GDPR

Adatvédelem mindenkinek / Data protection for everyone

GDPR fines in Hungary imposed in 2019

2019. április 08. 11:00 - poklaszlo

The possibility of imposing significant amount of fine for the violation of data protection rules drew immediate attention to the issue of data protection compliance. While the amount of administrative fine in the GDPR was only a theoretical maximum, fines imposed in specific cases could serve as important practical compass in several respects: on the one hand, the level of fines is indicative itself, and on the other hand, it is also important for data controllers and processors to see which articles of the GDPR are regularly cited in the decisions, what are the most important criteria that are taken into account by the authorities when deciding on the legal consequences (including fines) in a given case.

Below I have collected decisions of the Hungarian Data Protection Authority (NAIH) imposing fines (published in 2019) and I also indicated the articles of the GDPR that were referred to in the decisions by the authority. (Updated: 26.09.2020)

No. of the decision Date of the decision Amount of the fine Articles of the GDPR evaluated in the decision  Notes
NAIH/2018/5559 21.12.2018 HUF 1,000,000 (approx. EUR 3,100)
  • Art. 15 (right of access),
  • Art. 18 (1) c) (right to restriction of processing),
  • Art. 12 (4) (modalities for the exercise of the rights of the data subject)
NAIH/2019/363 08.02.2019 HUF 500,000  (approx. EUR 1,550)
  • Art. 5 (1) d) (accuracy),
  • Art. 12 (transparent information, communication and modalities for the exercise of the rights of the data subject)
NAIH/2019/1841 20.02.2019 HUF 500,000  (approx. EUR 1,550)
  • Art. 5 (1) a) (transparency),
  • Art. 5 (1) c) (data minimisation),
  • Art. 6 (1) c) (lawfulness of processing - processing is necessary for compliance with a legal obligation to which the controller is subject),
  • Art. 12 (2) and (4) (modalities for the exercise of the rights of the data subject),
  • Art. 15 (right of access),
  • Art. 17 (3) b) (right to erasure)
NAIH/2019/596 28.02.2019 HUF 1,000,000  (approx. EUR 3,100)
  • Art. 5 (1) a) (lawfulness, fairness and transparency),
  • Art. 6 (lawfulness of processing),
  • Articles 33-34 (personal data breach)
NAIH/2019/2526 04.03.2019 HUF 1,000,000  (approx. EUR 3,100)
  • Art. 5 (1) b) (purpose limitation),
  • Art. 5 (1) c) (data minimisation),
  • Art. 6 (1) f) (lawfulness of processing - legitimate interest),
  • Art. 6 (4) (processing for a purpose other than that for which the personal data have been collected),
  • Art. 13 (3) (information),
  • Art. 17 (right to erasure)

NAIH/2019/2668 

21.03.2019 HUF 11,000,000  (approx. EUR 34,500)
  • Art. 9 (1) (special categories of data),
  • Art. 32 (data security),
  • Articles 33-34 (personal data breach)

NAIH/2019/55

23.05.2019 HUF 30,000,000 (approx. EUR 93,000)
  • Art. 5 (1) b) (purpose limitation),
  • Art. 5 (1) c) (data minimisation),
  • Art. 5 (2) (accountability)
  • Art. 6 (1) f) (lawfulness of processing - legitimate interest),
  • Art. 6 (lawfulness of processing)
NAIH/2019/133 05.04.2019 HUF 600,000 (approx. EUR 1,900)
  • Art. 12 (3) and (4) (modalities for the exercise of the rights of the data subject),
  • Art. 15 (right of access)
NAIH/2019/167 17.04.2019 HUF 2,000,000 + HUF 1,000,000 (EUR 6,250 + EUR 3,125)
  • Art. 5 (1) a) (lawfulness, fairness and transparency),
  • Art. 5 (1) d) (accouracy),
  • Art. 5 (2) (accountability)
  • Art. 6 (1) b) (lawfulness of processing - contracts),
  • Art. 15 (1) and (3) (right of access)

