Skip to content
Enforcement · NAIH (Hungary) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

NAIH fines online store HUF 10M for missing and inadequate privacy notice

Original title: NAIH (Hungary) - NAIH-4462-5-2026

Summary

Facts — The DPA initiated an investigation into the processing of the personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The controller’s main business activity was the wholesale distribution of beverages. The personal data of the data subjects was processed on the website of the online store for registration, placing orders, billing, communication, delivery, creation of user accounts, and newsletter subscription. During the period under review, i.e. between January 2020 and October 2025, no standalone privacy notice was available on the website. The previously archived privacy notice and the data processing section included in the general terms and conditions described the processing operations in a rather brief and general manner. The controller argued that the inaccessibility of the privacy notice followed from a technical error that was corrected upon discovery. Holding — The DPA found that the controller had violated Articles 5(1)(a), 5(2), 12(1), 13(1)(a), (c), and (e) as well as 13(2)(a)–(e) GDPR and issued it a fine of HUF 10,000,000 (€27,300). When issuing the fine, the DPA took into account that the identified infringements followed from systemic inadequacies of the privacy notice and were of continuous nature. In addition, the DPA ordered the controller to develop and publish a uniformly structured privacy notice that is aligned with its actual processing operations. First, the DPA identified a violation of the principle of transparency laid down in Article 5(1)(a) GDPR: the information provided to data subjects about the processing of their personal data was either incomplete or completely absent, and changes could not be tracked. Second, the DPA held that the controller had violated the principle of accountability set forth in Article 5(2) GDPR, as it had failed to submit appropriate documentation covering the period under review. In addition, the controller’s data processing practices could not be continuously monitored or subsequently verified based on the documentation it had provided. Finally, the DPA confirmed that the controller had not complied with the requirements laid down in Articles 12(1), 13(1)(a), (c) and (e), and 13(2)(a)–(e) GDPR. Due to the lack of a privacy notice, the controller could not demonstrate that it had provided data subjects with the information required under Article 13 GDPR apart from brief, general statements in the archived privacy notice and the general terms and conditions. The controller had thus failed to provide the data subjects clear and differentiated information regarding the purpose and legal basis for each processing operation. Furthermore, the controller had not adequately identified the recipients or the storage period of personal data or information on the data subjects' rights. Due to the form and scope of the information provided, the controller had also infringed Article 12(1) GDPR.

How it connects

Full text

Case No.: NAIH-4462-4/2026. Subject: Decision in an ex officio data protection Background: NAIH-15138/2025 administrative proceeding NAIH-9722/2025. Case Officer: DECISION The National Authority for Data Protection and Freedom of Information (hereinafter: the Authority), with respect to the […] website (hereinafter: the Website), regarding the data processing practices of the online store operating on the Website , specifically regarding prior notification, against […] hereinafter: the Company, as the operator of the online store operating on the Website, pursuant to the Regulation on the protection of natural persons with regard to the processing of personal data and the free movement of such data, and repealing Directive 95/46/EC Regulation (EU) 2016/679 (hereinafter: General Data Protection Regulation or GDPR), the Authority hereby issues the following decisions. 1. The Authority finds that the Company negligently violated - Article 5(1)(a) of the General Data Protection Regulation; - Article 5(2) of the General Data Protection Regulation; - Article 12(1) of the General Data Protection Regulation; - Article 13(1)(a), (c), and (e) of the General Data Protection Regulation; and - Article 13(2)(a) through (e) of the General Data Protection Regulation. 2. In light of the identified violations—pursuant to Article 58(2)(d) of the GDPR —the Authority hereby orders the Company, ex officio, to amend the data processing notice practices on the Website under review to remedy the deficiencies identified in paragraphs (76) through (112) of this decision, and to ensure that is actually made available to data subjects. The Company is required to develop a uniformly structured privacy notice aligned with its actual data processing operations and to publish it on the Website, which is easily accessible to data subjects, transparent, understandable, and clearly worded, and which, for each data processing activity, specifies in particular the purpose and legal basis of the data processing, the data being processed, the recipients or categories of recipients, the duration of the data processing or the criteria for determining it, as well as information regarding the data subjects’ rights and how to exercise them . The Company is also required to ensure that the privacy notice is continuously available on the Website and that its availability is not interrupted for technical reasons; and is also required to document the individual versions of the notice, their effective dates, and the dates of their publication in such a way that compliance with the GDPR can be verified at a later date. The Company is required to demonstrate compliance by submitting the amended privacy notice to the Authority in such a way that the amendments are clearly identifiable. 3. Due to the violations set forth in paragraph 1, ........................................................................................................................................................................................................................................................................ 1055 Budapest Tel.: +36 1 391-1400 naih.hu/adatkezelesi-tajekoztatok 9–11 Falk Miksa Street KR ID: 429616918 ugyfelszolgalat@naih.hu 2 10,000,000 HUF, that is, ten million forints data protection fine . * * * The Company must take the measures prescribed in Section 2 within , together with supporting evidence, to the Authority. The data protection fine must be paid within 30 days of this decision becoming final to the Authority’s forint account for the collection of centralized revenues (10032000- 01040425-00000000 Centralized Collection Account, IBAN: HU83 1003 2000 0104 0425 0000 0000). When transferring the amount, please reference case number NAIH-4462/2026. BÍRS. . If the Company fails to meet its obligation to pay the data protection fine by the deadline, it it shall be required to pay a late payment penalty to the above account number. The late payment penalty shall be equal to the statutory interest rate, which corresponds to the central bank’s base rate in effect on the first day of the calendar half-year affected by the delay. In the event of failure to comply with the obligations set forth in Section 2, as well as failure to pay the data protection fine and the late payment penalty, the Authority shall order the enforcement of this decision. There is no right to administrative appeal against this decision; however, it may be challenged in administrative court by filing a complaint addressed to the Budapest Metropolitan Court within 30 days of notification. The complaint must be submitted to the Authority electronically, which will forward it to the court together with the case files. A request for a hearing must be indicated in the complaint. For those not eligible for full exemption from personal fees, the administrative court fee is 30,000 HUF; the case is subject to the right to record a fee entry. Legal representation is mandatory in proceedings before the Budapest Regional Court. STATEMENT OF REASONS I. Course of the Proceedings I.1. The Administrative Inspection (1) On April 9, 2025, the Authority decided to initiate an administrative inspection regarding the data processing activities of the online store operating on the […] website , covering preliminary information regarding compliance with the General Data Protection Regulation, under case number NAIH-9722/2025. (2) On June 16, 2025, the Authority conducted an unannounced inspection, which consisted of viewing the website, making backups, and performing a test registration. 