Hungary
Part of the European Union, so bloc-wide rules apply here too. Checked today.
The answer
Hungary has no general rule that data must stay in the country. It runs on the European rulebook: you may send data abroad if you have the right legal paperwork in place. Hungary used to force state registers to be processed on Hungarian soil, but that rule was scrapped in April 2024. The privacy regulator is real, staffed and issuing decisions, though its fines are small by European standards.
Eight questions about Hungary
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Hungary's rules apply to my company?
Yes. A company with no office in Hungary is still caught if it offers goods or services to people in Hungary or watches their behaviour, because the European privacy rules reach outside Europe. There is no revenue or headcount threshold to hide under. If you have no establishment anywhere in Europe you must appoint a written representative inside Europe, and Hungary is a perfectly ordinary place to put one.
Layer 1 is Regulation (EU) 2016/679 (the General Data Protection Regulation, or GDPR), Articles 3 and 27. Layer 2 is Hungary's own Act CXII of 2011 on informational self-determination and freedom of information (the 'Info Act', Infotv.). Section 2 of the Info Act splits the field: for processing inside the scope of the GDPR it applies only a named list of supplementary provisions, and for processing outside GDPR scope — law enforcement, national security, defence — Chapters III to V of the Info Act apply on their own terms, including its own third-country transfer rules in sections 10 and 11. The Info Act also carries Hungary's freedom-of-information regime, which reaches bodies performing public duties, state-owned companies and, in practice, their contractors. On 14 August 2026 the regulator announced an expansion of the entities and data categories covered by the Central Information Public Data Registry, so this exposure is widening, not narrowing.
Sources
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act CXII of 2011 on informational self-determination and freedom of information (Infotv.), consolidated text, sections 2, 10 and 11
njt.jog.gov.hu
Link checked 18 August 2026
- Official sourceNemzeti Adatvedelmi es Informacioszabadsag Hatosag (NAIH)National Authority for Data Protection and Freedom of Information — remit and August 2026 announcements
naih.hu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (GDPR), Articles 3 and 27
eur-lex.europa.eu
Link checked 18 August 2026
Can I store my users' data outside Hungary?
Yes, on the normal European terms — nothing in general Hungarian law says data must be stored in Hungary. This is a change worth noticing: the rule that state registers could only be processed on Hungarian soil was repealed with effect from 1 April 2024, and the law that replaced it has no territorial restriction at all. Two sectors override this. An online casino must keep its game server inside the European Economic Area. And any company or public body inside the scope of Hungary's cybersecurity law must finish a formal data classification before it uses a shared cloud service or processes data abroad.
The repeal chain matters because many trackers still list Hungary as a localisation country. Act CLVII of 2010 required that processing of state registers in the 'national data asset' happen only on Hungarian territory; it was repealed on 26 July 2021. Its successor, Act XCI of 2021 on the national data asset, repeated the rule in section 13 — 'A 12. § (3) bekezdese szerint meghatarozott nyilvantartasokhoz kapcsolodo adatfeldolgozasi muveletet az adatfeldolgozo kizarolag Magyarorszag teruleten vegezhet' — and was itself repealed with effect from 1 April 2024 by Act CI of 2023. Act CI of 2023, on the system for utilising the national data asset, contains no equivalent territorial restriction; it builds an opening-up framework around a National Data Asset Agency, the National Data Platform and a public data portal, and expressly contemplates foreign data intermediaries. Sector by sector: BANKING, PAYMENTS, INSURANCE AND SECURITIES — no localisation. The central bank's Recommendation 2/2025 on community and public cloud services says institutions must act with 'kulonos gondossaggal' (particular diligence) for cloud outside the European Economic Area because of data-protection and geopolitical risk, and must document that they considered third-country processing rules; that is a diligence duty, not a wall. HEALTH — no territorial rule found in the Health Data Act or the EESZT rules as at 18 August 2026; the national health data space is state-operated and physically in Hungary, but that is an operating fact, not a prohibition on private controllers. TELECOM — no storage-location rule found; the electronic communications regime is about retention and lawful access, not residency. GOVERNMENT — no residency rule found in current law, but the cybersecurity classification gate below bites hardest here. GEOSPATIAL — Act XLVI of 2012 requires state basic mapping data and aerial and satellite imagery to be held in national archives, which is a custody rule for the state's own copies rather than an export ban. GAMING — a genuine wall, see the rule entry. DEFENCE — not researched in depth; defence mapping databases sit with the defence ministry.
