Hungary
Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Hungary — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Hungary has no general rule that data must stay in the country. It follows the European rulebook. You may send data abroad if you have the right legal paperwork in place. Hungary used to make state registers run on Hungarian soil. That rule was scrapped in April 2024. The privacy regulator is real, staffed and issuing decisions. Its fines are small by European standards.
Data governance in Hungary
The eight things that decide how you handle data about people in Hungary. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. A company with no office in Hungary is still caught. That happens if it offers goods or services to people in Hungary, or watches what they do. European privacy rules reach outside Europe. There is no revenue or staff-count limit to hide under. If you have no office anywhere in Europe, you must appoint a written representative inside Europe. Hungary is a perfectly ordinary place to put one.
- What you have to do here:
- Appoint a representative
The first layer is Regulation (EU) 2016/679, the General Data Protection Regulation. The second layer is Hungary's own Act CXII of 2011 on informational self-determination and freedom of information, known as the Info Act or Infotv. The Info Act splits the field in two. For work covered by the General Data Protection Regulation, it adds only a named list of extra rules. For work outside that Regulation, it applies on its own terms. That means law enforcement, national security and defence, including the Info Act's own rules on sending data to countries outside Europe. The Info Act also carries Hungary's freedom-of-information rules. Those reach bodies performing public duties, state-owned companies and, in most cases, their contractors. On 14 August 2026 the regulator announced it was widening the bodies and data types covered by the Central Information Public Data Registry. So this exposure is growing, not shrinking.
Sources
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act CXII of 2011 on informational self-determination and freedom of information (Infotv.), consolidated text, sections 2, 10 and 11
njt.jog.gov.hu
Link checked 18 August 2026
- Official sourceNemzeti Adatvedelmi es Informacioszabadsag Hatosag (NAIH)National Authority for Data Protection and Freedom of Information — remit and August 2026 announcements
naih.hu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (GDPR), Articles 3 and 27
eur-lex.europa.eu
Link checked 18 August 2026
Where the data is allowed to live
Yes, on the normal European terms. Nothing in general Hungarian law says data must be stored in Hungary. This is a change worth noticing. The rule that state registers could only run on Hungarian soil was repealed with effect from 1 April 2024. The law that replaced it has no location restriction at all. Two industries override this. An online casino must keep its game server inside the European Economic Area. And any company or public body covered by Hungary's cybersecurity law must finish a formal data classification first. That comes before it uses a shared cloud service or handles data abroad.
The chain of repeals matters, because many trackers still list Hungary as a country where data must stay put. Act CLVII of 2010 said state registers in the 'national data asset' could only be handled on Hungarian territory. It was repealed on 26 July 2021. Its successor, Act XCI of 2021 on the national data asset, repeated the rule: 'A 12. § (3) bekezdese szerint meghatarozott nyilvantartasokhoz kapcsolodo adatfeldolgozasi muveletet az adatfeldolgozo kizarolag Magyarorszag teruleten vegezhet'. That Act was itself repealed with effect from 1 April 2024 by Act CI of 2023. Act CI of 2023, on using the national data asset, has no equivalent location restriction. It builds an opening-up structure around a National Data Asset Agency, the National Data Platform and a public data portal. It expressly allows for foreign data intermediaries. Industry by industry. BANKING, PAYMENTS, INSURANCE AND SECURITIES: no rule that data must stay in Hungary. The central bank's Recommendation 2/2025 covers community and public cloud services. It says firms must act with 'kulonos gondossaggal', meaning particular care, for cloud outside the European Economic Area. The reason is data protection and geopolitical risk. Firms must also record that they considered the rules of the destination country. That is a duty to take care, not a ban. HEALTH: we found no location rule in the Health Data Act or the EESZT rules as at 18 August 2026. The national health data space is run by the state and sits physically in Hungary. That is how it happens to work, not a ban on private companies. TELECOM: we found no storage-location rule. The electronic communications rules are about keeping data and lawful access, not about where data sits. GOVERNMENT: we found no location rule in current law. The cybersecurity classification step below hits hardest here. GEOSPATIAL: Act XLVI of 2012 requires state basic mapping data and aerial and satellite imagery to be held in national archives. That is a custody rule for the state's own copies, not a ban on export. GAMING: a real restriction, see the rule entry. DEFENCE: not researched in depth. Defence mapping databases sit with the defence ministry.
Sources
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act XCI of 2021 on the national data asset, section 13 — repealed with effect from 1 April 2024 by Act CI of 2023
njt.jog.gov.hu
“A 12. § (3) bekezdese szerint meghatarozott nyilvantartasokhoz kapcsolodo adatfeldolgozasi muveletet az adatfeldolgozo kizarolag Magyarorszag teruleten vegezhet.”
