Skip to main content

PRIVACY POLICY

ON THE RIGHTS OF NATURAL PERSONS

REGARDING THE PROCESSING OF THEIR PERSONAL DATA

TABLE OF CONTENTS

INTRODUCTION

CHAPTER I – IDENTIFICATION OF THE DATA CONTROLLER

CHAPTER II – DATA PROCESSORS

  1. Our Company's IT Service Provider
  2. Our Company's Accounting Service Provider
  3. Postal Services, Delivery and Parcel Shipping

CHAPTER III – DATA PROCESSING RELATED TO EMPLOYMENT

  1. Employment and Personnel Records
  2. Data Processing Related to Fitness-for-Work Examinations
  3. Processing of Personal Data of Job Applicants, Applications and CVs
  4. Monitoring the Use of Company Email Accounts
  5. Monitoring the Use of Company Computers, Laptops and Tablets
  6. Monitoring Workplace Internet Usage
  7. Monitoring the Use of Company Mobile Phones

CHAPTER IV – DATA PROCESSING RELATED TO CONTRACTUAL RELATIONSHIPS

  1. Processing of Data of Contracting Partners – Customer and Supplier Records
  2. Contact Details of Representatives of Corporate Clients, Customers and Suppliers
  3. Processing of Website Visitor Data
  4. Information on the Use of Cookies

CHAPTER V – DATA PROCESSING BASED ON LEGAL OBLIGATIONS

  1. Data Processing for Compliance with Tax and Accounting Obligations
  2. Payroll-Related Data Processing
  3. Processing of Records of Permanent Archival Value under the Archives Act
  4. Data Processing for Compliance with Anti-Money Laundering Obligations

CHAPTER VI – SUMMARY OF THE RIGHTS OF DATA SUBJECTS

CHAPTER VII – DETAILED INFORMATION ON THE RIGHTS OF DATA SUBJECTS

CHAPTER VIII – SUBMISSION OF REQUESTS BY DATA SUBJECTS AND MEASURES TAKEN BY THE DATA CONTROLLER


INTRODUCTION

Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as the "GDPR" or the "Regulation"), requires the Data Controller to take appropriate measures to ensure that all information relating to the processing of personal data is provided to data subjects in a concise, transparent, intelligible and easily accessible form, using clear and plain language. The Regulation also requires the Data Controller to facilitate the exercise of the rights of data subjects.

The obligation to provide prior information to data subjects is also prescribed by Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information.

This Privacy Policy has been prepared in order to comply with these legal obligations.

The Privacy Policy shall be published on the Company's website and, upon request, shall also be provided to the data subject.



PRIVACY POLICY

Chapter I

DATA CONTROLLER

This Privacy Policy is issued by and the Data Controller is:

Business Name: József Rubóczki Sole Proprietor

Registered Office:
55 Népszínház Street
1081 Budapest
Hungary

Tax Number: 73818638-2-42

Representative: József Rubóczki

Telephone: +36 42 508 670

E-mail: info@europahotel.hu

Websites: www.europahotel.hu

(hereinafter referred to as the "Data Controller")


Chapter II

DATA PROCESSORS

A Data Processor is a natural or legal person, public authority, agency or other body that processes personal data on behalf of the Data Controller in accordance with Article 4(8) of the General Data Protection Regulation (GDPR).

The appointment of a Data Processor does not require the prior consent of the data subject; however, the Data Controller is obliged to inform the data subject about the involvement of such processor.

Accordingly, the following information is provided.


1. IT Service Provider

The Data Controller uses an external IT service provider for the operation and maintenance of its websites.

This Data Processor provides web hosting services and, for the duration of its contractual relationship with the Data Controller, stores the personal data submitted through the websites on its servers.

Data Processor

Company Name: Cweb.hu Informatikai Kft.

Registered Office:
12–32 Borsó Street
1173 Budapest
Hungary

Company Registration Number: 01-09-436264

Tax Number: 32666032-1-42

Telephone: +36 70 282 7206

E-mail: info@cweb.hu

Website: https://cweb.hu



Chapter III

EMPLOYMENT-RELATED DATA PROCESSING

1. Employee Records and Personnel Administration

Only personal data that are necessary for establishing, maintaining, or terminating an employment relationship, or for providing employee welfare benefits, may be requested and processed. Such processing must not infringe upon the employee's personal rights.