1. The form designated NAIH_K01 is used to initiate administrative proceedings: NAIH_K01 form (September 16, 2019) The form can be filled out using the general form-filling program (ÁNYK program). The form is available at the following link: https://naih.hu/kozig-hatarozat-birosagi-felulvizsgalata 3 (3) After reviewing the Website, the Authority identified a suspected violation regarding the adequacy of the data processing notice related to the operation of the online store. I.2. Administrative Proceedings (4) The Authority concluded its official inspection and, pursuant to Section 60 (1) , on October 28, 2025, under case number NAIH-15138/2025, initiated a data protection procedure covering the Website’s data processing practices, specifically the data processing notice authority proceeding, in which it also utilized data and documents from previous official inspections and audits. The proceeding did not extend to examining other data protection requirements, nor to a comprehensive review of the Company’s data processing procedures. (5) The Authority may examine compliance with the provisions of the General Data Protection Regulation—applicable as of May 25, 2018— . The Authority refrained from examining the period prior to January 1, 2020. (6) The period under review lasted until the initiation of this proceeding; therefore, the period following the initiation of the proceeding is not included. (7) Based on the foregoing, the period under review extends from January 1, 2020, to the date of initiation of this proceeding, that is, October 28, 2025. I.2.1. Clarification of the Facts (8) In its order dated October 28, 2025, case number NAIH-15138-2/2025, notified the Company of the initiation of the data protection authority proceedings and called upon it to submit a statement for the purpose of clarifying the facts. (9) In its response letter dated November 17, 2025, filed under case number NAIH-15138-4/2025, the Company stated that during the period under review, it generated the data processing documentation using the […] system and embedded them into the Website from there. According to its statement, the documents were up to date; however, due to a change in the external service provider’s system caused the embedding to “malfunction,” so the privacy notice did not appear on the Website. As a result, the relevant content was not accessible via the “Privacy Policy” link was also unavailable. (10) They were unable to determine the exact time the error occurred, as it was related to a modification to the external service provider’s system, about which they had not received separate notification. However, they stated that upon detecting the error, they took immediate steps to correct it, and currently the privacy notice is directly and independently accessible on the Website. (11) The Company further emphasized that, in its opinion, the error may have occurred after March 2025, during a one-year re-deployment process, and that it had no intention of misleading the data subjects or providing them with incomplete information. (12) According to the Company’s statement, during the period under review, there were no GTCs published as separate versions that differed substantially from one another. Based on its presentation, the Company applied the GTC generated by the […] system, which was automatically updated as part of the service to reflect changes in legislation. Accordingly, the Company did not maintain separate versions, and was unable to submit any earlier GTC documents with different content. (13) According to its statement, the Company uses cookies that are technically necessary on the website, as well as […] cookies for statistical and marketing purposes related to its services, and […] 4 related cookies. It stated that the use of non-essential cookies is based on the prior consent of the data subjects, and that information regarding these cookies was included in the privacy policy, which was available via a separate link. (14) At the same time, the Company expressly acknowledged that, during the period under review, the cookie notice was not displayed in an appropriate, standalone format on the Website. According to the Company’s statement, following the Authority’s inquiry, it introduced a cookie management solution that appears upon the first visit, allows users to accept or reject cookies by category, and ensures that, in the absence of consent, only strictly necessary will function. (15) Users may withdraw their consent via the cookie management interface or through their browser settings. The Company also indicated that it had not received it had not received any specific technical recommendations regarding the implementation of cookie management. (16) In the Company’s view, the primary cause of the incomplete or inadequate information was the same technical error that also affected the availability of the privacy notice. It explained that it used a single, comprehensive document in its […] system, which included the data controller’s identification details, the purpose and legal basis of data processing, the rights of data subjects, the legal framework, and the relevant provisions of the General Terms and Conditions. (17) According to the Company, due to a fault in the external system, this document was either not or was not properly available on the Website; therefore, the detailed information was not actually accessible. The error was corrected upon discovery, and as a result, the data processing information has once again become fully and transparently available on the Website. (18) The Company uses a simple pre-entry declaration mechanism, under which the visitor declares whether they are over or under 18 years of age. It was explained that, during the operation of the system, no date of birth or other personal data is requested; access is granted or denied solely based on the user’s declaration, and no separate data fields need to be filled out. (19) In his view, the age verification process does not involve data processing capable of identifying the data subject; the solution serves exclusively a functional purpose, namely restricting access to alcoholic beverages. A brief notice appears on the interface stating that the site is accessible only to those 18 years of age or older, and by accessing the site, the user declares that they are of legal age. (20) The Company provided annual, estimate-based data on visitors to the Website, according to which […] people visited the site in 2020, […] in 2021, […] people, in 2023 […] people, in 2024 […] people, and in 2025 […] people visited the site. The number of customers, i.e., the number of orders, during the same period was […] in 2020, […] in 2021, […] in 2022, […] people, […] people in 2024, and […] people in 2025. (21) The Company attached several screenshots to support its statement. These include, on the one hand, an email dated March 6, 2025, which states that during the use of the embedded codes, an “error message 1002” appeared, caused by a discrepancy in the domain names ([…] and […]), which may have led to the embedding not functioning properly. Furthermore, based on the attached invoice, it can be established that on March 5, 2025, the Company for the […] service, which covered the use of two domains ([…] and […]). 5 (22) The Company also attached additional correspondence in which, during communication with the web service provider, also raised technical issues related to the settings and subscription restrictions, in connection with which the system displayed error code “1002.” (23) In its order dated November 24, 2025, case number NAIH-15138-5/2025, the Authority called upon the Company to submit a further statement in order to clarify the facts of the case. The Authority requested that the Company verify what privacy notices it provided during the period under review, and identify the previous , their scope of application, and the date of their publication, and to attach the documents containing substantive amendments and proof of their publication. The Authority also requested that the attached form be used for each document in the response. (24) In its response dated December 11, 2025, registered under No. NAIH-15138-6/2025, submitted a single completed form without a statement, which contained data exclusively regarding the GTC document. On the form, the Company indicated the versions effective as of July 1, 2016, and the version effective as of February 23, 2022, noting in the latter case that a comprehensive, uniform amendment had been made. As proof of publication, the Company provided URL links and Wayback Machine archives. (25) In its order dated March 17, 2026, case number NAIH-4462-1/2025, the Authority called upon the Company to submit a further statement in order to clarify the facts of the case, and urged it to submit all documents and technical information on the basis of which the duration of the occurrence or existence of the error related to the display of the privacy notice on the Website could be approximately determined, and once again requested a detailed description of the content of the privacy notice, the scope of document versions, their validity, publication, and amendments, as well as verification of the relevant documents and their publication. (26) In its response dated April 2, 2026, filed under reference number NAIH-4462-2/2025, the Company that it had already submitted to the Authority all documents at its disposal, as well as the materials obtained from the IT specialist responsible for operating the Website. According to the Company, it is unable to obtain any further documents, and in his view, he had already answered the Authority’s questions to the best of his knowledge. (27) In its order No. NAIH-4462-3/2026, dated April 7, 2026, the Authority informed the Company that the evidentiary proceedings had been concluded and that it could review the evidence uncovered during the clarification of the facts in accordance with the rules governing access to documents and could submit further motions for evidence. (28) The Company did not state that it intended to exercise its right to inspect the documents, nor did it make any further motions for evidence. I.2.2. Established Facts (29) During its examination of the Website, the Authority found that no separate privacy policy compliant with the GDPR was available on the Website. Although the Website did feature a link titled “Privacy Statement,” during the Authority’s inspection, this link did not lead to an accessible data processing notice. The Authority therefore proceeded from the premise in its Order No. NAIH-15138- 2/2025 that no accurate, understandable, and transparent privacy policy available to data subjects. 