific data processing purpose the data transfer relates, nor does it specify the legal basis for the data transfer. 2 of the Notice—in particular, those concerning additional recipients identified in the context of data processing for marketing and analytical purposes. 2 of the Notice by adding […], as a new recipient, this amendment was not accompanied by a substantive review of the structure of the information provided; thus, the purpose of the data transfer, its legal basis, and its connection to the individual’s data processing operations remain unclear in this regard as well.
The Authority therefore notes that these deficiencies do not constitute a new violation but rather confirm the continued existence and extent of the previously established violations of information disclosure obligations. (242) Overall, the Authority found that the amendments to the successive versions of the privacy notice published throughout the entire investigation period did not result in any substantive improvement in terms of providing adequate information to data subjects. 2. content of the Notice, these additions were not accompanied by a systematic reevaluation or coherent restructuring of the information provided. Consequently, the previously identified shortcomings persisted throughout the entire review period, while the newly added data processing elements resulted in further ambiguities and contradictions. In the Authority’s view, the successive amendments to the notices thus did not contribute to compliance but further impaired the clarity and comprehensibility of the information provided.
3. Information Related to a Sweepstakes (243) The Authority found that the Privacy Notice related to the prize drawing dated May 16, 2022 (hereinafter: 1. Prize Draw Notice, attached to the Company’s response letter dated December 12, 2025, registered under No. NAIH-15402-7/2025) did not provide data subjects with the comprehensive and unambiguous information required by Article 13 of the GDPR. (244) Although the document does include the purpose of data processing, a portion of the scope of the data processed, and consent indicated as the legal basis, the information is incomplete or unclear with respect to several essential elements. The Authority determined that the 46 does not comply with the requirements of the GDPR, as, in addition to data processing based on consent, it also cites compliance with a legal obligation regarding the retention of winners’ data; but it does not clearly assign the applicable legal basis to the individual data processing purposes and categories of data; thus, data subjects cannot determine on what legal basis specific data processing operations are carried out.
(245) The Authority further notes that the Information Notice for Prize Contest No. 1 does not contain specific information regarding the particular characteristics of the prize contest in question or details illustrating the actual circumstances of the data processing; in particular, it does not provide detailed information on the data processing procedure, the manner in which the data is used, any potential disclosures, or the parties involved in the data processing. Such a general, boilerplate formulation of the information does not allow data subjects to actually understand the specific characteristics of the data processing in question. (246) The Authority further found that the document does not contain adequate information regarding the recipients of data transfers and the data processors, as it does not specifically identify them, nor does it provide information on whether data will be transferred to a third country, or, in the event of such transfers, what safeguards are in place to protect the rights of data subjects.
(247) The Authority notes that the information regarding the duration of data processing is also unclear, since, on the one hand, the document specifies a short retention period of no more than 30 days, while on the other hand it prescribes a retention obligation of several years for certain data, without clearly distinguishing the retention periods associated with each specific data processing activity. (248) The Authority also found that the Information Notice for Prize Draw No. 1 does not contain information regarding whether the provision of data is mandatory or what the consequences are of failing to provide data, nor does it provide information on the use of automated decision-making or profiling, or the absence thereof. (249) In the Authority’s assessment, the designation of consent as the legal basis does not comply with the requirements of the GDPR, since, according to Prize Contest Information Notice No.
1, Prize Contest Information Notice, consent to data processing is not given through a separate, explicit statement, but rather takes place in connection with and as part of participation in the prize contest. Consent given in this manner does not qualify as voluntary, unambiguous, and appropriate consent under the GDPR. (250) Based on the foregoing, the Authority determined that the Company violated Article 13 (1)(c), (e), and (f), as well as Article 13(2)(a) and (e). (251) The Authority found that, with regard to the prize drawing conducted in cooperation with […], effective as of September 1, 2023 (hereinafter: 2nd Prize Draw Information), the legal basis for data processing is uniformly stated as the consent of the data subjects; however, it does not contain information that would allow data subjects to assess the actual nature of their consent and its relationship to the data processing activities.