Sources
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act XCI of 2021 on the national data asset, section 13 — repealed with effect from 1 April 2024 by Act CI of 2023
njt.jog.gov.hu
“A 12. § (3) bekezdese szerint meghatarozott nyilvantartasokhoz kapcsolodo adatfeldolgozasi muveletet az adatfeldolgozo kizarolag Magyarorszag teruleten vegezhet.”
Link checked 18 August 2026
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act CI of 2023 on the system for utilising the national data asset and on certain services — the replacement law, with no territorial restriction
njt.jog.gov.hu
Link checked 18 August 2026
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act LXIX of 2024 on the cybersecurity of Hungary, section 9(2) and 9(4) — classification required before non-private cloud or foreign processing
njt.jog.gov.hu
“Az 1. § (1) bekezdes a)-c) pontja szerinti szervezet kizarolag az adatosztalyozas alapjan ... vehet igenybe nem privat felhoszolgaltatast, vagy kezelhet kulfoldon adatot”
Link checked 18 August 2026
- Official sourceSzerencsejatek Felugyelet (Gambling Supervisory Authority)Online casino games — licensing conditions, including server location
szf.gov.hu
“Az online kaszino szerveret EGT-allamban kell elhelyezni”
Link checked 18 August 2026
- Official sourceMagyar Nemzeti Bank (central bank and financial supervisor)Recommendation 2/2025 (I.13.) on the use of community and public cloud services
mnb.hu
“Az Intezmeny az Europai Gazdasagi Tersegen kivuli felhoszolgaltatas eseten az adatvedelmi kockazatok, valamint a felugyeleti tevekenysegek gyakorlasat veszelyezteto geopolitikai kockazatok miatt kulonos gondossaggal jar el.”
Link checked 18 August 2026
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act XLVI of 2012 on surveying and mapping activity, section 4 — state basic data held in national archives
njt.jog.gov.hu
Link checked 18 August 2026
What do I need in place before data leaves Hungary?
You need a European transfer tool before the data leaves, and Hungary adds no extra permit, filing or fee on top. The model is an approved-list one: you may send data to a country the European Commission has declared safe, or you sign the standard European contract clauses and write down a risk assessment of the destination. There is no Hungarian government sign-off, and no Hungarian list of banned countries. For police, security and other work outside the European privacy rules, Hungary's own Info Act sets the conditions instead.
Layer 1 is Chapter V of the GDPR, and everything in the shared European brief applies unchanged: the 2021 Standard Contractual Clauses are the operative set, Binding Corporate Rules remain available, the Schrems II transfer impact assessment is still expected, and the EU-US Data Privacy Framework remains valid on 18 August 2026 while under active pressure. The adequacy list is the Commission's, not Hungary's. Layer 2 for non-GDPR processing is Info Act sections 10 and 11: a transfer to a third country needs the person's explicit consent, or necessity plus adequate safeguards, and section 10(4) treats protection as adequate where an EU legal act says so, where an international treaty guarantees the rights, or where the controller has examined the circumstances and concluded there are 'megfelelo garanciak' (adequate guarantees). Section 11 allows a narrow set of transfers without consent — vital interests, a threat to public security, or an individual case where no disproportionate restriction of rights results. There is no Hungarian registration or notification step for ordinary commercial transfers.
Sources
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Info Act, sections 10 and 11 — third-country transfer conditions for processing outside GDPR scope
njt.jog.gov.hu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (GDPR), Chapter V — transfers to third countries
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionCommission Implementing Decision (EU) 2021/914 — Standard Contractual Clauses
eur-lex.europa.eu
Who enforces the rules in Hungary, and what can they do?
The National Authority for Data Protection and Freedom of Information, known by its Hungarian initials NAIH, and it is genuinely working. It has published decisions right through to May 2026, released its report on 2025 activity on 30 March 2026, and issued public statements in July and August 2026. Its president is Dr Attila Peterfalvi. The catch is size, not activity: a typical fine is small — two million forint, roughly six thousand dollars, in an April 2025 data-security case.
NAIH is a single national authority; Hungary has no regional data protection regulators. Evidence of live operation, all from the authority's own site and checked on 18 August 2026: a decisions register running to 29 May 2026; the 2025 annual report published 30 March 2026; a 7 July 2026 statement on the political use of children's personal data on social media; a 14 August 2026 announcement expanding the Central Information Public Data Registry. Decision NAIH-7395-6/2025 of 8 April 2025 fined a processor 2,000,000 forint (about $6,000) for failing to check firewall settings while migrating a roughly 900,000-record customer database, after which an attacker reached personal data including bank account numbers. That is the shape of Hungarian enforcement: regular, technically competent, and modest in money. Other regulators that matter here and are all operating: the Regulated Activities Supervisory Authority (SZTFH) as national cybersecurity authority; the National Cyber Security Institute (NKI) as incident response centre; the Magyar Nemzeti Bank for financial institutions; the Szerencsejatek Felugyelet for gambling; the National Media and Infocommunications Authority (NMHH) for electronic communications.