Link checked 18 August 2026
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act CI of 2023 on the system for utilising the national data asset and on certain services — the replacement law, with no territorial restriction
njt.jog.gov.hu
Link checked 18 August 2026
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act LXIX of 2024 on the cybersecurity of Hungary, section 9(2) and 9(4) — classification required before non-private cloud or foreign processing
njt.jog.gov.hu
“Az 1. § (1) bekezdes a)-c) pontja szerinti szervezet kizarolag az adatosztalyozas alapjan ... vehet igenybe nem privat felhoszolgaltatast, vagy kezelhet kulfoldon adatot”
Link checked 18 August 2026
- Official sourceSzerencsejatek Felugyelet (Gambling Supervisory Authority)Online casino games — licensing conditions, including server location
szf.gov.hu
“Az online kaszino szerveret EGT-allamban kell elhelyezni”
Link checked 18 August 2026
- Official sourceMagyar Nemzeti Bank (central bank and financial supervisor)Recommendation 2/2025 (I.13.) on the use of community and public cloud services
mnb.hu
“Az Intezmeny az Europai Gazdasagi Tersegen kivuli felhoszolgaltatas eseten az adatvedelmi kockazatok, valamint a felugyeleti tevekenysegek gyakorlasat veszelyezteto geopolitikai kockazatok miatt kulonos gondossaggal jar el.”
Link checked 18 August 2026
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act XLVI of 2012 on surveying and mapping activity, section 4 — state basic data held in national archives
njt.jog.gov.hu
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Hungary.
Not fully verified — see “What we're not sure about” below.Sending data out of the country
You need a European transfer tool before the data leaves. Hungary adds no extra permit, filing or fee on top. You may send data to a country the European Commission has declared safe. Or you sign the standard European contract clauses and write down why the destination is safe. There is no Hungarian government sign-off, and no Hungarian list of banned countries. For police, security and other work outside European privacy rules, Hungary's own Info Act sets the conditions instead.
- What you have to do here:
- Put a transfer safeguard in place
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent
The first layer is Chapter V of the General Data Protection Regulation. Everything in the shared European brief applies unchanged. The 2021 standard contract clauses are the current set. Company-wide binding rules remain available. You are still expected to write down why the destination country is safe, following the Schrems II judgment. The EU-US Data Privacy Framework is still valid on 18 August 2026, though it is under active pressure. The list of approved countries is the European Commission's, not Hungary's. The second layer covers work outside that Regulation, and comes from the Info Act. Sending data to a country outside Europe needs the person's explicit consent. Or it must be necessary and come with adequate safeguards. Protection counts as adequate in three cases. A European Union legal act says so. Or an international treaty guarantees the rights. Or the company has examined the circumstances and concluded there are 'megfelelo garanciak', meaning adequate guarantees. A narrow set of transfers is allowed without consent. Those are vital interests, a threat to public security, or a single case where no rights are restricted out of proportion. There is no Hungarian registration or notification step for ordinary business transfers.
Sources
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Info Act, sections 10 and 11 — third-country transfer conditions for processing outside GDPR scope
njt.jog.gov.hu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (GDPR), Chapter V — transfers to third countries
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionCommission Implementing Decision (EU) 2021/914 — Standard Contractual Clauses
eur-lex.europa.eu
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The National Authority for Data Protection and Freedom of Information, known by its Hungarian initials NAIH. It is working. It has published decisions right through to May 2026. It released its report on 2025 activity on 30 March 2026. It issued public statements in July and August 2026. Its president is Dr Attila Peterfalvi. The catch is size, not activity. A typical fine is small. One April 2025 data security case brought a fine of two million forint, roughly six thousand US dollars.
NAIH is a single national authority. Hungary has no regional privacy regulators. Here is the evidence that it is working, all from the authority's own site and checked on 18 August 2026. Its decisions register runs to 29 May 2026. Its 2025 annual report was published on 30 March 2026. It issued a 7 July 2026 statement on the political use of children's personal data on social media. On 14 August 2026 it announced it was widening the Central Information Public Data Registry. Decision NAIH-7395-6/2025 of 8 April 2025 fined a supplier 2,000,000 forint (about 6,000 US dollars). The supplier had failed to check firewall settings while moving a customer database of roughly 900,000 records. An attacker then reached personal data including bank account numbers. That is what Hungarian enforcement looks like: regular, technically competent, and modest in money. Other regulators that matter here are all working. The Regulated Activities Supervisory Authority (SZTFH) is the national cybersecurity authority. The National Cyber Security Institute (NKI) is the incident response centre. The Magyar Nemzeti Bank covers financial firms. The Szerencsejatek Felugyelet covers gambling. The National Media and Infocommunications Authority (NMHH) covers electronic communications.