The 2nd Prize Draw Information Notice does not clarify under what conditions the data processing related to participation in the prize draw and the awarding of prizes takes place, nor how these activities relate to the service used by the data subject. Consequently, it is unclear to data subjects to what extent consent is truly voluntary and on what basis the data processing takes place; thus, the 2nd Sweepstakes Notice does not provide transparent and unambiguous information regarding the legal basis for data processing. (252) The Authority further found that the 2nd Prize Draw Information Notice does not provide sufficiently clear and unambiguous information regarding the scope of data controllers. Although the title and 47 introductory section refer to data processing carried out in cooperation between the Company and its Partners, the 2nd Prize Contest Information Notice actually identifies only the Company as the data controller and does not clarify the role of the Partners, specifically whether they act as independent data controllers, joint data controllers, or data processors.
In the absence of such clarification, data subjects cannot clearly determine which organizations process their personal data and in what capacity. (253) The 2nd Sweepstakes Notice also fails to provide sufficiently structured and clear information regarding data transfers. The identification of recipients varies depending on the specific data processing activity and is, in some cases, incomplete; furthermore, the role of data processors— in particular […] and […]—as well as the nature and purpose of the data processing operations they perform, are not detailed. All of this prevents data subjects from understanding the data flow processes in which their personal data are involved. (254) The Authority also found that the 2nd Prize Draw Information Notice contains an internal contradiction regarding data transfers. Point 1 of the document states, with regard to the data processed in connection with participation in the prize draw, that “the Company does not transfer personal data to third parties,” while Section 2, in connection with notifying the winner and delivering the prize, explicitly provides for the transfer of personal data to […], and also designates […] and […] as data processors.
The Notice also states that these service providers may transfer personal data to a third country under specific contractual terms. In the Authority’s view, the relationship between these provisions is unclear: it cannot be unequivocally determined for the data subject which personal data, in connection with which data processing operation, are transferred to which recipients or data processors, or when and under what conditions a transfer to a third country may occur. This internal contradiction violates the requirement for clear and transparent information set forth in Article 12(1) of the GDPR. (255) With regard to data transfers to third countries, the 2nd Prize Draw Information Notice merely states in general terms that data processors may transfer data under specific contractual terms, but it does not specify the type of safeguards applied, their essential characteristics, or information relevant to data subjects.
Due to this deficiency, data subjects do not receive adequate information about the conditions and risks associated with the transfer of their personal data to a third country. (256) The Authority further found that the provisions regarding data subjects’ rights in the 2nd Sweepstakes Notice were formulated in a general, boilerplate manner and are not linked to specific data processing operations or their legal bases. Consequently, the Information Notice for the 2nd Sweepstakes does not ensure that data subjects actually understand what their rights are in specific cases and under what conditions they may exercise them. (257) Based on the foregoing, the Authority finds that the Company has violated its obligation under Article 12(1) of the GDPR to provide transparent, understandable, and clear information, as well as its information obligations set forth in Article 13(1)(a), (e), and (f) of the GDPR.
(258) The Authority found that while the Sweepstakes Rules (hereinafter: Sweepstakes Rules), effective as of October 10, 2022, do contain certain provisions regarding the processing of personal data, they do not provide the comprehensive and unambiguous information required by Article 13 of the GDPR. The document does not distinguish between the various purposes of data processing and the related data processing operations, nor does it provide a clear and unambiguous presentation of the legal bases for such processing. 48 (259) The Authority further found that the Sweepstakes Rules link participation in the sweepstakes to data processing for marketing purposes, as they require participants to subscribe to the newsletter and consent to the use of their data for marketing purposes as a condition of participation when providing their email address. However, the Sweepstakes Rules do not provide a separate and clear description of these data processing purposes, so it is not clear to data subjects for what purposes and under what conditions the various data processing operations take place.