Sources
- Official sourceNemzeti Adatvedelmi es Informacioszabadsag Hatosag (NAIH)Register of NAIH decisions and orders — published decisions through 29 May 2026
naih.hu
Link checked 18 August 2026
- Official sourceNemzeti Adatvedelmi es Informacioszabadsag Hatosag (NAIH)NAIH annual reports — report on 2025 activity published 30 March 2026
naih.hu
Link checked 18 August 2026
- Official sourceNemzeti Adatvedelmi es Informacioszabadsag Hatosag (NAIH)Decision NAIH-7395-6/2025, 8 April 2025 — 2,000,000 HUF fine on a processor for security failures during a database migration
naih.hu
Link checked 18 August 2026
- Official sourceSzabalyozott Tevekenysegek Felugyeleti Hatosaga (SZTFH)Cybersecurity supervision — registers of auditors, deadlines and guidance
sztfh.hu
Link checked 18 August 2026
How long do I have to keep the data?
Hungary pushes hard in both directions. The floor is long: accounting records and vouchers must be kept for eight years, and health records for decades — the health data law works in periods of thirty years and more. The ceiling is the European rule that you delete personal data once the purpose is spent. When the two collide, the specific statutory keep-period wins, so a deletion request does not empty your ledgers or a hospital's files.
FLOOR. Act C of 2000 on accounting, section 169, sets an eight-year minimum for the annual report, the inventory, the general ledger and the supporting vouchers. Tax records are pinned to the limitation period under the tax procedure rules. Act XLVII of 1997 on health data (Euak.) sets very long minimums for health documentation, with discharge summaries kept longer than ordinary records; we could not retrieve the exact section text on 18 August 2026 because the official database truncates long statutes, so treat the specific year counts as medium confidence. Act LXIX of 2024 requires organisations in scope to hold a cybersecurity audit cycle, with the first audit due by 30 June 2026, which creates its own evidence-retention expectation. CEILING. GDPR Article 5(1)(e) storage limitation plus the Article 17 erasure right. CONFLICT. The GDPR itself resolves it: Article 17(3)(b) disapplies erasure where processing is needed to comply with a legal obligation under member state law, so the Hungarian keep-periods override the delete request for the documents they cover — but only for those documents, not for the marketing database that happens to sit next to them.
Sources
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act C of 2000 on accounting, section 169 — retention of the annual report, ledgers and vouchers
njt.jog.gov.hu
Link checked 18 August 2026
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act XLVII of 1997 on the processing and protection of health and related personal data (Euak.) — retention of health documentation
njt.jog.gov.hu
Link checked 18 August 2026
- Official sourceSzabalyozott Tevekenysegek Felugyeleti Hatosaga (SZTFH)Cybersecurity supervision — audit contract deadline 31 August 2025, first audit by 30 June 2026
sztfh.hu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (GDPR), Articles 5(1)(e) and 17(3)(b)
eur-lex.europa.eu
Link checked 18 August 2026
What happens if there is a breach?
Count at least two clocks, and three if you are a bank. A personal data breach goes to the privacy regulator within 72 hours. A cyber incident at a company or public body covered by the cybersecurity law goes to the national incident response centre, and the European rules that Hungary is copying use a 24-hour first alert followed by a fuller report at 72 hours. Financial firms have a separate and faster set of deadlines under the European operational resilience rules.
CLOCK 1 — GDPR Article 33: notify NAIH without undue delay and where feasible within 72 hours of becoming aware; Article 34 adds notice to the affected individuals where the risk is high. CLOCK 2 — Act LXIX of 2024 on the cybersecurity of Hungary. Sections 6(5)(e), 18(1) and 19(2) require in-scope organisations and central system operators to report cyber threats and incidents to the competent cybersecurity incident handling centre, which is the National Cyber Security Institute. We could not retrieve the numeric deadlines from the official consolidated text on 18 August 2026 because the database truncates the statute; the underlying Directive (EU) 2022/2555 requires an early warning within 24 hours, a fuller notification within 72 hours and a final report within one month, and Hungary transposed that directive, so plan to those figures and verify before relying on them. CLOCK 3 — Regulation (EU) 2022/2554 (DORA) has applied to financial entities since 17 January 2025 and runs its own major-ICT-incident timetable. The common failure is treating a ransomware event as a single report: in Hungary it is simultaneously a personal data breach for NAIH, a cyber incident for the incident response centre, and, for a bank, an ICT incident for the supervisor.