6 (30) The Authority subsequently examined earlier, archived versions of the Website. Based on the Wayback Machine backups from September 21, 2020, and October 25, 2021, the Privacy Policy subpage was available at that time, but it contained only a brief, general privacy policy. According to the essence of this statement, the Company used personal data to fulfill orders, issue invoices, send newsletters (with consent), and, in the case of package delivery, […] to transfer data to a courier service. However, the statement did not separately list, for each data processing activity, the mandatory information required under Article 13 of the GDPR , in particular the specific purpose, legal basis, retention period, and recipients of each data processing activity, as well as the detailed procedures for exercising the data subject’s rights. (31) Based on the archived version as of May 27, 2022, the Authority also found that the Privacy Policy subpage was no longer accessible at that time, but led to a “404 – Not Found” error. This indicates that the privacy notice on the Website was not only incomplete in terms of content at certain points in time, but was also completely inaccessible at other points in time. (32) The Authority also reviewed the archived versions of the General Terms and Conditions. The versions of the GTC dated September 27, 2020, and June 17, 2021, contained a chapter on data processing; however, these data processing provisions did not differ in substance, and both documents were published as the GTC effective as of July 1, 2016. This is consistent with the Company’s statement that there were no GTCs published as separate versions that differed substantially from one another . (33) Although the section on data processing in the GTC did contain certain data protection information, it was not sufficient to fulfill the information obligation under the GDPR. Rather than presenting the circumstances of data processing in a separate and clear structure related to each specific instance of data processing, it used general, partly boilerplate, and outdated wording. It presented the legal basis for data processing and the rights of data subjects partly based on the former logic of the Information Act, referred to registration in the data protection registry, and furthermore did not contain comprehensive information differentiated by each data processing activity, as required . (34) In its statements, the Company claimed that it applied the General Terms and Conditions (GTC) generated by the […] system, which, according to the Company, were automatically updated as part of the service. It further stated that it did not maintain separate versions and was unable to submit an earlier version of the GTC with different content. The Company attributed the error regarding the availability of the disclosure to a technical problem; however, it was unable to substantiate with documentation the exact time the error occurred, its duration, or its progression. (35) Despite repeated requests from the Authority, the Company failed to submit a data processing notice or version control document that would have made it possible to determine exactly what information regarding data processing was available to data subjects exact content of the privacy notice available to data subjects during the period under review, its effective dates, when it was published, and when and how its content was amended. Subsequently, the Company expressly stated that it had already submitted documents at its disposal had already been submitted, and it had no possibility of obtaining additional documents. 7 (36) To summarize the above, according to the facts established by the Authority, the Company’s data processing practices were problematic on three levels. 1. During the Authority’s inspection, no standalone data processing notice was available. 2. The previously archived Privacy Statement was merely a brief, general text that did not fully include the content required under Article 13 of the GDPR . 3. The data processing section included in the General Terms and Conditions did not remedy this deficiency, as it did not provide differentiated, up-to-date, and GDPR-compliant information for each specific data processing activity. I.2.2.1. Identity of the Data Controller (37) The Company is the operator of the Website and the domain holder. (38) The Company’s primary activity is “wholesale of beverages.” (39) Pursuant to Section 3 of Act XXXIV of 2004 on Small and Medium-Sized Enterprises and the Support of Their Development, , a microenterprise is defined as an enterprise with a total number of employees of fewer than 10 and annual net sales or total assets not exceeding the forint equivalent of 2 million euros. According to available data, in 2025 the Company employed […] people, and its annual net sales were […] HUF, based on which the Company qualifies as a small enterprise. I.2.2.2. The Data Processing Notice Published on the Website (40) During the administrative proceedings, the Company did not submit a data processing notice for the period under review that would have allowed for a substantive assessment could have been substantively assessed. The Company did not verify what specific content the notice on the Website contained, nor did it provide supporting documentation regarding its publication, scope, and amendments. (41) The Authority examined the Company’s data protection notification practices based on the available evidence—in particular, the forensic backups of the Website and the archived versions of the Website. According to the archived content, a link titled “Privacy Statement” was available on the Website, which was a brief, general description. The document did not contain the mandatory information elements required under Article 13 of the GDPR; for further details , it directed users to the link for the General Terms and Conditions. Its content reads as follows: “PRIVACY STATEMENT—The personal (name, address, phone number, etc.) and your user data will be processed in accordance with the Data Protection Act solely for the purpose of issuing the invoice necessary to fulfill the order you placed and, with your consent, for our own advertising purposes (newsletter). We will not disclose the data to any third parties other than the […] courier service, which is necessary to fulfill the specific order (i.e., in the case of package delivery). The transfer of data to third parties may only take place with your prior, explicit consent. For a detailed description, please see our General Terms and Conditions! ([…])” (emphasis added by the Authority). (42) The content of subsequent archived versions remained essentially unchanged; however, the Authority also identified an archived version in which the Privacy Policy was not available at all, and the link led to a “404 – Not Found” error. This latter archived version—from 2022— indicates that, during part of the period under review, the Company also failed to provided accessible privacy information to data subjects. (43) The Authority found that previously, the General Terms and Conditions (as per the annex to Memorandum No. NAIH-9722-3/2025 , as of June 2, 2025, hereinafter: GTC) also contained, albeit sporadically, brief provisions on data protection and data processing. 8 (44) The first page of the GTC listed the hosting provider’s details; page 5 contained general statements regarding the storage of digital content in the database and the encryption and encoding of “sensitive data,” as well as information in the description of the purchase process stating that the customer could choose between an order method requiring registration and one that did not involve saving data. On page 6 of the GTC, under the heading “Data Processing Notice,” the data controller’s identification details and contact information were listed, and a separate section titled “The : legal framework, legal basis, purpose, scope of personal data processed, and duration of data processing ,” but no substantive, case-by-case explanation of the data processing activities was provided under this heading. On pages 6–7 of the GTC, there is general information regarding the use of cookies, the section titled “Additional Data Processing Activities,” and the section on data processors—left blank with no names or contact information for data processors—data security measures, data subjects’ rights, the Authority’s mailing address and email address, as well as information regarding registration in the data protection registry . (45) The Authority also examined other sections of the Website; however, information regarding the essential circumstances of data processing was not available on other pages or under other menu items. (46) The Authority also examined other sections of the Website and the purchasing process in order to determine what operations involving the processing of personal data actually take place on the Website. In its memorandum No. NAIH-9722-2/2025, the Authority determined that the Website also allowed private individuals to place orders and register. Several types of purchasing processes were available on the Website: logging in as a registered customer, placing an order without registration, and placing an order with a new registration. During the “placing an order with a new registration” process, the required information included full name, phone number, email address, ZIP code, city, street, and house number, as well as a password. The order interface also offered the option to subscribe to a newsletter; however, this was not a mandatory part of the purchasing process. (47) The Authority further found that on the data entry page during the purchasing process, there was a checkbox for accepting the General Terms and Conditions, and accepting this was a prerequisite for a successful order. However, based on the available screenshots, no separate notice regarding the essential circumstances of personal data processing appeared during the order process involving registration, , nor was there any separate information element that would have drawn the data subject’s attention to the