(260) The Sweepstakes Rules contain incomplete information regarding data transfers and data processors. Although Section V of the document states that “we do not transfer data to third parties other than the data processor,” this only implies that the Company uses a data processor; however, the Rules do not specify the identity or category of the data processor, the scope of data transferred to the data processor, or the purpose and nature of the data processing. Consequently, data subjects cannot determine to which data processor their personal data is transferred in connection with the administration of the sweepstakes, the drawing, communication, or the delivery of prizes, for what purpose, or for the purpose of performing which data processing operations. (261) The Sweepstakes Rules also do not provide information on whether data transfers to third countries occur during data processing related to the sweepstakes.
The document does not state whether the data processor or other service provider engaged carries out data transfers outside the EEA, and if so, under what safeguards. Due to this omission, data subjects do not receive adequate information regarding the possible transfer of their personal data to a third country. (262) The Authority further found that the Sweepstakes Rules do not contain information regarding the duration of personal data storage or the criteria for determining such duration; thus, data subjects are not provided with adequate information regarding how long their data will be processed. (263) The Authority notes that, with regard to provisions on data processing, the Sweepstakes Rules primarily refer to Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information, and do not contain specific and detailed information tailored to individual data processing operations as required by the GDPR.
Furthermore, the Sweepstakes Rules stipulate that, for matters not regulated therein, the privacy policy available on the Company’s website shall prevail; this results in fragmented information and fails to ensure that data subjects can access the full terms and conditions of data processing in a single, transparent location. (264) Based on the foregoing, the Authority finds that, with respect to the Prize Draw Rules, the Company has violated its obligation under Article 12(1) of the GDPR to provide transparent, understandable, and easily accessible information, as well as its obligations under Article 13(1)(c), (e), and (f), as well as its information obligations set forth in Article 13(2)(a). 4. General Terms and Conditions (265) The Authority found that the Company’s General Terms and Conditions for Consumers and Users (hereinafter: Website Terms and Conditions) allowed users, during the period from February 1, 2020, to August 31, 2022, to provide their child’s name, gender, and age (broken down by year, month, and day) during registration.
49 (266) The Authority notes that none of the Company’s privacy notices applicable during the period under review contained information regarding the processing of this personal data; thus, the data subjects were not informed of the purpose, legal basis, duration, or recipients of the data processing. (267) In the Authority’s assessment, the processing of personal data relating to children in this manner resulted in a particularly serious lack of transparency. The Authority found that the Company allowed users to provide data concerning children (specifically, to record information regarding the children and their dates of birth); however, in this context, the Privacy Notice did not contain explicit and unambiguous information stating that such data processing would take place. (268) Under these circumstances, it was not apparent to the data subjects that the data provided would be processed as personal data relating to children, nor was it clear for what purposes and under what conditions the Company would process such data.
The fact and scope of the data processing thus remained hidden from the data subjects. (269) In the Authority’s assessment, the fact that the Company did not specify the processing of personal data relating to children in the Privacy Notice should be considered a particularly aggravating circumstance, as this made it impossible for the data subjects not only to understand the data processing but also to recognize that it was taking place. (270) Based on the foregoing, the Authority determined that the Company violated Article 13 (1)(c) and (e), as well as its information obligations under Article 13(2)(a)–(d), as it did not make this information available to data subjects at all. (271) The Authority further found that Chapter XII of the Website’s General Terms and Conditions (GTC), effective as of August 31, 2022, does not provide clear and unambiguous information regarding the legal bases for data processing.
4 of the GTC gives the impression that the processing of personal data may take place solely on the basis of the data subject’s consent, and that in the absence of consent, data processing may only occur in an anonymous manner; however, based on the Company’s actual data processing practices and other data processing documents, much of the data processing is based on the performance of a contract, the fulfillment of a legal obligation, or a legitimate interest. Such wording does not make the actual legal basis for each data processing operation clear to data subjects; therefore, the information provided does not meet the requirement for clear and transparent information set forth in Article 12(1) of the GDPR. 3 of the General Terms and Conditions, the Company “shall not disclose or transfer personal data to third parties,” a statement that is inconsistent with the Company’s actual data processing practices and the provisions set forth in its other data processing documents.