Sources
- Official sourceNemzeti Adatvedelmi es Informacioszabadsag Hatosag (NAIH)Register of NAIH decisions and orders — published decisions through 29 May 2026
naih.hu
Link checked 18 August 2026
- Official sourceNemzeti Adatvedelmi es Informacioszabadsag Hatosag (NAIH)NAIH annual reports — report on 2025 activity published 30 March 2026
naih.hu
Link checked 18 August 2026
- Official sourceNemzeti Adatvedelmi es Informacioszabadsag Hatosag (NAIH)Decision NAIH-7395-6/2025, 8 April 2025 — 2,000,000 HUF fine on a processor for security failures during a database migration
naih.hu
Link checked 18 August 2026
- Official sourceSzabalyozott Tevekenysegek Felugyeleti Hatosaga (SZTFH)Cybersecurity supervision — registers of auditors, deadlines and guidance
sztfh.hu
Link checked 18 August 2026
How long you must keep it — and when to delete it
Hungary pushes hard in both directions. The minimums are long. Accounting records and receipts must be kept for eight years. Health records run for decades, because the health data law works in periods of thirty years and more. The maximum is the European rule that you delete personal data once you no longer need it. When the two collide, the specific keeping period set by law wins. So a deletion request does not empty your ledgers or a hospital's files.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period
MINIMUMS. Act C of 2000 on accounting sets an eight-year minimum for the annual report, the inventory, the general ledger and the supporting receipts. Tax records are tied to the time limit in the tax procedure rules. Act XLVII of 1997 on health data, known as Euak., sets very long minimums for health records. Discharge summaries are kept longer than ordinary records. We could not retrieve the exact text on 18 August 2026, because the official database cuts off long laws. So treat the specific year counts as medium confidence. Act LXIX of 2024 makes covered organisations run a cybersecurity audit cycle. The first audit was due by 30 June 2026. That creates its own need to keep evidence. MAXIMUM. The General Data Protection Regulation says do not keep personal data longer than you need it. It also gives people the right to have data erased. CONFLICT. The Regulation settles this itself. The right to erasure does not apply where you need the data to meet a legal duty under national law. So the Hungarian keeping periods beat the deletion request for the documents they cover. Only those documents. Not the marketing database that happens to sit next to them.
Sources
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act C of 2000 on accounting, section 169 — retention of the annual report, ledgers and vouchers
njt.jog.gov.hu
Link checked 18 August 2026
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act XLVII of 1997 on the processing and protection of health and related personal data (Euak.) — retention of health documentation
njt.jog.gov.hu
Link checked 18 August 2026
- Official sourceSzabalyozott Tevekenysegek Felugyeleti Hatosaga (SZTFH)Cybersecurity supervision — audit contract deadline 31 August 2025, first audit by 30 June 2026
sztfh.hu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (GDPR), Articles 5(1)(e) and 17(3)(b)
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
Count at least two deadlines, and three if you are a bank. A personal data breach goes to the privacy regulator within 72 hours. A cyber incident goes to the national incident response centre. That applies to any company or public body covered by the cybersecurity law. The European rules Hungary is copying use a 24-hour first alert, then a fuller report at 72 hours. Financial firms have a separate and faster set of deadlines under the European operational resilience rules.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
CLOCK 1. Under the General Data Protection Regulation, tell NAIH without undue delay and, where you can, within 72 hours of finding out. You must also tell the people affected where the risk to them is high. CLOCK 2. Act LXIX of 2024 on the cybersecurity of Hungary. Covered organisations and central system operators must report cyber threats and incidents to the relevant cybersecurity incident handling centre. That is the National Cyber Security Institute. We could not get the deadlines in hours from the official consolidated text on 18 August 2026, because the database cuts off the law. Hungary copied Directive (EU) 2022/2555 into national law. That directive requires an early warning within 24 hours, a fuller notice within 72 hours and a final report within one month. Plan to those figures, and check them before you rely on them. CLOCK 3. Regulation (EU) 2022/2554, the Digital Operational Resilience Act, has applied to financial firms since 17 January 2025. It runs its own timetable for major technology incidents. The common mistake is treating a ransomware attack as one report. In Hungary it is three at once. It is a personal data breach for NAIH. It is a cyber incident for the incident response centre. And for a bank it is a technology incident for the supervisor.
