Hungary Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Info Act)
Evidence request list. 10 controls, 10 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
HU Infotv Chap1 - Scope + Coverage + Definitions
Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information (Infotorveny / Infotv) is the foundational Hungarian data protection + freedom of information law. Dual statute: Chapter I General Provisions + Chapter II Personal Data Processing + Chapter III Data Public on Grounds of Public Interest (FOI) + Chapter IV Special Provisions + Chapter V National Authority for Data Protection and Freedom of Information (NAIH) + Chapter VI Closing Provisions. Pursuant to Article VI of Hungarian Fundamental Law (Constitution). Applies to all data control + data processing activities undertaken in Hungary relating to data of natural persons + data of public interest + data public on grounds of public interest (Section 2). Applies to automated + manual processing. Extraterritorial: applies if controller outside EU contracts a processor with seat in Hungary (designate
- Infotv Act CXII of 2011 register of applicability + amendments since 2011
- Mapping of GDPR + Infotv parallel obligations + Hungarian specifics
- Hungarian definitions register (data control vs data processing vs data transfer)
- Extraterritorial Section 2(3) Hungarian processor representative designation
- Coordination matrix with GDPR + Penal Code Sec 219 + Cybersecurity Act XXIII of 2023 + NIS2
- Treating Infotv as GDPR replica (it is parallel with Hungarian specifics)
- Missing Section 2(3) extraterritorial assessment for non-EU controllers using Hungarian processors
- Stale references to pre-GDPR Infotv structure
- Conflating Infotv Chapter II (DP) with Chapter III (FOI)
- Missing Penal Code Sec 219 criminal exposure assessment
HU Infotv Chap2 - Lawful Basis + Special Categories
Chapter II Personal Data Processing establishes lawful processing requirements. Section 5 (Lawfulness) requires processing be based on: (a) data subject consent, or (b) legal authorisation. Consent must be voluntary, specific, informed, unambiguous indication of will (aligned with GDPR Article 4(11) + 6(1)(a) + 7). Section 6 (Special Categories - kulonleges adat) defines special category data: racial origin + nationality + political opinion + religious or worldview belief + membership in interest representation organisations + sexual life + health status + addiction + criminal record (penal data). Processing of special category requires: data subject explicit written consent + or processing necessary to enforce vital interest + or expressly authorised by Act + or required by international agreement + or implementation of constitutional right (Chapter IV). Hungarian specifics: criminal da
- Lawful basis register per processing activity (Section 5(1)(a) consent / (b) legal authorisation)
- Consent management platform + opt-in + withdrawal log + age verification
- Special category data register per Section 6(2) categories (incl. Hungarian-specific criminal data)
- Explicit written consent records for special category processing
- Section 5(4) journalism/academic/artistic/scientific exception application records
- Implied consent treated as Section 5(1)(a) compliant
- Criminal data processed as ordinary personal data (Hungarian regime stricter than GDPR Art 10)
- Missing written explicit consent for Section 6(2) processing
- Section 5(4) journalism exception over-applied for marketing
- No consent withdrawal mechanism with equivalent ease of withdrawal as giving
HU Infotv Chap2 - Security + Processor + Breach
Chapter II Section 7 establishes data security obligations. Controller and processor shall apply appropriate technical + organisational measures + procedures to protect personal data and the privacy rights of data subjects. Considerations: state of the art + costs + nature + scope + context + purposes + risks (similar to GDPR Article 32 but adapted to Hungarian terminology). Specific measures: prevention of unauthorised access + unauthorised disclosure + accidental + intentional erasure + alteration + loss + accidental access of unauthorised persons. Encryption + pseudonymisation + access controls + audit logs + backup + incident response + secure transmission. Section 25 onwards (Sections 25A-25K added by 2018 GDPR Implementation Act) cover: Section 25A controller obligations + Section 25B Data Protection Officer obligations + Section 25C records of processing + Section 25D security + S
