CLVPartners

data protection

New service of CLVPartners© – Provision of Data Protection Officer (DPO) services with the involvement of a cooperating partner

We are pleased to inform our Clients that CLVPartners© has expanded its service portfolio: with the involvement of our trusted partner, we now also undertake the provision of Data Protection Officer (DPO) services in accordance with the GDPR requirements for organisations for which this is a legal obligation or a business necessity.

What does the DPO service mean?

The appointment of a DPO is not merely a formal requirement – CLVPartners© ensures real, substantive, and active involvement in data protection compliance. The appointed DPO:

carries out the registration required for the commencement of its activities and establishes appropriate communication channels for data subjects

monitors the compliance of personal data processing with GDPR requirements,

participates in, provides information and professional advice on the development and review of data protection documentation, as well as on new processes to be introduced or any other data processing issues, in order to ensure compliance with the GDPR and other EU or Hungarian data protection provisions,

maintains contact with the National Authority for Data Protection and Freedom of Information (NAIH) and with data subjects,

supervises the enforcement of data subject rights,

supports the organisation in data protection incidents and data protection impact assessments.

What is the difference between the DPO and our Law Firm’s advisory role?

The DPO performs an independent supervisory function and carries out only the tasks defined in the GDPR. The DPO provides information and advice to ensure compliance and maintains contact with the supervisory authority on behalf of the organisation; however, it may not act as legal representative before the authority.

In contrast, our Law Firm continues to provide support to Clients in the field of data protection law in reviewing their data protection practices, preparing implementation plans, and, where necessary, adjusting practices to ensure compliance with the GDPR. Our data protection services cover the following areas:

Supporting GDPR implementation in line with Hungarian legislation and the guidance of the data protection authority

Periodic mandatory review of existing policies and privacy notices, including client support in their practical application

Training for employees involved in the processing of personal data (e.g. HR, IT, controlling, payroll)

Addressing data protection issues arising in connection with employment, including the preparation of information materials, policies and employment contract clauses, drafting whistleblowing regulations, and examining “bring-your-own-device” data protection aspects

Advising on technological solutions based on the use of personal data (AI applications, user profiling, targeted marketing activities, social media solutions, database monitoring, maintenance of internal communication systems)

Professional cooperation – real added value

The DPO and our Law Firm work closely together in the development and documentation of data processing practices. The review and preparation of documentation is always carried out with the professional support of our Law Firm.

Ez a modell lehetővé teszi, hogy szervezete:

megfeleljen a törvényi előírásoknak,

biztosítsa a függetlenséget és szakértelmet a DPO szerepkörben,

továbbra is számíthasson Irodánkra mint adatvédelmi jogi tanácsadóra.

Vegye fel velünk a kapcsolatot, ha szeretné felmérni, szükséges-e DPO-t kijelölni a szervezeténél – és ha fontos Önnek, hogy ez a feladat valóban hozzáadott értéket is jelentsen.

Photo source: pexels.com, shox

New service of CLVPartners© – Provision of Data Protection Officer (DPO) services with the involvement of a cooperating partner Read More »

The Data Protection Officer – Part 1: Appointment Requirements

Reading time: 10 minutes

Companies are required to comply with data protection legislation in a variety of roles, including as employers, customers, and suppliers. Data controllers and processors must not only establish their own internal policies but also ensure compliance with the applicable European Union and national data protection legislation.

One of the obligations that medium-sized and large companies should carefully assess is whether they are required to appoint a Data Protection Officer (“DPO”). Our firm acts as an external Data Protection Officer for a number of clients and regularly encounters questions of legal interpretation regarding the obligation to appoint a DPO. For this reason, we consider it useful to provide a more detailed overview of this service.

This topic may also be relevant to clients with whom our law firm cooperates in the context of data protection advisory services. Subject to compliance with the applicable conflict of interest rules, we are also able to provide DPO services to such clients. The purpose of this two-part series is to provide practical guidance on the rules governing the appointment of a Data Protection Officer and their application in practice.

The General Data Protection Regulation (GDPR) requires the appointment of a DPO in certain circumstances. In other cases, although not legally required, appointing a DPO may be strongly recommended to ensure compliance with data protection requirements and lawful processing of personal data.

In this article, we summarise the circumstances in which the appointment of a Data Protection Officer is mandatory and when it may be advisable in the course of a company’s operations. In the second part of this series, we will discuss practical considerations regarding who should be appointed as a DPO and the benefits of having an external expert fill this role..

When is the appointment of a Data Protection Officer mandatory?

Not every business is required to appoint a Data Protection Officer. Under the GDPR, this obligation does not depend on the size of the company or its annual turnover, but rather on the nature of its processing activities.

The appointment of a DPO is mandatory where the organisation’s core activities consist of:

processing, on a large scale, special categories of personal data (such as health data) or personal data relating to criminal convictions and offences; or

processing operations that require regular, systematic and large-scale monitoring of data subjects.

In our experience, the second scenario is the most common among our clients.

However, the concepts used in the GDPR are not always self-explanatory. Below, we explain what is meant in practice by “core activities” and “regular, systematic and large-scale monitoring”, as well as the factors that should be considered when determining whether a business is required to appoint a DPO. Since data processing activities may change significantly over time, it is advisable to review these criteria periodically during the course of the company’s operations.

What are “core activities”?

The term “core activities” does not merely refer to the company’s registered main business activity. Rather, it encompasses the key operations that are essential for achieving the organisation’s objectives and form an integral part of its business activities. Here are a few examples:

The core activity of a manufacturing company is the production and sale of its products (for example, paper products, tobacco products or machinery). During these operations, personal data processing forms an inseparable part of the business, for example when employees and visitors are granted access to company premises, when the personal data of business contacts are processed on a daily basis, or when CCTV systems are used to secure company facilities.

If a company provides healthcare services or services directly related to healthcare as part of its core business, it necessarily processes health data. This also constitutes a case where the appointment of a Data Protection Officer is mandatory.

In the case of temporary staffing agencies or recruitment service providers, the company processes large volumes of employee and applicant data in connection with payroll, taxation, human resources administration and other employment-related matters.

What constitutes regular and systematic monitoring?

