Skip to content
NewOFAC Watcher checks your watchlist each day and emails you when a sanctions-list change looks like a possible match.See OFAC Watcher · $29 / month
Covered
  • OFAC SDN list
  • UN sanctions list
  • EU sanctions list
  • Public on-chain data
  • MiCA
  • EU AI Act
  • GDPR
  • DORA
  • FinCEN BOI
  • VARA
  • SOC 2
  • AML / KYC

GDPR compliance in Hungary: who is in scope and what is owed

How GDPR applies to companies operating in or serving Hungary — scope tests, the obligations that follow, and the primary sources to verify each one against.

Organisations established in Hungary, as well as those outside Hungary targeting data subjects within its territory, are subject to the General Data Protection Regulation. EU supervisory authorities and the European Data Protection Board enforce these rules uniformly across member states. Compliance requires assessing whether processing activities fall within extraterritorial reach and establishing appropriate operational safeguards.

Extraterritorial Reach and Applicability to Hungarian Operations

The application of the regulation depends on the establishment of a controller or processor in the Union, or the targeting of individuals located in the Union. Entities based in Hungary must evaluate their processing activities regardless of where the actual data processing takes place. When foreign organisations offer goods or services to individuals in Hungary, or monitor their behavior within the territory, the rules apply. This jurisdictional scope covers both local businesses and international companies interacting with the Hungarian market.

Determining whether an entity acts as a data controller or a data processor is a primary step for compliance teams. Controllers determine the purposes and means of processing, while processors handle data on behalf of controllers. Organisations must document these roles clearly in their operational records and contractual agreements. Misidentifying a role can lead to regulatory scrutiny from supervisory authorities.

Operational teams must review all data flows originating from or targeting Hungary to map processing activities accurately. Entities operating across borders within the EU must coordinate with relevant regulatory bodies as guided by the EDPB — guidelines, recommendations and best practices. This mapping exercise forms the foundation for subsequent accountability measures and documentation obligations under the legal framework.

| Processing Type | Primary Responsibility | Key Documentation Requirement | |---|---|---| | Direct Collection | Data Controller | Privacy Notice & Consent Records | | Outsourced Processing | Data Processor | Processing Agreement under GDPR Article 28 — Processor | | Cross-Border Transfer | Exporter/Importer | Standard Contractual Clauses |

The table above outlines how responsibilities vary across different data processing arrangements. Every entity within the scope must maintain transparency and adhere to the strict accountability principles set out in the primary text of Regulation (EU) 2016/679 (GDPR) — full text.

Core Obligations for Controllers and Processors in Hungary

Entities subject to the regulation must implement technical and organisational measures to protect personal data. These measures must be documented and reviewed regularly to reflect changes in processing operations and risk profiles. Organisations often utilize a record of processing activities to track categories of data, processing purposes, and security measures. Maintaining these records is a statutory requirement for many organisations based on their size or processing activities.

When engaging third-party vendors, controllers must bind them through specific contractual terms that meet statutory standards. These requirements are detailed in GDPR Article 28 — Processor, which dictates how processors must assist controllers with data subject rights and security. Both parties must ensure that any sub-processors are engaged only with prior specific or general written authorization from the controller.

Accountability also extends to demonstrating compliance upon request by supervisory authorities. Organisations should establish internal policies, conduct training, and perform regular audits of their data processing systems. Reviewing guidance from the EDPB — guidelines, recommendations and best practices helps compliance teams align their internal controls with expected regulatory standards across member states.

Documentation and Record-Keeping Requirements

Maintaining accurate documentation is a cornerstone of regulatory accountability for entities operating in Hungary. According to GDPR Article 30 — Records of processing activities, controllers and processors must maintain records of processing activities under their responsibility. These records must contain specific details, including the name and contact details of the controller, purposes of processing, and categories of data subjects and personal data.

To operationalise these requirements, compliance teams frequently establish a centralized record of processing activities repository. This repository allows organizations to quickly respond to supervisory authority inquiries and provides a clear overview of data flows. If an enterprise employs a data protection officer, that individual typically oversees the maintenance and accuracy of these records.

Small and medium-sized enterprises sometimes qualify for exemptions from certain record-keeping duties, provided their processing does not pose high risks to the rights and freedoms of data subjects. However, evaluating whether an exemption applies requires careful analysis of the specific data processing activities. Organisations should consult the text of Regulation (EU) 2016/679 (GDPR) — full text to verify the exact criteria for any claimed exemptions.