- Security policies + standards + procedures mapped to Section 7 + 25D
- Processor contracts with Section 25H mandatory clauses + audit + return + erasure
- Joint controller arrangement (Section 25I) defining responsibilities + transparent point of contact
- Breach notification playbook + 72-hour NAIH online form + high-risk DPB notification
- DPIA register per Section 25E for high-risk processing + prior consultation Section 25F trigger criteria
- Incident response + forensics + lessons-learned + tabletop exercises
- Processor contracts missing Hungarian Section 25H clauses (similar to GDPR Art 28 but Hungarian-specific)
- Joint controller arrangement undocumented (Section 25I)
- 72-hour breach SLA missed or notification incomplete (Section 25G)
- DPIA only at IT level not for high-risk profiling/biometric (Section 25E)
- Prior consultation Section 25F threshold not assessed
HU Infotv Chap2 - Transparency + Data Subject Rights
Chapter II Sections 14-23 establish data subject rights and transparency obligations. Section 14 (Right to Information) requires controller to provide privacy notice at or before collection covering: identity + contact of controller + processor + DPO + purposes + lawful basis + recipients + transfers outside EU + retention + rights + complaint to NAIH + automated decision-making (Section 15). Section 16 (Right of Access) - data subject may request: confirmation of processing + categories + purposes + recipients + retention + source + automated decision-making logic + transfer details. 30-day response (extendable in complex cases by 30 days with notification). Section 17 (Right to Rectification) inaccurate data correction within 25 days; refusal in writing with reasons. Section 18 (Right to Erasure) right to be forgotten; mandatory erasure grounds. Section 19 (Right to Restriction). Secti
- Privacy notices per processing point (Section 14) + Hungarian + English versions
- DAR intake + tracking + 25-day SLA + extension records (Section 16)
- Rectification + erasure decision register + recipient notification log (Section 17-18-22)
- Restriction marking on data systems (Section 19)
- Direct marketing absolute opt-out + audit (Section 20)
- Portability format conversion + machine-readable export (Section 21)
- Section 23 damages claim register
- GDPR 30-day SLA applied where Hungarian 25-day required
- Erasure refused without written reasons + grounds (Section 18)
- Recipient notification skipped on rectification/erasure (Section 22)
- Portability scope unclear (lawful basis consent or contract only)
- No machine-readable format for portability
HU Infotv Chap3 - Freedom of Information
Chapter III establishes Hungarian freedom of information regime, distinct from data protection. Section 26 (Right to Access Data of Public Interest) - everyone has right to access data of public interest (public bodies + state-funded private bodies) and data public on grounds of public interest. Section 27 (Refusal grounds) - limited grounds: classified data + decision preparation + intellectual property + tax/customs + business secret + state security/defence. Section 28-29 (Request procedure) - 15-day response (extendable 15 days with notification); refusal in writing with appeal information; fee schedule limited to actual cost. Section 30 (Reasons for refusal of fee-based requests) limited. Section 31-32 (Court appeal) - 30-day appeal to Hungarian court (originally Pesti Central District Court, now general court). Sections 33-37 (Mandatory Proactive Disclosure - Annex 1 General Public
- FOI request intake + tracking + 15-day SLA + extension log
- Fee schedule + actual cost calculation methodology + transparency
- Section 27 refusal decision register + classification + business secret + state security justification
- Annex 1 General Publication Scheme mandatory publication map + kozadattar.hu + own website
- Section 31-32 court appeal procedures + legal team readiness + reporting
- GDPR 30-day SLA applied where FOI 15-day required (Section 28)
- Excessive fee charged beyond actual cost (Section 29)
- Refusal grounds invoked without written reasons + appeal information (Section 27)
- Mandatory Annex 1 publications missing or stale on kozadattar.hu
- Misapplied data protection ground to FOI request (Section 27 grounds limited)
HU Infotv Chap5 - NAIH