The GDPR does not provide a precise definition of this concept. According to established practice, it includes all forms of online tracking and profiling. Processing personal data for the purposes of behavioural advertising also falls within this category. However, regular and systematic monitoring is not limited to the online environment. Monitoring may also be regarded as regular where it is continuous, carried out at recurring intervals, or repeated at predetermined times. For example:

the employer continuously monitors the work performance of employees performing customer service duties using IT tools to ensure quality,

a transport or logistics company tracking the activities and routes of its employees during the performance of their work.

What constitutes large-scale monitoring?

The GDPR does not establish specific quantitative thresholds for determining whether processing is carried out on a large scale. In practice, personal data processing is generally considered large-scale where the data are processed, stored or analysed not merely at a local level but across an entire country or internationally (for example, within the European Union). A typical example is a corporate group employing a large number of employees across multiple locations nationally or internationally, where employee or customer data are processed centrally across several countries for HR, IT or compliance purposes.

The following factors should be taken into account when assessing whether processing is carried out on a large scale:

the number of data subjects concerned,

the volume of personal data processed,

the range of different categories of personal data processed,

the duration or permanence of the processing activities,

the geographical scope of the processing activities.

Examples commonly regarded as large-scale processing include personal data processed by internet search engines for behavioural advertising purposes, as well as the processing of HR records, working time records, access control data and CCTV recordings relating to a large workforce.

Cases recommended by the European Data Protection Board

Even where the GDPR does not expressly require the appointment of a Data Protection Officer, doing so may nevertheless be justified. According to the guidelines of the European Data Protection Board (EDPB), involving a DPO in processing operations that present a higher level of data protection risk may facilitate compliance with the GDPR and support effective management of data protection risks.

In particular, organizations should consider appointing a DPO where they:

process the personal data of a large number of data subjects,

carry out extensive or complex processing operations,

regularly need to conduct Data Protection Impact Assessments (DPIAs).

Although the appointment of a DPO is not a legal obligation in such case, it may nevertheless constitute an important element of an effective data protection governance framework.

Cases requiring a Data Protection Impact Assessment

A Data Protection Impact Assessment (DPIA) may be required where a particular type of processing – especially where new technologies are used – is likely to result in a high risk to the rights and freedoms of natural persons, taking into account the nature, scope, context and purposes of the processing. Examples of processing activities that may present a high risk include:

Systematic monitoring, for example where a manufacturing company operates CCTV systems on its premises to protect the life and physical integrity of employees, investigate workplace accidents or prevent criminal offences.

The use of GPS tracking in company vehicles in order to monitor employees’ movements.

A temporary staffing or recruitment agency maintaining a database containing the personal data of a large number of job applicants across numerous categories of personal information.

The processing of large volumes of health data or other special categories of personal data.

According to the EDPB’s guidance, where it is not clear whether a particular processing activity presents a high risk, a DPIA should be carried out in order to demonstrate compliance.

Although the obligation to conduct a DPIA does not automatically create an obligation to appoint a Data Protection Officer, the two issues are closely linked in practice. Organizations whose processing activities regularly require DPIAs should consider appointing a DPO. A DPO can assist in identifying risks, preparing Data Protection Impact Assessments and ensuring the continuous compliance of processing activities with the GDPR.

Large-scale processing of personal data

Even where data processing does not form part of an organization’s core activities and does not involve regular and systematic monitoring, processing large volumes of personal data may significantly increase the risk of data protection incidents. In such circumstances, the professional support of a Data Protection Officer can contribute to reviewing existing processing activities, identifying potential weaknesses and reducing data protection risks before they materialize.

Focusing on the prevention and management of personal data breaches

The appointment of a DPO may also be justified where, due to the nature of the organization’s processing activities or previous experience, there is an increased likelihood of personal data breaches. A Data Protection Officer can assist in establishing internal procedures aimed at preventing data protection incidents, increasing employees’ awareness of data protection obligations, and ensuring that any incidents that do occur are handled, documented and reported in accordance with the applicable legal requirements.

In all of the above cases, adopting a proactive approach by voluntarily appointing a DPO may facilitate compliance with data protection legislation, reduce data protection risks and support the implementation of the GDPR’s accountability principle.

Closing remarks

Where any of the mandatory criteria described above apply to your organization, the appointment of a Data Protection Officer is not optional but constitutes a legal obligation under the GDPR. Even where the appointment of a DPO is not legally required, the nature or risk profile of the organization’s processing activities may nevertheless justify such an appointment. In these circumstances, a DPO can provide considerable added value to the organization.

The role of the Data Protection Officer extends beyond supporting legal compliance. A DPO continuously monitors data processing activities, identifies potential risks and assists the organization in addressing them before they result in personal data breaches or regulatory investigations.

Today, effective data protection governance is no longer merely a matter of legal compliance; it has become an integral component of responsible corporate governance. A suitably qualified Data Protection Officer can contribute to greater transparency of processing activities, reinforce the GDPR’s accountability principle and strengthen the confidence of clients, business partners and other stakeholders in the organisation.

As the obligation – or practical need – to appoint a Data Protection Officer can only be assessed following a detailed review of an organisation’s processing activities, businesses should periodically reassess whether their operations require the appointment of a DPO and whether their existing data protection framework remains appropriate and effective.

Photo source: pexels.com Ron Lach

The Data Protection Officer – Part 1: Appointment Requirements Read More »

Data protection updates: the data subject’s right of access and expected developments

Reading time: 7 minutes

Recently, we have received an increasing number of questions from clients regarding the scope of the data subject’s right of access and the practical requirements for responding to access requests. The topic is particularly timely, as legislative work is currently underway to amend certain procedural provisions of the General Data Protection Regulation, i.e. GDPR.

Under GDPR the right of access is one of the cornerstone data subject rights. On the one hand, it is essential for ensuring transparent data processing; on the other hand, it is one of the most frequently disputed rights in practice, with a significant proportion of supervisory authority proceedings and court cases relating to its exercise. Complying with the right of access involves much more than simply providing copies of personal data. It also requires the proper identification of the data subject, compliance with the principle of data minimisation, and the appropriate handling of potentially abusive requests.

In this newsletter, we provide an overview of the content of the right of access, the key guidance shaping its practical application in Europe, and the most recent and expected legislative developments.

