Law / Hungary

NAIH Enforcement, GDPR Article 82, and Infotörvény Section 24 Sérelemdíj

Regulation (EU) 2016/679, Art. 82; 2011. evi CXII. torveny, 24. section

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 1 January 2012.

An enforcement supervision rule binding public and private bodies.

As of 2 September 2026.

What it requires

  • Expect NAIH to have General Data Protection Regulation (GDPR) Article 83 fining power over your processing of personal data of a person in Hungary.
  • Expect a person in Hungary whose personality right to data protection was infringed to be able to claim serelemdij compensation from you as controller or processor, jointly and severally with any processor acting on your instructions, on top of ordinary GDPR Article 82 damages.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Buntetes Torvenykonyv (Btk., 2012. evi C. torveny) Section 219, Szemelyes adattal visszaeles (Misuse of personal data): unlawfully or purpose-divergently processing personal data, or failing to implement a data-security measure, in breach of the statutory or EU-law rules on personal-data protection, for the purpose of financial gain or causing significant harm to interests, is a misdemeanour punishable by imprisonment of up to 1 year (Section 219(1)); the same conduct as to failing to inform a data subject of their access rights while significantly harming interests is punished the same way (Section 219(2)); the offence is punishable by imprisonment of up to 2 years where it involves special-category or criminal personal data (Section 219(3)); and by imprisonment of up to 3 years, as a felony, where committed by an official person, using a public mandate, or with an unlawfully made image or audio recording of a court proceeding (Section 219(4)).

Penalty structure

Article 83(5) sets the higher administrative-fine tier, up to EUR 20,000,000 or 4 percent of total worldwide annual turnover of the preceding financial year, whichever is higher, for the gravest infringement categories. Article 83(4) sets a lower tier, up to EUR 10,000,000 or 2 percent, for other listed provisions. Infotorveny Section 61(4), read in full from the Act's own text, sets a Hungary-specific fine cap of HUF 100,000 to HUF 20,000,000 that displaces the GDPR figure in two situations: a fine NAIH imposes for processing under Infotorveny Section 2(3) (law enforcement, national security, and national defense processing, which is outside GDPR's own scope), and, separately, any fine NAIH imposes under GDPR Article 83 itself where the fined entity is a koltsegvetesi szerv (a body financed from the state budget).

Rule
Higher of
As of
2 September 2026
Currency
EUR
Fixed cap
20,000,000
Turnover percentage cap
4

Who enforces it

Enforcement body

Nemzeti Adatvedelmi es Informacioszabadsag Hatosag (NAIH), Hungary's independent supervisory authority, an autonomous state administrative body under the Infotorveny Section 38.

Enforcement record

NAIH's own 2025 annual report to Parliament ('NAIH beszamolo a 2025. evi tevekenysegrol', published 2026-03-30): the Authority imposed HUF 98,235,000 in fines during 2025, of which HUF 67,195,000 was data-protection fines (adatvedelmi birsag) specifically, HUF 27,965,000 procedural fines, and HUF 3,075,000 execution fines; the report also states the Authority's fine-account annual turnover was HUF 70.9 million, and that fines are paid into the central budget, not retained by the Authority. actions_per_year counts the report's own I.1 statistics table for new 2025 data-protection authority proceedings (adatvedelmi hatosagi eljaras): 929 opened on complaint (kerelemre indult) plus 76 opened by the Authority on its own initiative (hivatalbol indult), 1,005 total, excluding the 11 and 12 respectively carried over from prior years. The report gives no separate count of how many of these proceedings concluded with a fine.

As of
2 September 2026
Currency
HUF
Source link
https://www.naih.hu/eves-beszamolok?download=1431:naih-beszamolo-a-2025-evi-tevekenysegrol
Fines per year
67,195,000
Actions per year
1,005

What it reaches

Obligation class

Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Nemzeti Adatvedelmi es Informacioszabadsag Hatosag (NAIH), the National Authority for Data Protection and Freedom of Information, is Hungary's supervisory authority, with General Data Protection Regulation (GDPR) Article 83 fines.

Section 24(2) of the Infotorveny, read verbatim, confirms a genuine Hungarian civil-law addition that predates and now sits alongside GDPR Article 82 (Section 24 itself is original, unamended 2011 Act text, in force since 1 January 2012, six years before GDPR Article 82's own 25 May 2018 application date): a person whose personality right has been infringed may claim serelemdij (compensation for infringement of a personality right) from the controller or processor, and Section 24(5) makes joint controllers and their processors jointly and severally liable for both ordinary damages and serelemdij.

Section 24(3)-(4) give a force-majeure-style exemption for an unavoidable cause outside the scope of the processing.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics
  • processes_voice

Read the law

njt.jog.gov.hu, Infotorveny sec. 24 (verbatim)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app