Based on the legitimate interests of the employer pursuant to Article 6(1)(f) of the GDPR, the Company processes the following employee data for the purposes of establishing, maintaining, and terminating employment:

  • Full name

  • Birth name

  • Date of birth

  • Mother's maiden name

  • Residential address

  • Citizenship

  • Tax identification number

  • Social security number (TAJ)

  • Pension identification number (for retired employees)

  • Telephone number

  • E-mail address

  • Identity card number

  • Address card number

  • Bank account number

  • Online identifier (if applicable)

  • Employment start and end dates

  • Job title

  • Copies of educational and professional qualification certificates

  • Photograph

  • Curriculum Vitae (CV)

  • Salary information and other employment-related remuneration

  • Deductions from salary based on legal obligations, court decisions, or the employee's written consent

  • Employee performance evaluations

  • Method and reason for termination of employment

  • Criminal record certificate (where required by the position)

  • Summary of occupational medical examinations

  • Membership information relating to private pension funds or voluntary mutual insurance funds

  • Passport number and work authorization documents (for foreign employees)

  • Data contained in occupational accident reports

  • Information required for employee welfare services or commercial accommodation benefits

Information concerning an employee's health or trade union membership shall only be processed where required by applicable labour legislation.

Recipients of Personal Data

Personal data may be accessed by:

  • the employer,

  • persons exercising employer rights,

  • employees responsible for HR administration,

  • authorised data processors.

Only the personal data of executive employees may be disclosed to the owners of the Company.

Retention Period

Personal data shall be retained for three (3) years following the termination of the employment relationship.

Employees shall be informed before the commencement of processing that the legal basis for processing is the Hungarian Labour Code and the legitimate interests of the employer.


2. Processing of Data Related to Fitness-for-Work Examinations

Employees may only be required to undergo medical or occupational fitness examinations where prescribed by law or where necessary for exercising rights or fulfilling obligations arising from the employment relationship.

Before any examination, employees shall receive detailed information regarding:

  • the purpose of the examination;

  • the skills or abilities being assessed;

  • the methods and procedures applied;

  • where required by law, the relevant legal provisions governing the examination.

The employer may require employees or job applicants to complete aptitude or competency tests before or during employment.

Psychological or personality assessments involving larger groups of employees may only be conducted where:

  • they serve legitimate organisational purposes;

  • the results cannot be linked to individual employees;

  • data are processed anonymously.

Personal Data Processed

Only information concerning:

  • occupational fitness;

  • the conditions required for performing the job safely.

Legal Basis

The legitimate interests of the employer.

Purpose

  • Establishing employment

  • Maintaining employment

  • Assessing suitability for a specific position

Recipients

The results may only be accessed by:

  • the examined employee;

  • the examining medical professional.

The employer may only receive information as to whether the employee is:

  • fit for work;

  • unfit for work;

  • fit subject to certain conditions.

The employer is not entitled to receive the detailed medical documentation.

Retention Period

Three (3) years following termination of employment.


3. Processing of Job Applicants' Personal Data

The following personal data may be processed:

  • Name

  • Date and place of birth

  • Mother's maiden name

  • Residential address

  • Educational qualifications

  • Photograph

  • Telephone number

  • E-mail address

  • Notes prepared by the employer during the recruitment process (if any)

Purpose

The purpose of processing is:

  • evaluating job applications;

  • selecting candidates;

  • concluding an employment contract with the successful applicant.

Applicants shall be informed if they are not selected for the position.

Legal Basis

The applicant's consent.

Recipients

  • persons authorised to make hiring decisions;

  • HR employees responsible for recruitment.

Retention Period

Personal data shall be retained until the recruitment procedure has been completed.

The personal data of unsuccessful applicants shall be deleted without undue delay.

The same applies where an applicant withdraws their application.

Applications may only be retained after completion of the recruitment process if the applicant has provided explicit, informed and voluntary consent, and only where retention serves a legitimate recruitment purpose.




4. Monitoring of Company E-mail Accounts

Where the Company provides an employee with a company e-mail account, the account shall be used exclusively for work-related purposes. It is intended for communication between employees and for correspondence conducted on behalf of the Company with clients, business partners, and other organisations.

The employee is not permitted to use the company e-mail account for private purposes or to store personal correspondence within the account.

The Company is entitled to regularly monitor the use and contents of the company e-mail account based on its legitimate business interests.

The purpose of such monitoring is to:

  • verify compliance with Company policies regarding the use of corporate e-mail;

  • ensure fulfilment of employees' work-related obligations.

Monitoring may only be carried out by:

  • the employer;

  • a person authorised to exercise employer rights.

Where circumstances permit, the employee shall be allowed to be present during the inspection.

Before any inspection, the employee shall be informed of:

  • the legitimate business reason for the inspection;

  • the person authorised to carry it out;

  • the rules governing the inspection (including the principle of proportionality);

  • the procedure to be followed;

  • the employee's rights and available legal remedies.

The inspection shall comply with the principle of proportionality.

As a first step, only the sender, recipient and subject line of e-mails should be examined to determine whether they relate to business purposes.

E-mails clearly related to business activities may be reviewed without restriction.

