Skip to content
Enforcement · Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Unknown Company: Non-compliance with general data processing principles

The employer restored the mailbox of a director who had left the company a year before and found an email containing a work-related document.

Full text

The employer restored the mailbox of a director who had left the company a year before and found an email containing a work-related document. The director received no warning that his former inbox would be activated and did not have a chance to copy / delete his private data (passwords and financial information). According to NAIH, an employee or a representative should be present when the employee's data is being accessed, even if the employment has been terminated. Employees should be able to request a copy or the deletion of their private data. Employers must record the access with minutes and photos; when the employee cannot be present, then in the presence of independent witnesses. Employers must adopt internal policies on archiving and the use of IT assets and e-mail accounts, including procedural rules such as the steps of an inspection and the officials authorised to carry it out.

Industry: Employment

How it connects

C-65/23 MK v K GmbH In a preliminary ruling requested by the German Federal Labour Court (Bundesarbeitsgericht), the Court of Justice of the European Union interpreted Article 88 of the GDPR… CJEU ·Eighth Chamber Dec 19, 2024 Personal Data Integrity and Confidentiality Principle Legitimate Interest
Guidelines 3/2018 territorial scope of the GDPR (Article 3) Guidelines on the territorial scope of the GDPR Guidelines ·EDPB Nov 12, 2019 Territorial scope (GDPR) IP Address Processors
C-710/23 L. H. v Ministerstvo zdravotnictví In Case C-710/23, the Court of Justice of the European Union (First Chamber) addressed a preliminary reference from the Czech Supreme Administrative Court concerning whether… CJEU ·First Chamber Apr 3, 2025 Personal Data Legitimate Interest IP Address
C-638/23 Amt der Tiroler Landesregierung v Datenschutzbehörde In Case C-638/23, the Court of Justice interpreted Article 4(7) GDPR in response to a preliminary reference from the Austrian Verwaltungsgerichtshof in proceedings between the Amt… CJEU ·Eighth Chamber Feb 27, 2025 Public Authority Controllers Personal Data
C-757/22 Meta Platforms Ireland Limited v Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V In a preliminary ruling requested by the German Federal Court of Justice (Bundesgerichtshof), the Court of Justice of the European Union interpreted Article 80(2) GDPR in the… CJEU ·Fourth Chamber Jul 11, 2024 Personal Data Transparency Fairness & Transparency