Skip to the content
Global Data RulesData governance rules, country by country

Hungary

Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Hungary — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: HighEnforcement: Active

Hungary has no general rule that data must stay in the country. It follows the European rulebook. You may send data abroad if you have the right legal paperwork in place. Hungary used to make state registers run on Hungarian soil. That rule was scrapped in April 2024. The privacy regulator is real, staffed and issuing decisions. Its fines are small by European standards.

Data governance in Hungary

The eight things that decide how you handle data about people in Hungary. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. A company with no office in Hungary is still caught. That happens if it offers goods or services to people in Hungary, or watches what they do. European privacy rules reach outside Europe. There is no revenue or staff-count limit to hide under. If you have no office anywhere in Europe, you must appoint a written representative inside Europe. Hungary is a perfectly ordinary place to put one.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Yes, on the normal European terms. Nothing in general Hungarian law says data must be stored in Hungary. This is a change worth noticing. The rule that state registers could only run on Hungarian soil was repealed with effect from 1 April 2024. The law that replaced it has no location restriction at all. Two industries override this. An online casino must keep its game server inside the European Economic Area. And any company or public body covered by Hungary's cybersecurity law must finish a formal data classification first. That comes before it uses a shared cloud service or handles data abroad.

What to do: Get the paperwork for one of the routes below signed before any data leaves Hungary.

Not fully verified — see “What we're not sure about” below.

Sending data out of the country

You need a European transfer tool before the data leaves. Hungary adds no extra permit, filing or fee on top. You may send data to a country the European Commission has declared safe. Or you sign the standard European contract clauses and write down why the destination is safe. There is no Hungarian government sign-off, and no Hungarian list of banned countries. For police, security and other work outside European privacy rules, Hungary's own Info Act sets the conditions instead.

What you have to do here:
Put a transfer safeguard in place
Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The National Authority for Data Protection and Freedom of Information, known by its Hungarian initials NAIH. It is working. It has published decisions right through to May 2026. It released its report on 2025 activity on 30 March 2026. It issued public statements in July and August 2026. Its president is Dr Attila Peterfalvi. The catch is size, not activity. A typical fine is small. One April 2025 data security case brought a fine of two million forint, roughly six thousand US dollars.

How long you must keep it — and when to delete it

Hungary pushes hard in both directions. The minimums are long. Accounting records and receipts must be kept for eight years. Health records run for decades, because the health data law works in periods of thirty years and more. The maximum is the European rule that you delete personal data once you no longer need it. When the two collide, the specific keeping period set by law wins. So a deletion request does not empty your ledgers or a hospital's files.

What you have to do here:
Keep data for a minimum period · Delete data after a period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

Count at least two deadlines, and three if you are a bank. A personal data breach goes to the privacy regulator within 72 hours. A cyber incident goes to the national incident response centre. That applies to any company or public body covered by the cybersecurity law. The European rules Hungary is copying use a 24-hour first alert, then a fuller report at 72 hours. Financial firms have a separate and faster set of deadlines under the European operational resilience rules.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

Not fully verified — see “What we're not sure about” below.

What catches people out

Five things. One: mishandling personal data is a crime in Hungary, not just a fine. You face up to one year in prison, two years for sensitive data, three years for public officials. Two: the old rule forcing state data to stay in Hungary is dead. Quoting it makes you look out of date. The new cybersecurity classification step is very much alive, and most checklists miss it. Three: several cybersecurity deadlines have already passed. Newly covered companies are late on day one. Four: an online casino's game server must sit in the European Economic Area. Five: Hungary's freedom-of-information rules can make your contract with a state body public.

What you have to do here:
Register or notify · Hold a security certificate · Keep the data in the country
What it costs if you get it wrong:
Criminal liability

What's changing next

Three dated items. The Court of Justice will rule on Hungary's sovereignty protection law. The court's adviser said on 12 February 2026 that it breaks European law. The judgment could land any time. From 12 January 2027 cloud providers across Europe, Hungary included, must charge nothing to move your data out. And Hungary's cybersecurity supervision moves from paperwork to inspections, now that the first audit deadline of 30 June 2026 has passed.

What to do: Diarise 12 January 2027 — that is the date this changes.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Online gaming

Online gaming data must stay in the country

Official name: 1991. evi XXXIV. torveny a szerencsejatek szervezeserol es a vegrehajtasi rendeletei (online kaszinojatek engedelyezesi feltetelei) · Act XXXIV of 1991 and implementing decrees, incl. SZTFH Decree 20/2021 (X. 29.) · Licence condition

In forceNo — it stays put

The one real location rule in Hungary. An online casino serving Hungarian players must keep its game server inside the European Economic Area. It must give the gambling authority continuous remote access to that server. Players may only connect from Hungarian internet addresses.