If it is established that the employee has used the company e-mail account for personal purposes contrary to Company policy, the employee shall be instructed to delete all personal data immediately.

Where the employee is absent or fails to cooperate, the employer may remove such personal data during the inspection.

Improper use of the company e-mail account may result in disciplinary or other employment-related consequences.

Employees may exercise all rights granted under this Privacy Policy in connection with such processing.


5. Monitoring of Company Computers, Laptops and Tablets

Computers, laptops and tablets provided by the Company are intended solely for carrying out work-related duties.

Private use of these devices is prohibited.

Employees may not:

  • store personal files;

  • process personal data unrelated to their work;

  • maintain private correspondence on Company devices.

The Company is entitled to inspect data stored on these devices.

The same rules governing inspections and legal consequences described in the previous section regarding company e-mail accounts shall also apply to Company computers, laptops and tablets.


6. Monitoring of Internet Usage

Employees may only access websites necessary for performing their work-related duties.

Private internet use during working hours is prohibited.

Any online registrations created on behalf of the Company shall belong exclusively to the Company.

Where registration requires personal information, the Company shall ensure that such personal data are deleted when the employment relationship ends.

The Company is entitled to monitor employees' internet usage.

The inspection procedure and any legal consequences shall be governed by the provisions applicable to company e-mail monitoring.


7. Monitoring of Company Mobile Phones

Private use of Company-issued mobile phones is not permitted.

Company mobile phones may only be used for business-related communication.

The employer is entitled to inspect:

  • outgoing call records;

  • telephone usage data;

  • information stored on the device.

Employees are required to notify the employer if they have used the Company mobile phone for private purposes.

In such cases, the employer may request an itemised call statement from the telecommunications provider.

The employee shall be entitled to obscure the telephone numbers relating exclusively to private calls before the statement is reviewed.

The employer may require the employee to reimburse the costs of private calls.

The rules governing inspections and any employment-related consequences are otherwise identical to those applicable to company e-mail monitoring.


Chapter IV

CONTRACT-RELATED DATA PROCESSING

1. Processing of Data of Contracting Parties (Customers and Suppliers)

The Company processes the personal data of its customers and suppliers for the purpose of:

  • concluding contracts;

  • performing contractual obligations;

  • terminating contractual relationships;

  • granting contractual benefits.

Categories of Personal Data Processed

The Company may process, where applicable:

  • Full name

  • Birth name

  • Date and place of birth

  • Mother's maiden name

  • Residential or business address

  • Tax identification number

  • Tax/VAT number

  • Identity document number

  • Bank account details

  • Telephone number

  • E-mail address

  • Online identifier

  • Information necessary for invoicing and contract performance

Legal Basis

Performance of a contract in accordance with Article 6(1)(b) GDPR.

Purpose

  • Contract conclusion

  • Contract performance

  • Customer administration

  • Supplier administration

  • Accounting and invoicing

  • Business communication

Recipients

Personal data may be accessed by:

  • employees responsible for customer service;

  • employees performing accounting and taxation duties;

  • authorised data processors.

Retention Period

Personal data shall be retained for five (5) years following termination of the contractual relationship.

Prior to processing, the data subject shall be informed that the legal basis of processing is the performance of a contract. Such information may also be included directly within the contract.

Where personal data are transferred to a data processor, the data subject shall also be informed accordingly.


2. Contact Details of Representatives of Legal Entity Customers and Suppliers

The Company may process the contact details of natural persons acting as representatives of corporate customers, suppliers or other business partners.

Categories of Personal Data

  • Full name

  • Address

  • Telephone number

  • E-mail address

  • Online identifier

Purpose

  • Performance of contracts concluded with legal entities

  • Business communication

  • Day-to-day administration of the business relationship

Legal Basis

The consent of the data subject.

Recipients

Employees responsible for customer service and business administration.

Retention Period

Five (5) years following the termination of the business relationship or the representative status of the individual concerned.


3. Processing of Website Visitor Data

The Company's website uses cookies to improve user experience and ensure the proper functioning of the website.

Cookies are small text files placed on the visitor's device by the website. Some cookies are temporary (session cookies), while others remain stored on the user's device until deleted (persistent cookies).

In accordance with the relevant guidelines of the European Commission, cookies that are not strictly necessary for the operation of the website may only be placed on the user's device with the user's prior consent.

Visitors shall receive appropriate information about the use of cookies upon their first visit to the website.

For cookies requiring consent, information may also be provided through the cookie banner displayed when the website is first accessed.

Where cookies are used in connection with a specific function expressly requested by the user, a concise notice together with a link to the full Privacy Policy is considered sufficient.


4. Cookie Policy

The Company uses cookies in accordance with common internet practice.