The content of the right of access

Pursuant to Article 15 GDPR, the data subject is entitled to obtain confirmation as to whether or not personal data concerning him or her are being processed and, where that is the case, access to the following information:

the purposes of the processing,

the categories of personal data concerned,

the recipients to whom the personal data are disclosed,

the retention period of the data,

information on the rights available to the data subject, including the right to request rectification, erasure or restriction of processing of personal data and to object to such processing,

information on lodging a complaint with a supervisory authority and the manner thereof,

as well as the source of the data (where the data are not collected from the data subject).

One of the critical elements of exercising this right is the provision of a copy of the personal data. Case law has made it clear that this does not merely mean providing summary information, but the actual disclosure of specific data relating to the data subject. In certain cases, this may also include providing the relevant parts of complete documents (e.g. emails, reports).

The importance of handling access requests

Properly responding to access requests is not merely a procedural obligation; it is a key element of GDPR compliance as it directly supports the principles of transparency and accountability.

Where access requests are handled correctly, data controllers:

ensure compliance with the GDPR principle of transparent processing;

enable data subjects to effectively exercise their rights;

reduce the risk of supervisory investigations and administrative fines;

minimise the likelihood of disputes and litigation; and

strengthen trust in their data processing activities.

Conversely, inadequate or incomplete responses—such as failing to provide a copy of the personal data, insufficient redaction of third-party information or unjustified refusal of the request—may constitute standalone GDPR infringements and often lead to supervisory investigations following complaints lodged by data subjects.

Top 10 key considerations for exercising the right of access

Based on the European Data Protection Board (EDPB) Guidelines, the following practical considerations deserve particular attention when handling the exercise of the right of access:

  1. Access requests must be assessed based on their substance. They may not be rejected solely on formal grounds, and any request seeking access to personal data should be treated as a request to exercise the right of access.
  2. The data controller must conduct a search across all relevant systems, including electronic systems, email accounts, and archived data, and, where necessary, paper-based records.
  3. Where the data subject requests a copy of their personal data, the data controller must provide the actual personal data being processed. A summary or list alone is not sufficient. Depending on the circumstances, this may require providing the relevant excerpts from documents such as emails or reports, of course, while maintaining business confidentiality.
  4. The information provided must be intelligible. Where the disclosed data are technical, coded, or otherwise difficult to understand, explanatory information may also need to be provided.
  5. Where documents to be disclosed contain personal data relating to other individuals, the data controller must apply anonymisation or masking. Withholding the entire document is justified only in exceptional circumstances.
  6. Where the data controller has reasonable doubts regarding the identity of the requester, it must verify the data subject’s identity to ensure that personal data are disclosed only to the authorised individual, thereby safeguarding both the protection of personal data and the effective exercise of data subject rights.
  7. Identity verification should primarily rely on information already available to the data controller. Where necessary, supplementary verification measures may be used, such as email verification or online or in-person identification.
  8. Only the minimum amount of information necessary for identification may be requested. Excessive or unjustified authentication requirements may themselves constitute a breach of data protection law.
  9. Identity verification must always be proportionate and secure, taking into account the sensitivity of the personal data, the circumstances of the request, and the risk of misuse.
  10. Where appropriate, the data controller should document and be able to demonstrate that the identification and fulfilment measures applied were necessary and proportionate.

Proposed GDPR amendment – Procedural reform

Under the current GDPR framework, data subject requests must, as a general rule, be handled free of charge. A data controller may charge a reasonable fee or refuse to act on a request only where it is manifestly unfounded or excessive, in particular because of its repetitive nature. In such cases, the burden of proof rests with the data controller.

The proposed amendment to the GDPR would clarify this framework by expressly addressing abusive requests. A request could be regarded as abusive, for example, where there are reasonable grounds to believe that the data subject is exercising the right not for the purpose of protecting their personal data, but for another purpose, such as exerting pressure on the data controller or preparing for litigation.

One of the key elements of the proposal is that it would ease the data controller’s evidentiary burden. Rather than having to establish abuse with complete certainty, it may be sufficient to demonstrate that abuse is reasonably likely.

At the same time, the European Data Protection Board emphasises that any restriction of the right of access must remain exceptional, and that the concept of an “abusive request” should be interpreted narrowly. The proposal would not alter the substance of the right of access itself but is instead intended primarily to streamline procedures and promote greater consistency in regulatory enforcement.

Conclusion

The right of access remains one of the most critical areas of data protection compliance. Recent regulatory practice increasingly focuses on ensuring that data subjects receive meaningful access to information, while requiring data controllers to strike an appropriate balance between facilitating data subject rights, complying with the principle of data minimisation, and maintaining the security of personal data.

Data controllers should therefore ensure that they maintain an up-to-date record of processing activities and data inventories, establish consistent internal procedures for handling data subject requests, implement effective anonymisation and document review mechanisms, and provide regular training for employees involved in responding to such requests. It is equally important for data controllers to document the decisions taken throughout the handling of data subject requests, including the identity verification process and the factors considered when assessing whether a request may be abusive. This is particularly significant in light of the anticipated regulatory changes and increased scrutiny by supervisory authorities, which are likely to make these processes a key area of regulatory review.

Photo source: pexels.com, El Jundi

Data protection updates: the data subject’s right of access and expected developments Read More »

Uncertainty Surrounding U.S. Data Transfers: What to expect following the Trump v. Slaughter decision

Reading time: 4 minutes

The U.S. Supreme Court decision issued on 29 June 2026 (Trump v. Slaughter; hereinafter “Decision”) is likely to affect the legal assessment of international data transfers between the European Union and the United States and may mark a turning point in current practices in this area.

In its decision, the Supreme Court of the United States (“Supreme Court”), relying on the theory of a unified executive branch, concluded that all independent executive agencies operating in the United States are unconstitutional. The decision also directly affects the U.S Federal Trade Commission (“FTC”).

This development is of particular significance from the perspective of European data protection law, as the current EU–US Data Privacy Framework (the “EU–US Data Privacy Framework”, hereinafter “Framework”), adopted by the European Commission’s (“Commission”) Implementing Decision No. 2023/1795, designates the FTC as the independent supervisory authority responsible for ensuring compliance with data protection rules.

In our newsletter, we provide an overview of the most important rules governing data transfer practices between the European Union and the United States, and we also review what changes companies need to prepare for as a result of the Decision.