The provision fails to account for the involvement of courier services, payment service providers, IT and marketing service providers, as well as other data processors and recipients, and thus does not provide data subjects with adequate information regarding the recipients of their personal data and data transfers. (273) Consequently, the Company has violated Article 12(1) of the GDPR and Article 13(1)(e) of the GDPR. 5. Information Regarding the Blog (274) The Authority found that the Data Processing and Privacy Notice (hereinafter: “Blog Notice”) applicable to the […] website, effective as of September 2, 2022, 50 does contain certain information required under Article 13 of the GDPR regarding data processing related to posting comments and the exercise of data subjects’ rights, it does not provide comprehensive, sufficiently clear, and consistent information regarding additional data processing activities related to the operation of the Website—in particular, the use of cookies, the processing of IP addresses, and data processing for web analytics and remarketing purposes in connection with the use of the […] and […] services.
In this regard, the Blog Privacy Policy does not present, in a clear and organized manner, the purpose, legal basis, scope of data processed, retention period, or the role of recipients for each data processing activity, even though the document itself states that users’ IP addresses are processed and that […] collects, stores, and uses data in connection with the use of the Website for remarketing purposes. (275) The Authority further notes that the Blog Privacy Notice contains an internal contradiction regarding the information provided on recipients and data transfers. 2 explicitly describes the use of the […] and […] services, as well as the fact that the information stored by cookies—including the User’s IP address—is stored on […]’s servers in the United States and may be transferred to third parties as necessary. However, the Blog Privacy Policy does not provide adequate information regarding the safeguards in place for such data transfers to third countries, nor does it clarify the exact role that […] plays in the data processing.
As a result, it is not clear to data subjects to which recipients their personal data is transferred, for what purposes, and under what legal conditions. (276) In the Authority’s assessment, the Blog Privacy Notice is not only incomplete with regard to cookie and analytics data processing but also suffers from general structural and content-related issues, as the legal basis, duration, and recipients of the data processing are in many cases not presented clearly and consistently; furthermore, the document is based in part on general, declarative content rather than actual information regarding data processing. (277) Based on the foregoing, the Authority determined that the Company violated Article 12 of the GDPR Paragraph (1), as the Blog Privacy Notice failed to provide data subjects with a concise, transparent, understandable, and easily accessible presentation of information regarding the processing of personal data.
Furthermore, the Company violated Article 13(1)(c) of the GDPR, as the legal basis for the processing of cookies, IP addresses, and data for web analytics and remarketing purposes was not clearly defined; Article 13(1)(e) of the GDPR, as the scope of recipients and service providers involved in data processing was not presented in a clear and unambiguous manner; and Article 13(1)(f) of the GDPR, as it did not provide adequate information regarding the appropriate safeguards for data transfers to third countries, and Article 13(2)(a) of the GDPR, as the duration of the data processing in this context and the criteria for determining it were not adequately described. 6. Assessment of the Company’s Statements (278) In the Authority’s view, the Company cited circumstances in several of its statements that do not excuse the violation of the obligation to provide information regarding data processing.
The mere fact that the Company claims it had no intention of engaging in unlawful data processing, or that it acted in the belief that its documents complied with the law, does not affect its liability under the GDPR. Similarly, the fact that an external expert or a service provider performing the duties of a data protection officer was involved in drafting the documents is not sufficient to excuse the violations, as under the GDPR, the data controller itself is responsible in all cases for compliance and for demonstrating such compliance. 51 (279) The obligation to provide information under Articles 12–13 of the GDPR is not fulfilled merely because the data controller provides information in multiple documents, or because certain data processing activities may be presumed to be known to the data subjects. The requirement for transparent information stipulates that the data controller must present the circumstances of the data processing to the data subject in a clear, precise, and consistent manner, either in a single location or at least in a way that is clearly linked; the provision of scattered, inaccurate, or contradictory information does not satisfy this obligation.
