INFORMATION SHEET
ON THE PROCESSING OF NATURAL PERSONS’ DATA BY THE COMPANY AND THE RIGHTS OF DATA SUBJECTS
TABLE OF CONTENTS
INTRODUCTION
I. CHAPTER – IDENTIFICATION OF THE DATA CONTROLLER
1. The publisher of this information, who is also the Data Controller: András Nonn, sole trader
CHAPTER II – IDENTIFICATION OF DATA PROCESSORS
2. Our company does not have any partnerships with other businesses for the purposes of data processing.
CHAPTER III – INFORMATION ON SPECIFIC DATA PROCESSING OPERATIONS
- 3. Information on data processing based on the data subject’s consent
- 4. Information on the processing of customer data, contracting partners’ data and contact details
- 5. Information on data processing based on compliance with a legal obligation
- 6. Information on data processing carried out for the purpose of complying with tax and accounting obligations
- 7. Information on the processing of payers’ data
- 8. Information on the processing of data relating to records of enduring value under the Archives Act
- 9. Promoting the rights of data subjects
CHAPTER IV – PROCESSING OF VISITOR DATA ON THE COMPANY’S WEBSITE – INFORMATION ON THE USE OF COOKIES
- 10. General information about cookies
- 11. Information on the cookies used on the Company’s website and the data generated during a visit
CHAPTER V – INFORMATION ON THE RIGHTS OF THE DATA SUBJECT
- 12. A brief summary of the data subject’s rights
- 13. The data subject’s rights in detail:
INTRODUCTION
REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (EU) 2016/679 (hereinafter: the Regulation) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, stipulates that the Data Controller shall take appropriate measures to ensure that all information relating to the processing of personal data is provided to the data subject in a concise, transparent, comprehensible and easily accessible form, expressed in clear and plain language, and that the Data Controller shall facilitate the exercise of the data subject’s rights.
The data subject’s obligation to provide prior information is also laid down in Act CXII of 2011 on the right to informational self-determination and freedom of information.
We fulfil this legal obligation by providing the information set out below.
The information must be published on the company’s website or sent to the data subject upon request.
I. CHAPTER
NAME OF THE DATA CONTROLLER
1. The publisher of this information, who is also the Data Controller:
| COMPANY NAME: | András Nonn (retired). |
| REGISTERED OFFICE: | 1074 Budapest, 30/B Dohány Street, 2nd floor, flat 3. |
| REGISTRATION NUMBER: | 57350820 |
| TAX NUMBER: | 59331001-1-42 |
| WEBSITE: | www.ncz.hu |
| E-MAIL ADDRESS: | info@ncz.hu |
| TELEPHONE NUMBER: | +36 20 420-8090 |
| NAME OF MP: | András Nonn |
(hereinafter referred to as: the Company or the Data Controller)
CHAPTER II
LIST OF DATA PROCESSORS
Data processor: a natural or legal person, public authority, agency or any other body which processes personal data on behalf of the data controller; (Article 4(8) of the Regulation)
The use of a data processor does not require the data subject’s prior consent, but they must be informed. Accordingly, we provide the following information:
2. Our company’s data processors
2.1. Our company does not have an IT service provider
2.2. Our company does not use a logistics service provider
CHAPTER III
INFORMATION ON SPECIFIC DATA PROCESSING ACTIVITIES
3. Information on data processing based on the data subject’s consent
3.1. Where the Company intends to process data on the basis of consent, the data subject’s consent to the processing of their personal data must be sought using the content and information set out in the data request form specified in the data protection policy.
3.2. Consent is also deemed to have been given if the data subject ticks a relevant box whilst viewing the Company’s website, makes the relevant technical settings whilst using information society services, or makes any other statement or takes any other action which, in the given context, clearly indicates the data subject’s consent to the intended processing of their personal data. Silence, a pre-ticked box or inaction shall therefore not be deemed to constitute consent.
3.3. Consent covers all data processing activities carried out for the same purpose or purposes. Where data processing serves more than one purpose at the same time, consent must be given in respect of all such purposes.
3.4. If the data subject gives their consent by way of a written statement that also relates to other matters – e.g., the conclusion of a sales or service contract – the request for consent must be presented in a manner that is clearly distinguishable from those other matters, in an intelligible and easily accessible form, using clear and plain language. Any part of such a statement containing the data subject’s consent which contravenes the Regulation is not legally binding.