The regulatory framework for data transfers to third countries under the GDPR and the legacy of the Schrems decisions

Under Regulation 2016/679 on the protection of personal data (“GDPR”), the transfer of personal data to a third country is, as a general rule, lawful only if that country ensures an adequate level of protection. A key consideration in assessing adequacy is whether the third country has an independent and effective data protection supervisory authority capable of effectively enforcing and ensuring compliance with data protection rules. In the absence of such an authority or if it functions inadequately, a system of safeguards comparable to that at the EU level cannot be ensured. For this reason, the Commission may adopt an adequacy decision regarding a third country only if the legal system of the country under review – including through such an independent supervisory authority – ensures an adequate level of protection for personal data.

In this context, it is also important to note that the legal framework governing data transfers from the European Union to the United States has long been fraught with uncertainty. In its decisions in the Schrems I and Schrems II cases, the Court of Justice of the European Union previously invalidated the Safe Harbor framework and, subsequently, the Privacy Shield framework governing data transfers between the EU and the U.S. The court justified its decision by stating that, due to the mass surveillance practices applied in the United States and the lack of effective legal remedies, data subjects are not guaranteed a level of protection in accordance with EU data protection rules.

Thereafter, the current Framework was introduced as a sort of “third-generation” data transfer adequacy decision, which designates the FTC as the independent supervisory authority with respect to the United States. However, as a result of the Decision, it has become unclear whether the conditions necessary for the FTC’s independence continue to be met.

Why is this relevant for EU data controllers?

In the past few decades, many EU companies have outsourced their data processing activities to U.S. cloud service providers. However, the GDPR clearly stipulates that companies may lawfully transfer personal data to a third country – including the United States – only if the transfer is based on appropriate safeguards and a legal basis.

One possible legal basis for data transfers is what are known as adequacy decisions. In the context of relations between the European Union and the United States, the Framework serves currently this function. In the absence of an adequacy decision, data transfers may only take place lawfully if the organization in question provides appropriate safeguards, such as the use of the Standard Contractual Clauses (“SCC”) adopted by the European Commission or the implementation of Binding Corporate Rules (“BCR”).

If it is concluded that the FTC no longer meets the independence requirements set forth in the Framework, it is likely that the Commission will review the Framework in the future and, if necessary, repeal it.

We emphasize that this development may not be limited to data transfers carried out under the Framework. Data controllers who use SCCs or BCRs may also be affected, as, in accordance with the principle of accountability under the GDPR, companies are required to assess, as part of a data transfer impact assessment, whether the laws of the third country ensure the necessary level of protection. If this assessment concludes that the U.S.’s legal system – particularly with regard to government access or remedy mechanisms – does not provide adequate safeguards, then the use of SCCs or BCRs alone is not sufficient to maintain the lawfulness of the data transfer, and therefore they cannot provide an adequate basis for data transfers to the United States.

Recommended steps

Based on the above, the current developments require increased caution from all data controllers involved in international data transfers to the United States. The decision does not require immediate direct action; rather, it calls for a review of internal processes and appropriate risk management:

a comprehensive review of internal procedures governing data transfers;

updating data transfer impact assessments;

assessing whether it is necessary to implement additional technical measures, including, for example, the use of encryption;

identifying alternative data processing solutions.

Summary

It can therefore be concluded that the adequacy of the Framework is not clear; however, the Framework itself remains in effect until the Commission repeals it or the Court of Justice of the European Union annuls it. Consequently, the Decision does not currently have a direct impact on EU data controllers. However, companies are advised to review their practices regarding data transfers to the United States and, if necessary, prepare to implement alternative solutions.

Photo source: pexels.com, Mark Stebnicki

Uncertainty Surrounding U.S. Data Transfers: What to expect following the Trump v. Slaughter decision Read More »

The EDPS 2025 Annual Report: A New Era in Corporate Data Protection and Technological Compliance

Reading time: 6 minutes

The European Data Protection Supervisor (EDPS) has published its 2025 Annual Report (hereinafter: the “Report“), providing a detailed account of its activities to protect personal data in a rapidly changing digital world. The Report clearly signals that the European data protection and digital regulatory environment has entered a new phase: the focus is no longer merely on formal GDPR policies, but on the actual operational controls of AI systems, cloud services, and international data transfers. The investigations typically center on tools and processes that most organizations use on a daily basis: Microsoft 365, cloud infrastructure, generative AI solutions, mobile applications, and HR systems. In this article, we present the main findings of the Report and outline the key aspects and recommendations necessary for compliance.

AI Governance: A new dimension of compliance

One of the most important messages of the Report is that corporate control over artificial intelligence (AI governance) will shortly develop into a standalone, high-priority compliance area. Artificial intelligence is no longer an experimental technology; it has become an integral part of daily operations within EU institutions and an increasing number of organizations. In preparation, the EDPS has already taken the first major steps:

Established a dedicated AI unit: It has strengthened its newly created AI unit to prepare for supervisory duties under the EU Artificial Intelligence Act.

Mapped generative AI usage: It assessed the current AI ecosystem regarding prohibited practices and high-risk systems, and published a report highlighting the dominant areas of AI use and enforcement priorities.

Launched an AI regulatory sandbox program: Within the framework of a pilot project, it created a safe regulatory testing environment for developing and testing innovative AI systems under supervisory oversight.

Issued a new AI risk management guide for identifying and mitigating technical risks associated with the development and deployment of AI systems.

Regulatory focus is intensifying particularly in the following specific areas:

the corporate use of generative AI tools;

the compliance of off-the-shelf AI solutions;

the strict control of high-risk AI systems;

the legal relationship between AI and personal data;

the technical risk management of AI systems.

In a corporate environment, this means that the use of AI is no longer exclusively an IT or innovation issue, but a key legal, compliance, and data protection risk area. Therefore, organizations must prepare now to introduce, document, supervise, and use AI solutions in their daily operations in accordance with the requirements of the GDPR and the EU Artificial Intelligence Act.

Microsoft 365 and enterprise IT systems

In 2025, the EDPS further strengthened its oversight over large IT systems, including cloud services similar to Microsoft 365. The lesson from previous investigations is that compliance is not solely a contractual matter but requires an assessment covering the entire lifecycle of data processing.