(280) In the Authority’s view, the Company’s statement that it has no direct information regarding the data processing practices of certain partners—in particular, whether profiling is taking place—is also problematic from a data protection perspective, given that the Company itself listed these partners in its disclosure as recipients or as parties involved in data processing. It follows from the principle of accountability that the data controller must be aware of the role of the service providers it engages, the legal nature of the data transfer, and the material circumstances of data processing affecting the data subjects, and must be able to provide accurate information regarding these matters. Therefore, an approach whereby the data controller itself cannot explain why and in what capacity a particular recipient was listed in the notice is unacceptable. (281) Furthermore, in the Authority’s view, the Company erroneously attached significance to the fact that, as it claimed, certain contested provisions were not applied in practice, and that the number of requests, objections, or erasure requests from data subjects was low.
A violation of the information obligation under the GDPR occurs simply through the provision of incomplete, inaccurate, or misleading information. It is not a prerequisite for establishing a violation that data subjects actually exercise their rights, file a complaint, or that the data controller applies the erroneous provision in a specific case. On the contrary, one consequence of inadequate information may be that the data subject does not recognize their rights or the true nature of the data processing, and therefore does not seek to enforce their rights. 3. , changes made to the data processing notice after the Company became aware of the proceeding. However, the Authority will take the measures taken by the Company into account as mitigating circumstances when imposing the fine. IV. Legal Consequences (283) The Authority examined whether the established violations justified the imposition of a data protection fine against the Company.
In this regard, the Authority assessed all relevant circumstances of the case in accordance with , taking into account the criteria set forth in Guideline No. 4/2022 of the European Data Protection Board2 (hereinafter: the Guideline). (284) In the Authority’s view, given the nature, gravity, duration, and impact on data subjects of the violations identified in this case, issuing a warning cannot be considered a proportionate sanction; therefore, the requirements of specific and general prevention necessitate the imposition of a data protection fine. 2 Guideline No. pdf 52 (285) The infringements found—violation of the principle of transparency and failure to comply with the obligations to inform data subjects under Articles 12–13—are classified as infringements falling within the higher category of fines under Article 83(5) of the General Data Protection Regulation. (286) In determining the amount of the fine, the Authority took into account the Company’s financial data.
Based on the Company’s publicly available annual report for fiscal year 2024, the Company’s net revenue was […] HUF, which, according to the classification set forth in the Guidelines, places it in the category of enterprises with annual revenue between 10 million and 50 million euros. (287) Pursuant to Article 83(5) of the General Data Protection Regulation, the Company may be subject to an administrative fine of up to 20,000,000 euros in this case, or an amount not exceeding 4% of the Company’s total worldwide annual turnover for the preceding fiscal year, whichever of the two is higher. Four percent of the Company’s 2024 revenue amounts to […] HUF, which does not exceed the fixed maximum fine; therefore, the statutory upper limit in this case is the amount equivalent to 20,000,000 euros. (288) Based on the available information, the Authority did not identify any circumstances that would indicate that the violations were committed intentionally.
Given the nature of the identified deficiencies, the Authority assessed the violations as negligent in nature. (289) In determining the amount of the fine, the Authority assessed the following aggravating circumstances based on the criteria set forth in Article 83(2) of the GDPR: – Taking into account the nature, gravity, and duration of the violations [Article 83(2)(a) of the GDPR], the violations found persisted throughout the period under review from January 1, 2020, to November 12, 2025. The Authority also considered it an aggravating circumstance that the information provided in one of the Company’s notices regarding the exercise of data subjects’ rights did not comply with the relevant provisions of the GDPR but interpreted them restrictively by raising the prospect of charging administrative fees and by stipulating in advance the possibility of refusing to take action in the event of repeated requests.
– Regarding the size of the group of data subjects [GDPR Article 83(2)(a)]: traffic to the Website was exceptionally high during the period under review. According to the Company, the site was visited by […] people in 2021, […] in 2022, […] in 2023, […] in 2024, and […] in 2025. In addition, a significant number of orders were recorded in the online store (more than […] in 2024 and more than […] in the first half of 2025). Thus, the group of data subjects was extremely broad. – With regard to the existence of prior infringements [GDPR Article 83(2)(e)]: the Authority had previously found the Company liable in Case No. NAIH-7905/2025, which, although it did not concern the provision of information on data processing but rather the ensuring of data subjects’ rights, nevertheless, in the Authority’s view, this circumstance indicates that the Company’s data protection compliance practices were generally deficient, and that the Authority’s previous findings did not lead to comprehensive, system-wide compliance.