3.5. The Company may not make the conclusion or performance of a contract conditional upon the provision of consent to the processing of personal data that is not necessary for the performance of the contract.
3.6. It must be just as easy to withdraw consent as it is to give it.
3.7. Where personal data has been collected with the data subject’s consent, the data controller may, in the absence of any provision to the contrary in law, process the data collected for the purpose of fulfilling a legal obligation to which it is subject, without requiring further specific consent, and even after the data subject has withdrawn their consent.
4. Information on the processing of customer data, contracting partners’ data and contact details
4.1. On the legal basis of the performance of a contract, the Company processes the name, birth name and date of birth of any natural person with whom it has entered into a contract as a customer or supplier, as well as mother’s name, address, tax identification number, tax registration number, business licence number, primary producer’s licence number, identity card number, residential address, registered office and business premises addresses, telephone number, email address, website address, bank account number, customer number (client number, order number), online identifier (lists of customers and suppliers, regular customer lists), This data processing is considered lawful even if it is necessary to take steps at the data subject’s request prior to entering into a contract. Recipients of personal data: the Company’s employees responsible for customer service tasks, employees responsible for accounting and tax matters, and data processors. Retention period for personal data: 5 years following the termination of the contract.
4.2. The legal basis for the processing of the personal data of a natural person who is a contracting party, as provided in the contract, for accounting and tax purposes is compliance with a legal obligation; in this context, the data retention period is 8 years.
4.3. The Company shall process the personal data of the natural person acting on behalf of the legal entity contracting with it – the person signing the contract – as specified in the contract, as well as their address, email address, telephone number and online identifier of the natural person acting on behalf of the legal entity contracting with it – the signatory to the contract – on the grounds of legitimate interest for the purposes of maintaining contact and exercising the rights and obligations arising from the contract. The retention period for this data is 5 years following the termination of the contract. In the case of data processing based on legitimate interests, the data subject has the specific right to object to the processing of their data.
4.4. The Company processes the name, address, telephone number, email address and online identifier of the natural person designated as the contact person – who is not a signatory – in the contract concluded with it, on the grounds of legitimate interest for the purposes of maintaining contact and and to exercise the rights and obligations arising from the contract, on the basis of a legitimate interest, provided that the contact person is in an employment relationship with the contracting party; thus, this data processing does not adversely affect the data subject’s rights. The contracting party declares that it has informed the contact person concerned of the data processing relating to their status as a contact person. The retention period for this data is 5 years following the termination of their status as a contact person.
4.5. For all data subjects, the recipients of personal data are: the Company’s managing director, employees performing customer service duties, contact persons, employees performing accounting and tax duties, and data processors.
4.6. Personal data may be disclosed for the purposes of data processing, such as taxation, accounting purposes to the accountancy firm appointed by the company; for postal and delivery purposes to Magyar Posta or the appointed courier service; and for the purposes of property protection to the company’s property protection representative.
4.7. Data processing is considered lawful if it is necessary in the context of a contract or an intention to enter into a contract (Recital 44) if it is necessary for taking steps at the data subject’s request prior to entering into a contract (Article 6(1)(b)). Thus, personal data collected in the context of contractual offers may also be processed on the legal basis of the performance of a contract, as set out in this point. When making or accepting an offer, the Company is obliged to inform the offeror or the addressee of the offer of this.
5. Information on data processing based on compliance with a legal obligation
5.1. In the case of data processing based on a legal obligation, the scope of the data that may be processed, the purpose of the data processing, the duration of data storage and the recipients are governed by the provisions of the relevant legislation.
5.2. Data processing based on the legal ground of compliance with a legal obligation is independent of the data subject’s consent, as such processing is prescribed by law. In such cases, the data subject must be informed prior to the commencement of data processing that such processing is mandatory; furthermore, the data subject must be provided, prior to the commencement of data processing, with clear and detailed information on all matters relating to the processing of their data, including, in particular, the purpose and legal basis of the data processing, the person authorised to carry out data processing and data handling, the duration of data processing, whether the data controller is processing the data subject’s personal data pursuant to a legal obligation applicable to the data controller, and who may have access to the data. The information must also cover the data subject’s rights and remedies in relation to the data processing. In the case of mandatory data processing, the information may also be provided by publishing a reference to the statutory provisions containing the aforementioned information.