The investigations focused on issues that are also critical for large enterprises:

international data transfers to third countries;

the transparency of complex sub-processing chains;

the control of access to data;

the existence of appropriate technical and organizational guarantees.

A key message of the Report is that a service agreement or a “GDPR-compliant” label alone is no longer sufficient. Supervisory practice increasingly examines actual operational controls, technical measures, and documented risk assessments. For this reason, it is definitely recommended to conduct a limited review of supplier contracts from a data protection perspective – based on our recommendation, it is sufficient to do this once and then incorporate a control into the process that ensures compliance in the event of changes or that allows for periodic reviews and follow-up checks.

International data transfers

Data transfers to third countries remain a high-priority enforcement area. The EDPS emphasizes that appropriate contractual clauses are not sufficient on their own. In assessing compliance, an increasingly important role is played by the actual content of the Transfer Impact Assessment (TIA), the evaluation of the legal and practical environment of the third country, and the real-world operation of the applied technical and organizational measures. In modern cloud-based systems, according to data protection law, remote access also constitutes a data transfer. If a third-country IT engineer (e.g., from India or the United States) logs into a database stored in Europe for support or system maintenance purposes, the data legally leaves the EEA. These risks can only be meaningfully assessed by a TIA. This is particularly relevant in environments where global cloud infrastructures or centralized IT support operate. In practice, this means that companies should assess whether data transfers outside the EU occur due to the nature of the supplier’s operations or due to the processes required by the corporate group, and classify them accordingly.

The future of data protection will be technologically focused

Based on the EDPS Report, European data protection practice has definitively shifted in a technological direction. At the center of the supervisory focus stands the understandable and accountable operation of artificial intelligence, the continuous monitoring of cloud services, and the complete fusion of cybersecurity and data protection. Data protection compliance is thus no longer an isolated legal task, but a shared, daily responsibility of corporate management, procurement, digital transformation, and IT security.

Based on the EDPS Report, it is clearly visible: in the coming years, organizations that recognize this paradigm shift and build a real, auditable technological governance system – rather than just a formal, paper-based GDPR compliance – will hold a clear competitive advantage.

Photo source: pexels.com, Fotó: Jcmotive

The EDPS 2025 Annual Report: A New Era in Corporate Data Protection and Technological Compliance Read More »

CLVPartners has achieved outstanding results in the 2026 guides of Chambers and Partners Europe© and Legal 500©

We are pleased to announce that Chambers and Partners© and Legal 500© have ranked our firm for the 13th consecutive year in 2026, and in multiple categories: we are one of the few firms in Hungary to have been recognized in the areas of labor law, commercial law, corporate law, and M&A, as well as data protection.

This year marks a particularly significant milestone for us, as we have moved up one category and achieved a higher band rating.

As a boutique law firm competing against the largest international firms with nearly 100 employees, this achievement is a significant recognition for us, one that reaffirms our professional commitment and our dedication to providing our clients with the highest level of service.

We are particularly pleased that our managing partner, Anna Papp, has also received individual recognition and was listed in the guide among Hungary’s notable practitioners in the field of labour law.

We would like to share some feedback that is particularly valuable to us, which our clients provided to the certification body:

„The law firm’s technical strength, practical mindset and outstanding client care make it genuinely distinctive within the employment law market.”

„The team is approachable, easy to reach and provides timely advice, even on short notice. Its ability to balance quick turnarounds with well-considered, practical guidance is a key strength.”

“The firm has particularly extensive experience in designing whistleblowing systems and managing data protection requirements for internal workplace investigations. This includes ensuring that the principle of ‘privacy by design’ is upheld even when investigating sensitive corporate matters or reports of harassment.”

“CLVPartners is always flexible, proactive, and solution-oriented. Their approach is holistic: beyond solving the immediate problem, they highlight areas we may not have considered but which are essential.”

“Anna Papp demonstrates flexibility, preparedness, extensive experience, precision and client focus. In addition to her comprehensive expertise, she also understands the practical side of things.”

“We can count on Anna Papp for all our questions. We don’t have a problem that she doesn’t have a suggestion for. Her professional knowledge and dedication are outstanding”.

“Barbara Seregély has extensive experience in cross-border mergers and acquisitions and corporate law.”

“Anikó Hrebenku delivers an excellent client experience, ensuring that each matter is handled by experts who provide consistent support.”

We would like to thank our clients for their trust and valuable feedback throughout the year. We remain committed to continuing to effectively support our clients’ day-to-day operations.

Photo source: pexels.com, Fotó: Pixabay

CLVPartners has achieved outstanding results in the 2026 guides of Chambers and Partners Europe© and Legal 500© Read More »

Data protection considerations related to the development of AI models

Reading time: 5 minutes

Artificial intelligence (“AI“) is a rapidly evolving family of technologies that contributes to a wide range of economic, environmental, and social benefits across all sectors and social activities. By improving predictive accuracy, optimizing operational processes and the allocation of resources, and enabling the personalization of digital solutions available to individuals and organizations, the use of AI can confer a decisive competitive advantage on businesses while also delivering beneficial social and environmental outcomes.

The use of artificial intelligence, alongside its potential benefits, is also associated with certain risks. In order to mitigate these risks, Regulation (EU) 2024/1689 of the European Parliament and of the Council on artificial intelligence (“AI Act”) has been adopted, several provisions of which have already entered into force. At the same time, the development of many AI models involves the use of personal data, which raises the question of how the AI Act affects data processing activities related to AI systems.

The relationship between the AI Act and the GDPR

The AI Act makes it clear that it does not amend the application of existing EU rules on the processing of personal data, including the requirements set out in the GDPR. Accordingly, organizations falling within the scope of the AI Act must, in the course of their data processing activities, comply fully with the provisions of the GDPR.

Through the enforcement of the right to the protection of personal data, the GDPR also supports the effective exercise of other fundamental rights, including, inter alia, freedom of thought and expression, the right to information and education, and the freedom to conduct a business. On this basis, it can be concluded that the GDPR establishes a legal framework that facilitates responsible innovation, including the responsible development and deployment of AI-related technologies.

Data protection considerations in relation with the development of AI Models

In connection with the development of AI models, the European Data Protection Board (“EDPB”) adopted a standalone opinion on data protection aspects arising in relation to the processing of personal data in the context of artificial intelligence models (“Opinion”).