Cross-Border Data Transfers from Hungary to Third Countries

Transferring personal data outside the European Economic Area requires specific legal mechanisms to ensure the protection travels with the data. When sending data to a jurisdiction without an adequacy decision, organizations commonly rely on the tools approved by the European Commission. The Commission Implementing Decision (EU) 2021/914 — Standard Contractual Clauses provides standard contractual clauses that parties can implement to legitimize these transfers.

Before executing transfers using standard clauses, data exporters must conduct transfer impact assessments to evaluate the legal framework of the destination country. If local laws in the third country prevent the data importer from fulfilling its obligations under the clauses, supplementary measures must be adopted. Guidance on assessing third-country legislation and implementing supplementary measures is frequently updated by the EDPB — guidelines, recommendations and best practices.

When working with complex supply chains involving multiple sub-processor tiers, ensuring that transfer safeguards flow down contractually is essential. Compliance teams should map every international data route and verify that appropriate agreements are in place before any data leaves the EU territory from Hungarian operations.

Governance, Audits, and Evidencing Accountability

Demonstrating adherence to data protection principles requires continuous governance and proactive internal auditing. Organisations should appoint a data protection officer when core activities require regular and systematic monitoring of data subjects on a large scale. This officer acts as an independent point of contact for supervisory authorities and advises management on statutory obligations.

When processing activities are likely to result in a high risk to the rights and freedoms of natural persons, conducting a data protection impact assessment is mandatory before processing begins. Similarly, when relying on legitimate interests as a legal basis, teams should perform a structured legitimate interests assessment to balance the organization's interests against the fundamental rights of data subjects. These assessments must be documented and retained for review.

To verify that operational controls function correctly, legal and compliance teams should implement periodic internal audits. Reviewing the provisions in Regulation (EU) 2016/679 (GDPR) — full text ensures that governance frameworks remain aligned with statutory mandates. Maintaining an audit trail of all compliance decisions supports the organization in demonstrating accountability during regulatory reviews.

Uncertainties and Local Law Interactions in Hungary

While the regulation applies uniformly across the European Union, national member states retain competence to specify rules in certain areas, such as employment contexts and specific administrative fines. Organisations operating in Hungary must check local statutory enactments that supplement the primary European text. These local nuances can affect employee monitoring, public sector processing, and specific sectoral requirements.

Determining whether local exemptions or specific processing conditions apply often requires consulting local legal counsel or referring directly to the supervisory authority's published guidance. Because enforcement priorities and administrative procedures can vary, compliance teams should not rely solely on generalized interpretations. Cross-checking operational practices against Regulation (EU) 2016/679 (GDPR) — full text and national legislation is necessary.

When ambiguities arise regarding the interpretation of cross-border processing or supervisory competence, organizations can consult the resources provided by the EDPB — guidelines, recommendations and best practices. Resolving these uncertainties proactively reduces regulatory exposure and ensures that compliance programs remain defensible before competent authorities.

BizLegal AI is regulatory research software, not a law firm. This page is general information, not legal advice, and does not create a lawyer-client relationship. Verify every deadline, threshold and obligation against the primary source cited before you act on it, and consult qualified counsel in the relevant jurisdiction.

Frequently asked questions

Does the regulation apply to non-EU companies selling into Hungary?

Yes, entities established outside the Union are caught if they offer goods or services to individuals in Hungary or monitor their behavior within the territory.

What is the primary difference between a controller and a processor?

A controller determines the purposes and means of processing personal data, whereas a processor performs processing operations strictly on behalf of the controller.

Are all organisations required to maintain a record of processing activities?

Not all entities are subject to this requirement, as certain small enterprises with fewer employees may be exempt unless their processing poses specific risks.

What mechanism should be used for international data transfers outside the EEA?

Organisations frequently rely on approved instruments such as standard contractual clauses published by the European Commission when adequacy decisions are absent.

When is a data protection officer mandatory for an operation?

Appointment is required when core activities involve regular and systematic monitoring of data subjects on a large scale or large-scale processing of sensitive data.

Sources

BizLegal AI is regulatory research software, not a law firm. This page is general information, not legal advice, and does not create a lawyer-client relationship. Verify every deadline, threshold and obligation against the primary source cited before you act on it, and consult qualified counsel in the relevant jurisdiction.

Last reviewed 2026-10-08.

Contact