purpose, legal basis, duration, and recipients of the data processing, or to the data subject’s rights . Users were required to accept the General Terms and Conditions (GTC) during the purchase process; however, the Authority found that the data processing provisions contained in the GTC did not provide the comprehensive and easily understandable information required for each specific data processing activity under Article 13 of the GDPR. (48) Based on the foregoing, the Authority determined that the Website did in fact personal data processing on the Website, at least for the purposes of registration, order fulfillment, invoicing, maintaining contact, shipping, creating a user account, and, optionally, subscribing to the newsletter. In contrast, no privacy notice was made available to data subjects on the Website that would have described these actual data processing operations for each specific processing activity in a clear and comprehensive manner. II. Applicable Legal Provisions (49) Pursuant to Article 2(1) of the General Data Protection Regulation, the General Data Protection Regulation applies to the processing of personal data, whether fully or partially automated, as well as to the non-automated processing of personal data 9 that form part of a filing system or are intended to be included in a filing system. (50) Pursuant to Section 2(2) of the Information Act, the General Data Protection Regulation shall be applied with the supplements specified in the provisions indicated therein. (51) Pursuant to Section 38(2) of the Information Act, the Authority is responsible for monitoring and promoting the protection of personal data, as well as the right of access to data of public interest and data made public in the public interest, , as well as to promote the free flow of personal data within the European Union. (52) Pursuant to Section 38(2a) of the Information Act, the duties and powers established for the supervisory shall be exercised by the Authority with respect to legal entities subject to the jurisdiction of Hungary, as specified in the General Data Protection Regulation and this Act. (53) Pursuant to Section 38(3)(b) of the Information Act, within the scope of its responsibilities under Sections 38(2) and (2a), as specified in this Act, the Authority shall, in particular, upon the request of the data subject and ex officio, data protection authority proceedings. (54) Pursuant to Section 60/A(1) of the Information Act, the administrative deadline in proceedings before the data protection authority is one hundred and fifty days. (55) Pursuant to Section 60(1) of the Information Act, in order to ensure the enforcement of the right to the protection of personal data, the Authority shall initiate a data protection authority proceeding upon the data subject’s request to that effect and may initiate such a proceeding ex officio. (56) Pursuant to Section 71(2) of the Information Act: “The Authority may use documents, data, or other means of evidence lawfully obtained during its proceedings in other proceedings.” (57) Pursuant to Section 99 of Act CL of 2016 on General Administrative Procedure (hereinafter: Ákr.) , the Authority—within the scope of its jurisdiction—shall verify compliance with the and the fulfillment of the provisions set forth in enforceable decisions. (58) Pursuant to Section 103(1) of the Ákr., in ex officio proceedings, the provisions of this Act applicable to shall apply, subject to the exceptions set forth in this chapter. (59) Pursuant to Article 4(1) of the General Data Protection Regulation: “personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to the one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.” (60) According to Article 4(2) of the General Data Protection Regulation: “processing” means any data or data sets, whether by automated or non-automated means, including collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.” (61) Pursuant to Article 4(7) of the General Data Protection Regulation: “controller” means the natural or legal person, public authority, agency, or any other body that determines the purposes and means of the processing of personal data, either alone or jointly with others where the purposes and means of processing are determined by Union or Member State law 10 , Union or Member State law may also specify the controller or the specific criteria for designating the controller.” (62) Pursuant to Article 5(1)(a) of the General Data Protection Regulation: “The processing of personal data: (a) must be carried out lawfully, fairly, and in a transparent manner in relation to the data subject (“lawfulness, fairness, and transparency”);” (63) According to Article 5(2) of the General Data Protection Regulation: “The controller shall be responsible for and must be able to demonstrate such compliance (“accountability”).” (64) Pursuant to Article 12(1)–(6) of the General Data Protection Regulation: “(1) The controller shall take appropriate measures to ensure that the data subject is provided with all information regarding the processing of personal data referred to in Articles 13 and 14, as well as all information provided pursuant to Articles 15–22 and 34, in a concise, transparent, intelligible, and easily accessible form, using clear and plain language, particularly in the case of any information addressed to children. The information must be provided in writing or by other means—including, where appropriate, by electronic means. At the request of the data subject, oral information may also be provided, provided that the identity of the data subject has been verified by other means.” (65) According to Article 13 of the General Data Protection Regulation: “(1) Where personal data relating to a data subject are collected from the data subject, the controller shall, at the time of obtaining the personal data, provide the data subject with all of the following information: a) the identity and contact details of the data controller and, where applicable, the data controller’s representative; b) the contact details of the data protection officer, where applicable; c) the purposes of the intended processing of personal data and the legal basis for the processing; d) in the case of processing based on Article 6(1)(f), the legitimate interests of the controller or a third party; e) where applicable, the recipients or categories of recipients of the personal data, if any; f) where applicable, the fact that the controller intends to transfer personal data to a third country or to an international organization, as well as the existence or absence of a Commission adequacy decision, or, in the case of a transfer referred to in Article 46, Article 47, or the second subparagraph of Article 49(1), an appropriate and suitable safeguards, as well as a reference to the means of obtaining copies of them or to their availability. (2) In addition to the information referred to in paragraph (1), the data controller shall, at the time of collection, in order to ensure fair and transparent data processing, the data controller shall inform the data subject of the following additional information: a) the period for which the personal data will be stored, or, if this is not possible, the criteria used to determine that period; b) the data subject’s right to request from the data controller access to personal , to have it rectified, erased, or restricted, and to object to the processing of such personal data, as well as the data subject’s right to data portability; (c) in the case of processing based on Article 6(1)(a) or Article 9(2)(a), the right to withdraw consent at any time, which does not affect the lawfulness of the processing carried out on the basis of consent prior to withdrawal; d) the right to lodge a complaint with a supervisory authority; e) whether the provision of personal data is required by law or based on a contractual obligation, or is a prerequisite for entering into a contract, whether the data subject is required to provide the personal data, and the possible consequences of failing to provide such data; 11 f) the existence of automated decision-making referred to in Article 22(1) and (4), including profiling, as well as, at least in these cases, the logic applied and , the significance of such processing, and the expected consequences for the data subject. (3) If the data controller intends to further process personal data for a purpose other than that for which they were collected , the controller must, prior to such further processing, inform the data subject of this different purpose and of all relevant additional information referred to in paragraph (2). (4) Paragraphs (1), (2), and (3) do not apply if and to the extent that the data subject already possesses the information.” (66) Pursuant to Article 22 of the General Data Protection Regulation: “(1) The data subject has the right not to be subject to a decision based solely on automated processing—including profiling— that produces legal effects concerning him or her or similarly significantly . (2) Paragraph (1) shall not apply where the decision: a) is necessary for the conclusion or performance of a contract between the data subject and the data controller (b) is authorized by Union or Member State law to which the data controller is subject, which also provides for appropriate measures to safeguard the data subject’s rights, freedoms, and legitimate interests; or c) is based on the data subject’s explicit consent. (3) In the cases referred to in points (a) and (c) of paragraph (2), the data controller shall take appropriate measures to protect the data subject’s rights, freedoms, and legitimate interests , including, at a minimum, the data subject’s right to request human intervention by the data controller, to express his or her point of view, and to object to the decision. (4) The decisions referred to