The Opinion examines how personal data may be used in the development of AI models and highlights the issues requiring particular attention when placing on the market AI systems developed using personal data.

Lifecycle of AI Models

The EDPB divides the lifecycle of AI models into two stages, emphasizing that data processing may occur in either of them. The first stage covers the processes preceding the deployment of the model (including e.g. its creation, development, the training, the fine-tuning). The second stage relates to the deployment phase, encompassing the use of the model following its development.

Existence of a legal basis for data processing by data controllers

One of the cornerstones of data protection regulation is that personal data may only be processed where a specific legal basis exists. The Opinion reiterates the general expectation that data controllers must determine the appropriate legal basis for their processing activities.

However, the EDPB found that, as a general rule, an AI model developer may rely on legitimate interest as a legal basis, provided that the existence of such legitimate interest is duly substantiated. For this purpose, a three-step test – already familiar to those with experience in data protection compliance practice – serves to properly assess whether a legitimate interest genuinely exists.

The EDPB emphasizes that the balancing test must take into account whether the data subjects can reasonably expect their personal data to be used. The Opinion is significant in this regard because it sets out several criteria intended to assist data protection authorities in assessing the “reasonably foreseeable” criteria

The Opinion also recalls that, where it appears that the interests, rights, and freedoms of data subjects override the legitimate interests of the data controller or of a third party, all is not lost. Namely, the data controller may consider the implementation of mitigating measures to limit such adverse effects. These may include, for example, pseudonymization, or measures aimed at masking personal data or replacing them with fictitious personal data within the training dataset. The introduction of appropriate data protection measures can make data processing lawful again.

Anonymity

The GDPR classifies as personal data any information relating to an identified or identifiable natural person, whether directly or indirectly. According to the position of the EU institution, in the context of AI model development, personal data may only be used where they are properly anonymized, such that even in the event of a potential reverse engineering of the model, the identification of data subjects is not possible. With regard to anonymization, the EDPB emphasizes that the competent data protection authorities must assess, on a case-by-case basis, whether the organization developing the AI model has complied with this requirement. The body also sets out several recommended technique that may be suitable for preserving anonymity (e.g. prevent or limit the extraction of personal data used for training purposes).

Summary

The EU body emphasizes in its Opinion that compliance with data protection requirements governing the processing of personal data must be ensured throughout both the development and deployment of AI models. It is evident that the expansion of AI and its potential risks are being treated and monitored as a priority in law enforcement, and therefore numerous regulatory guidelines from authorities can be expected in the near future.

Photo source: pexels.com, Tara Winstead

Data protection considerations related to the development of AI models Read More »

Data and Information Security: The Relationship Between GDPR and NIS2

Reading time: 6 minutes

With the rise of digitalization and data-driven decision-making, the volume of sensitive information has increased, along with the associated cyber risk. It has become necessary to establish a regulatory framework that provides guidance on managing expectations, responsibilities, and approaches shaped by the technological environment. Its two main pillars are the European Parliament and Council Directive (EU) 2022/2555 (14 December 2022) (general EU cybersecurity directive, hereinafter: “NIS2 Directive”), implemented in Hungary through Act LXIX of 2024 on Cybersecurity (“Cybersecurity Act”), and the European Parliament and Council Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and the free movement of such data, repealing Directive 95/46/EC (“GDPR”), which ensures data protection compliance.

The NIS2 Directive, the resulting national cybersecurity regulations, and GDPR apply different perspectives; however, the affected areas often overlap in practice, particularly in electronic information systems that process personal data. Therefore, aligning the requirements of these two regulatory frameworks is essential for the lawful and secure operation of the affected organizations. This article outlines the relationship between the NIS2 Directive and national regulations with GDPR, their overlaps, conflicts, and practical resolutions.

Scope of NIS2 and GDPR: Dual obligations

The GDPR applies to all organizations that qualify as data controllers, meaning they determine the purposes and means of processing personal data either independently or jointly with others. The scope of NIS2 is determined based on a complex set of criteria, which may include various enterprises depending on their activities, size, and revenue. Consequently, if an entity falls under both NIS2 and GDPR, it must comply with the rules of both frameworks simultaneously. For example, a medium- or large-sized company in the manufacturing sector may be subject to cybersecurity regulations based on its activities and size, and in the course of its activities, it typically processes at least employee and supplier data as a data controller, thus requiring the application of both the GDPR and NIS2 provisions.

In practice, electronic information systems often process personal data, such as HR systems or customer databases. In the event of an incident, both GDPR and NIS2 impose obligations on the organization. A data protection incident involves a breach of security that results in accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access to personal data, whereas a cybersecurity incident refers to an event that threatens the availability, integrity, or confidentiality of data stored, transmitted, or processed in electronic information systems, or the services provided or accessible through such systems. Therefore, if a cybersecurity incident involves personal data—for example, data loss or leakage due to a phishing email or a ransomware attack—it simultaneously constitutes a data protection incident. Consequently, incident handling must comply with both regulations, and notifications to the competent authorities must be made when conditions are met. For this purpose, it is advisable to establish an internal procedure that accounts for the obligations required by both frameworks.

Proper classification of incidents is particularly important, as different types of incidents have distinct notification obligations, content requirements, and deadlines. In a data protection incident, the organization must first assess whether the event poses a risk to the rights and freedoms of natural persons. If such a risk is likely, the incident must be reported to the National Authority for Data Protection and Freedom of Information within 72 hours, and, in case of high risk, the affected individuals must also be notified. Cybersecurity incidents, on the other hand, follow a different procedure: the organization must report the incident within 24 hours based on the available information, submit a detailed report within 72 hours, and, after completing the investigation, submit a final report to the national cybersecurity incident handling center no later than 30 days. Since GDPR and cybersecurity rules define incidents and related obligations differently, situations may arise where an event qualifies as a cybersecurity incident but does not require a data protection incident report.

The practical significance of dual compliance is illustrated by a medium- or large-sized company engaged in “other machinery manufacturing,” which falls under the scope of the NIS2 Directive. If the company suffers an incident as a result of which the attacker gains unauthorized access to a server containing employees’ personal data, the event must be assessed not only from a data protection perspective but also under the Cybersecurity Act. According to the law, any threat, near-incident, or actual incident—including operational cybersecurity incidents—that causes severe disruption or financial loss to the organization or significant material or immaterial harm to others must be reported without undue delay, but no later than 24 hours, to the competent cybersecurity incident handling center. This example highlights that organizations must comply with both legal frameworks simultaneously and design incident handling accordingly.