Cookies may:

  • remember user preferences;

  • improve browsing experience;

  • facilitate website functionality;

  • assist in the operation of online services;

  • help prevent abuse;

  • enable website performance analysis.

Cookies used on the website do not, by themselves, identify individual visitors.

Strictly Necessary Session Cookies

These cookies are essential for the proper operation of the website and enable visitors to browse and use its services without interruption.

Examples of processed technical identifiers include:

  • AVChatUserId

  • JSESSIONID

  • portal_referer

Purpose

To ensure the proper technical operation of the website.

Legal Basis

Section 13/A(3) of Act CVIII of 2001 on Certain Issues of Electronic Commerce and Information Society Services.

Retention Period

Only for the duration of the current browsing session. These cookies are automatically deleted when the browser is closed.


Preference Cookies

These cookies allow the website to remember visitor preferences and improve usability.

Legal Basis: User consent.

Purpose:

  • improving user experience;

  • making website navigation more convenient;

  • increasing service efficiency.

Retention Period: Six (6) months.


Performance Cookies

The website may use performance and analytical cookies, including:

  • Google Analytics

  • Google Ads (formerly Google AdWords)

These cookies collect anonymous statistical information regarding website usage and help improve the performance and effectiveness of the website.



Chapter V

PROCESSING OF PERSONAL DATA BASED ON LEGAL OBLIGATIONS


1. Processing for Tax and Accounting Obligations

The Company processes personal data in order to comply with its statutory tax and accounting obligations.

Purpose

  • bookkeeping;

  • accounting;

  • taxation;

  • compliance with legal obligations arising from tax legislation.

Legal Basis

Compliance with a legal obligation pursuant to Article 6(1)(c) of the GDPR.

Personal Data Processed

The Company may process, where required by applicable legislation:

  • Tax identification number;

  • VAT number;

  • Full name;

  • Residential or registered address;

  • Tax status;

  • Data required on accounting documents;

  • Name of the person authorising the transaction;

  • Signatures required on accounting and financial documents;

  • Entrepreneur registration number;

  • Agricultural producer registration number;

  • Personal tax identification number.

Retention Period

Personal data shall be retained for eight (8) years following the termination of the legal relationship giving rise to the processing.

Recipients

The data may be accessed by:

  • employees responsible for taxation;

  • accounting personnel;

  • payroll staff;

  • social security administrators;

  • authorised data processors.


2. Payroll Processing

The Company processes personal data relating to employees and other beneficiaries in order to fulfil statutory payroll, tax and social security obligations.

Purpose

  • payroll administration;

  • calculation of taxes and tax advances;

  • calculation of social security contributions;

  • pension administration;

  • compliance with Hungarian tax legislation.

Categories of Data

Depending on legal requirements, the Company may process:

  • full name;

  • previous name (if applicable);

  • title;

  • gender;

  • citizenship;

  • tax identification number;

  • social security identification number (TAJ);

  • health-related data where expressly required by tax legislation;

  • trade union membership where required by law for payroll purposes.

Legal Basis

Compliance with a legal obligation.

Retention Period

Eight (8) years following termination of the legal relationship.

Recipients

  • payroll administrators;

  • tax administration staff;

  • social security administrators;

  • authorised data processors.


3. Processing of Archival Records

The Company processes documents classified as records of permanent value pursuant to Act LXVI of 1995 on Public Records, Public Archives and the Protection of Private Archive Materials.

Purpose

To preserve documents of permanent archival value in a complete and usable condition for future generations.

Legal Basis

Compliance with a legal obligation.

Retention Period

Until the documents are transferred to the competent public archives.

Any further requirements relating to recipients and processing are governed by the applicable archival legislation.


4. Processing for Anti-Money Laundering (AML) Obligations

Where required by law, the Company processes personal data in order to comply with obligations arising from Act LIII of 2017 on the Prevention and Combating of Money Laundering and Terrorist Financing (Pmt.).

Purpose

  • customer identification;

  • prevention of money laundering;

  • prevention of terrorist financing;

  • fulfilment of statutory AML obligations.

Categories of Personal Data

The following data may be processed:

  • family name and given name;

  • birth name;

  • nationality;

  • place and date of birth;

  • mother's birth name;

  • residential address or place of stay;

  • type and number of identification document;

  • address card number;

  • copies of presented identification documents.

Recipients

Personal data may be accessed by:

  • employees responsible for customer service;

  • the Company's managing director;

  • the Company's designated Anti-Money Laundering (AML) officer.

Retention Period

Personal data shall be retained for eight (8) years following the termination of the business relationship or completion of the relevant transaction, in accordance with the applicable AML legislation.



Chapter VI

SUMMARY OF THE RIGHTS OF DATA SUBJECTS

For the sake of transparency and clarity, this chapter provides a concise overview of the rights granted to data subjects under the General Data Protection Regulation (GDPR). Detailed provisions concerning the exercise of these rights are set out in the following chapter.