Sources
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act LXIX of 2024 on the cybersecurity of Hungary, sections 6(5), 18 and 19 — duty to report to the competent incident handling centre
njt.jog.gov.hu
“gyors es hatekony reagalasrol, az illetekes kiberbiztonsagi incidenskezelo kozpontnak valo bejelentesrol”
Link checked 18 August 2026
- Official sourceNemzeti Kibervedelmi Intezet (NKI)National Cyber Security Institute — legal basis and incident reporting service
nki.gov.hu
Link checked 18 August 2026
- Official sourceEuropean Union Agency for Cybersecurity (ENISA)Act LXIX of 2024 on the cybersecurity of Hungary — text hosted by the EU cybersecurity agency, in force from 3 January 2025
enisa.europa.eu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (GDPR), Articles 33 and 34 — 72-hour breach notification
eur-lex.europa.eu
Link checked 18 August 2026
What trips people up in Hungary?
Five things that are not in the summary. One: mishandling personal data is a crime in Hungary, not just a fine — up to one year in prison, two years for sensitive data, three years for public officials. Two: the old rule forcing state data to stay in Hungary is dead, so quoting it makes you look out of date, while the new cybersecurity classification gate is very much alive and most checklists miss it. Three: several cybersecurity deadlines have already passed, so newly in-scope companies are late on day one. Four: an online casino's game server must sit in the European Economic Area. Five: Hungary's freedom-of-information regime can make your contract with a state body public.
(1) CRIMINAL LIABILITY. Section 219 of Act C of 2012, the Criminal Code, punishes processing personal data without authorisation or for a purpose other than the stated one, or failing to take data security measures, where done for gain or causing significant harm: up to one year of imprisonment, up to two years where special-category data is involved, and up to three years, as a felony, where committed by a person acting in an official capacity. This is a personal exposure for named individuals, which changes how Hungarian managers behave in an incident. (2) THE DEAD LOCALISATION RULE. Act CLVII of 2010 and then Act XCI of 2021 required national-data-asset registers to be processed only on Hungarian territory. Both are repealed; the second stopped applying on 1 April 2024. Advisers still citing it are wrong, and advisers relying on that repeal without reading Act LXIX of 2024 are also wrong. (3) EXPIRED CLOCKS. Under the cybersecurity regime an organisation must register within 30 days of coming into scope, survey its systems within 90 days, complete classification within 120 days and file a security policy within 180 days; organisations already operating before 1 January 2025 had to contract an auditor by 31 August 2025 and complete a first audit by 30 June 2026. (4) GAMBLING. Beyond the European Economic Area server rule, access must be restricted to players connecting from Hungarian IP addresses and the authority must have continuous remote access to the server. (5) TRANSPARENCY. The Info Act's public-data regime reaches bodies performing public duties and state-owned companies, and the regulator announced on 14 August 2026 that the Central Information Public Data Registry is being widened. (6) SOVEREIGNTY LAW. Act LXXXVIII of 2023 created a Sovereignty Protection Office with broad powers to demand information; on 12 February 2026 Advocate General Kokott advised the Court of Justice that the law breaches EU law, including data protection rules, but the judgment is not out and the powers remain on the books.
Sources
- Official sourceMagyarorszag Birosagai (Courts of Hungary)Misuse of personal data — Criminal Code section 219, elements and sentences (judicial training material)
projektjeink.birosag.hu
“jogosulatlanul vagy a celtol elteroen szemelyes adatot kezel”
Link checked 18 August 2026
- Official sourceSzabalyozott Tevekenysegek Felugyeleti Hatosaga (SZTFH)Cybersecurity supervision — registration within 30 days, auditor contract by 31 August 2025, first audit by 30 June 2026
sztfh.hu
Link checked 18 August 2026
- Official sourceSzerencsejatek Felugyelet (Gambling Supervisory Authority)Online casino licensing conditions — EEA server, Hungarian IP access only, continuous authority access
szf.gov.hu
“Online kaszinojatek kizarolag magyarorszagi IP cimrol kapcsolodo jatekos szamara teheto hozzaferhetove”
Link checked 18 August 2026
- Official sourceCourt of Justice of the European UnionPress release, 12 February 2026 — Advocate General Kokott's Opinion in Case C-829/24 Commission v Hungary
curia.europa.eu
Link checked 18 August 2026
What is changing soon in Hungary?