Sources
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act LXIX of 2024 on the cybersecurity of Hungary, sections 6(5), 18 and 19 — duty to report to the competent incident handling centre
njt.jog.gov.hu
“gyors es hatekony reagalasrol, az illetekes kiberbiztonsagi incidenskezelo kozpontnak valo bejelentesrol”
Link checked 18 August 2026
- Official sourceNemzeti Kibervedelmi Intezet (NKI)National Cyber Security Institute — legal basis and incident reporting service
nki.gov.hu
Link checked 18 August 2026
- Official sourceEuropean Union Agency for Cybersecurity (ENISA)Act LXIX of 2024 on the cybersecurity of Hungary — text hosted by the EU cybersecurity agency, in force from 3 January 2025
enisa.europa.eu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (GDPR), Articles 33 and 34 — 72-hour breach notification
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
Not fully verified — see “What we're not sure about” below.What catches people out
Five things. One: mishandling personal data is a crime in Hungary, not just a fine. You face up to one year in prison, two years for sensitive data, three years for public officials. Two: the old rule forcing state data to stay in Hungary is dead. Quoting it makes you look out of date. The new cybersecurity classification step is very much alive, and most checklists miss it. Three: several cybersecurity deadlines have already passed. Newly covered companies are late on day one. Four: an online casino's game server must sit in the European Economic Area. Five: Hungary's freedom-of-information rules can make your contract with a state body public.
- What you have to do here:
- Register or notify · Hold a security certificate · Keep the data in the country
- What it costs if you get it wrong:
- Criminal liability
(1) CRIMINAL LIABILITY. Act C of 2012, the Criminal Code, punishes three things. Using personal data without authority. Using it for a purpose other than the stated one. And skipping data security measures. This applies where it was done for gain or caused significant harm. The penalty is up to one year in prison. It is up to two years where special-category data is involved. It is up to three years, as a felony, where a person acting in an official capacity did it. This exposes named individuals personally, which changes how Hungarian managers behave in an incident. (2) THE DEAD RULE ABOUT DATA STAYING IN HUNGARY. Act CLVII of 2010, and then Act XCI of 2021, required national-data-asset registers to be handled only on Hungarian territory. Both are repealed. The second stopped applying on 1 April 2024. Advisers still citing it are wrong. So are advisers who rely on that repeal without reading Act LXIX of 2024. (3) DEADLINES THAT HAVE ALREADY PASSED. Under the cybersecurity law you must register with the authority within 30 days of being covered. You must survey your systems within 90 days. You must finish classification within 120 days. You must file a security policy within 180 days. Organisations already running before 1 January 2025 had to hire an auditor by 31 August 2025 and finish a first audit by 30 June 2026. (4) GAMBLING. Beyond the European Economic Area server rule, access must be limited to players connecting from Hungarian internet addresses. The authority must have continuous remote access to the server. (5) TRANSPARENCY. The Info Act's public-data rules reach bodies performing public duties and state-owned companies. On 14 August 2026 the regulator announced that the Central Information Public Data Registry is being widened. (6) SOVEREIGNTY LAW. Act LXXXVIII of 2023 created a Sovereignty Protection Office with broad powers to demand information. On 12 February 2026 Advocate General Kokott advised the Court of Justice that the law breaks European Union law, including privacy rules. The judgment is not out, and the powers remain in force.
Sources
- Official sourceMagyarorszag Birosagai (Courts of Hungary)Misuse of personal data — Criminal Code section 219, elements and sentences (judicial training material)
projektjeink.birosag.hu
“jogosulatlanul vagy a celtol elteroen szemelyes adatot kezel”
Link checked 18 August 2026
- Official sourceSzabalyozott Tevekenysegek Felugyeleti Hatosaga (SZTFH)Cybersecurity supervision — registration within 30 days, auditor contract by 31 August 2025, first audit by 30 June 2026
sztfh.hu
Link checked 18 August 2026
- Official sourceSzerencsejatek Felugyelet (Gambling Supervisory Authority)Online casino licensing conditions — EEA server, Hungarian IP access only, continuous authority access
szf.gov.hu
“Online kaszinojatek kizarolag magyarorszagi IP cimrol kapcsolodo jatekos szamara teheto hozzaferhetove”
Link checked 18 August 2026
- Official sourceCourt of Justice of the European UnionPress release, 12 February 2026 — Advocate General Kokott's Opinion in Case C-829/24 Commission v Hungary
curia.europa.eu
Link checked 18 August 2026
What's changing next
Three dated items. The Court of Justice will rule on Hungary's sovereignty protection law. The court's adviser said on 12 February 2026 that it breaks European law. The judgment could land any time. From 12 January 2027 cloud providers across Europe, Hungary included, must charge nothing to move your data out. And Hungary's cybersecurity supervision moves from paperwork to inspections, now that the first audit deadline of 30 June 2026 has passed.