In force since 1 January 2023

Enforced by Gambling Supervisory Authority

How this country controls where data goes: Not allowed

Not fully verified — see “What we're not sure about” below.
Government

Government data rules

Official name: 2021. evi XCI. torveny a nemzeti adatvagyonrol, 13. § · Act XCI of 2021, section 13; repealed by Act CI of 2023 section 104(b) · Act of parliament

RepealedNo — it stays put

Included because it is the most common error in write-ups about Hungary. Hungary really did require state registers to be handled only on Hungarian soil, first from 2010 and again from 2021. That duty ended on 1 April 2024, and the replacement law contains nothing like it. Any current advice that cites it is out of date. The government has passed this twice, so it could do so again.

In force since 26 July 2021

Enforced by National Authority for Data Protection and Freedom of Information

How this country controls where data goes: Not allowed

Finance

Cloud and outsourcing rules

Official name: A Magyar Nemzeti Bank 2/2025. (I.13.) szamu ajanlasa a kozossegi es nyilvanos felhoszolgaltatasok igenybevetelerol · MNB Recommendation 2/2025 (I.13.), replacing Recommendation 4/2019 · Regulator guideline

In forceYes, with paperwork

Hungarian financial rules do not require data to stay in the country. The central bank's cloud recommendation demands extra, documented care instead. That applies when a bank, insurer or investment firm puts data in a cloud outside the European Economic Area. It is what the supervisor expects, not a ban. The European operational resilience rules sit on top of it.

In force since 17 January 2025

Enforced by Magyar Nemzeti Bank

How this country controls where data goes: Approval each time · Accepted routes: Security review needed

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

State and security data rules

Official name: 2011. evi CXII. torveny az informacios onrendelkezesi jogrol es az informacioszabadsagrol (Infotv.) · Act CXII of 2011 · Act of parliament

In forceYes — store it anywhere

Hungary's own data law. It no longer repeats the European rules for ordinary business use. It adds to them and carries the freedom-of-information rules. It also supplies the whole rulebook for work outside European privacy law, such as police work and national security. It has no rule about where data must be stored.

In force since 1 January 2012Enforced from 25 May 2018

Enforced by National Authority for Data Protection and Freedom of Information

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Explicit consent, To save someone’s life, Important public interest

Personal data must stay in the country

Official name: 2024. evi LXIX. torveny Magyarorszag kiberbiztonsagarol (Kiberbiztonsagi tv.) · Act LXIX of 2024 · Act of parliament

In forceYes, with paperwork

Hungary's version of the European network and information security directive. It is quietly the most important storage rule in the country. Covered companies and public bodies may only put data in a shared cloud, or handle it abroad, once they have classified that data. It is a step you must complete, not a ban. Most transfer checklists do not include it.

In force since 3 January 2025

Enforced by Regulated Activities Supervisory Authority

How this country controls where data goes: Approval each time · Accepted routes: Security review needed

General data protection law

Official name: 2012. evi C. torveny a Bunteto Torvenykonyvrol, 219. § (szemelyes adattal visszaeles) · Act C of 2012, section 219 · Act of parliament

In forceYes — store it anywhere

In Hungary a data protection failure can be a crime as well as a regulatory matter. Three things can be punished by prison. Handling personal data without authority. Using it for the wrong purpose. Or skipping security measures. This applies where it was done for gain or caused significant harm. The maximum is higher for sensitive data and for officials.

In force since 1 July 2013

Enforced by National Authority for Data Protection and Freedom of Information

Applies across the European Union2 rules

Written once for the whole bloc, and in force in every member country.

Europe's main privacy law

Official name: Az Europai Parlament es a Tanacs (EU) 2016/679 rendelete (altalanos adatvedelmi rendelet) · Regulation (EU) 2016/679 · Directly binding regulation

In forceYes, with paperwork

The European baseline that governs Hungary. It sets the conditions for data leaving Europe rather than where data is stored. Fines are the higher of a fixed cap or a share of worldwide group turnover. Hungarian fines are far below the cap.

In force since 25 May 2018

Enforced by European Data Protection Board

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

Cloud and outsourcing rules (2027)

Official name: Az Europai Parlament es a Tanacs (EU) 2023/2854 rendelete (adatrendelet) · Regulation (EU) 2023/2854 · Directly binding regulation

Partly in forceYes — store it anywhere

The European data rules that make it cheaper to leave a cloud provider. Most of it has applied since 12 September 2025. From 12 January 2027 a provider may charge nothing at all to move your data out. Non-personal data cannot be handed to a foreign government without a proper legal route.