(290) In determining the amount of the fine, the Authority assessed the following mitigating circumstances based on the criteria set forth in Article 83(2) of the GDPR: - the infringements were committed through negligence; intent was not proven [Article 83(2)(b) of the General Data Protection Regulation]; 53 - the Company took measures to remedy the violations [Article 83(2)(f) of the GDPR]; - the Authority exceeded the administrative deadline. (291) Based on an assessment of all the circumstances of the case, the Authority deemed the violations to be of a serious nature, given their systemic nature, their duration, and their impact on a wide range of affected parties. (292) Taking all of this into account, the Authority determined the amount of the fine not at a level close to the maximum, but at an amount proportionate to the nature of the violations, the Company’s economic situation, and the objectives of specific and general prevention.
The circumstances set forth in Article 83(2)(h), (i), and (j) of the GDPR did not apply in this case. (293) The Authority determined the amount of the fine in the exercise of its statutory discretion. The Authority imposed a fine that is proportionate to the gravity of the violations and suitable for achieving the objectives of specific and general deterrence. (294) Based on the foregoing, the Authority has decided as set forth in the operative part. V. Other Issues (295) The Authority’s jurisdiction is defined by Sections 38(2) and (2a) of the Information Act, and its jurisdiction extends to the entire territory of the country. (296) This decision of the Authority is based on Sections 80–81 of the Ákr. and Section 61(1) of the Infotv. The decision becomes final upon its notification pursuant to Section 82(1) of the Ákr. , an appeal against this decision may be filed through administrative litigation.
, the obligor is required to pay a late payment penalty at the statutory interest rate if the obligor fails to fulfill a monetary payment obligation by the due date. (298) Pursuant to Section 6:48(1) of Act V of 2013 on the Civil Code, in the case of a monetary debt, the obligor is required to pay late payment interest at a rate equal to the central bank’s base rate in effect on the first day of the calendar half-year affected by the delay, calculated from the date the delay began. ). , the Budapest Regional Court has exclusive jurisdiction. Pursuant to Section 27 (1)(b) of the Code of Civil Procedure, legal representation is mandatory in legal disputes over which the court has exclusive jurisdiction. Pursuant to Section 39(6) of the Code of Civil Procedure, filing a complaint does not have the effect of suspending the entry into force of the administrative act. (300) Pursuant to Section 29(1) of the Kp.
and, in light thereof, Section 604 of Act CXXX of 2016 on the Code of Civil Procedure, and pursuant to Section 19(1)(b) of Act CIII of 2023 on the Digital State and Certain Rules Governing the Provision of Digital Services, the client’s legal representative is required to communicate electronically. 54 (301) The time and place for filing the complaint are specified in Section 39(1) of the Code of Civil Procedure. Information regarding the possibility of requesting a hearing is based on Sections 77(1) and (2) of the Code of Civil Procedure. ). Section 59(1) and Section 62(1)(h) of the Itv. exempt the party initiating the proceedings from the requirement to pay the fee in advance. (303) If the Company fails to adequately demonstrate compliance with the prescribed obligations, the Authority shall deem that the Company has failed to fulfill the obligation by the deadline. , if the Company has not complied with the obligations set forth in the Authority’s final decision, the decision shall be enforceable.
Pursuant to Section 82(1) of the Administrative Procedure Act, the Authority’s decision becomes final upon notification. Pursuant to Section 133 of the Administrative Procedure Act, enforcement—unless otherwise provided by law or government decree—shall be ordered by the authority that issued the decision. Pursuant to Section 134 , enforcement is carried out by the state tax authority, unless otherwise provided by law, a government decree, or—in matters within the jurisdiction of a local government—a local government ordinance. Pursuant to Section 61(7) of the Information Act, with respect to an obligation set forth in the Authority’s decision to perform a specific act, engage in specific conduct, tolerate a situation, or cease a certain activity, the Authority shall enforce the decision Dated: Budapest, date as per the electronic signature Dr. habil. Attila Péterfalvi, Chair, Professor