Right to Prior Information

The data subject has the right to receive information concerning the processing of their personal data before such processing begins.


Right of Access

The data subject has the right to obtain confirmation from the Data Controller as to whether personal data concerning them are being processed and, where that is the case, to obtain access to:

  • the personal data being processed;

  • the purposes of the processing;

  • the categories of personal data concerned;

  • the recipients or categories of recipients to whom the personal data have been or will be disclosed;

  • the planned period for which the personal data will be stored;

  • the right to request rectification, erasure or restriction of processing;

  • the right to object to processing;

  • the right to lodge a complaint with the competent supervisory authority;

  • the source of the personal data where they were not collected directly from the data subject;

  • information regarding automated decision-making, including profiling, where applicable.


Right to Rectification

The data subject has the right to request that inaccurate personal data concerning them be corrected without undue delay.

Taking into account the purpose of the processing, the data subject also has the right to have incomplete personal data completed, including by means of providing a supplementary statement.


Right to Erasure ("Right to be Forgotten")

The data subject has the right to request that the Data Controller erase personal data relating to them without undue delay where one of the grounds specified in Article 17 of the GDPR applies.

The Data Controller shall erase such personal data where:

  • the data are no longer necessary for the purposes for which they were collected;

  • the data subject withdraws consent and there is no other legal basis for processing;

  • the data subject objects to the processing and there are no overriding legitimate grounds for continuing it;

  • the personal data have been processed unlawfully;

  • erasure is required in order to comply with a legal obligation;

  • the personal data were collected in relation to information society services offered directly to a child.

Further details are provided in the following chapter.


Right to Restriction of Processing

The data subject has the right to request restriction of processing where the conditions laid down in Article 18 of the GDPR are fulfilled.

Further details are provided in the following chapter.


Notification Regarding Rectification, Erasure or Restriction

The Data Controller shall communicate any rectification, erasure or restriction of processing to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort.

Upon request, the Data Controller shall inform the data subject about those recipients.


Right to Data Portability

Subject to the conditions laid down in the GDPR, the data subject has the right to:

  • receive the personal data concerning them in a structured, commonly used and machine-readable format;

  • transmit those data to another data controller without hindrance;

  • where technically feasible, request the direct transmission of the data from one controller to another.

Further details are provided in the following chapter.


Right to Object

The data subject has the right to object, on grounds relating to their particular situation, at any time to the processing of personal data based on the legitimate interests of the Data Controller or on the performance of a task carried out in the public interest.

Where the objection is justified, the Data Controller shall no longer process the personal data unless compelling legitimate grounds exist that override the interests, rights and freedoms of the data subject, or unless the processing is necessary for the establishment, exercise or defence of legal claims.


Right to Object to Direct Marketing

Where personal data are processed for direct marketing purposes, the data subject has the right to object at any time to such processing, including profiling related to direct marketing.

Once such an objection has been made, the personal data shall no longer be processed for direct marketing purposes.


SUMMARY OF THE RIGHTS OF DATA SUBJECTS

Automated Individual Decision-Making, Including Profiling

The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, where such decision produces legal effects concerning them or similarly significantly affects them.

This right does not apply where the decision:

  • is necessary for entering into or performing a contract;

  • is authorised by applicable European Union or Member State law;

  • is based on the data subject's explicit consent.

Where automated decision-making is permitted, appropriate safeguards shall be implemented to protect the rights, freedoms and legitimate interests of the data subject.

Further details are provided in the following chapter.


Restrictions

European Union or Member State legislation may restrict certain rights and obligations provided for in Articles 12–22 and Article 34 of the GDPR where such restriction is necessary and proportionate in a democratic society in order to protect, among others:

  • national security;

  • defence;

  • public security;

  • the prevention, investigation, detection or prosecution of criminal offences;

  • important objectives of general public interest;

  • judicial independence and judicial proceedings;

  • regulatory and supervisory functions;

  • the rights and freedoms of others;

  • the enforcement of civil law claims.

Further details are provided in the following chapter.


Right to be Informed of a Personal Data Breach

Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the Data Controller shall inform the affected data subject without undue delay.

The notification shall describe in clear and plain language:

  • the nature of the personal data breach;

  • the likely consequences;

  • the measures taken or proposed by the Data Controller to address the breach;

  • the contact details of the person from whom further information may be obtained.

Further details are provided in the following chapter.


Right to Lodge a Complaint with a Supervisory Authority

The data subject has the right to lodge a complaint with the competent supervisory authority if they consider that the processing of personal data relating to them infringes the GDPR.

The complaint may generally be submitted to the supervisory authority of:

  • the Member State of the data subject's habitual residence;

  • the Member State of the data subject's place of work;

  • the Member State where the alleged infringement occurred.

