Skip to the content
Global Data RulesData governance rules, country by country

Hungary

Part of the European Union, so bloc-wide rules apply here too. Checked today.

The answer

Yes, with paperworkWork: HighEnforcement: Active

Hungary has no general rule that data must stay in the country. It runs on the European rulebook: you may send data abroad if you have the right legal paperwork in place. Hungary used to force state registers to be processed on Hungarian soil, but that rule was scrapped in April 2024. The privacy regulator is real, staffed and issuing decisions, though its fines are small by European standards.

Eight questions about Hungary

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Hungary's rules apply to my company?

Yes. A company with no office in Hungary is still caught if it offers goods or services to people in Hungary or watches their behaviour, because the European privacy rules reach outside Europe. There is no revenue or headcount threshold to hide under. If you have no establishment anywhere in Europe you must appoint a written representative inside Europe, and Hungary is a perfectly ordinary place to put one.

High confidenceBloc rulesNational rulesAppoint a local representative

Can I store my users' data outside Hungary?

Yes, on the normal European terms — nothing in general Hungarian law says data must be stored in Hungary. This is a change worth noticing: the rule that state registers could only be processed on Hungarian soil was repealed with effect from 1 April 2024, and the law that replaced it has no territorial restriction at all. Two sectors override this. An online casino must keep its game server inside the European Economic Area. And any company or public body inside the scope of Hungary's cybersecurity law must finish a formal data classification before it uses a shared cloud service or processes data abroad.

Medium confidenceYes, with paperworkAllowlistRepealed

What do I need in place before data leaves Hungary?

You need a European transfer tool before the data leaves, and Hungary adds no extra permit, filing or fee on top. The model is an approved-list one: you may send data to a country the European Commission has declared safe, or you sign the standard European contract clauses and write down a risk assessment of the destination. There is no Hungarian government sign-off, and no Hungarian list of banned countries. For police, security and other work outside the European privacy rules, Hungary's own Info Act sets the conditions instead.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesExplicit consentPut a transfer safeguard in place

Who enforces the rules in Hungary, and what can they do?

The National Authority for Data Protection and Freedom of Information, known by its Hungarian initials NAIH, and it is genuinely working. It has published decisions right through to May 2026, released its report on 2025 activity on 30 March 2026, and issued public statements in July and August 2026. Its president is Dr Attila Peterfalvi. The catch is size, not activity: a typical fine is small — two million forint, roughly six thousand dollars, in an April 2025 data-security case.

High confidenceActiveRegulator

How long do I have to keep the data?

Hungary pushes hard in both directions. The floor is long: accounting records and vouchers must be kept for eight years, and health records for decades — the health data law works in periods of thirty years and more. The ceiling is the European rule that you delete personal data once the purpose is spent. When the two collide, the specific statutory keep-period wins, so a deletion request does not empty your ledgers or a hospital's files.

Medium confidenceKeep data for a minimum periodDelete data after a period

What happens if there is a breach?

Count at least two clocks, and three if you are a bank. A personal data breach goes to the privacy regulator within 72 hours. A cyber incident at a company or public body covered by the cybersecurity law goes to the national incident response centre, and the European rules that Hungary is copying use a 24-hour first alert followed by a fuller report at 72 hours. Financial firms have a separate and faster set of deadlines under the European operational resilience rules.

Medium confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Hungary?

Five things that are not in the summary. One: mishandling personal data is a crime in Hungary, not just a fine — up to one year in prison, two years for sensitive data, three years for public officials. Two: the old rule forcing state data to stay in Hungary is dead, so quoting it makes you look out of date, while the new cybersecurity classification gate is very much alive and most checklists miss it. Three: several cybersecurity deadlines have already passed, so newly in-scope companies are late on day one. Four: an online casino's game server must sit in the European Economic Area. Five: Hungary's freedom-of-information regime can make your contract with a state body public.

High confidenceCriminal liabilityRegister or notifyHold a security certificateKeep the data in the country

What is changing soon in Hungary?

Three dated items. The Court of Justice will rule on Hungary's sovereignty protection law; the court's adviser said on 12 February 2026 that it breaks European law, and the judgment could land any time. From 12 January 2027 cloud providers across Europe, Hungary included, must charge nothing to move your data out. And Hungary's cybersecurity supervision moves from paperwork to inspections now that the first audit deadline of 30 June 2026 has passed.

Medium confidenceIn forceProposed

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    Bloc rules

    Made by a group of countries together. Applies inside every member country.

    2 rules here

  2. Layer 2

    National rules

    Added by this country on top of any bloc rules.