WITH DATES. (a) Case C-829/24, Commission v Hungary, on Act LXXXVIII of 2023 on the protection of national sovereignty. Advocate General Kokott's Opinion of 12 February 2026 found the Sovereignty Protection Office's investigation and disclosure powers incompatible with European Union law, including privacy rules. Judgment was still pending as at 18 August 2026. (b) 12 January 2027: the Data Act's rule that moving your data out of a cloud must cost nothing, from the shared European layer. (c) Cybersecurity audits were due by 30 June 2026, so supervision and fees come next. (d) Act CI of 2023 on using the national data asset starts in stages, with more parts applying from 1 January 2026. We could not pin down the exact staging, so it is listed as unconfirmed. POWERS ALREADY HELD, which matter more. (1) Hungary has twice passed a Hungary-only handling rule for state registers, and twice repealed it. One ordinary law could bring it back, and the drafting already exists. (2) Under the cybersecurity law, the classification rules are the lever. Tightening them would tighten foreign handling across energy, transport, banking, health, water, digital infrastructure and public administration. The privacy law would not need to change at all. (3) The gambling authority's licence conditions are set by ministerial and authority decree, not by an Act of Parliament. So the European Economic Area server rule could be narrowed to Hungary alone by decree. (4) The Sovereignty Protection Office can keep using its information-gathering powers unless and until the Court of Justice rules otherwise.
Sources
- Official sourceCourt of Justice of the European UnionPress release, 12 February 2026 — Advocate General's Opinion, Case C-829/24 Commission v Hungary; judgment pending
curia.europa.eu
Link checked 18 August 2026
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act CI of 2023 on utilising the national data asset — staged commencement
njt.jog.gov.hu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2023/2854 (Data Act) — switching charges to fall to zero on 12 January 2027
eur-lex.europa.eu
What to do: Diarise 12 January 2027 — that is the date this changes.
Not fully verified — see “What we're not sure about” below.The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Online gaming data must stay in the country
Official name: 1991. evi XXXIV. torveny a szerencsejatek szervezeserol es a vegrehajtasi rendeletei (online kaszinojatek engedelyezesi feltetelei) · Act XXXIV of 1991 and implementing decrees, incl. SZTFH Decree 20/2021 (X. 29.) · Licence condition
The one real location rule in Hungary. An online casino serving Hungarian players must keep its game server inside the European Economic Area. It must give the gambling authority continuous remote access to that server. Players may only connect from Hungarian internet addresses.
Enforced by Gambling Supervisory Authority
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryThe online casino server must be located in a state of the European Economic Area. Outside the EEA is not permitted.
- Independent auditThe gambling authority must have continuous remote access to the server.
- Secure the dataAccess is restricted to players connecting from Hungarian IP addresses, and the operator must verify this continuously.
What it costs if you get it wrong
- Loss of your licenceBreach of licensing conditions for online casino games
Sources
- Official sourceSzerencsejatek Felugyelet (Gambling Supervisory Authority)Online casino games — licensing conditions
szf.gov.hu
“Az online kaszino szerveret EGT-allamban kell elhelyezni”
Link checked 18 August 2026
- Official sourceNemzeti Jogszabalytar (National Legislation Database)SZTFH Decree 20/2021 (X. 29.) on the authorisation, conduct and supervision of certain games of chance
njt.jog.gov.hu
Government data rules
Official name: 2021. evi XCI. torveny a nemzeti adatvagyonrol, 13. § · Act XCI of 2021, section 13; repealed by Act CI of 2023 section 104(b) · Act of parliament
Included because it is the most common error in write-ups about Hungary. Hungary really did require state registers to be handled only on Hungarian soil, first from 2010 and again from 2021. That duty ended on 1 April 2024, and the replacement law contains nothing like it. Any current advice that cites it is out of date. The government has passed this twice, so it could do so again.
Enforced by National Authority for Data Protection and Freedom of Information
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryNO LONGER BINDING. It required work on designated state registers to be carried out only on the territory of Hungary. The supplier also had to be a state body or a Hungarian-registered 'transparent organisation'. It stopped applying on 1 April 2024.