In force since 12 September 2025In force now, but not enforced until 12 January 2027

That is a long gap: the duty is real law today, but no penalty can follow until 12 January 2027. A contract you sign can still hold you to it from day one — and government contracts often do.

Enforced by European Data Protection Board

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Who you would hear from

  • Nemzeti Adatvedelmi es Informacioszabadsag Hatosag (NAIH)

    Data protection and freedom of information, all sectors

    Fully operational. President Dr Attila Peterfalvi. Decisions published to 29 May 2026. The 2025 annual report was published on 30 March 2026. Public statements followed in July and August 2026. Fines are frequent but modest: 2,000,000 HUF (about 6,000 US dollars) in decision NAIH-7395-6/2025.

  • Szabalyozott Tevekenysegek Felugyeleti Hatosaga (SZTFH)

    National cybersecurity authority under Act LXIX of 2024; cybersecurity certification, audits and supervision

    Operating. Maintains public registers of cybersecurity auditors and assessors, has issued its own decrees (1/2025, 2/2025, 3/2025) and set compliance deadlines running to 30 June 2026.

  • Nemzeti Kibervedelmi Intezet (NKI)

    Cybersecurity incident handling centre; receives incident reports

    Operating an incident reporting service and publishing the governing legislation.

  • Magyar Nemzeti Bank (MNB)

    Central bank and integrated supervisor for banking, payments, insurance and securities

    Issued new information technology and cloud recommendations (1/2025 and 2/2025) effective 17 January 2025 to align with the EU operational resilience regulation.

  • Szerencsejatek Felugyelet

    Licensing and supervision of games of chance, including online casino games

    Publishes licensing conditions and forms; took over the gambling functions previously exercised by SZTFH.

  • Nemzeti Media- es Hirkozlesi Hatosag (NMHH)

    Electronic communications and media supervision

    Publishes annual supervision plans for electronic communications and postal services.

  • Consistency and guidance across the European Union; bloc layer

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The exact incident reporting deadlines in hours under Act LXIX of 2024 on cybersecurity

    We could not confirm the reporting deadlines in hours. The official law database cuts off long laws, and the reporting chapter would not open on 18 August 2026. The figures we give (24 hours, 72 hours, one month) come from the European directive Hungary copied. They are not quoted from Hungarian law. Check them before you rely on them.

  • The maximum fine under the Hungarian cybersecurity regime, and the fine range NAIH may impose under the Info Act for processing outside GDPR scope

    We could not confirm the maximum fines. The relevant parts of the Info Act and the cybersecurity act sit past the point where the official database cuts off the text. We have not substituted a figure from anywhere else.

  • The precise retention periods for health documentation in section 30 of the Health Data Act, and the eight-year accounting retention in section 169 of the Accounting Act

    We could not confirm the exact keeping periods. Both laws are long and the official text was cut off before those parts. The general direction is well established: decades for health records, years for accounting. The exact figures were not read from a government source on 18 August 2026.

  • The current status of the telecommunications data retention obligation in the Electronic Communications Act (Act C of 2003, around section 159/A)

    We could not confirm the current state of the telecoms data keeping duty. The relevant parts would not load from the official database. We also found no Hungarian Constitutional Court or Court of Justice ruling striking them down on a government or court website. This is a live question, given European court rulings on blanket data keeping. We deliberately state nothing either way.

  • The exact commencement staging of Act CI of 2023 on utilising the national data asset

    We could not confirm the exact start dates. One copy of the official text reported it started on 30 December 2023, another reported 1 January 2026. That fits a staged start, but we could not build a part-by-part table.

  • Whether any localisation condition applies to remote gambling other than online casino games, and whether player account data as opposed to the game server may sit outside the European Economic Area

    The authority's page states the server rule for online casino games. We could not confirm the conditions for other remote gambling products, or how player records are treated, from the decree text. If you run remote gambling, check before you rely on this.

  • Whether the Hungarian government has issued any decree since 1 April 2024 reintroducing a Hungary-only processing rule for particular state registers

    We can show that the rule in the main law was repealed. We cannot prove that no narrower decree brings it back for particular registers. Hungarian government decrees are numerous. Check if you handle state registers.

  • Whether the age of consent for information society services in Hungary is 16

    Hungary appears to have kept the default age in Regulation (EU) 2016/679 rather than setting a lower one. We could not confirm that from a Hungarian law or a regulator statement on 18 August 2026. Check before you build an age gate.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.