Three dated items. The Court of Justice will rule on Hungary's sovereignty protection law; the court's adviser said on 12 February 2026 that it breaks European law, and the judgment could land any time. From 12 January 2027 cloud providers across Europe, Hungary included, must charge nothing to move your data out. And Hungary's cybersecurity supervision moves from paperwork to inspections now that the first audit deadline of 30 June 2026 has passed.
DATED. (a) Case C-829/24, Commission v Hungary, on Act LXXXVIII of 2023 on the protection of national sovereignty: Advocate General Kokott's Opinion of 12 February 2026 found the Sovereignty Protection Office's investigative and disclosure powers incompatible with EU law, including data protection rules; judgment pending as at 18 August 2026. (b) 12 January 2027: the Data Act's zero data-egress-fee obligation, from the shared European layer. (c) Cybersecurity audits were due by 30 June 2026, so supervisory action and fees are the next phase. (d) Act CI of 2023 on utilising the national data asset has staged commencement, with further provisions applying from 1 January 2026; the exact staging could not be pinned down and is listed as unconfirmed. DORMANT SWITCHES, which matter more. (1) Hungary has twice legislated a Hungary-only processing rule for state registers and twice repealed it; a single ordinary statute could bring it back, and the drafting precedent already exists. (2) Under the cybersecurity law the classification framework is the lever: tightening the classification rules would tighten foreign processing across energy, transport, banking, health, water, digital infrastructure and public administration without touching the privacy law at all. (3) The gambling authority's licensing conditions are set by ministerial and authority decree, not primary legislation, so the European Economic Area server rule can be narrowed to Hungary by decree. (4) The Sovereignty Protection Office's information-gathering powers remain exercisable until and unless the Court of Justice rules otherwise.
Sources
- Official sourceCourt of Justice of the European UnionPress release, 12 February 2026 — Advocate General's Opinion, Case C-829/24 Commission v Hungary; judgment pending
curia.europa.eu
Link checked 18 August 2026
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act CI of 2023 on utilising the national data asset — staged commencement
njt.jog.gov.hu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2023/2854 (Data Act) — switching charges to fall to zero on 12 January 2027
eur-lex.europa.eu
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
Bloc rules
Made by a group of countries together. Applies inside every member country.
2 rules here
Layer 2
National rules
Added by this country on top of any bloc rules.
3 rules here
Layer 3
Industry rules
Made by an industry regulator. These usually beat the general position.
4 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
Bloc rules2 rules
Az Europai Parlament es a Tanacs (EU) 2016/679 rendelete (altalanos adatvedelmi rendelet)
Directly binding regulation · Regulation (EU) 2016/679
The European baseline that governs Hungary. It regulates the conditions for data leaving Europe rather than where data is stored. Fines are the higher of a fixed cap or a share of worldwide group turnover, though Hungarian fines in practice are far below the cap.
Enforced by European Data Protection Board
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What it makes you do
- Get consent
- Document a legitimate interest
- Tell people what you do
- Keep records of processing
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Assess high-risk projects
- Written vendor contract
- Appoint a local representativeRequired where there is no establishment in the European Union.
- Put a transfer safeguard in placePlus a documented transfer impact assessment after the Schrems II judgment.
- Do not hand data to foreign authorities on demandA third-country authority's order is not by itself a lawful basis to disclose (EDPB Guidelines 02/2024).
- Delete data after a period
- Get a parent's consent for children — applies at: 16 in Hungary — Hungary did not lower the age below the default
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group turnover or €20,000,000, whichever is higher — about $22 millionBasic principles, individual rights, unlawful international transfers, defying a regulator order
- Percentage of global turnover: 2% of worldwide group turnover or €10,000,000, whichever is higher — about $11 millionController and processor obligations
- Order to stopThe regulator can order processing to stop or suspend flows to a third country
- Claims by individualsIndividuals can claim compensation
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (GDPR), consolidated text
eur-lex.europa.eu
Link checked 18 August 2026
Az Europai Parlament es a Tanacs (EU) 2023/2854 rendelete (adatrendelet)
Directly binding regulation · Regulation (EU) 2023/2854
The European data rules that make it cheaper to leave a cloud provider. Most of it has applied since 12 September 2025, and from 12 January 2027 a provider may charge nothing at all to move your data out. Non-personal data cannot be handed to a foreign government without a proper legal route.
