Based on its 2025 inspection plan, the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) examined the compliance of general privacy information provided on the websites of 21 online stores. The inspections were not initiated on the basis of individual complaints or requests, but were aimed at assessing the online stores’ general transparency practices. According to the NAIH’s report, published on 30 March 2026, 18 of the 21 inspections resulted in data protection authority proceedings, no proceedings were initiated in two cases, and in one case the investigation continued in cooperation with a foreign supervisory authority. At the time the report was prepared, approximately half of the proceedings initiated were still ongoing, while the others had either been concluded by a decision or were at the stage of verifying compliance with the measures ordered in the decision.
As at the closing date of this manuscript, 26 July 2026, the five published decisions therefore represent some of the first public results of a broader, pre-planned enforcement programme: NAIH-11128-5/2025, NAIH-4021-1/2026, NAIH-450-7/2026, NAIH-4462-4/2026 and NAIH-11443-3/2026. In these cases, the NAIH imposed data protection fines totalling HUF 27.7 million. The individual fines ranged from HUF 200,000 to HUF 15 million. In three of the five cases, the Authority also found an infringement of the principle of transparency under Article 5(1)(a) GDPR, while in case NAIH-4462-4/2026 it additionally found a separate infringement of the principle of accountability under Article 5(2).
The decisions do not fundamentally rewrite the GDPR’s transparency requirements. They do, however, clearly demonstrate that the NAIH no longer regards privacy information merely as a document-drafting exercise. The controller must not only prepare appropriate wording, but must also ensure that the information reflects actual operations, remains continuously accessible and can still be reconstructed years later, including which information was provided to data subjects during which period.
Process-based supervisory inspections
The methodology of the investigations is at least as important as the individual legal findings. According to the NAIH’s report, the Authority specifically reviewed the relevant content of the websites, made forensic copies of that content and recorded additional publicly available information, including company extracts, domain registration data and archived versions of websites. The Authority described its inspection approach as process-based. It did not merely read the published privacy documentation, but compared it with the online store’s actual transparency practices and data processing operations. According to the NAIH’s report, it examined different historical versions using version-control forms and text-comparison methods. In the individual proceedings, controllers were also required to complete forms relating to different versions of their documents, meaning that businesses had to reconstruct retrospectively the content and period of validity of each document.
In one case, the NAIH also carried out a test registration and followed the user journey that triggered the processing of personal data. To place an order with registration, users were required to provide their full name, telephone number, email address, postal code, city, street, house number and password, while newsletter subscription was optional. The Authority was therefore able to see not only what the privacy notice stated, but also what data customers actually had to provide, what checkboxes were displayed and what information they received during the ordering or registration process.
Recurring patterns emerged during the inspections. In many cases, the information provided was fragmented, contradictory and difficult for users to understand. Outdated, copied or template-based texts were common and did not describe the processing actually carried out. Some privacy notices continued to identify the Hungarian Privacy Act (Infotv.) as the applicable legislation or referred to data protection registration numbers that no longer existed. In some cases, even the identity or contact details of the controller were unclear, while in others the privacy notice was technically difficult or impossible to access. In the Authority’s assessment, these deficiencies did not merely indicate drafting errors. For a significant proportion of the businesses examined, data protection compliance had not been meaningfully integrated into their operations, and the privacy notice served more to create the appearance of documentary compliance than to provide a transparent description of actual processing operations.
Privacy information must be genuinely accessible
A privacy notice does not become easily accessible merely because a link to it appears somewhere on the website.
In one case, a data subject could reach the privacy information only after scrolling through the entire general terms and conditions. The NAIH considered it more appropriate for the privacy notice to appear as a separate menu item, or at least to be directly linked at the beginning of the terms and conditions.
In case NAIH-4462-4/2026, the Authority took an even stricter position: providing privacy information as part of the general terms and conditions, embedded among other substantive provisions, does not in itself comply with Articles 12 and 13 GDPR. Data subjects must also be able to access the privacy information in one place, in a coherent structure and in a targeted manner, in a separate document. In this context, the NAIH referred to paragraph 33 of the WP29 Guidelines on transparency, WP260 rev.01, according to which the controller must actively provide the information and data subjects should not be expected to search for it among general contractual terms.
In another proceeding, the purchasing process displayed only a checkbox for accepting the general terms and conditions. There was no separate transparency element drawing the data subject’s attention to the purpose and legal basis of processing, its duration, recipients and the rights that could be exercised. According to the NAIH, scattered data protection provisions in the general terms and conditions did not replace the complete, processing-specific information required under Article 13 GDPR.