Chapter V establishes Nemzeti Adatvedelmi es Informacioszabadsag Hatosag (NAIH) - National Authority for Data Protection and Freedom of Information. Independent autonomous central public body. President appointed by Hungarian President on Prime Minister proposal for 9-year non-renewable term. Functions (Section 38): supervise + advise + register + cooperate. Section 51 onwards (Powers) - investigation (own-motion or complaint) + inspection + access to data + access to systems + audit; Section 55-61 (Procedure) - data subject complaint + remedy 60 days NAIH + court appeal; Section 56 NAIH may order: cease processing + restriction + blocking + erasure + correction + fine. Administrative fines (Section 59A added GDPR alignment): up to EUR 20 million or 4 percent global turnover (tier 2 GDPR Article 83(5)) for serious violations; up to EUR 10 million or 2 percent global turnover (tier 1 Arti
- NAIH cooperation playbook + legal liaison + evidence preservation + Hungarian counsel
- Compliance Check + Inspection readiness materials + RoPA + DPIA + audit trail
- Section 59A administrative fine risk register + global turnover calculation + insurance
- Penal Code Section 219 criminal risk register + personal liability + insurance for officers
- Hungarian administrative court appeal procedures + Government Decree 217/2018 + retained Hungarian counsel
- No NAIH cooperation playbook or Hungarian-speaking legal liaison
- Section 59A fine calculation ignored (global turnover not company turnover)
- Penal Code Section 219 personal criminal liability for directors/DPOs ignored
- Hungarian administrative court appeal route confused with EU/general court
- No Government Decree 217/2018 procedural compliance
HU Infotv Coordination + International + NIS2
Infotv operates in parallel with EU GDPR (Regulation (EU) 2016/679) since May 2018 with Hungarian specifics: criminal data treatment + 25-day SLA + 16-year age + works council + Hungarian-language privacy notices + NAIH-Hungarian-specific DPIA triggers. International Transfers: Articles 44-49 GDPR Standard Contractual Clauses (2021/914) + Adequacy Decisions + BCRs apply directly + supplemented by NAIH Guidance on International Transfers post-Schrems II 2021/2022 + Transfer Impact Assessment template. Sub-processor cascading: Hungarian-specific contractual addendum. Hungarian Cybersecurity Act XXIII of 2023 (Cybersecurity Act / Kibervedelmi torveny) transposes NIS2 Directive (EU) 2022/2555 with significant elements: in force October 2024; covers essential + important entities; CSIRT functions to National Cyber Defence Centre (NKI) under Special Service for National Security (SSNS); incide
- Coordination matrix Infotv + GDPR + Hungarian specifics (25-day + age 16 + criminal data + works council)
- International transfer register + SCCs (2021/914) + Transfer Impact Assessment per NAIH 2021/2022 Guidance
- Cybersecurity Act XXIII of 2023 (NIS2) compliance assessment + NKI registration + incident reporting integration with Infotv breach notification
- EU AI Act readiness + DSA + DMA scope assessment + Hungarian-specific implementation
- EDPB cooperation + Visegrad privacy authority engagement evidence (Czech/Slovak/Polish)
- Treating Infotv as redundant with GDPR (ignoring Hungarian specifics)
- Missing TIA for transfers to third countries post-Schrems II
- NIS2 incident reporting + Infotv breach notification handled separately (should be integrated)
- EU AI Act high-risk system deployment without Hungarian transposition gap analysis
- No EDPB cooperation + Visegrad regional engagement
HU Infotv Governance + DPO + Records + Training
Section 25A-25C (added by 2018 GDPR Implementation Act) establish governance obligations. Section 25A general controller obligations including appropriate technical + organisational measures + data protection policies. Section 25B Data Protection Officer (DPO) - mandatory for: public authorities and bodies (any size); core activities consisting of regular and systematic monitoring of data subjects on a large scale; core activities consisting of processing on a large scale of special categories or criminal data. DPO tasks (mirroring GDPR Article 39): inform + advise + monitor compliance + cooperate with NAIH + first point of contact for NAIH and data subjects + DPIA advice. DPO reporting line to highest management + independence + no instructions on tasks + protection from dismissal for performing tasks. Section 25C Records of Processing Activities (RoPA - similar to GDPR Article 30 with