Further details are provided in the following chapter.


Right to an Effective Judicial Remedy Against a Supervisory Authority

Every natural or legal person has the right to an effective judicial remedy against a legally binding decision of a supervisory authority.

The data subject is also entitled to seek judicial remedy where the competent supervisory authority fails to handle a complaint or fails to inform the data subject within three months of the progress or outcome of the complaint.

Further details are provided in the following chapter.


Right to an Effective Judicial Remedy Against the Data Controller or Processor

Without prejudice to any available administrative remedies, every data subject has the right to an effective judicial remedy if they consider that their rights under the GDPR have been infringed as a result of the unlawful processing of their personal data.

Proceedings may generally be brought before:

  • the courts of the Member State where the Data Controller or Data Processor has an establishment; or

  • the courts of the Member State where the data subject has their habitual residence.

Further details are provided in the following chapter.


The following chapter provides a detailed explanation of the rights guaranteed to data subjects under the GDPR and describes the procedures by which these rights may be exercised.



Chapter VII

DETAILED INFORMATION ON THE RIGHTS OF DATA SUBJECTS

Right to Prior Information

A data subject has the right to receive clear and transparent information about the processing of their personal data before such processing begins.


A. Information to Be Provided Where Personal Data Are Collected from the Data Subject

Where personal data are collected directly from the data subject, the Data Controller shall, at the time the personal data are obtained, provide the following information:

  • the identity and contact details of the Data Controller and, where applicable, its representative;

  • the contact details of the Data Protection Officer, where one has been appointed;

  • the purposes of the intended processing and its legal basis;

  • where processing is based on legitimate interests (Article 6(1)(f) GDPR), a description of those legitimate interests;

  • the recipients or categories of recipients of the personal data, where applicable;

  • where applicable, the intention to transfer personal data to a third country or an international organisation, together with information on the safeguards applied.

The Data Controller shall also provide the following additional information necessary to ensure fair and transparent processing:

  • the period for which the personal data will be stored, or the criteria used to determine that period;

  • the data subject's rights to request access, rectification, erasure or restriction of processing;

  • the right to object to processing;

  • the right to data portability, where applicable;

  • where processing is based on consent, the right to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal;

  • the right to lodge a complaint with the competent supervisory authority;

  • whether the provision of personal data is required by law or by contract, and the possible consequences of failing to provide such data;

  • the existence of automated decision-making, including profiling, together with meaningful information about the logic involved and the significance and expected consequences of such processing for the data subject.


B. Information to Be Provided Where Personal Data Have Not Been Obtained from the Data Subject

Where personal data have not been obtained directly from the data subject, the Data Controller shall provide the information listed above together with the following:

  • the categories of personal data concerned;

  • the source from which the personal data originate;

  • where applicable, whether the data originate from publicly accessible sources.

The required information shall be provided:

  • within a reasonable period after obtaining the personal data, and no later than one month thereafter;

  • if the personal data are to be used for communication with the data subject, at the latest at the time of the first communication;

  • if disclosure to another recipient is envisaged, at the latest when the personal data are first disclosed.


If the Data Controller intends to process the personal data for a purpose other than that for which they were originally collected, the data subject shall be informed of that new purpose and all other relevant information before such further processing begins.

The above information need not be provided where, and insofar as:

  • the data subject already possesses the information;

  • providing the information proves impossible or would involve a disproportionate effort, particularly in cases of archiving in the public interest, scientific or historical research, or statistical purposes;

  • obtaining or disclosure of the data is expressly laid down by European Union or Member State law that provides appropriate measures to protect the legitimate interests of the data subject;

  • the personal data must remain confidential under an obligation of professional secrecy imposed by law.


Right of Access (Article 15 GDPR)

The data subject has the right to obtain confirmation from the Data Controller as to whether personal data concerning them are being processed.

Where such processing takes place, the data subject has the right to obtain access to:

  • the personal data concerned;

  • the purposes of the processing;

  • the categories of personal data processed;

  • the recipients or categories of recipients to whom the personal data have been or will be disclosed, including recipients in third countries or international organisations;

  • where possible, the envisaged period for which the personal data will be stored, or, where this is not possible, the criteria used to determine that period;

  • the right to request rectification, erasure or restriction of processing;

  • the right to object to processing;

  • the right to lodge a complaint with a supervisory authority;

  • where the personal data were not collected from the data subject, any available information regarding their source;

  • the existence of automated decision-making, including profiling, and meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing.

Where personal data are transferred to a third country or to an international organisation, the data subject shall have the right to be informed of the appropriate safeguards relating to such transfer in accordance with Article 46 of the GDPR.

The Data Controller shall provide the data subject with a copy of the personal data undergoing processing.

