CLVPartners

GDPR

Resolution on criteria for setting administrative fines

In its resolution published on 19 September 2018, the National Authority for Data Protection and Freedom of Information (NAIH) assessed the criteria to take into consideration during the process of setting a fine, especially the level of the fine that NAIH may impose in case of the first infringement of the data protection regulations.

The Authority is being guided by the provisions of the Regulation (EU) 2016/679 of the European Parliament and of the Council (“Regulation”) and the Act CXII of 2011 on Informational Self-determination and Freedom of Information (“Info Act”) with regard to the determination of the fine.

Article 83 (1) of the Regulation states, that the administrative fines shall be effective, proportionate and dissuasive. Pursuant to Preamble (148) in a case of a minor infringement or if the fine likely to be imposed would constitute a disproportionate burden to a natural person, a reprimand may be issued instead of a fine.

This provision was completed by Section 75/A of the Info Act according to which the Authority shall exercise its competence provided for in Article 83 (2)-(6) of the Regulation in due consideration of the principle of proportionality, in particular with the provision that in the event of any non-compliance with the Regulation for the first time, the Authority shall in principle issue warning to the data controller or data processor in order to arrange the remedy of the infringement.

The Authority shall take into account the Data Protection Working Party (WP29) guidelines on the application and setting of administrative fines for the purposes of the Regulation 2016/679, available at the following link: http://ec.europa.eu/newsroom/article29/item-detail.cfm?item_id=611237

Resolution on criteria for setting administrative fines Read More »

The National Authority for Data Protection and Freedom of Information regulates “cookies”

The National Authority for Data Protection and Freedom of Information published a notice about the data protection requirements of “cookies” this February.
The National Authority for Data Protection and Freedom of Information in its February announcement summarised the experiences on the data protection requirements of the “cookies” used by webshops, with a clear intention to create a legitimate and coherent practice.

The Authority draws attention to the fact that the at the same time, on 25 May 2018, both the new regulations on the general data protection and the new electronic communication regulation will enter into force, and the latter will regulate and standardise the cookies in the European Union.

The publication pointed out that to the direct marketing newsletters (DM Letters) not only the Law on Advertising and the Electronic Commerce Act shall be applied, but the Data Protection Law as well.

The National Authority for Data Protection and Freedom of Information regulates “cookies” Read More »

The new EU General Data Protection Regulation has been approved

After long years of negotiations, on 14 April 2016 the EU Parliament approved the general data protection regulation (“Regulation”), which – compared to the current rules – means changes both for private persons and companies.

The Regulation shall replace the current EU Directive, being implemented by the member states in certain cases quite different ways, and a new, consolidated regime shall be directly implemented by the member states.

The Regulation will enter into force after two years from its approval, however, due to the significant changes included therein, it is advisable for companies to start reviewing their internal rules and prepare for their potential amendments. The infringement of the new rules may be subject to a fine of up to 20.000.000 EUR, or in case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year (whichever is higher).

Should you have any questions regarding the above, please feel free to contact us.
Dr. Marianna Csabai
H-1126 Budapest, Tartsay Vilmos u. 3.
Tel: + 36 1 488 7008
Fax: + 36 1 488 7009
E-mail:

 

The new EU General Data Protection Regulation has been approved Read More »

News on adendment of information act with the effect form 1 October, 2015

The act CXII of 2011 on information self-determination and freedom of information („Information Act”) has been amended with the effect of 1 October, 2015.

The amendments provide new possibilities regarding the forwarding of personal data to third countries as it is possible for the datacontroller to provide adequate level of protection to forward the data to third countries with the preparation and application of binding corporate rules („BCR”). It is a significant change also in the light of the recent EU Court decision on the invalidity of the Safe Harbour agreement.

Moreover to the significant amendments above the provisions of Information Act regarding the rights of affected people are amended as well and the amount of fine give by NAIH is also amended as it can be twenty million forints at the highest (instead of the prior ten million forints).
 

Should you have any questions regarding the above, please feel free to contact us.
 
Dr. Marianna Csabai
H-1126 Budapest, Tartsay Vilmos u. 3.
Tel: + 36 1 488 7008
Fax: + 36 1 488 7009
E-mail:

News on adendment of information act with the effect form 1 October, 2015 Read More »

CLVPartners
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.