Sources
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act XCI of 2021 on the national data asset, section 13, with the repeal footnote citing Act CI of 2023 section 104(b), effective 1 April 2024
njt.jog.gov.hu
“A torvenyt a 2023. evi CI. torveny 104. § b) pontja hatalyon kivul helyezte 2024. aprilis 1. napjaval”
Link checked 18 August 2026
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act CLVII of 2010 on the enhanced protection of state registers in the national data asset — the earlier Hungary-only rule, repealed 26 July 2021
njt.hu
Link checked 18 August 2026
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act CI of 2023 on the system for utilising the national data asset — the replacement, containing no territorial restriction
njt.jog.gov.hu
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: A Magyar Nemzeti Bank 2/2025. (I.13.) szamu ajanlasa a kozossegi es nyilvanos felhoszolgaltatasok igenybevetelerol · MNB Recommendation 2/2025 (I.13.), replacing Recommendation 4/2019 · Regulator guideline
Hungarian financial rules do not require data to stay in the country. The central bank's cloud recommendation demands extra, documented care instead. That applies when a bank, insurer or investment firm puts data in a cloud outside the European Economic Area. It is what the supervisor expects, not a ban. The European operational resilience rules sit on top of it.
Enforced by Magyar Nemzeti Bank
How this country controls where data goes: Approval each time · Accepted routes: Security review needed
What you have to do
- Written vendor contractCloud contracts must give the institution and the supervisor audit and access rights, and an exit plan, aligned with the EU operational resilience regulation.
- Assess high-risk projectsFor cloud outside the European Economic Area the firm must take particular care. It must record that it considered the rules of the destination country.
What it costs if you get it wrong
- Order to stopSupervisory measures for institutions that cannot demonstrate control over an outsourced cloud arrangement
Sources
- Official sourceMagyar Nemzeti BankMNB Recommendation 2/2025 (I.13.) on community and public cloud services
mnb.hu
“dokumentaltan igazolja, hogy a felhoszolgaltatas igenybevetele soran figyelembe vette a harmadik orszagban torteno adatkezelesre vonatkozo eloirasokat”
Link checked 18 August 2026
- Official sourceMagyar Nemzeti BankMNB Recommendation 1/2025 (I.13.) on information technology systems, amended for the EU operational resilience regulation
mnb.hu
Health data rules
Official name: 1997. evi XLVII. torveny az egeszsegugyi es a hozzajuk kapcsolodo szemelyes adatok kezeleserol es vedelmerol (Euak.) · Act XLVII of 1997, with EMMI Decree 39/2016 (XII. 21.) on the EESZT · Act of parliament
We found no restriction on where Hungarian health data may be stored. That surprises people who expect a health data rule in a European country. What Hungary does instead is centralise. Every healthcare provider must connect to the state-run Electronic Health Service Space and upload defined records. Records are kept for decades.
Enforced by National Authority for Data Protection and Freedom of Information
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What you have to do
- Keep data for a minimum period — 30 yearsHealth records carry very long minimum keeping periods, measured in decades. We could not retrieve the exact text from the official database on 18 August 2026.
- Keep records of how you use dataHealthcare providers must connect to the national Electronic Health Service Space and upload defined data. Access must be logged.
Sources
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act XLVII of 1997 on the processing and protection of health and related personal data (Euak.)
njt.jog.gov.hu
Link checked 18 August 2026
- Official sourceElektronikus Egeszsegugyi Szolgaltatasi Ter (EESZT)EESZT information portal — governing legislation, operator and provider connection duties
e-egeszsegugy.gov.hu
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
State and security data rules
Official name: 2011. evi CXII. torveny az informacios onrendelkezesi jogrol es az informacioszabadsagrol (Infotv.) · Act CXII of 2011 · Act of parliament
Hungary's own data law. It no longer repeats the European rules for ordinary business use. It adds to them and carries the freedom-of-information rules. It also supplies the whole rulebook for work outside European privacy law, such as police work and national security. It has no rule about where data must be stored.
Enforced by National Authority for Data Protection and Freedom of Information
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Explicit consent, To save someone’s life, Important public interest
What you have to do
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Secure the data
- Put a transfer safeguard in placeThe Info Act sets the conditions for sending data outside Europe, for work that European privacy law does not cover.
- Appoint a data protection officerMandatory for bodies performing public duties.