    3 rules here

  3. Layer 3

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    4 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

Bloc rules2 rules

Az Europai Parlament es a Tanacs (EU) 2016/679 rendelete (altalanos adatvedelmi rendelet)

Directly binding regulation · Regulation (EU) 2016/679

In forceYes, with paperwork

The European baseline that governs Hungary. It regulates the conditions for data leaving Europe rather than where data is stored. Fines are the higher of a fixed cap or a share of worldwide group turnover, though Hungarian fines in practice are far below the cap.

In force since 25 May 2018

Enforced by European Data Protection Board

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

High confidence

Az Europai Parlament es a Tanacs (EU) 2023/2854 rendelete (adatrendelet)

Directly binding regulation · Regulation (EU) 2023/2854

Partly in forceYes — store it anywhere

The European data rules that make it cheaper to leave a cloud provider. Most of it has applied since 12 September 2025, and from 12 January 2027 a provider may charge nothing at all to move your data out. Non-personal data cannot be handed to a foreign government without a proper legal route.

In force since 12 September 2025But only enforceable from 12 January 2027

Enforced by European Data Protection Board

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

National rules3 rules

2011. evi CXII. torveny az informacios onrendelkezesi jogrol es az informacioszabadsagrol (Infotv.)

Act of parliament · Act CXII of 2011

In forceYes — store it anywhere

Hungary's own data law. It no longer duplicates the European rules for ordinary commercial processing; it supplements them, carries the freedom-of-information regime, and supplies the whole rulebook for processing that sits outside European privacy law, such as law enforcement and national security. It imposes no storage-location requirement.

In force since 1 January 2012But only enforceable from 25 May 2018

Enforced by National Authority for Data Protection and Freedom of Information

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Explicit consent, Someone's life is at risk, Important public interest

High confidence

2024. evi LXIX. torveny Magyarorszag kiberbiztonsagarol (Kiberbiztonsagi tv.)

Act of parliament · Act LXIX of 2024

In forceYes, with paperwork

Hungary's implementation of the European network and information security directive, and quietly the most important storage rule in the country. Companies and public bodies in scope may only put data in a shared cloud, or process it abroad, once they have classified that data. It is a gate rather than a wall, but it is a gate that most transfer checklists do not have on them.

In force since 3 January 2025

Enforced by Regulated Activities Supervisory Authority

Transfer model: Approval each time · Accepted routes: Security review needed

High confidence

2012. evi C. torveny a Bunteto Torvenykonyvrol, 219. § (szemelyes adattal visszaeles)

Act of parliament · Act C of 2012, section 219

In forceYes — store it anywhere

In Hungary a data protection failure can be a crime as well as a regulatory matter. Handling personal data without authorisation, using it for the wrong purpose, or skipping security measures is punishable by imprisonment where it was done for gain or caused significant harm, with higher maximums for sensitive data and for officials.

In force since 1 July 2013

Enforced by National Authority for Data Protection and Freedom of Information

High confidence

Industry rules4 rules

1991. evi XXXIV. torveny a szerencsejatek szervezeserol es a vegrehajtasi rendeletei (online kaszinojatek engedelyezesi feltetelei)

Licence condition · Act XXXIV of 1991 and implementing decrees, incl. SZTFH Decree 20/2021 (X. 29.) · Online gaming

In forceNo — it stays put

The one genuine hard wall in Hungary. An online casino serving Hungarian players must keep its game server inside the European Economic Area and give the gambling authority continuous remote access to it. Players may only connect from Hungarian internet addresses.

In force since 1 January 2023

Enforced by Gambling Supervisory Authority

Transfer model: Not allowed

Medium confidence

2021. evi XCI. torveny a nemzeti adatvagyonrol, 13. §

Act of parliament · Act XCI of 2021, section 13; repealed by Act CI of 2023 section 104(b) · Government

RepealedNo — it stays put

Included because it is the single most common error in Hungary write-ups. Hungary really did require state registers to be processed only on Hungarian soil, first from 2010 and again from 2021, but that duty ended on 1 April 2024 and the replacement law contains nothing like it. Treat any current advice that cites it as out of date — while noting the government has legislated this twice and could do so again.