Providing information through multiple documents or in layers is not, however, unlawful in itself. Alongside an online store’s general privacy notice, it may also use a separate cookie notice, prize competition rules, newsletter subscription text and short notices displayed next to individual forms. The scope of the documents and their relationship to one another must nevertheless be clear, and the various texts must form a coherent and non-contradictory system. Data subjects cannot be expected to reconstruct from several documents which legal basis, retention period or recipient applies to a particular processing operation, or to resolve discrepancies between different notices themselves.
It is particularly noteworthy that in case NAIH-4021-1/2026 the NAIH found only an infringement of Article 12(1) GDPR. It did not find a separate infringement relating to any particular information element under Article 13 GDPR. This demonstrates that poor structure, fragmented information, inconsistent terminology and the difficulty of understanding the document may in themselves be sanctionable.
Providing too much information may also constitute an infringement
According to the decisions, a privacy notice may be unlawful not only because information is missing. Excessive amounts of irrelevant, repetitive or general legal information may also impede understanding. One privacy notice explained in detail why the controller had not appointed a data protection officer, described the GDPR’s basic concepts and principles, and discussed data security and breach management obligations at length. According to the NAIH, these sections did not concern the specific processing of data subjects’ personal data and therefore did not constitute relevant information for the purposes of advance transparency. The same notice repeatedly set out the controller’s contact details, the applicable legislation, the categories of employees authorised to access data and the manner in which data subject rights could be exercised. The Authority considered that these repetitions unnecessarily increased the document’s length while reducing its clarity.
Nor does a section on data subject rights become more appropriate merely because it paraphrases the GDPR over several pages. In one case, the NAIH found a section on pages 7 to 10 of a privacy notice disproportionately long, unnecessarily detailed and cumbersome.
An appropriate privacy notice is therefore not a general data protection handbook. It must contain all information necessary to understand the processing actually carried out, while avoiding lengthy reproductions of legislation, general explanations of legal rules, details of the controller’s internal compliance obligations and repetitive passages.
The privacy notice must describe how the online store actually operates
The NAIH identified several documents that had been taken from other websites or from general templates without being adapted to the operation of the particular online store.
In one case, the same privacy notice was used on several websites. The “Who we are” section gave the impression that food products could be purchased on the website concerned, even though the online store under investigation sold an entirely different category of products. According to the Authority, a common template document does not satisfy the transparency obligation if it does not describe the processing carried out on the specific website.
Other privacy notices referred to discontinued registration functions, obsolete data protection registration numbers, profiling and automated decision-making that did not actually take place, and data transfers that did not occur. The NAIH treated these as false, unnecessary or misleading information that infringed the requirement of clear and transparent information under Article 12(1) GDPR. In one case, the systemic accumulation of such errors also resulted in a separate infringement of the principle of transparency.
One online store’s privacy notice also included processing related to warehouse and workplace CCTV monitoring and events, even though the document was addressed to visitors and customers of the online store. The notice also referred to processing based on the exercise of official authority, although the controller was a commercial undertaking.
The use of a single corporate privacy notice is not unlawful in itself. Its scope must, however, be precisely defined, and it must be clear which processing operations apply to which categories of data subjects, interfaces and processing situations. Failing that, it is advisable to describe processing relating to different categories of data subjects in separate documents.
Uncritical use of outdated data protection terminology should also be avoided. The NAIH, for example, objected to the use of the obsolete concept of “blocking” under the former Hungarian Privacy Act instead of properly describing the right to restriction of processing under Article 18 GDPR.
Neither a legaltech system nor an external expert assumes the controller’s responsibility
Automated generation of privacy notices or the use of a legaltech system is not objectionable in itself. Such tools can assist in identifying typical processing operations and drafting documentation. Before publication, however, the generated text must be compared by a competent person with the processing operations actually carried out.
In one case, the NAIH expressly stated that human review of the generated document is the controller’s responsibility. The controller must verify whether the selected processing operations actually take place, whether the purposes and legal bases are appropriate, and whether irrelevant or inaccurate template wording remains in the notice.
One system generated and published the privacy notice with a new date even when the controller modified another document stored in the system, apparently the general terms and conditions, while the data protection content of the privacy notice itself remained unchanged. The existence of documents with different dates but identical substantive content made it more difficult to determine when a material amendment had occurred and which version was applicable.
The NAIH expressly stated that the involvement of an external expert or a service provider performing data protection officer functions does not relieve the controller of responsibility. The controller itself remains responsible for compliance with the GDPR and for demonstrating that compliance. The same accountability logic may also apply where lawyers, web developers or other external contributors are involved.