For any additional copies requested by the data subject, the Data Controller may charge a reasonable fee based on administrative costs.

Where the request is submitted electronically, the information shall, unless otherwise requested, be provided in a commonly used electronic format.

The right to obtain a copy shall not adversely affect the rights and freedoms of others.


Right to Rectification (Article 16 GDPR)

The data subject has the right to obtain from the Data Controller, without undue delay, the rectification of inaccurate personal data concerning them.

Taking into account the purposes of the processing, the data subject also has the right to have incomplete personal data completed, including by providing a supplementary statement.


Right to Erasure ("Right to be Forgotten") (Article 17 GDPR)

The data subject has the right to obtain from the Data Controller the erasure of personal data concerning them without undue delay.

The Data Controller shall erase the personal data where one of the following grounds applies:

  • the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;

  • the data subject withdraws the consent on which the processing is based and there is no other legal ground for processing;

  • the data subject objects to the processing and there are no overriding legitimate grounds for the processing;

  • the personal data have been unlawfully processed;

  • the personal data must be erased for compliance with a legal obligation under European Union or Member State law;

  • the personal data were collected in relation to the offer of information society services directly to a child.

The right to erasure shall not apply where processing is necessary, in particular:

  • for exercising the right of freedom of expression and information;

  • for compliance with a legal obligation;

  • for reasons of public interest in the area of public health;

  • for archiving purposes in the public interest, scientific or historical research, or statistical purposes;

  • for the establishment, exercise or defence of legal claims.


Right to Restriction of Processing (Article 18 GDPR)

The data subject has the right to obtain restriction of processing where one of the following applies:

  • the accuracy of the personal data is contested by the data subject;

  • the processing is unlawful and the data subject opposes erasure, requesting restriction instead;

  • the Data Controller no longer needs the personal data, but the data subject requires them for the establishment, exercise or defence of legal claims;

  • the data subject has objected to processing pending verification of whether the legitimate grounds of the Data Controller override those of the data subject.

Where processing has been restricted, such personal data may, with the exception of storage, only be processed:

  • with the data subject's consent;

  • for the establishment, exercise or defence of legal claims;

  • for the protection of the rights of another natural or legal person;

  • for important reasons of public interest.

The Data Controller shall inform the data subject before lifting any restriction of processing.


Notification Obligation Regarding Rectification, Erasure or Restriction (Article 19 GDPR)

The Data Controller shall communicate any rectification, erasure or restriction of processing to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort.

Upon request, the Data Controller shall inform the data subject about those recipients.


Right to Data Portability (Article 20 GDPR)

Where processing is based on consent or on a contract and is carried out by automated means, the data subject has the right to:

  • receive the personal data concerning them in a structured, commonly used and machine-readable format;

  • transmit those data to another data controller without hindrance;

  • where technically feasible, have the personal data transmitted directly from one controller to another.

The exercise of this right shall not adversely affect the rights and freedoms of others.



Right to Object (Article 21 GDPR)

The data subject has the right to object, on grounds relating to their particular situation, at any time to the processing of personal data concerning them where such processing is based on:

  • Article 6(1)(e) GDPR (processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority); or

  • Article 6(1)(f) GDPR (processing necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party),

including profiling based on those provisions.

In such cases, the Data Controller shall no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing that override the interests, rights and freedoms of the data subject, or unless the processing is necessary for the establishment, exercise or defence of legal claims.

Where personal data are processed for direct marketing purposes, the data subject has the right to object at any time to such processing, including profiling related to direct marketing.

If the data subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.

The right to object must be explicitly brought to the attention of the data subject no later than at the time of the first communication, and this information shall be presented clearly and separately from any other information.

In connection with information society services, the data subject may also exercise the right to object by automated means using technical specifications.

Where personal data are processed for scientific or historical research purposes or statistical purposes pursuant to Article 89(1) GDPR, the data subject has the right to object, on grounds relating to their particular situation, unless the processing is necessary for the performance of a task carried out for reasons of public interest.


Automated Individual Decision-Making, Including Profiling (Article 22 GDPR)

The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, where such decision produces legal effects concerning them or similarly significantly affects them.

This restriction shall not apply where the decision:

  • is necessary for entering into or performing a contract between the data subject and the Data Controller;

  • is authorised by European Union or Member State law that provides appropriate safeguards for the rights and freedoms of the data subject; or

  • is based on the explicit consent of the data subject.

Where the decision is based on a contract or on explicit consent, the Data Controller shall implement appropriate safeguards to protect the rights, freedoms and legitimate interests of the data subject, including at least the right:

  • to obtain human intervention by the Data Controller;

  • to express their point of view; and

  • to contest the decision.