in paragraph (2) may not be based on special categories of personal data referred to in Article 9 (1), unless points (a) or (g) of Article 9(2) applies, and appropriate measures have been taken to protect the data subject’s rights, freedoms, and legitimate interests.” (67) Pursuant to Article 58(2) of the General Data Protection Regulation: “The supervisory authority, acting in its corrective capacity, shall: (a) issue a warning to the controller or processor that certain proposed data processing activities are likely to infringe the provisions of this Regulation; (b) issue a reprimand to the controller or processor if its data processing activities have infringed the provisions of this Regulation; (c) order the controller or processor to comply with the data subject’s request ; d) order the controller or processor to bring its data processing operations into compliance with the provisions of this Regulation, where applicable, in a specified manner and within a specified time frame; […] i) impose an administrative fine in accordance with Article 83, depending on the circumstances of the case, in addition to or in lieu of the measures referred to in this paragraph; and j) order the suspension of data flows to a recipient in a third country or to an international organization .” (68) Pursuant to Article 83(2) and (5) of the General Data Protection Regulation: “[…] (2) Administrative fines shall be imposed, depending on the circumstances of the case, in addition to or in lieu of the measures referred to in Article 58(2) (a) through (h) and (j). When determining whether an administrative fine should be imposed, and when setting the amount of the administrative fine, due consideration must be given in each individual case to the following: 12 a) the nature, gravity, and duration of the violation, taking into account the nature, scope, or purpose of the data processing in question, as well as the number of data subjects affected by the violation and the extent of the damage suffered by them; b) whether the infringement was intentional or negligent; c) any measures taken by the data controller or data processor to mitigate the damage suffered by the data subjects; d) the degree of liability of the data controller or data processor, taking into account the technical and organizational measures implemented by them pursuant to Articles 25 and 32; e) any relevant prior infringements committed by the controller or processor; f) the extent of cooperation with the supervisory authority to remedy the infringement and mitigate any negative effects of the infringement; ; g) the categories of personal data affected by the breach; h) how the supervisory authority became aware of the breach, with particular regard to whether the data controller or data processor reported the breach, and if so, to what degree of detail; i) whether any of the measures referred to in Article 58(2) had previously been ordered against the data controller or data processor in question—in the same matter—compliance with the measures in question; j) whether the data controller or data processor has complied with approved codes of conduct under Article 40 or approved certification mechanisms under Article 42; and k) other aggravating or mitigating factors relevant to the circumstances of the case, such as financial gain or avoided loss resulting directly or indirectly from the infringement. […] (5) Violations of the following provisions shall be subject—in accordance with paragraph (2)—to an administrative fine of up to 20 ,000,000 EUR, or, in the case of undertakings, to a fine up to 4% of the total annual worldwide turnover in the preceding fiscal year, whichever is higher: (a) the principles of data processing—including the conditions for consent—in accordance with Articles 5, 6, 7, and 9; (b) the rights of data subjects in accordance with Articles 12–22; (c) the transfer of personal data to a recipient in a third country or to an international organization in accordance with Articles 44–49; (d) obligations under Member State law adopted pursuant to Chapter IX; e) failure to comply with an instruction from the supervisory authority pursuant to Article 58(2), or with a or, in violation of Article 58(1), a failure to grant access; […]” […]” (69) Directive 2002/58/EC of the European Parliament and of the Council of July 12, 2002, concerning the processing of personal data and the protection of privacy (“Electronic Communications Privacy Directive”) Article 5(3) provides: “Member States shall ensure that the storage of data in a subscriber’s or user’s terminal equipment is permitted only on the condition that the subscriber or user concerned has given his or her prior consent, based on clear and comprehensive information—including, inter alia, the purposes of the data processing—provided in accordance with Directive 95/46/EC —including, among other things, information on the purposes of the data processing— has given his or her prior consent. This provision does not preclude technical storage or technical access whose sole purpose is the transmission of communications via an electronic communications network, or which is user has expressly requested, and which is strictly necessary for the provider to provide an information society service.” 13 III. Decision III.1. The Requirement for Prior Information on Data Processing (70) The purpose of the information obligations set forth in Articles 12–14 of the General Data Protection Regulation is to ensure that the data subject can in advance and can monitor the processing throughout its entire duration . The GDPR ensures this in several ways and regulates the right to information . These rights enable data subjects to review the processing it begins, to effectively monitor it throughout its entire duration, and to exercise any additional rights they may have or seek legal remedies. (71) The system of appropriate information in the General Data Protection Regulation serves to ensure that the data subject is aware of which of their personal data will be processed, by which data controller, for what purpose, on what legal basis, and for how long. This is essential to ensure that the to be in a position to effectively exercise their rights as data subjects. (72) Pursuant to Article 12(1) of the General Data Protection Regulation, the data controller shall take appropriate measures to ensure that the data subject is provided with all information relevant to the processing of personal data , as referred to in Articles 13 and 14, and all information required under Articles 15–22 and 34, in a concise, transparent, intelligible, and easily accessible , expressed clearly and in plain language. Incomplete or ambiguous information—particularly, but not exclusively, regarding the purpose and legal basis— may directly affect the data subject’s ability to exercise their rights. (73) Articles 13 and 14 of the General Data Protection Regulation set forth the requirements, content, and specific rules regarding information, based on two aspects. On the one hand, Article 13 governs the information to be provided when personal data is collected from the data subject by data controllers; on the other hand, Article 14 sets forth the rules for situations where personal data was not obtained from the data subject by the data controllers. (74) With regard to data processing by online stores, since personal data is collected from the data subjects, a central element of the obligation to provide information is Regulation, which lists the essential data processing circumstances about which the data controller must provide information. (75) In the context of prior information, the data controller must strive to ensure that data subjects receive as complete and accurate a picture as possible of the processing of their personal data, since only in this way can they assess how a given data processing operation affects them. Paragraphs (1) and (2) of Article 13 of the General Data Protection Regulation specify the minimum information regarding the circumstances of data processing that data controllers must provide to data subjects; however, this does not preclude the data controller from providing more detailed information. III.2. The Data Processing Notice Published on the Website (76) The Authority found that, for the period under review, the Company failed to demonstrate that it had provided data subjects with a privacy notice containing the information required under Article 13 of the GDPR. Despite the Authority’s repeated requests, the Company did not submit a privacy notice or any other document from which the specific content of the privacy notice applied during the period under review, as well as its effective start and end dates, the method of publication, and any amendments could be traced 14 . The Company expressly stated that it had already submitted all documents at its disposal, and that it has no means of obtaining additional documents, from which it follows that it cannot provide further evidence supporting compliance with the obligation to provide information . (77) At the same time, the Authority examined the available electronic evidence—in particular the forensic backups of the Website (Record No. NAIH-15138-3/2025) and the archived versions of the website (Annex to Order No. NAIH-15138-2/2025)— to examine the content actually available on the Website. The archived documents examined constitute the annexes to Record No. NAIH-9722- 3/2025. Of the available archived snapshots, the Authority examined in particular those recorded on September 21, 2020, and October 25, 2021. (78) In the above snapshots, the Privacy Policy subpage was accessible; however, it contained only brief, general information with the following content: “The personal data you provide (name, address, phone number, etc.) and your user data will be used, in accordance