In force since 26 July 2021

Enforced by National Authority for Data Protection and Freedom of Information

Transfer model: Not allowed

High confidence

A Magyar Nemzeti Bank 2/2025. (I.13.) szamu ajanlasa a kozossegi es nyilvanos felhoszolgaltatasok igenybevetelerol

Regulator guideline · MNB Recommendation 2/2025 (I.13.), replacing Recommendation 4/2019 · Finance

In forceYes, with paperwork

Hungarian financial regulation contains no localisation requirement. The central bank's cloud recommendation instead demands heightened, documented diligence when a bank, insurer or investment firm puts data in a cloud outside the European Economic Area. It is supervisory expectation, not a prohibition, and the European operational resilience rules sit on top of it.

In force since 17 January 2025

Enforced by Magyar Nemzeti Bank

Transfer model: Approval each time · Accepted routes: Security review needed

High confidence

Who you would hear from

  • Nemzeti Adatvedelmi es Informacioszabadsag Hatosag (NAIH)

    Data protection and freedom of information, all sectors

    Fully operational. President Dr Attila Peterfalvi. Decisions published to 29 May 2026, 2025 annual report published 30 March 2026, public statements in July and August 2026. Fines are frequent but modest — 2,000,000 HUF (about $6,000) in decision NAIH-7395-6/2025.

  • Szabalyozott Tevekenysegek Felugyeleti Hatosaga (SZTFH)

    National cybersecurity authority under Act LXIX of 2024; cybersecurity certification, audits and supervision

    Operating. Maintains public registers of cybersecurity auditors and assessors, has issued its own decrees (1/2025, 2/2025, 3/2025) and set compliance deadlines running to 30 June 2026.

  • Nemzeti Kibervedelmi Intezet (NKI)

    Cybersecurity incident handling centre; receives incident reports

    Operating an incident reporting service and publishing the governing legislation.

  • Magyar Nemzeti Bank (MNB)

    Central bank and integrated supervisor for banking, payments, insurance and securities

    Issued new information technology and cloud recommendations (1/2025 and 2/2025) effective 17 January 2025 to align with the EU operational resilience regulation.

  • Szerencsejatek Felugyelet

    Licensing and supervision of games of chance, including online casino games

    Publishes licensing conditions and forms; took over the gambling functions previously exercised by SZTFH.

  • Nemzeti Media- es Hirkozlesi Hatosag (NMHH)

    Electronic communications and media supervision

    Publishes annual supervision plans for electronic communications and postal services.

  • Consistency and guidance across the European Union; bloc layer

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The exact incident reporting deadlines in hours under Act LXIX of 2024 on cybersecurity

    The official consolidated text on the national legislation database truncates long statutes on retrieval, and the reporting chapter could not be opened on 18 August 2026. The figures given (24 hours, 72 hours, one month) are those of the EU directive Hungary transposed, not a quoted Hungarian provision.

  • The maximum fine under the Hungarian cybersecurity regime, and the fine range NAIH may impose under the Info Act for processing outside GDPR scope

    Sections 61 and 75/A of the Info Act, and the penalty chapter of the cybersecurity act, sit beyond the point at which the official database truncated the text. No secondary figure has been substituted.

  • The precise retention periods for health documentation in section 30 of the Health Data Act, and the eight-year accounting retention in section 169 of the Accounting Act

    Both statutes are long and the official text was truncated before those sections. The direction of travel (decades for health, years for accounting) is well established, but the exact figures were not read off a government source on 18 August 2026.

  • The current status of the telecommunications data retention obligation in the Electronic Communications Act (Act C of 2003, around section 159/A)

    The relevant sections could not be retrieved from the official database, and no Hungarian Constitutional Court or Court of Justice ruling annulling or disapplying them was located on a government or court domain. This is a live question given the Court of Justice case law on general and indiscriminate retention, and it is deliberately not asserted here in either direction.

  • The exact commencement staging of Act CI of 2023 on utilising the national data asset

    One retrieval of the official text reported entry into force on 30 December 2023 and another reported 1 January 2026, which is consistent with staged commencement but was not resolved to a provision-by-provision table.

  • Whether any localisation condition applies to remote gambling other than online casino games, and whether player account data as opposed to the game server may sit outside the European Economic Area

    The authority's page states the server rule for online casino games. The equivalent conditions for other remote gambling products, and the treatment of player records, were not confirmed from the decree text.

  • Whether the Hungarian government has issued any decree since 1 April 2024 reintroducing a Hungary-only processing rule for particular state registers

    We can evidence that the primary-law rule was repealed. We cannot prove the absence of a narrower sectoral decree, and Hungarian government decrees are numerous.

  • Whether the age of consent for information society services in Hungary is 16

    Hungary appears to have left the default in Regulation (EU) 2016/679 untouched rather than legislating a lower age, but no Hungarian provision or regulator statement confirming this was opened on 18 August 2026.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.