Such decisions shall not be based on special categories of personal data referred to in Article 9(1) GDPR unless one of the exceptions provided for in Article 9(2) applies and appropriate safeguards have been implemented.


Restrictions (Article 23 GDPR)

European Union or Member State legislation may restrict the scope of the rights and obligations laid down in Articles 12–22 and Article 34 of the GDPR, provided that such restrictions respect the essence of fundamental rights and freedoms and constitute a necessary and proportionate measure in a democratic society.

Such restrictions may serve, among others, the protection of:

  • national security;

  • defence;

  • public security;

  • the prevention, investigation, detection and prosecution of criminal offences;

  • important objectives of general public interest, including economic and financial interests;

  • public health;

  • social security;

  • judicial independence and judicial proceedings;

  • professional ethics in regulated professions;

  • supervisory, inspection and regulatory functions;

  • the rights and freedoms of others; and

  • the enforcement of civil claims.


Notification of a Personal Data Breach (Article 34 GDPR)

Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the Data Controller shall communicate the breach to the affected data subject without undue delay.

The notification shall describe, in clear and plain language:

  • the nature of the personal data breach;

  • the likely consequences;

  • the measures taken or proposed to remedy the breach and mitigate its possible adverse effects.

Notification to the data subject shall not be required where:

  • appropriate technical and organisational protection measures, such as encryption, rendered the personal data unintelligible to unauthorised persons;

  • subsequent measures ensure that the high risk is no longer likely to materialise; or

  • individual notification would involve disproportionate effort, in which case public communication or a similar measure shall be used.

Where the Data Controller has not informed the data subject, the supervisory authority may require such notification if it determines that the breach is likely to result in a high risk.


Right to Lodge a Complaint with a Supervisory Authority (Article 77 GDPR)

Without prejudice to any other administrative or judicial remedy, every data subject has the right to lodge a complaint with a supervisory authority if they consider that the processing of personal data relating to them infringes the GDPR.

The supervisory authority with which the complaint has been lodged shall inform the complainant of the progress and outcome of the complaint, including the possibility of seeking a judicial remedy under Article 78 GDPR.


Right to an Effective Judicial Remedy Against a Supervisory Authority (Article 78 GDPR)

Every natural or legal person has the right to an effective judicial remedy against a legally binding decision of a supervisory authority.

A data subject also has the right to an effective judicial remedy where the competent supervisory authority fails to handle the complaint or fails to inform the data subject within three months of the progress or outcome of the complaint.

Proceedings against a supervisory authority shall be brought before the courts of the Member State where that supervisory authority is established.

Where proceedings concern a decision on which the European Data Protection Board has previously issued an opinion or adopted a decision under the consistency mechanism, the supervisory authority shall transmit that opinion or decision to the court.


Right to an Effective Judicial Remedy Against the Data Controller or Data Processor (Article 79 GDPR)

Without prejudice to any available administrative remedies, including the right to lodge a complaint with a supervisory authority, every data subject has the right to an effective judicial remedy where they consider that their rights under the GDPR have been infringed.

Proceedings may be brought before:

  • the courts of the Member State in which the Data Controller or Data Processor has an establishment; or

  • the courts of the Member State in which the data subject has their habitual residence,

unless the Data Controller or Data Processor is a public authority acting in the exercise of its official powers.




Chapter VIII

SUBMISSION OF REQUESTS BY THE DATA SUBJECT AND MEASURES TAKEN BY THE DATA CONTROLLER

  1. The Data Controller shall provide the data subject with information on the action taken in response to a request concerning the exercise of their rights without undue delay and, in any event, within one month of receipt of the request.

  2. Where necessary, taking into account the complexity of the request and the number of requests received, this period may be extended by a further two months.

The Data Controller shall inform the data subject of any such extension, together with the reasons for the delay, within one month of receiving the request.

  1. Where the data subject submits the request electronically, the information shall, where possible, also be provided by electronic means, unless the data subject requests otherwise.

  2. If the Data Controller does not take action in response to the request, it shall inform the data subject, without undue delay and at the latest within one month of receipt of the request, of:

  • the reasons for not taking action; and

  • the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.

  1. The information required under Articles 13 and 14 of the GDPR, as well as information relating to the rights of the data subject (Articles 15–22 and Article 34 GDPR) and any action taken in response to a request, shall be provided free of charge.

However, where a request is manifestly unfounded or excessive, in particular because of its repetitive nature, the Data Controller may, taking into account the administrative costs of providing the information or taking the requested action:

  • charge a fee of HUF 6,350; or

  • refuse to act on the request.

The burden of demonstrating that the request is manifestly unfounded or excessive rests with the Data Controller.

  1. Where the Data Controller has reasonable doubts concerning the identity of the natural person making the request, it may request the provision of additional information necessary to confirm the identity of the data subject.


Budapest, 1 May 2026