with the Data Protection Act, solely for the purpose of issuing the invoice necessary to fulfill the order you placed and, with your consent, for our own advertising purposes (newsletter). We will not transfer the data to any other third party—including to the […] courier service; we do not transfer it to any other third parties. The transfer of data to third parties may only take place after you have given your prior, explicit consent .” (79) The Authority found that this notice did not comply with the requirements set forth in Article 13(1) of the GDPR. The notice did not include the information necessary to identify the data controller or its contact details, nor did it provide clear and differentiated information for each data processing activity regarding the purpose and legal basis of the data processing. In the case of data processing related to billing, the controller failed to specify the legal basis based on a statutory obligation, while for data processing for marketing purposes, the controller inaccurately defined the legal basis of consent as “consent.” (80) The Authority further found that the notice did not identify the recipients of the personal data with sufficient detail, as the reference to “[…] courier service” did not it possible to unambiguously identify the recipient or to assess its role in the data processing. Furthermore, the notice did not contain information regarding the retention period of the personal data or the criteria used to determine it. (81) The Authority noted that the notice did not provide adequate information regarding the data subjects’ rights and how to exercise them; it did not address the , the right to lodge a complaint with the supervisory authority, or the fact that the provision of data is based on a legal obligation and the consequences of failure to do so; thus, the requirements set forth in Article 13(2) of the GDPR were not met either. (82) The Authority further found that the information, by referring to the “Data Protection Act,” did not reflect the current legal framework. (83) Based on the foregoing, the Authority determined that the Company violated Article 13 (1)(a), (c), and (e), as well as Article 13(2)(a)–(e), and, due to the , due to the form and scope of the information provided, it also failed to meet the requirements set forth in Article 12(1) of the GDPR . (84) The Authority found that the archived versions of the General Terms and Conditions available on the Website also contained a chapter on data processing . In this regard, the Authority examined the versions of the GTC archived on September 27, 2020, and June 17, 2021. A comparison of the two documents reveals that they contain no discrepancies with regard to data processing provisions; their structure and content are identical, and both were indicated as effective as of July 1, 2016. (85) The Authority notes, first and foremost, that the practice whereby the data controller provides as part of the General Terms and Conditions, embedded among other content elements, to data subjects. The requirement for transparent and easily accessible information that the data subject be able to access information regarding data processing in a single location, in a uniform structure, and in a targeted manner, even in a separate document. In contrast, in the present case, the information regarding data processing appeared in the GTC, integrated into its structure, scattered throughout the GTC, even though a separate section titled “Privacy Policy” existed on the Website; thus, the data subject could not reasonably be expected to search the GTC for additional material details regarding data processing. (86) In this regard, the Authority refers to paragraph 33 of WP260 rev.01, the WP29 guidelines on the application of Articles 13 and 14, which states that the data controller must take active steps to make the information available to the data subject, and the data subject should not be expected to search for it among other information—such as general terms and conditions— on their own. According to the guidelines, the privacy notice must be available in one place or in a single document, in an easily accessible manner. (87) The Authority further found that the content of the data processing section of the GTC did not meet the requirements under the GDPR. The document did not describe with sufficient detail and clarity what data processing activities actually take place on the Website, for what specific purposes, on what legal basis, with what data transfers, and for what duration. The Authority found that the GTC did not contain the information required under Article 13(1)(c) and (e) of the GDPR, specifically the specific purpose and legal basis of each data processing activity, as well as the exact scope of recipients. Furthermore, the document did not comply with the requirements set forth in Article 13(2)(a), (c), and (e) either, as it did not specify the retention period for personal data or the criteria for determining , the detailed procedures for exercising the data subject’s rights, and the basis for the data disclosure as well as the consequences of failure to comply. The Authority further notes that although certain parties—in particular the hosting provider—were mentioned in the GTC, it was not clearly defined whether these organizations participate in data processing as data controllers or data processors, and certain sections pertaining to data processors remained without content. (88) The section on data processing contained general categories and a general description regarding cookies; however, it did not clarify exactly what types of cookies it actually uses, what legal basis applies to them, who the relevant recipients or 16 third parties are, and how long the data processing lasts; thus, data subjects were unable to ascertain the actual content of the data processing in this regard either. (89) The data processing notice included in the GTC presented the legal basis for data processing and the rights of data subjects not based on the GDPR framework, but typically following the previous regulatory logic of the Infotv. In this context, the legal basis for data processing related to cookies was explicitly identified as consent pursuant to Section 5(1)(a) of the Information Act, while the notice did not include a clear, data-processing-specific as required by Article 6 of the GDPR, for each specific data processing operation . In the General Terms and Conditions, certain elements of the data processing notice appeared intermingled with copyright and other provisions not related to data processing; furthermore, under the heading “Data Processing Notice,” in several instances only headings and lists appeared without any actual content. The document is difficult to navigate and not sufficiently structured, which suggests that the text was generated by an automated system and was not intended to describe actual data processing practices. (90) Although the information on data subject rights listed certain rights (in particular the rights to access, rectification, erasure, restriction of processing, and the right to object), its presentation did not follow the structure and substantive requirements set forth in the GDPR . The notice applied legal concepts and an approach characteristic of the Infotv., specifically by mentioning the right to “blocking” and by including references to the provisions of the Infotv., and furthermore, it did not define the deadlines and conditions for exercising these rights in accordance with in accordance with Article 12(3) of the GDPR. (91) The Company referred in the GTC to the obligation to register with the data protection registry. The information provided in this regard, citing the provisions of the Information Act, gives the impression that data processing activities are linked to some official registry. (92) The Authority notes that the legal institution of the data protection registry ceased to exist on May 25, 2018, with the entry into force of the GDPR; thus, the reference thereto during the period under review is considered obsolete. Information of this nature is likely to give data subjects the impression that the data processing is listed in an official registry or has undergone official inspection or approval. (93) The Authority notes that even prior to its termination, the data protection registry did not certify the lawfulness of data processing; it served solely to record data processing activities . In light of this, reference to the defunct legal institution in the present case is unnecessary and misleading. The Authority further found that the supervisory authority’s contact information was not listed up to date, as the General Terms and Conditions contained an outdated mailing address . (94) The Authority emphasizes that, when providing information, the data controller is required to omit any information that does not comply with the applicable legal framework or that distorts the actual situation . The reference to the discontinued data protection registry constitutes such information; therefore, its inclusion does not comply with the information requirements under the GDPR. (95) In the Authority’s view, based on the foregoing, it cannot be established that the Company, during the period under review, ensured the accessibility of information regarding data processing in accordance with the requirements set forth in Article 12(1) of the GDPR. Under that provision, the data controller is required to provide the information to data subjects in a form that is easily accessible, transparent, and understandable. In contrast, in the present case, the Company was unable to demonstrate the existence and content of a privacy notice privacy notice with appropriate content and that could be identified in a timely manner. The Authority found that, based on the