What it costs if you get it wrong
- Fixed maximum fine: Administrative fine under the Info Act for processing outside GDPR scopeBreach of the Info Act's own rules; exact HUF range not retrievable from the official consolidated text on 18 August 2026
Sources
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act CXII of 2011 (Infotv.), consolidated text — sections 2, 10, 11
njt.jog.gov.hu
Link checked 18 August 2026
- Official sourceNemzeti Adatvedelmi es Informacioszabadsag Hatosag (NAIH)NAIH — statutory remit under the Info Act
naih.hu
Link checked 18 August 2026
Personal data must stay in the country
Official name: 2024. evi LXIX. torveny Magyarorszag kiberbiztonsagarol (Kiberbiztonsagi tv.) · Act LXIX of 2024 · Act of parliament
Hungary's version of the European network and information security directive. It is quietly the most important storage rule in the country. Covered companies and public bodies may only put data in a shared cloud, or handle it abroad, once they have classified that data. It is a step you must complete, not a ban. Most transfer checklists do not include it.
Enforced by Regulated Activities Supervisory Authority
How this country controls where data goes: Approval each time · Accepted routes: Security review needed
What you have to do
- Keep the data in the countryThis is not a rule that data must stay in Hungary. A covered organisation may use a shared cloud service or handle data abroad ONLY once it has completed a data classification. The classification is compulsory precisely when a shared cloud or handling abroad is involved.
- Register or notifyRegistration with the authority within 30 days of coming into scope.
- Keep records of how you use dataSurvey of electronic information systems within 90 days.
- Secure the dataInformation security policy filed within 180 days.
- Hold a security certificateAuditor contracted by 31 August 2025 and first cybersecurity audit completed by 30 June 2026 for organisations already operating before 1 January 2025.
- Report cyber incidentsReport to the national cybersecurity incident handling centre (NKI). We could not get the deadlines in hours from the official text. The European directive Hungary copied uses 24 hours, 72 hours and one month.
What it costs if you get it wrong
- Fixed maximum fineSupervisory fines under the cybersecurity regime; the maximum could not be retrieved from the official consolidated text on 18 August 2026
- Order to stopAppointment of an information security supervisor and supervisory orders under SZTFH Decree 3/2025
Sources
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act LXIX of 2024 on the cybersecurity of Hungary, sections 8(4) and 9
njt.jog.gov.hu
“Az 1. § (1) bekezdes b) es c) pontja szerinti szervezet az adatosztalyozast nem privat felhoszolgaltatas igenybevetele es kulfoldi adatkezeles megvalositasa eseten koteles elvegezni”
Link checked 18 August 2026
- Official sourceSzabalyozott Tevekenysegek Felugyeleti Hatosaga (SZTFH)Cybersecurity supervision — scope, registration and audit deadlines
sztfh.hu
Link checked 18 August 2026
- Official sourceEuropean Union Agency for Cybersecurity (ENISA)Act LXIX of 2024 — Hungarian text, effective 3 January 2025
enisa.europa.eu
Link checked 18 August 2026
General data protection law
Official name: 2012. evi C. torveny a Bunteto Torvenykonyvrol, 219. § (szemelyes adattal visszaeles) · Act C of 2012, section 219 · Act of parliament
In Hungary a data protection failure can be a crime as well as a regulatory matter. Three things can be punished by prison. Handling personal data without authority. Using it for the wrong purpose. Or skipping security measures. This applies where it was done for gain or caused significant harm. The maximum is higher for sensitive data and for officials.
Enforced by National Authority for Data Protection and Freedom of Information
What you have to do
- Secure the data
- Tell people what you doFailing to tell the person their data is being used, where required, is itself an offence if it causes significant harm.
What it costs if you get it wrong
- Criminal liability: 1 year of imprisonmentProcessing personal data without authorisation or for a purpose other than the stated one, or failing to take security measures, for gain or causing significant harm
- Criminal liability: 2 years of imprisonmentWhere special-category personal data is involved
- Criminal liability: 3 years of imprisonmentWhere committed by a person acting in an official capacity
Sources
- Official sourceMagyarorszag Birosagai (Courts of Hungary)Criminal Code section 219, misuse of personal data — elements and sentencing (judicial training material)
projektjeink.birosag.hu
“az adatok biztonsagat szolgalo intezkedest elmulasztja”
Link checked 18 August 2026
- Official sourceMagyarorszag Birosagai (Courts of Hungary)Act C of 2012 on the Criminal Code, full text
birosag.hu
Applies across the European Union2 rules
Written once for the whole bloc, and in force in every member country.
Europe's main privacy law
Official name: Az Europai Parlament es a Tanacs (EU) 2016/679 rendelete (altalanos adatvedelmi rendelet) · Regulation (EU) 2016/679 · Directly binding regulation
The European baseline that governs Hungary. It sets the conditions for data leaving Europe rather than where data is stored. Fines are the higher of a fixed cap or a share of worldwide group turnover. Hungarian fines are far below the cap.
