Data Protection, Artificial Intelligence and Cybersecurity

Our firm provides comprehensive legal, compliance and strategic advice in the fields of data protection, artificial intelligence, cybersecurity and the data economy. Our work focuses on matters where legal requirements, technological operations and organisational processes are closely interconnected.

Our clients include international digital service providers, financial institutions, technology companies, operators of critical infrastructure and businesses operating data-intensive business models.

Our advice goes beyond drafting policies and legal documentation. We regularly work with legal, compliance, IT, information security and business teams, translating legal requirements into solutions that fit actual technological and organisational operations.

Data Protection and GDPR Compliance

We approach GDPR compliance not as a one-off documentation exercise, but as a governance and risk management framework embedded in the organisation’s operations.

Our services include in particular:

  • comprehensive GDPR compliance audits and implementation programmes;
  • development and review of data protection governance and compliance frameworks;
  • establishment and updating of records of processing activities;
  • development of data protection policies, procedures and internal controls;
  • preparation and review of privacy notices, cookie notices and consent mechanisms;
  • data protection impact assessments (DPIAs), legitimate interest assessments (LIAs) and other privacy risk assessments;
  • assessment of data retention requirements and development of retention and deletion rules;
  • support with the handling of data subject requests;
  • drafting and review of data processing agreements, joint controller arrangements and other data protection agreements;
  • professional support for data protection officers and internal privacy functions.

Artificial Intelligence and Automated Systems

We support clients with the legal and compliance aspects of developing, procuring and using artificial intelligence systems, including compliance with the EU AI Act.

Our advice covers, among other areas:

  • legal and compliance risk assessments of AI systems;
  • assessment of roles, obligations and risk classifications under the AI Act;
  • development of corporate AI governance frameworks and internal policies;
  • policies governing the corporate use of generative AI and other AI tools;
  • data protection assessment of automated decision-making and profiling;
  • development of human oversight, transparency and documentation requirements;
  • contractual issues relating to the procurement, development and use of AI systems as a service;
  • management of data protection, copyright and information security risks associated with AI systems.

Cybersecurity and Information Security

In the field of cybersecurity compliance, we assess legal requirements together with the organisation’s information security governance and technological environment.

We provide support in particular with:

  • compliance with Hungarian NIS2 requirements and the related Hungarian cybersecurity regulatory framework;
  • legal support for DORA compliance programmes;
  • legal and compliance aspects of implementing ISO/IEC 27001 and related information security frameworks;
  • development of information security policies, governance structures and allocation of responsibilities;
  • assessment of the adequacy of organisational, physical and technical controls;
  • development of access management, logging and monitoring requirements;
  • implementation of data protection by design and by default;
  • legal assessment of anonymisation and pseudonymisation solutions;
  • assessment of supplier and outsourcing risks;
  • integration of cybersecurity and data protection controls into websites, mobile applications and other IT systems.

Data Protection and Cybersecurity Incidents

In the event of a data protection or cybersecurity incident, we support clients from the initial legal assessment through to regulatory communications.

Our work includes:

  • development of incident response processes and internal procedures;
  • legal and data protection risk assessment of incidents;
  • assessment of notification and communication obligations;
  • preparation of notifications to supervisory authorities and communications to affected individuals;
  • legal support for internal investigations and forensic processes;
  • documentation of incidents and development of post-incident remediation measures.

International Data Transfers

For cross-border processing activities, we assess not only the contractual documentation but also the actual data flows and risks associated with access from third countries.

Our services include:

  • implementation and tailoring of Standard Contractual Clauses (SCCs);
  • preparation of Transfer Impact Assessments (TIAs);
  • support with the development of Binding Corporate Rules (BCRs);
  • structuring international data processing and data transfer arrangements;
  • analysis of data flows involving cloud services and multinational corporate groups;
  • assessment of risks arising from access by third-country public authorities.

Websites, Applications, Marketing and ePrivacy

For websites, online stores, mobile applications and digital marketing solutions, we assess legal compliance based on actual user journeys and the technologies deployed.

This includes in particular:

  • privacy audits of websites and mobile applications;
  • cookie and tracking audits;
  • assessment of consent management platforms and consent mechanisms;
  • privacy assessment of online analytics and advertising technologies;
  • assessment of the lawfulness of CRM and marketing databases;
  • advice on electronic direct marketing and ePrivacy requirements;
  • design of privacy processes for online stores and digital services;
  • legal support in domain name matters and online takedown requests.

Data Act and Data Governance

We advise on obligations under the EU Data Act and on the development of new data use models, particularly in relation to connected products, digital services and cloud solutions.

Our work covers:

  • assessment of data access and data-sharing obligations;
  • B2B and B2C data use arrangements;
  • drafting of data-sharing and data-use agreements;
  • legal issues relating to cloud switching;
  • development of corporate data governance frameworks;
  • mapping legal risks associated with data-driven business models.

Audits, Due Diligence and Transactions

We carry out data protection, information security and technology audits as standalone projects, as part of supplier assessments or in connection with transactions.

We provide support with:

  • corporate data protection and information security audits;
  • due diligence and risk assessments of suppliers and business partners;
  • assessment of outsourcing arrangements;
  • data protection, IT and information security due diligence in M&A transactions;
  • independent quality assurance of compliance and technology projects.

Regulatory Proceedings and Litigation

We represent clients before supervisory authorities and courts in data protection and related technology law matters.

This includes in particular:

  • representation before the Hungarian National Authority for Data Protection and Freedom of Information;
  • management of regulatory inspections and data protection authority proceedings;
  • support in cross-border data protection matters and cooperation procedures between supervisory authorities;
  • judicial review of data protection authority decisions;
  • disputes relating to data subject claims, damages and compensation for non-material harm.

Training and Organisational Preparedness

We provide data protection, AI and cybersecurity training for management, legal and compliance teams, as well as IT and information security professionals.

Our training programmes are tailored to the organisation’s operations, technological environment and risk profile, and focus on practical decision-making situations in addition to formal legal requirements.

Legal, Technological and Business Considerations in One Framework

Our advisory model is designed for complex organisational environments where legal compliance alone is not sufficient. Regulatory requirements must be translated into workable processes, technical controls and clearly allocated organisational responsibilities.

By working closely with legal, compliance, cybersecurity and technology teams, we develop solutions that meet regulatory requirements while also reflecting the organisation’s actual operations and risk profile.

Our Experts

Dr Ádám Liber

Attorney-at-law, Partner
PhD, LL.M., FIP, CIPP/E, CIPM, CISM

Ádám advises Hungarian and international clients on data protection, artificial intelligence, IT law and intellectual property matters. A significant part of his practice focuses on complex digital transformation, privacy and technology compliance projects.

Learn more

Dr Tamás Bereczki

Attorney-at-law, Partner
CIPP/E, CISM, CRISC

Drawing on his background in both law and IT engineering, Tamás specialises in data protection, artificial intelligence, cybersecurity, IT and e-commerce law. His work places particular emphasis on the practical alignment of legal and technological requirements.

Learn more