Enforced by European Data Protection Board
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Make switching cloud provider possible — from 12 January 2027All cloud switching charges and data egress fees must fall to zero.
- Do not hand data to foreign authorities on demandChapter VII restricts third-country government access to non-personal data held in the European Union.
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2023/2854 (Data Act)
eur-lex.europa.eu
National rules3 rules
2011. evi CXII. torveny az informacios onrendelkezesi jogrol es az informacioszabadsagrol (Infotv.)
Act of parliament · Act CXII of 2011
Hungary's own data law. It no longer duplicates the European rules for ordinary commercial processing; it supplements them, carries the freedom-of-information regime, and supplies the whole rulebook for processing that sits outside European privacy law, such as law enforcement and national security. It imposes no storage-location requirement.
Enforced by National Authority for Data Protection and Freedom of Information
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Explicit consent, Someone's life is at risk, Important public interest
What it makes you do
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Secure the data
- Put a transfer safeguard in placeSections 10 and 11 govern third-country transfers for processing outside GDPR scope.
- Appoint a data protection officerMandatory for bodies performing public duties.
What it costs if you get it wrong
- Fixed maximum fine: Administrative fine under the Info Act for processing outside GDPR scopeBreach of the Info Act's own rules; exact HUF range not retrievable from the official consolidated text on 18 August 2026
Sources
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act CXII of 2011 (Infotv.), consolidated text — sections 2, 10, 11
njt.jog.gov.hu
Link checked 18 August 2026
- Official sourceNemzeti Adatvedelmi es Informacioszabadsag Hatosag (NAIH)NAIH — statutory remit under the Info Act
naih.hu
Link checked 18 August 2026
2024. evi LXIX. torveny Magyarorszag kiberbiztonsagarol (Kiberbiztonsagi tv.)
Act of parliament · Act LXIX of 2024
Hungary's implementation of the European network and information security directive, and quietly the most important storage rule in the country. Companies and public bodies in scope may only put data in a shared cloud, or process it abroad, once they have classified that data. It is a gate rather than a wall, but it is a gate that most transfer checklists do not have on them.
Enforced by Regulated Activities Supervisory Authority
Transfer model: Approval each time · Accepted routes: Security review needed
What it makes you do
- Keep the data in the countryNot an outright localisation duty. Section 9(4): an in-scope organisation may use a non-private cloud service or process data abroad ONLY on the basis of a completed data classification. Section 9(2) makes the classification compulsory precisely when non-private cloud or foreign processing is involved.
- Register or notifyRegistration with the authority within 30 days of coming into scope.
- Keep records of processingSurvey of electronic information systems within 90 days.
- Secure the dataInformation security policy filed within 180 days.
- Hold a security certificateAuditor contracted by 31 August 2025 and first cybersecurity audit completed by 30 June 2026 for organisations already operating before 1 January 2025.
- Report cyber incidentsReport to the competent cybersecurity incident handling centre (NKI). Numeric deadlines not retrievable from the official text; the transposed EU directive uses 24 hours, 72 hours and one month.
What it costs if you get it wrong
- Fixed maximum fineSupervisory fines under the cybersecurity regime; the maximum could not be retrieved from the official consolidated text on 18 August 2026
- Order to stopAppointment of an information security supervisor and supervisory orders under SZTFH Decree 3/2025
Sources
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act LXIX of 2024 on the cybersecurity of Hungary, sections 8(4) and 9
njt.jog.gov.hu
“Az 1. § (1) bekezdes b) es c) pontja szerinti szervezet az adatosztalyozast nem privat felhoszolgaltatas igenybevetele es kulfoldi adatkezeles megvalositasa eseten koteles elvegezni”
Link checked 18 August 2026
- Official sourceSzabalyozott Tevekenysegek Felugyeleti Hatosaga (SZTFH)Cybersecurity supervision — scope, registration and audit deadlines
sztfh.hu
Link checked 18 August 2026
- Official sourceEuropean Union Agency for Cybersecurity (ENISA)Act LXIX of 2024 — Hungarian text, effective 3 January 2025
enisa.europa.eu
Link checked 18 August 2026
2012. evi C. torveny a Bunteto Torvenykonyvrol, 219. § (szemelyes adattal visszaeles)
Act of parliament · Act C of 2012, section 219
In Hungary a data protection failure can be a crime as well as a regulatory matter. Handling personal data without authorisation, using it for the wrong purpose, or skipping security measures is punishable by imprisonment where it was done for gain or caused significant harm, with higher maximums for sensitive data and for officials.