Enforced by European Data Protection Board
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What you have to do
- Get consent
- Document a legitimate interest
- Tell people what you do
- Keep records of how you use data
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Assess high-risk projects
- Written vendor contract
- Appoint a representativeRequired where there is no establishment in the European Union.
- Put a transfer safeguard in placePlus a written record of why the destination country is safe, following the Schrems II judgment.
- Do not hand data to foreign authorities on demandAn order from a government outside Europe is not by itself a legal reason to hand data over (EDPB Guidelines 02/2024).
- Delete data after a period
- Get a parent's consent for children — applies at: 16 in Hungary — Hungary did not lower the age below the default
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group turnover or €20,000,000, whichever is higher — about $22 millionBasic principles, individual rights, unlawful international transfers, defying a regulator order
- Percentage of global turnover: 2% of worldwide group turnover or €10,000,000, whichever is higher — about $11 millionController and processor obligations
- Order to stopThe regulator can order processing to stop or suspend flows to a third country
- Claims by individualsIndividuals can claim compensation
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (GDPR), consolidated text
eur-lex.europa.eu
Link checked 18 August 2026
Cloud and outsourcing rules (2027)
Official name: Az Europai Parlament es a Tanacs (EU) 2023/2854 rendelete (adatrendelet) · Regulation (EU) 2023/2854 · Directly binding regulation
The European data rules that make it cheaper to leave a cloud provider. Most of it has applied since 12 September 2025. From 12 January 2027 a provider may charge nothing at all to move your data out. Non-personal data cannot be handed to a foreign government without a proper legal route.
That is a long gap: the duty is real law today, but no penalty can follow until 12 January 2027. A contract you sign can still hold you to it from day one — and government contracts often do.
Enforced by European Data Protection Board
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Make switching cloud provider possible — from 12 January 2027All charges for switching cloud provider, and for moving your data out, must fall to zero.
- Do not hand data to foreign authorities on demandThe Data Act limits when a government outside Europe can get non-personal data held in the European Union.
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2023/2854 (Data Act)
eur-lex.europa.eu
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The exact incident reporting deadlines in hours under Act LXIX of 2024 on cybersecurity
We could not confirm the reporting deadlines in hours. The official law database cuts off long laws, and the reporting chapter would not open on 18 August 2026. The figures we give (24 hours, 72 hours, one month) come from the European directive Hungary copied. They are not quoted from Hungarian law. Check them before you rely on them.
The maximum fine under the Hungarian cybersecurity regime, and the fine range NAIH may impose under the Info Act for processing outside GDPR scope
We could not confirm the maximum fines. The relevant parts of the Info Act and the cybersecurity act sit past the point where the official database cuts off the text. We have not substituted a figure from anywhere else.
The precise retention periods for health documentation in section 30 of the Health Data Act, and the eight-year accounting retention in section 169 of the Accounting Act
We could not confirm the exact keeping periods. Both laws are long and the official text was cut off before those parts. The general direction is well established: decades for health records, years for accounting. The exact figures were not read from a government source on 18 August 2026.
The current status of the telecommunications data retention obligation in the Electronic Communications Act (Act C of 2003, around section 159/A)
We could not confirm the current state of the telecoms data keeping duty. The relevant parts would not load from the official database. We also found no Hungarian Constitutional Court or Court of Justice ruling striking them down on a government or court website. This is a live question, given European court rulings on blanket data keeping. We deliberately state nothing either way.
The exact commencement staging of Act CI of 2023 on utilising the national data asset
We could not confirm the exact start dates. One copy of the official text reported it started on 30 December 2023, another reported 1 January 2026. That fits a staged start, but we could not build a part-by-part table.
Whether any localisation condition applies to remote gambling other than online casino games, and whether player account data as opposed to the game server may sit outside the European Economic Area
The authority's page states the server rule for online casino games. We could not confirm the conditions for other remote gambling products, or how player records are treated, from the decree text. If you run remote gambling, check before you rely on this.
Whether the Hungarian government has issued any decree since 1 April 2024 reintroducing a Hungary-only processing rule for particular state registers
We can show that the rule in the main law was repealed. We cannot prove that no narrower decree brings it back for particular registers. Hungarian government decrees are numerous. Check if you handle state registers.
Whether the age of consent for information society services in Hungary is 16
Hungary appears to have kept the default age in Regulation (EU) 2016/679 rather than setting a lower one. We could not confirm that from a Hungarian law or a regulator statement on 18 August 2026. Check before you build an age gate.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.