It is particularly unfavourable if the business itself is unable to explain what processing is carried out by a service provider it has identified, in what capacity that provider acts, or whether profiling occurs as part of the service. Outsourcing may facilitate the preparation or technical publication of the privacy notice, but it cannot replace the controller’s own understanding and accountability.
Processing purposes and legal bases must be clearly linked
A controller may not simply list all possible legal bases under Article 6(1) GDPR without specifying which legal basis applies to each individual processing purpose.
One privacy notice stated that registration was simultaneously based on consent and performance of a contract, newsletter distribution on consent and legitimate interests, and the use of tracking technologies likewise on consent and legitimate interests.
According to the NAIH, multiple alternative legal bases cannot be assigned in parallel to the same processing activity and purpose. Where data are processed for several distinct purposes, those purposes must be identified separately and the appropriate legal basis must then be assigned to each. This does not prevent the same data from being processed for several successive or distinct purposes on different legal bases. Data required to perform an order may, for example, subsequently be retained on the basis of a statutory retention obligation. The privacy notice must, however, clearly distinguish the purposes, periods and legal bases.
Referring to national legislation also does not in itself replace identifying the legal basis under the GDPR. In one case, the controller cited the Hungarian Act on Electronic Commerce but did not properly identify the applicable legal basis under Article 6 GDPR. In another, it relied on the general limitation rules of the Hungarian Civil Code as a legal obligation. According to the NAIH, the existence of a limitation period and the possibility of bringing claims at a later stage do not, in themselves, amount to a statutory obligation requiring processing.
The purpose of processing must also be sufficiently specific. Terms such as “operation of the online store”, “business purpose” or “enhancing user experience” do not necessarily explain which data are processed, in what operation and for what intended result.
According to the NAIH, the description “processing related to the operation of the online store” may be so broad that virtually all processing activities of the business fall within it. Similarly, processing a first name and city for the purpose of “enhancing user experience” was not sufficiently specific because it did not explain which website function the processing related to or what event triggered it.
Retention periods must correspond to the purpose and categories of data
Retention periods cannot be treated as general information detached from the processing purpose and legal basis. In four of the five cases examined, the NAIH found an infringement of Article 13(2)(a) GDPR because the privacy notices did not properly specify the duration of processing or the criteria used to determine it.
In one case, the privacy notice extended the eight-year accounting retention period applicable to invoicing to email addresses and telephone numbers, even though those data did not form part of the mandatory content of accounting documents. According to the NAIH, the accounting retention obligation therefore did not automatically provide a legal basis for retaining those data.
Retention of evidence of consent raises a separate issue. According to the NAIH, while processing based on consent is ongoing, the controller must be able to demonstrate that consent was given. Once the underlying processing has ended or consent has been withdrawn, however, continued retention of the evidence requires a different legal basis, typically a properly substantiated legitimate interest. In this context, the Authority also rejected automatic reliance on the general civil-law limitation period.
Recipients must be linked to the relevant processing purpose and operation
A general list of processors and other recipients at the end of a document does not necessarily make data flows transparent. According to the NAIH’s expectations, data subjects must be able to determine which processing purpose each service provider is associated with, what personal data it receives, what operation it performs and in what data protection role it acts.
In one case, the list of recipients was detached from the description of processing operations relating to marketing, web analytics, customer service and online payment. Data subjects could therefore not determine which of their data were transferred, for what purpose and to which service provider.
The NAIH also criticised inconsistent use of the roles of processor, independent controller and joint controller. In one case, for example, Facebook was generally described as a processor, even though, depending on the nature of the service and data flow, it might have acted as an independent or joint controller.
At the same time, the Authority does not necessarily reclassify the parties’ legal relationship solely on the basis of terminology used in the privacy notice. In one case, it did not find an infringement of Article 26 GDPR on joint controllership because the controller stated that there was no joint controllership with its marketplace partners and that it would delete the provision suggesting otherwise. The NAIH nevertheless continued to treat the contradictory description of the partners’ roles as an infringement of the transparency obligation.
Cookie information cannot consist solely of external links
For cookies, web analytics, remarketing and profiling, it is not sufficient merely to identify the service provider and a general cookie category. The operator of the online store must provide information on what personal data are collected or transferred, the purpose and legal basis of processing, its duration, the role in which the technology provider acts and whether profiling takes place.
One privacy notice referred to conversion reports and detailed analysis of website use but did not specify the categories of personal data concerned, the service providers’ data protection roles or whether the processing involved profiling.