- DPO appointment + role description + reporting line to top management + independence statement
- Section 25B mandatory trigger assessment (public authority / regular monitoring / large scale special category)
- Section 25C RoPA register + Hungarian processing-specific fields + version control
- NAIH DPO database registration evidence + contact details published
- Annual training programme + role-based modules + works council representative training
- Hungarian DPO Association membership / professional development evidence
- No DPO appointed despite Section 25B trigger met
- DPO not registered with NAIH or contact not published
- RoPA only for IT systems not full processing inventory
- Generic GDPR training not adjusted to Hungarian Infotv + Penal Code Sec 219
- No works council training despite Hungarian labour requirements
HU Infotv Governance - DPIA + Privacy by Design
Section 25E (added by 2018 GDPR Implementation Act) establishes Data Protection Impact Assessment (DPIA) requirement for processing likely to result in high risk to rights and freedoms of natural persons. Triggers: systematic + extensive evaluation including profiling + automated decision-making with significant effects; large-scale processing of special categories or criminal data; systematic monitoring of publicly accessible area on a large scale. NAIH List of Processing Operations Requiring DPIA (NAIH-2018-2-V/2018 + updates) - includes additional Hungarian-specific triggers: large-scale biometric processing; large-scale location tracking; cross-border health data exchange; whistleblower scheme processing; combined large-scale registries. DPIA contents (mirror GDPR Article 35(7)): systematic description + necessity and proportionality + risk assessment + measures to address risks. Sec
- DPIA methodology + template + register per Section 25E
- NAIH List of Processing Requiring DPIA mapping to operations + Hungarian-specific triggers
- Section 25F prior consultation register + NAIH 8-week response tracking
- Privacy by Design + by Default checklist + system requirement integration evidence
- AI + facial recognition + automated decision-making PIA + NAIH 2022/2024 Guidance alignment
- DPIA only at IT level not for HR/marketing/biometric/AI
- NAIH List of Processing not consulted (Hungarian-specific triggers ignored)
- Section 25F prior consultation skipped despite high residual risk
- Privacy by Design checklist absent from system design lifecycle
- AI deployment without PIA per NAIH 2022/2024 Guidance
HU Infotv Sectoral
Sectoral application of Infotv augmented by Hungarian-specific guidance from NAIH. Direct marketing: requires explicit consent (opt-in) + register of consent + easy opt-out (Hungarian Act CXIX of 1995 on Direct Marketing parallel) + Section 6(5) special e-commerce/marketing rules. Cookies: requires consent under Act C of 2003 on Electronic Communications Section 155(4) (Hungarian transposition of EU ePrivacy Directive). Strictly necessary cookies exempted. Non-essential cookies (analytics + advertising + tracking) require prior informed consent with effective rejection option. CCTV: NAIH Recommendation on CCTV deployment (2014 + 2020 updates) - signage + necessity + proportionality + retention 3-30 days typical + access log + access control + processor or operator due diligence + privacy zones + facial recognition + AI analytics impact assessment. Employment: Hungarian Labour Code (Act I
- Direct marketing consent log + Act CXIX of 1995 register + opt-out
- Cookie banner + strictly necessary classification + non-essential opt-in + Section 155(4) Act C of 2003
- CCTV signage + retention 3-30 days + privacy zones + facial recognition PIA per NAIH 2014/2020 Recommendation
- Workplace monitoring 3-A test + works council consultation + Hungarian Labour Code Sections 9-11/86-93 + NAIH 2017 Recommendation
- Children under 16 parental consent verification + Hungarian-specific age 16 threshold
- Cookie banner accepting all by default (not Section 155(4) compliant)
- CCTV without NAIH-aligned signage + retention + privacy zones
- Workplace monitoring without works council consultation (Hungarian Labour Code)
- GDPR Article 8 age 13 applied where Hungary sets 16
- Direct marketing with Act CXIX of 1995 + Infotv parallel breach
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Hungary Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Info Act) framework page.