Aligning processes at the documentation and operational levels

If an organization falls under both GDPR and cybersecurity regulations, the documentation and operational processes required by both frameworks must be aligned for dual compliance. GDPR requires that the organization maintain a data protection policy, provide a privacy notice to data subjects, and, in some cases, conduct a data protection impact assessment. Similarly, cybersecurity rules require the establishment of an information security policy. In addition, both frameworks require regulation of incident management processes and training to raise awareness among relevant staff.

The organization’s leadership is responsible for complying with NIS2 and GDPR requirements, while the data protection officer and the professional responsible for the security of electronic information systems play a key role in ensuring compliance. To avoid parallel, isolated processes, it is essential for information security and data protection officers to collaborate actively on a daily basis. Aligning the requirements of both frameworks is not merely an administrative task: its significance lies in the fact that both areas rely on the same information systems, data flows, and risks, even if they examine them from different perspectives. When an organization designs its processes in a unified, coherent manner, overlaps can be avoided, error risks reduced, and both cybersecurity and data protection requirements can be ensured. Incident management processes should be designed to ensure that any potential event is handled in a way that fulfills the obligations of both frameworks. This approach is not only resource-efficient but also strengthens legal compliance, system security, and the trust of clients, partners, and employees.

NIS2 and GDPR serve different purposes and approach the same events differently. GDPR’s primary objective is to protect the rights and freedoms of natural persons, whereas NIS2 focuses on strengthening information system security, safeguarding service continuity, and increasing resilience against cyber threats. Accordingly, the two frameworks impose different expectations on organizations: GDPR emphasizes data minimization and purpose limitation, while NIS2 specifically requires detailed logging, continuous monitoring, and retention of log files. This often results in NIS2 compliance requiring the storage of large volumes of technically processed personal data, which must be handled carefully from a data protection perspective.

Apparent conflicts between the two regulations can be resolved in practice through a coordinated approach. One key step is integrating information security risk assessments with GDPR data protection impact assessments, as both assess the same systems, data flows, and risk factors from different perspectives. Equally important is designing internal policies that simultaneously comply with mandatory cybersecurity measures and GDPR provisions.

Both NIS2 and GDPR require that organizations properly train all personnel who have access to information systems or process personal data. Therefore, it is advisable to align the strategic planning and content of training programs, considering risk assessment results, previous incidents, regulatory changes, and the professional opinions of the organization’s security experts. True alignment between the two regulatory areas is important not only for legal compliance but also for operational security, risk reduction, and maintaining internal and external trust.

Conclusion

GDPR and the NIS2 Directive serve different purposes but converge on many points regarding information security requirements. Dual compliance therefore requires careful alignment: interpreting the regulations consistently and integrating related procedures can ensure that an organization meets the expectations of both frameworks simultaneously. Coherent revision of professional documentation and operational processes, coordination of internal responsibilities, and alignment of regular training and audits facilitate achieving both GDPR data protection and NIS2 cybersecurity goals. Compliance with these requirements strengthens the organization’s information security and data protection resilience, meeting the relevant EU and national legal obligations.

Photo source: pexels.com, Kevin Ku

Data and Information Security: The Relationship Between GDPR and NIS2 Read More »

Data Subject Rights and the Importance of Consent in Online Content Creation

Reading time: 4 minutes

With the development of digital platforms, anyone can become a content creator today: a smartphone, a good idea, and a few clicks are enough for our messages, videos, or pictures to reach thousands of people. However, online presence carries not only creative opportunities but also legal responsibilities and risk. When sharing various types of content – such as posts or videos – especially if identifiable persons appear in them, the processing of personal data occur.

General applicability of the GDPR

The General Data Protection Regulation (EU) 2016/679 of the European Parliament and of the Council (“GDPR”), on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, serves a dual purpose: it ensures the protection of individuals’ personal data while also providing a framework for the free flow of such data within the European Union. The GDPR sets out in detail the rights of data subjects and the obligations of data controllers.

At the same time, the GDPR does not be applicable in certain exceptional cases; one such exception applies when a natural person processes personal data exclusively for personal purposes. Examples include private correspondence whether on paper or electronically, storage of addresses or contact details, personal notes or diaries, family photographs, communication on social networks, and other online activities. These exceptions must be interpreted narrowly, and data processing only falls outside the scope of the GDPR if it serves a purely private purpose – that is, it has no community, professional, or economic aspect. Thus, if data can be accessed by an indefinite number of persons or is made public, the activity no longer qualifies as private data processing. In the case of data processing carried out by business entities, personal or household use cannot be invoked. Therefore, the publication of any online content containing personal data (such as photographs, audio recordings, or other information) – whether it concerns employees or any other natural person – requires appropriate legal diligence in all cases.

Data processing related to online content creation

Digital platforms widely enable users to create and share photos, videos, or audio recordings – even of other people. The question may arise whether data protection rules apply in such cases. Since uploaded recordings – including images, voices, or other identifiable information – constitute personal data and are made accessible to the public, their processing falls under the GDPR.

One of the fundamental principles of data protection is that any processing of personal data must be based on a valid legal basis. When a data controller undertakes any activity involving the processing of personal data, it must carefully assess which legal basis best suits the intended purpose. In the context of content creation, data processing most commonly relies on the data subject’s consent.

Obtaining consent is crucial, as recording or publishing someone else’s image or voice is only lawful if the data subject has given explicit, informed, and prior consent. Simply tolerating the presence of a camera or answering a question does not constitute valid consent. This demonstrates how strictly the GDPR defines the requirement of a lawful basis: unlike the Hungarian Civil Code (“Civil Code”), which allows certain exceptions for public figures or mass recordings, the GDPR does not provide such derogations. This highlights the coexistence of parallel legal frameworks – compliance with the Civil Code does not necessarily mean compliance with data protection law, thus each legal regime has distinct requirements for lawful conduct.