Enforced by National Authority for Data Protection and Freedom of Information
What it makes you do
- Secure the data
- Tell people what you doFailing to inform the data subject where required is itself an offence where it causes significant harm.
What it costs if you get it wrong
- Criminal liability: 1 year of imprisonmentProcessing personal data without authorisation or for a purpose other than the stated one, or failing to take security measures, for gain or causing significant harm
- Criminal liability: 2 years of imprisonmentWhere special-category personal data is involved
- Criminal liability: 3 years of imprisonmentWhere committed by a person acting in an official capacity
Sources
- Official sourceMagyarorszag Birosagai (Courts of Hungary)Criminal Code section 219, misuse of personal data — elements and sentencing (judicial training material)
projektjeink.birosag.hu
“az adatok biztonsagat szolgalo intezkedest elmulasztja”
Link checked 18 August 2026
- Official sourceMagyarorszag Birosagai (Courts of Hungary)Act C of 2012 on the Criminal Code, full text
birosag.hu
Industry rules4 rules
1991. evi XXXIV. torveny a szerencsejatek szervezeserol es a vegrehajtasi rendeletei (online kaszinojatek engedelyezesi feltetelei)
Licence condition · Act XXXIV of 1991 and implementing decrees, incl. SZTFH Decree 20/2021 (X. 29.) · Online gaming
The one genuine hard wall in Hungary. An online casino serving Hungarian players must keep its game server inside the European Economic Area and give the gambling authority continuous remote access to it. Players may only connect from Hungarian internet addresses.
Enforced by Gambling Supervisory Authority
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryThe online casino server must be located in a state of the European Economic Area. Outside the EEA is not permitted.
- Independent auditThe gambling authority must have continuous remote access to the server.
- Secure the dataAccess is restricted to players connecting from Hungarian IP addresses, and the operator must verify this continuously.
What it costs if you get it wrong
- Loss of your licenceBreach of licensing conditions for online casino games
Sources
- Official sourceSzerencsejatek Felugyelet (Gambling Supervisory Authority)Online casino games — licensing conditions
szf.gov.hu
“Az online kaszino szerveret EGT-allamban kell elhelyezni”
Link checked 18 August 2026
- Official sourceNemzeti Jogszabalytar (National Legislation Database)SZTFH Decree 20/2021 (X. 29.) on the authorisation, conduct and supervision of certain games of chance
njt.jog.gov.hu
2021. evi XCI. torveny a nemzeti adatvagyonrol, 13. §
Act of parliament · Act XCI of 2021, section 13; repealed by Act CI of 2023 section 104(b) · Government
Included because it is the single most common error in Hungary write-ups. Hungary really did require state registers to be processed only on Hungarian soil, first from 2010 and again from 2021, but that duty ended on 1 April 2024 and the replacement law contains nothing like it. Treat any current advice that cites it as out of date — while noting the government has legislated this twice and could do so again.
Enforced by National Authority for Data Protection and Freedom of Information
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryNO LONGER BINDING. Required that data processing operations connected to designated state registers be carried out by the processor exclusively on the territory of Hungary, and that the processor be a state body or a domestically established 'transparent organisation'. Stopped applying on 1 April 2024.
Sources
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act XCI of 2021 on the national data asset, section 13, with the repeal footnote citing Act CI of 2023 section 104(b), effective 1 April 2024
njt.jog.gov.hu
“A torvenyt a 2023. evi CI. torveny 104. § b) pontja hatalyon kivul helyezte 2024. aprilis 1. napjaval”
Link checked 18 August 2026
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act CLVII of 2010 on the enhanced protection of state registers in the national data asset — the earlier Hungary-only rule, repealed 26 July 2021
njt.hu
Link checked 18 August 2026
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act CI of 2023 on the system for utilising the national data asset — the replacement, containing no territorial restriction
njt.jog.gov.hu
Link checked 18 August 2026
A Magyar Nemzeti Bank 2/2025. (I.13.) szamu ajanlasa a kozossegi es nyilvanos felhoszolgaltatasok igenybevetelerol
Regulator guideline · MNB Recommendation 2/2025 (I.13.), replacing Recommendation 4/2019 · Finance
Hungarian financial regulation contains no localisation requirement. The central bank's cloud recommendation instead demands heightened, documented diligence when a bank, insurer or investment firm puts data in a cloud outside the European Economic Area. It is supervisory expectation, not a prohibition, and the European operational resilience rules sit on top of it.
Enforced by Magyar Nemzeti Bank
Transfer model: Approval each time · Accepted routes: Security review needed
What it makes you do
- Written vendor contractCloud contracts must give the institution and the supervisor audit and access rights, and an exit plan, aligned with the EU operational resilience regulation.