6. Information on data processing carried out for the purpose of complying with tax and accounting obligations
6.1. The Company processes the data of natural persons who enter into a business relationship with it as customers or suppliers, as defined by law, for the purpose of fulfilling its legal obligations and complying with statutory tax and accounting obligations (bookkeeping, taxation). The data processed, in accordance with Sections 169 and 202 of Act CXXVII of 2017 on Value Added Tax, include in particular: tax number, name, address, tax status; and, pursuant to Section 167 of Act C of 2000 on Accounting: name, address, identification of the person or organisation authorising the transaction, the authorising officer and the person certifying the execution of the order, as well as, depending on the organisation, the auditor’s signature; on stock movement documents and cash handling documents, the signature of the recipient; on receipt slips, the signature of the payer; pursuant to Act CXVII of 1995 on personal income tax: business licence number, primary producer’s licence number, tax identification number.
6.2. Data processing relating to the maintenance of journey logs and waybills: the Company processes data on the basis of a legal obligation, for the purposes of cost accounting, documentation, determining tax bases and accounting for fuel savings, processes the data specified by law regarding the use of company vehicles and employees’ own vehicles used for official or business purposes (driver’s name, vehicle type, registration number, date and purpose of the journey, route taken, name of the business partner visited). The relevant legislation is Act CXVII of 1995 (Personal Income Tax Act), Section 27(2), Annex 3, point 6, and Annex 5, point 7.
6.3. Personal data shall be retained for a period of 8 years following the termination of the legal relationship on which the processing is based.
6.4. Recipients of personal data: the Company’s employees and data processors responsible for its tax, accounting, payroll and social security duties.
7. Information on the processing of payers’ data
7.1. The Company processes the personal data of data subjects – employees and their family members – for the purpose of fulfilling its legal obligations, specifically to comply with statutory tax and social security contribution obligations (assessment of tax, tax advances and social security contributions, payroll processing, social security and pension administration) processes the personal data – as required by tax legislation – of data subjects – employees, their family members, staff, and other recipients of benefits – with whom it has a relationship as a paying agent (2017: Act CL on the Rules of Taxation (Art.), Section 7(31)). The scope of the data processed is defined in Section 50 of the Act, with particular emphasis on the following: the natural person’s personal identification data (including former names and titles), gender, nationality, tax identification number and social security number (TAJ number). Where tax legislation attaches legal consequences to this, the Company may process employees’ health-related (Section 40 of the Personal Income Tax Act) and trade union-related (Section 47(2) b.) for the purposes of fulfilling tax and social security obligations (payroll processing, social security administration).
7.2. Personal data shall be retained for a period of 8 years following the termination of the legal relationship on which the processing is based.
7.3. Recipients of personal data: the Company’s employees and data processors responsible for its tax, payroll and social security (paying agent) duties.
8. Information on the processing of data relating to records of enduring value under the Archives Act
8.1. The Company processes documents classified as having permanent value under Act LXVI of 1995 on the Protection of Public Records, Public Archives and Private Archival Material (Archives Act) for the purpose of ensuring that the part of the Company’s archival material deemed to be of enduring value is preserved in an intact and usable condition for future generations. Duration of data retention: until transfer to the public archives.
8.2. Recipients of personal data: the Company’s director, employees responsible for document management and archiving, and staff at the public records office.
9. Promoting the rights of data subjects
In all its data processing activities, the Company is obliged to ensure that data subjects can exercise their rights.
CHAPTER IV
VISITOR DATA PROCESSING ON THE COMPANY’S WEBSITE – INFORMATION ON THE USE OF COOKIES
10. General information about cookies
10.1. Visitors to the website must be informed about the use of cookies on the website, and their consent must be sought for this.
10.2. A cookie is a piece of data that a website sends to a visitor’s browser (in the form of a variable name and value) so that it can be stored and the website can subsequently retrieve its contents. Cookies may have a limited duration, remaining valid until the browser is closed, or they may be valid indefinitely. Subsequently, with every HTTP(S) request, the browser sends this data to the server. This modifies the data on the user’s device.
10.3. The purpose of a cookie is that, by the very nature of website services, it is necessary to identify a user (e.g. to record that they have visited the site) and to be able to manage their interaction with the site accordingly. The risk lies in the fact that the user is not always aware of this, and it may enable the website operator or another service provider whose content is embedded on the site (e.g. Facebook, Google Analytics), thereby creating a profile of them; in such cases, the contents of the cookie may be regarded as personal data.