NAIH/2019/3854

21.05.2019 HUF 100,000 (EUR 312)
  • Art. 33 (1) (personal data breach)
NAIH/2019/2471 25.06.2019 HUF 5,000,000 (EUR 15,625)
  • Art. 33 (1) (personal data breach)
As the data controller is a public body in Hungary, the maximum amount of the fine is limited to HUF 20,000,000. 
NAIH/2019/2402 26.06.2019 HUF 1,000,000 (EUR 3,125)
  • Art. 6 (1) f) (lawfulness of processing - legitimate interest),
  • Art. 17 (1) b) (right to erasure - withdrawal of consent)
NAIH/2019/1859 31.05.2019 HUF 700,000 (EUR 2,187)
  • Art. 12 (3) and (4) (modalities for the exercise of the rights of the data subject),
  • Art. 15 (1) and (3) (right of access),
  • Art. 18 (1) (right to restriction of processing)
NAIH/2019/1598 03.06.2019 HUF 1,000,000 (EUR 3,125)
  • Art. 5 (1) a) (lawfulness, fairness and transparency),
  • Art. 5 (1) b) (purpose limitation),
  • Art. 6 (1) (lawfulness of processing)
A procedural fine in the amount of HUF 50,000 (EUR 155) was also imposed. 
NAIH/2019/2472 17.07.2019

HUF 3,000,000 (EUR 9,375)

  • Art. 5 (1) b) (purpose limitation),
  • Art. 6 (1) (lawfulness of processing)
As the data controller is a public body in Hungary, the maximum amount of the fine is limited to HUF 20,000,000. 
NAIH/2019/1837 26.06.2019

HUF 1,000,000 (EUR 3,125)

  • Art. 5 (2) (accountability),
  • Art. 6 (1) (lawfulness of processing),
  • Art. 21 (4) (notification regarding the right to object)
NAIH/2019/2466 02.08.2019

HUF 1,500,000 (EUR 4,690)

  • Art. 5 (1) a) (lawfulness, fairness and transparency),
  • Art. 5 (1) b) (purpose limitation),
  • Art (5) (1) c) (data minimisation),
  • Art. 6 (1) (lawfulness of processing)
  • Art. 13 (1)-(2) and (4) (information)
NAIH/2019/2485 24.10.2019

HUF 2,500,000 (EUR 7,600)

  • Art. 25 (1) and (2) (data protection by design and by default)
  • Art. 32 (1) (security of processing)
  • Art. 33 (1) (personal data breach)
As the data controller is a public body in Hungary, the maximum amount of the fine is limited to HUF 20,000,000.
NAIH/2019/769 15.10.2019 HUF 1,000,000 (EUR 3,125)
  • Art. 5 (1) a) (lawfulness, fairness and transparency),
  • Art. 5 (2) (accountability),
  • Art. 13 (information)
  • Art. 24-25 (responsibility of the controller; data protection by design and by default)
NAIH/2019/2076 04.10.2019 HUF 5,000,000 (EUR 15,000)
  • Art. 5 (1) a) (lawfulness, fairness and transparency),
  • Art. 5 (1) b) (purpose limitation)
  • Art. 5 (2) (accountability),
  • Art. 6 (lawfulness of processing)
  • Art. 12 (1) and Art. 13 (1)-(2) (information)
NAIH/2019/51 11.12.2019 HUF 500,000 (EUR 1,562)
  • Art. 5 (1) a) (lawfulness, fairness and transparency),
  • Art. 5 (1) b) (purpose limitation),
  • Art. 5 (1) e) (storage limitation)
  • Art. 5 (2) (accountability),
  • Art. 6 (lawfulness of processing)
  • Art. 13 (information)
  • Art. 24-25 (responsibility of the controller; data protection by design and by default)
NAIH/2019/4424 11.11.2019 HUF 1,500,000 (EUR 4,690)
  • Art. 5 (1) a) (lawfulness, fairness and transparency),
  • Art. 5 (1) b) (purpose limitation),
  • Art. 5 (1) c) (data minimisation),
  • Art. 6 (lawfulness of processing)
NAIH/2019/1509 08.2019 HUF 600,000 (EUR 1,800)
  • Art. 5 (1) a) (lawfulness, fairness and transparency),
  • Art. 5 (1) c) (data minimisation)
NAIH/2019/ 15.11.2019 HUF 25,000,000 (EUR 72,000)
  • Art. 6 (lawfulness of processing)
  • Art. 12 (1) (transparency)
  • Art. 13 (1) c) and d) (information to be provided)

 

Szólj hozzá!

A bejegyzés trackback címe:

https://gdpr.blog.hu/api/trackback/id/tr1814747399

Kommentek:

A hozzászólások a vonatkozó jogszabályok  értelmében felhasználói tartalomnak minősülnek, értük a szolgáltatás technikai  üzemeltetője semmilyen felelősséget nem vállal, azokat nem ellenőrzi. Kifogás esetén forduljon a blog szerkesztőjéhez. Részletek a  Felhasználási feltételekben és az adatvédelmi tájékoztatóban.

Nincsenek hozzászólások.
süti beállítások módosítása