- Assess high-risk projectsFor cloud outside the European Economic Area the institution must act with particular diligence and document that it considered third-country processing rules.
What it costs if you get it wrong
- Order to stopSupervisory measures for institutions that cannot demonstrate control over an outsourced cloud arrangement
Sources
- Official sourceMagyar Nemzeti BankMNB Recommendation 2/2025 (I.13.) on community and public cloud services
mnb.hu
“dokumentaltan igazolja, hogy a felhoszolgaltatas igenybevetele soran figyelembe vette a harmadik orszagban torteno adatkezelesre vonatkozo eloirasokat”
Link checked 18 August 2026
- Official sourceMagyar Nemzeti BankMNB Recommendation 1/2025 (I.13.) on information technology systems, amended for the EU operational resilience regulation
mnb.hu
1997. evi XLVII. torveny az egeszsegugyi es a hozzajuk kapcsolodo szemelyes adatok kezeleserol es vedelmerol (Euak.)
Act of parliament · Act XLVII of 1997, with EMMI Decree 39/2016 (XII. 21.) on the EESZT · Health and social care
No territorial restriction was found on where Hungarian health data may be stored, which surprises people who expect a health wall in a European country. What Hungary does instead is centralise: every healthcare provider must plug into the state-run Electronic Health Service Space and upload defined records, and retention runs for decades.
Enforced by National Authority for Data Protection and Freedom of Information
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What it makes you do
- Keep data for a minimum period — 30 yearsHealth documentation carries very long statutory minimums, measured in decades. The exact section text could not be retrieved from the official database on 18 August 2026.
- Keep records of processingHealthcare providers must connect to the national Electronic Health Service Space and upload defined data (Euak. section 35/B); access must be logged (section 35/D).
Sources
- Official sourceNemzeti Jogszabalytar (National Legislation Database)Act XLVII of 1997 on the processing and protection of health and related personal data (Euak.)
njt.jog.gov.hu
Link checked 18 August 2026
- Official sourceElektronikus Egeszsegugyi Szolgaltatasi Ter (EESZT)EESZT information portal — governing legislation, operator and provider connection duties
e-egeszsegugy.gov.hu
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The exact incident reporting deadlines in hours under Act LXIX of 2024 on cybersecurity
The official consolidated text on the national legislation database truncates long statutes on retrieval, and the reporting chapter could not be opened on 18 August 2026. The figures given (24 hours, 72 hours, one month) are those of the EU directive Hungary transposed, not a quoted Hungarian provision.
The maximum fine under the Hungarian cybersecurity regime, and the fine range NAIH may impose under the Info Act for processing outside GDPR scope
Sections 61 and 75/A of the Info Act, and the penalty chapter of the cybersecurity act, sit beyond the point at which the official database truncated the text. No secondary figure has been substituted.
The precise retention periods for health documentation in section 30 of the Health Data Act, and the eight-year accounting retention in section 169 of the Accounting Act
Both statutes are long and the official text was truncated before those sections. The direction of travel (decades for health, years for accounting) is well established, but the exact figures were not read off a government source on 18 August 2026.
The current status of the telecommunications data retention obligation in the Electronic Communications Act (Act C of 2003, around section 159/A)
The relevant sections could not be retrieved from the official database, and no Hungarian Constitutional Court or Court of Justice ruling annulling or disapplying them was located on a government or court domain. This is a live question given the Court of Justice case law on general and indiscriminate retention, and it is deliberately not asserted here in either direction.
The exact commencement staging of Act CI of 2023 on utilising the national data asset
One retrieval of the official text reported entry into force on 30 December 2023 and another reported 1 January 2026, which is consistent with staged commencement but was not resolved to a provision-by-provision table.
Whether any localisation condition applies to remote gambling other than online casino games, and whether player account data as opposed to the game server may sit outside the European Economic Area
The authority's page states the server rule for online casino games. The equivalent conditions for other remote gambling products, and the treatment of player records, were not confirmed from the decree text.
Whether the Hungarian government has issued any decree since 1 April 2024 reintroducing a Hungary-only processing rule for particular state registers
We can evidence that the primary-law rule was repealed. We cannot prove the absence of a narrower sectoral decree, and Hungarian government decrees are numerous.
Whether the age of consent for information society services in Hungary is 16
Hungary appears to have left the default in Regulation (EU) 2016/679 untouched rather than legislating a lower age, but no Hungarian provision or regulator statement confirming this was opened on 18 August 2026.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.