available evidence, during certain phases of the period under review, only 17 incomplete notices were available, which did not meet the requirements set forth in Article 13 of the GDPR, while during other periods, no notice was available at all. The Authority notes that in the latter case, this is not merely a matter of incomplete information, but a complete failure to fulfill the obligation to provide information. (96) In the present case, the violation does not stem from specific deficiencies in a data processing notice with known content, but rather from the fact that the Company failed to demonstrate that it had provided the information required under Article 13 to the data subjects at all. Based on the available evidence, only a general statement that did not contain the required elements could be identified; furthermore, during certain periods, a complete lack of information was established. (97) The Company did not demonstrate that, during the period under review, it had provided data subjects with the mandatory data processing notice required under Article 13 of the GDPR at all. However, based on the available evidence, it can be established that during certain periods, only a brief, general statement was available, which did not contained information regarding the data controller’s identification and contact details, did not provide clear and differentiated information for each data processing activity regarding the purpose and legal basis for each data processing activity, and did not adequately identify the recipients of the personal data, the retention period or the criteria for determining it, as well as information regarding the data subject’s rights, the exercise of those rights, and the right to lodge a complaint with the supervisory authority. Based on all of the above , the Authority found that the Company had violated Article 13(1) (a), (c), and (e) of the GDPR, as well as the requirements set forth in Article 13(2)(a)–(e). III.3. The Principle of Transparency (98) Article 5(1)(a) of the General Data Protection Regulation stipulates that personal data must be processed lawfully, fairly, and in a manner that is transparent to the data subject . The requirement of transparency means that, based on the information provided, the data subject must be able to effectively understand and grasp the purposes for which their personal data is processed, the legal basis, and under what circumstances their personal data is processed, who is involved in the processing, and how they can exercise their rights. (99) In the Authority’s view, merely formally comply with the information obligations set forth in Articles 12–13 of the GDPR; rather, it requires that the data processing as a whole be effectively traceable, understandable, and interpretable for data subjects. The requirement of transparency thus extends to the entire data processing practice and encompasses the accessibility of the information, the clarity of its content, and its continuity over time. (100) The Authority found that the Company’s data processing disclosure practices during the period under review were not suitable for enabling data subjects to understand the data processing. Based on the available evidence, the information was incomplete during certain periods and periods it was entirely absent, meaning that data subjects did not have access to consistent and comprehensive information regarding data processing. (101) The Authority took into account that certain documents available on the Website—in particular the section on data processing contained in the General Terms and Conditions—were not suitable for remedying this deficiency. The data processing provisions contained in the General Terms and Conditions did not present the circumstances of data processing in a separate and unambiguous structure, but rather used general, partly formulaic, and partly outdated wording. Although the document contained certain identifying information, as well as a general description of cookies and certain data subject rights, it it did not provide data subjects with clear information that was differentiated by data processing activity and aligned with actual operations. 18 (102) The Authority emphasizes that, based on the content of the data processing notice, the legal bases for the individual data processing operations could not be clearly identified. The notice did not clearly assign a legal basis under Article 6(1) of the GDPR to each data processing purpose. In the Authority’s view, as a result of these shortcomings, the notice does not meet the requirement that data subjects be able to clearly understand the legal basis on which their personal data is processed. (103) Transparency is further undermined by the fact that the content of the available documents was not based on the framework of the GDPR but partly reflected the previous provisions of the Information Act . The outdated references to legislation and the structure that does not follow the logic of the GDPR combined result in the information provided being unsuitable for a clear and up-to-date presentation of data processing practices. (104) In the Authority’s view, the circumstances identified collectively indicate that the Company failed to ensure that the information was designed and operated at a level that would have guaranteed its substantive adequacy, up-to-date status, and continuous availability. The repeated occurrence of gaps in the information, as well as the fact that its content and availability could not be clearly tracked during the period under review, resulted in the essential circumstances of data processing not being transparent to the data subjects. (105) Based on the foregoing, the Authority concluded that the Company’s data processing practices were not transparent, as data subjects were not provided with access to the essential circumstances of data processing, the information was not continuously available, and its content, temporal scope, and changes could not be tracked. The Authority therefore determined that the Company’s obligation to provide information on data processing pursuant to Articles 12–13 of the GDPR did not meet the fundamental requirement of Article 5(1)(a) of the GDPR either. III.4. The Principle of Accountability (106) Based on the principle of accountability under Article 5(2) of the GDPR, the data controller is not only required to comply with the requirements set forth in the GDPR but must also be able to demonstrate such compliance. This principle requires the data controller to operate an internal regulatory, documentation, and record-keeping system from which the the content of data processing practices, their evolution over time, and regulatory compliance can be clearly established even retrospectively. (107) In the present case, the Authority found that the Company did not comply with these requirements. The Company was unable to present the versions of the privacy notices in effect during the period under review, failed to provide evidence of their publication, did not specify the duration of their validity, , nor could it demonstrate the substantive changes between the individual versions. In this context, the Company expressly stated that it had already submitted all documents at its disposal and that there was no possible to obtain any further documents. (108) In the Authority’s view, this circumstance indicates that the Company did not possess any documentation from which the content of the data processing notice applied during the period under review and its changes during the period under review could subsequently be determined. The fact that the Company submitted a completed version verification form exclusively regarding the GTC, while it was unable to comply with the request specifically directed at data protection documents, supports the conclusion that the data processing notice was not adequately documented and traceable. 19 (109) In this regard, the Authority also took into account that, based on the available evidence, the actual accessibility of the notice was not ensured. The Company itself acknowledged the accessibility issue; however, it was unable to determine when it arose or how long it lasted, nor could it substantiate this with documentation. (110) In the Authority’s view, all of this supports the conclusion that the Company was unable to track and verify when, with what content, and by what means the information was available to the data subjects. This circumstance constitutes a failure to fulfill the obligation to provide information. (111) The Authority emphasizes that the violation of the principle of accountability is not merely due to the fact that the Company was unable to submit appropriate documents for the period under review, but also that it did not operate a system that would have enabled the continuous monitoring and subsequent verification of data processing practices. The lack of document versions, the lack of proof of publication, and the indeterminacy of the time frame collectively result in the Company being unable to demonstrate its compliance with the GDPR. (112) Based on the foregoing, the Authority determined that the Company failed to fulfill its obligation to demonstrate the compliance of its data processing practices, which constituted a violation of Article 5(2) of the GDPR. III.5. Information Provided After the Period Under Review (113) The present administrative proceeding did not cover the information regarding data processing provided , i.e., changes made by the Data Controller to the notice following its awareness of the proceedings. In imposing the fine, the Authority considers it a mitigating circumstance that the Company took measures after the proceedings were initiated. IV. Legal Consequences (114) The Authority examined whether the established violations justify the imposition of