A link to the service provider’s own privacy or cookie notice may supplement, but cannot replace, the online store’s own information. Data subjects cannot be expected to reconstruct the online store’s processing themselves from several external documents that may change continuously or be available only in a foreign language.
If an online store analyses purchasing habits, browsing histories or interests, it must assess whether the operation constitutes profiling within the meaning of the GDPR. If it does, this must be clearly explained. If no profiling takes place, template wording referring to profiling must be removed.
International data transfers must be explained
Information concerning data transfers must coherently cover all relevant service providers located outside the European Economic Area.
In one case, the privacy notice specified a transfer safeguard in relation to only one service provider, although other parts of the document referred to additional service providers in third countries. Data subjects could therefore not determine precisely to which recipients their personal data were transferred, for what purpose and under what legal conditions.
Another privacy notice stated that, exceptionally, a full IP address could be transferred to a server in the United States, but did not identify the transfer mechanism used or explain where data subjects could obtain or request a copy of the relevant safeguards.
The controller does not need to reproduce the entire contractual documentation in the privacy notice. It must, however, identify the legal mechanism used, explain its essence and indicate where the data subject can obtain further information.
Prize competitions and other online-store functions require separate assessment
An online store’s processing is not limited to orders, invoicing and delivery. Contact forms, warranty and complaint-handling processes, product reviews, image uploads and prize competitions may also constitute separate processing purposes.
In one case, the NAIH found that the online store operated a contact form and processed warranty and statutory warranty claims, but failed to provide adequate information about these activities.
For product reviews, the solicitation and publication of a review must be distinguished from any subsequent use, for example for marketing purposes. If a data subject can also upload a photograph, it must be made clear where the image will be accessible, to what audience, for what purpose and for how long.
For prize competitions, the voluntary and separate nature of consent is particularly important. In one case, consent did not appear as a separate, explicit declaration but was linked to participation in the competition. According to the NAIH, consent given in this manner did not constitute voluntary, unambiguous and valid consent within the meaning of the GDPR. Another set of competition rules made newsletter subscription and consent to marketing use a condition of participation, but failed to clearly distinguish the purposes and conditions relating to the administration of the prize competition from those relating to marketing. As a result, data subjects could not clearly determine the purpose and conditions applicable to each processing operation.
Processing children’s data requires particular attention
One of the most serious findings concerned the processing, during registration, of children’s names, sex and full dates of birth. None of the privacy notices applicable during the period under investigation described the purpose, legal basis, duration or recipients of this processing.
According to the NAIH, the fact and extent of the processing remained hidden from data subjects. The Authority treated the failure to identify the processing of children’s data as a separate aggravating circumstance because the deficiency made it impossible not only to understand the processing, but even to recognise that it was taking place.
Multi-year investigation periods make past compliance relevant as well
In some cases, the NAIH examined periods of almost six years. Case NAIH-4462-4/2026 covered the period from 1 January 2020 to 28 October 2025, while case NAIH-450-7/2026 covered the period from 1 January 2020 to 12 November 2025. In case NAIH-11443-3/2026, the investigation likewise reached back to early 2020. Businesses therefore had to demonstrate compliance not only of their current documents and publication practices, but also of previous versions.
In case NAIH-11443-3/2026, the controller raised an objection to the Authority’s competence by relying on the three-year time limit under Section 5(4) of Act CXXV of 2017 on Sanctions for Administrative Offences. According to the NAIH, where an unlawful situation continues over time, the time limit can begin to run only when that unlawful situation ceases. The policy under investigation had been in force from 23 May 2018 until 30 April 2025, that is, for almost seven years. The Authority also considered that the Sanctions Act had to be interpreted consistently with the GDPR, while the GDPR itself does not establish a general temporal limit on the processing operations that may be investigated.
This is the NAIH’s administrative position, and the documents available provide no information on any potential judicial review. Its practical significance is nevertheless clear: correcting the current privacy notice does not in itself eliminate an infringement that existed in the past, nor does it replace evidence of past compliance.
Controllers must also retain evidence of compliance
One of the most important developments reflected in the decisions is the strengthened role of accountability and version control.
In case NAIH-4462-4/2026, the controller generated its privacy notice in an external system and then embedded it in its website. It claimed that, as a result of a technical change, the content later disappeared, but it could not determine when the problem had arisen or how long it had persisted.
The NAIH examined archived website versions and found that earlier documents had already been significantly incomplete before the alleged technical error. In an archived 2022 version, the link returned a 404 error. The controller was unable to document which privacy notice had been in force during which period, when it had been published or whether it had in fact been accessible.