Consequences of Non-Compliance

Publishing content online without a valid legal basis – such as consent – constitutes a violation of data protection rules. Unlawful data processing can have serious consequences, including regulatory procedures and administrative fines. If a recording is made or published without permission and results in significant harm to an individual’s interests, the act may not only be unlawful under data protection law but could also amount to a criminal offence or establish a claim for non-pecuniary damages under the Civil Code, depending on the circumstances. Liability always lies with the person who created or published the recording.

Particularly high-risk situations include cases involving children, healthcare settings, political opinions, or other sensitive personal data. If such content is shared without the data subject’s knowledge or consent, it does not qualify as private activity and is considered full-fledged data processing under the GDPR. In such cases, data subjects have the right to request information, withdraw consent, demand deletion of recordings, and pursue legal remedies.

Summary

Presence in the online space – particularly in the context of corporate communications, marketing, or HR content creation – requires careful data protection practices. What may not entail legal consequences under the Civil Code can still constitute a data protection violation.

Consent is therefore not a mere formality, but one of the fundamental prerequisites for lawful data processing. Organizations – whether content creators or employers – are advised to establish internal procedures, training programs, or policies to manage the data protection risks associated with online content creation.

Respecting data subject rights, properly documenting consents, and complying with GDPR requirements are not only matters of legal compliance, but also essential for maintaining corporate reputation and trust.

Photo source: pexels.com, Plann

Data Subject Rights and the Importance of Consent in Online Content Creation Read More »

The European Data Protection Board’s strategy and the proposal to ease the GDPR to reduce the administrative burden on businesses

The European Data Protection Board’s strategy and the proposal to ease the GDPR to reduce the administrative burden on businesses

Reading time: 4 minutes

The European Data Protection Board has published its report for 2024 (“Report“) again this year, setting out the fundamental goals of its strategy for the period up to 2027, one of them is to promote compliance with data protection rules. In May this year, the European Commission (“Commission“) submitted a proposal (“Simplification Proposal“) aimed at simplifying the GDPR in order to reduce the administrative burden on businesses, which was also welcomed by the European Data Protection Board. In this article, we summarize the main conclusions of the Report and future strategy of the Board, and address the Simplification Proposal.

The role of European Data Protection Board in the field of data protection

The European Data Protection Board’ has a multifaceted mission and legal mandate:

  • ensures the consistent application of EU data protection rules,
  • promotes effective cooperation between data protection authorities in the European Economic Area (EEA),
  • supports the harmonised enforcement of the GDPR,
  • examines issues relating to the application of the regulation,
  • issues guidelines, recommendations, and best practices to promote the consistent application of the GDPR and review their application where necessary.

Key findings of the Report

The European Data Protection Board may examine and issue an opinion on any matter of general application or having implications in more than one Member State, at the request of any supervisory authority, the Chair of the European Data Protection Board, or the European Commission. The European Data Protection Board continues its activities this year, adopting new guidelines on pseudonymization, which we discussed in this article. The European Data Protection Board announces coordinated enforcement actions every year. In 2024, it focused on the right of access, while in 2025, it plans to review the enforcement of the right to erasure, as reported in this article.

The European Data Protection Board also continued its active dialogue with data subjects and organizations involved in data processing, which resulted in the publication of articulate factsheets. For example, in a such factsheet, the Board presented the most significant positive and negative effects of artificial intelligence on cybersecurity. (The factsheet in English can be opened in this link).

Strategy for the period between 2024-2027

In its strategy for the period 2024–2027, the European Data Protection Board has set out four main pillars of objectives.

  • promoting consistent application of data protection rules and compliance,
  • strengthening international cooperation between data protection authorities,
  • ensuring data protection in an emerging digital environment covering multiple regulatory areas (e.g., artificial intelligence),
  • support for global dialogue on privacy and data protection issues.

The Board also confirmed that it intends to continue to play an active role in shaping the regulatory environment for small and medium-sized enterprises („SME”). In addition, it has set as a priority to help SMEs comply with the law through specific tools and to contribute to raising public awareness of the importance of data protection rights.

Simplification Proposal

The Commission pointed out that the complexity of EU legislation hinders market entry and limits growth potential. In order to achieve the objective, set out in the report, in May 2025 it published its fourth so called omnibus package, in which the Commission proposed amendments to various EU rules, including those relating to GDPR rules on record keeping obligation.

According to the GDPR the record of processing activities currently is a fundamental tool for data controllers and processors to identify and document their data processing activities. For illustrative purposes only, we mention that such elements the purpose of data processing, the categories of data subjects and recipients, the retention period, and, where applicable, the transfer of data to third countries.

According to the applicable regulation, data controllers and data processors are only exempt from the obligation to maintain their record of processing activities if they employ fewer than 250 persons. However, companies with fewer than 250 employees are also required to keep records if

  • the processing is likely to result in a risk to the rights and freedoms of data subjects;
  • the processing is not occasional;
  • the processing concerns special categories of data or personal data relating to criminal convictions and offenses.

Due to the subjective nature of the list, we recommend that companies striving for compliance keep records in all cases in order to minimize risks.

This was also recognized by the Commission, namely that even with a threshold of 250 employees, there were very few cases in which companies were exempt from the record keeping requirement. Therefore, according to the Simplification Proposal, in the future, companies that employ fewer than 750 employees and whose turnover does not exceed EUR 150 million or whose total assets do not exceed EUR 129 million will not be required to keep records. Data processing activities that are expected to impose a high risk on data subjects, such as employees or customers, would continue to be subject to the company’s record keeping obligation.

The Commission estimates that this measure would exempt around 38,000 businesses in the EU from the registration requirement and reduce the administrative burden on businesses by around EUR 400 million per year.

The European Data Protection Board expressed its endorsement of the Simplification Proposal. At the same time, it also made data controllers aware of the fact that keeping records of data processing activities not only makes it possible to comply with the regulations but also serves as a useful tool for meeting other GDPR requirements.

In summary, it is clear that companies are still expected to:

  • have up-to-date information regarding their data processing (whether with or without a record);
  • ensure transparency in data processing and to take data processing considerations into account when designing their processes.
  • consciously consider what documentation obligations they have;
  • to enforce the stricter regulations in key areas.

Image soruce: pexels.com, Marco

The European Data Protection Board’s strategy and the proposal to ease the GDPR to reduce the administrative burden on businesses Read More »

CLVPartners
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.