a data protection fine on the Company. In this regard, the Authority considered all relevant circumstances of the case pursuant to , taking into account the criteria set forth in Guideline No. 4/2022 of the European Data Protection Board (hereinafter: the Guideline). (115) In the Authority’s view, given the nature, gravity, duration, and impact on data subjects of the violations identified in this case, the issuance of a warning cannot be considered a proportionate sanction. The violations do not consist of isolated, technical shortcomings, but rather of structural shortcomings affecting several data protection principles and several key provisions of the GDPR; therefore, the requirements of specific and general prevention necessitate the imposition of a data protection fine. (116) The Authority notes that the infringements found—breaches of transparency and accountability, as well as the failure to comply with the obligations to inform data subjects under Articles 12–13— — constitute infringements falling within the higher category of fines under Article 83(5) of the General Data Protection Regulation. Guideline No. 2 04/2022 on the calculation of administrative fines under the General Data Protection Regulation (Version 2.1 version). Online: https://www.edpb.europa.eu/system/files/2024- 01/edpb_guidelines_042022_calculationofadministrativefines_hu_0.pdf 20 (117) In determining the amount of the fine, the Authority took into account the Company’s financial data. The Company’s net revenue in each fiscal year, as reported in the annual financial statements for the respective year, was as follows: - in the 2020 fiscal year, […] Ft (i.e., […] forints), - in the 2021 fiscal year, […] Ft (i.e., […] forints), - in the 2022 fiscal year, […] Ft (i.e., […] forints), - in the 2023 fiscal year, […] Ft (i.e., […] forints), - in the 2024 fiscal year, […] Ft (i.e., […] forints), - in the 2025 fiscal year, […] Ft (i.e., […] forints). In imposing the fine, the Authority based its calculation on the most recent and lowest net revenue, according to which the Company, based on the categories defined in the European Data Protection Board’s Guideline No. 4/2022, , falls within the category of enterprises with revenue exceeding 2 million euros but not exceeding 10 million euros. (118) Pursuant to Article 83(5) of the General Data Protection Regulation, the Company may be subject in this case to an administrative fine of up to 20,000,000 euros or an amount not exceeding 4% of the enterprise’s financial year, whichever is higher. The Company’s net revenue for the year 2025 is 4% of […] HUF, which does not exceed 20,000,000 euros. 4% of the Company’s net sales revenue for 2025 amounts to […] HUF, which does not exceed the amount equivalent to 20,000,000 euros; therefore, in the present case, the upper limit of the fine is the static maximum set at 20,000,000 euros. (119) Based on the available information, the Authority did not identify any circumstances that would indicate the intentional commission of the violations. The nature of the identified deficiencies points to negligence; however, this was not a one-time error but was of a continuous nature, and therefore the Authority assessed the violations as being of a grossly negligent nature. (120) In determining the amount of the fine, the Authority assessed the following aggravating circumstances : - with regard to the nature and gravity of the infringements [Article 83(2)(a) ], the Authority assessed that the deficiencies identified in this case did not stem merely from the partial or formal absence of certain elements of the information provided, but rather indicated a systemic inadequacy in the data processing notice; - with regard to the duration of the infringements [Article 83(2)(a) of the GDPR], the Authority found that the identified deficiencies were not of a temporary nature, but were continuously present during the period under review, and the Company’s data processing notification practices consistently failed to meet the requirements of the GDPR; - with regard to the size of the group of data subjects [Article 83(2)(a) of the GDPR], given that traffic to the Website was significant during the period under review, and based on the Company’s , […] individuals visited the Website in 2020, […] in 2021, […] in 2022, […] , […] in 2024, and […] in 2025 visited the Website, meaning the number of data subjects was high in every year. (121) In determining the amount of the fine, the Authority assessed the following mitigating circumstances based on the criteria set forth in Article 83(2) of the GDPR: 21 - with regard to the absence of previous relevant infringements [Article 83(2)(e) of the GDPR], that no data protection infringement had previously been established against the Company; - the Company took measures during the proceedings to remedy the violations [General Data Protection Regulation, Article 83(2)(f)]; - the violations were committed through gross negligence; intent has not been proven [General Data Protection Regulation, Article 83(2)(b)]; - the Authority exceeded the administrative deadline. Based on a consideration of all the circumstances of the case, the Authority assessed the infringements, taken as a whole and in their entirety, as being of medium severity. (122) In light of the foregoing, the Authority determined the amount of the fine based on the criteria set forth in Article 83(2) of the GDPR , in proportion to the nature and gravity of the infringements, the Company’s economic situation, and the objectives of specific and general deterrence, acting within its statutory discretion. The circumstances set forth in Article 83(2) (c), (h), (i), and (j) did not exist in the present case. (123) Based on the foregoing, the Authority decided as set forth in the operative part. V. Other Issues (124) The Authority’s powers are defined in Section 38(2) and (2a) of the Information Act, and its jurisdiction extends to the entire territory of the country. (125) This decision of the Authority is based on Sections 80–81 of the Administrative Procedure Act and Section 61(1) of the Information Act. The decision becomes final upon its notification pursuant to Section 82(1) of the Administrative Procedure Act. Pursuant to Section 112, and § 116(1) and (4)(d), as well as § 114(1) of the Ákr., an appeal against this decision may be filed through administrative litigation. * * * (126) Pursuant to Section 135 of the Ákr., the obligor is required to pay a late payment penalty at a rate equal to the statutory interest rate if the obligor fails to fulfill its monetary payment obligation by the due date. (127) Pursuant to Section 6:48(1) of Act V of 2013 on the Civil Code, in the case of a monetary debt, the debtor is obligated to pay late payment interest at a rate equal to the central bank’s base rate in effect on the first day of the calendar half-year affected by the delay, calculated from the date the delay began. (128) The rules governing administrative litigation are set forth in Act I of 2017 on Administrative Procedure (hereinafter referred to as “Kp.”). Pursuant to Section 12(1) of the Kp., administrative litigation challenging a decision of the Authority falls within the jurisdiction of the courts; pursuant to Section 13(3) (a)(aa) of the Kp., the Budapest Regional Court has exclusive jurisdiction. Pursuant to Section 27 (1)(b) of the Kp., in legal disputes in which the regional court has exclusive has exclusive jurisdiction, legal representation is mandatory. Pursuant to Section 39(6) of the Civil Procedure Code, the filing of the complaint does not have the effect of suspending the entry into force of the administrative act. (129) Pursuant to Section 29(1) of the Code of Civil Procedure and, in light thereof, Section 604 of Act CXXX of 2016 , as applicable, and pursuant to Section 19(1)(b) of Act CIII of 2023 on the Digital State and Certain Rules Governing the Provision of Digital Services, , the client’s legal representative is required to communicate electronically. (130) The time and place for filing the complaint are specified in Section 39(1) of the Civil Procedure Code. The information regarding the possibility of requesting a hearing is based on Section 77(1)-(2) of the Code of Civil Procedure . (131) The amount of the administrative court fee is determined by Section 45/A(1) of Act XCIII of 1990 on Fees (hereinafter: Itv.). The party initiating the proceedings is exempt from the requirement to pay the fee in advance pursuant to Section 59(1) and Section 62(1)(h) of the Itv. . (132) If the Company fails to adequately demonstrate compliance with the prescribed obligations, the Authority shall deem that the Company has failed to fulfill the obligation by the deadline. Pursuant to Section 132 of the Administrative Procedure Act, if the Company has not complied with the obligations set forth in the Authority’s final decision, the decision becomes enforceable. Pursuant to Section 82(1) of the Administrative Procedure Act, the Authority’s decision . Pursuant to Section 133 of the Administrative Procedure Act, enforcement—unless otherwise provided by law or a government decree—shall be ordered by the authority that issued the decision. Pursuant to Section 134 of the Administrative Procedure Act, enforcement—unless otherwise provided by law, a government decree, or, in matters within the jurisdiction of a local government authority, a local government ordinance— shall be carried out by the state tax authority. Pursuant to Section 61(7) of the Information Act, with respect to the obligation set forth in the Authority’s decision to perform a specific act, to engage in specific conduct, to tolerate a situation, or cessation—the Authority shall enforce the decision. Dated: Budapest, date as per the electronic signature Dr. habil. Attila Péterfalvi Chairman, Professor

Similar Content