The Authority therefore also found a separate infringement of the principle of accountability and ordered the controller to document the different versions of the privacy notice, their periods of validity and dates of publication in a manner that could be verified retrospectively.
Controllers should therefore retain not only previous versions of the text but also evidence of publication and accessibility. Such evidence may include screenshots, content-management-system logs, publication histories, internal approvals and version tables showing changes.
The current privacy notice does not in itself prove that data subjects also received appropriate information years earlier.
Fines do not follow a linear tariff
No automatic fine schedule can be derived from the fines of HUF 200,000, HUF 500,000, HUF 2 million, HUF 10 million and HUF 15 million.
When determining the fines, in addition to the factors set out in Article 83 GDPR, the NAIH applied the European Data Protection Board’s Guidelines 04/2022 on the calculation of administrative fines. It took into account the undertakings’ turnover, the seriousness and duration of the infringements, the number of data subjects affected, any previous infringements and corrective measures implemented during the proceedings.
The undertakings involved in cases NAIH-11128-5/2025 and NAIH-11443-3/2026 fell within the same turnover category of between EUR 2 million and EUR 10 million, yet the fines imposed were HUF 500,000 and HUF 2 million respectively. This was primarily because the Authority classified the infringements as low seriousness in one case and medium seriousness in the other, although the amount of the fine was also influenced by case-specific aggravating and mitigating circumstances.
Under the turnover- and seriousness-based calculation in the EDPB Guidelines, the amount used in case NAIH-11128-5/2025, classified as low seriousness, was EUR 40,000, while in case NAIH-11443-3/2026, classified as medium seriousness, it was EUR 80,000. These were not the statutory maximum amounts under Article 83(5) GDPR. The statutory ceiling was the higher of EUR 20 million and 4 per cent of the total worldwide annual turnover of the preceding financial year, which for these two undertakings was EUR 20 million. The actual fines of HUF 500,000 and HUF 2 million represented only a fraction even of the amounts calculated under the EDPB methodology.
The decisions also demonstrate that the classification of seriousness cannot simply be inferred from the number of GDPR provisions infringed or from whether a separate infringement of a fundamental principle was found. In case NAIH-11128-5/2025, which was classified as low seriousness, the Authority found an infringement of the principle of transparency and also took into account the significant number of data subjects affected. In case NAIH-11443-3/2026, classified as medium seriousness, by contrast, no separate infringement of a fundamental principle was found.
In case NAIH-4462-4/2026, the Authority characterised the infringements as systemic and the conduct as seriously negligent. In case NAIH-450-7/2026, the long duration, the exceptionally broad group of data subjects affected, the restrictive presentation of data subject rights and a previous data protection infringement also played a role in determining the fine.
Corrections implemented during the proceedings may constitute a mitigating factor, but they do not eliminate an infringement that existed previously.
What should businesses do?
Based on the decisions, a review of a privacy notice should begin not with the wording of the existing document, but with mapping the website’s actual data flows.
The controller should review all forms, purchasing processes, cookies, analytics and advertising tools, payment and delivery services, and determine the data protection role of external parties. It can then assess whether the privacy notice describes all processing operations that actually take place and whether it contains operations that have been discontinued or never took place.
For each processing purpose, the categories of personal data, legal basis, recipients and retention period must be clearly identified, together with whether provision of the data is a statutory or contractual requirement, a prerequisite for entering into a contract, and what consequences may follow if the data are not provided. General corporate templates, texts generated by legaltech systems and documentation supplied by external service providers should all be subject to human review.
The accessibility of the privacy notice should be tested in practice after website updates and changes of service providers. Previous versions, their periods of validity and their publication should be retained in a manner that allows compliance to be demonstrated at a later stage.
The topic is also likely to remain a priority in European enforcement. On 19 March 2026, the European Data Protection Board launched a coordinated enforcement action specifically focusing on transparency and information obligations under Articles 12 to 14 GDPR. Twenty-five European data protection authorities are participating in the initiative. During the second half of 2026, the authorities will share and jointly assess their findings, after which a consolidated report will be prepared and submitted to the EDPB for adoption. (EDPB, CEF 2026: EDPB launches coordinated enforcement action on transparency and information obligations, 19 March 2026)
The NAIH’s decisions show that transparency is no longer simply a question of whether a website has a privacy notice. The controller must ensure that the document reflects its actual operations, remains continuously accessible and can be supported by evidence covering the entire period under investigation.