10.4. Types of cookies:
10.4.1. Technically essential session cookies: without which the website simply would not function; these are required to identify the user, e.g. to manage whether they are logged in, what they have added to their basket, etc. This typically involves storing a session ID; the rest of the data is stored on the server, which is therefore more secure. There are security implications: if the value of the session cookie is not generated correctly, there is a risk of a session hijacking attack; it is therefore essential that these values are generated appropriately. In other terminology, ‘session cookies’ refer to all cookies that are deleted when the browser is closed (a session being a single instance of browser use from start to finish).
10.4.2. Usability cookies: this is the term usually used to describe cookies that remember a user’s preferences, such as how the user wishes to view the website. These types of cookies essentially consist of settings data stored in the cookie.
10.4.3. Performance cookies: although they have little to do with „performance”, this is the term generally used to describe cookies that collect information about a user’s behaviour on a website, such as the time spent on the site and the links clicked. These are typically third-party applications (e.g. Google Analytics, AdWords or Yandex.ru cookies). They can be used to create a profile of the visitor.
You can find out more about Google Analytics cookies here: https://developers.google.com/analytics/devguides/collection/analyticsjs/cookie-usage
You can find out more about Google AdWords cookies here: https://support.google.com/adwords/answer/2407785?hl=hu
10.5. You are not obliged to accept or allow the use of cookies. You can reset your browser settings to reject all cookies or to notify you when a cookie is being sent. Although most browsers accept cookies automatically by default, these settings can usually be changed to prevent automatic acceptance and to offer you the choice each time.
10.6. You can find out more about the cookie settings for the most popular web browsers via the links below
- Google Chrome: https://support.google.com/accounts/answer/61416?hl=hu
- Firefox: https://support.mozilla.org/hu/kb/sutik-engedelyezese-es-tiltasa-amit-website usage
- Microsoft Internet Explorer 11: http://windows.microsoft.com/hu-hu/internet-explorer/delete-manage-cookies#ie=ie-11
- Microsoft Internet Explorer 10: http://windows.microsoft.com/hu-hu/internet-explorer/delete-manage-cookies#ie=ie-10-win-7
- Microsoft Internet Explorer 9: http://windows.microsoft.com/hu-hu/internet-explorer/delete-manage-cookies#ie=ie-9
- Microsoft Internet Explorer 8: http://windows.microsoft.com/hu-hu/internet-explorer/delete-manage-cookies#ie=ie-8
- Microsoft Edge: http://windows.microsoft.com/hu-hu/windows-10/edge-privacy-faq
- Safari: https://support.apple.com/hu-hu/HT201265
However, we would like to point out that certain website features or services may not function properly without cookies.
11. Information on the cookies used on the Company’s website and the data generated during a visit
11.1. Data processed during a visit: When using our website, our company may record and process the following data relating to the visitor and the device they use to browse the site:
- the IP address used by the visitor,
- the type of browser,
- the characteristics of the operating system of the device used for browsing (language setting),
- date of visit,
- the (sub)page, feature or service visited.
- click.
We retain this data for a maximum of 90 days and may use it primarily to investigate security incidents.
11.2.1. Technically essential session cookies Purpose of data processing: to ensure the website functions properly. These cookies are necessary to enable visitors to browse the website and make full and seamless use of its features and the services available via the website, including – amongst other things – in particular, recording the actions performed by the visitor on the relevant pages or the identification of the logged-in user during a single visit. The duration of data processing for these cookies relates solely to the visitor’s current visit; once the session has ended or the browser has been closed, this type of cookie is automatically deleted from your computer. The legal basis for this data processing is Section 13/A(3) of Act CVIII of 2001 (Elkertv.), which states that the service provider may process personal data that is technically indispensable for the provision of the service for the purpose of providing that service. Provided that all other conditions are the same, the service provider must select and, in all cases, operate the equipment used in the provision of information society services in such a way that personal data are processed only if this is absolutely necessary for the provision of the service and the fulfilment of the other purposes specified in this Act; however, even in such cases, only to the extent and for the duration necessary.
11.2.2. Cookies that enhance the user experience:
These cookies remember the user’s preferences, such as how the user wishes to view the page. These types of cookies essentially consist of settings data stored in the cookie.
The legal basis for data processing is the visitor’s consent.
Purpose of data processing: To improve the efficiency of the service, enhance the user experience and make the website easier to use.
This data is actually stored on the user’s computer; the website merely accesses it and uses it to recognise the visitor.
11.2.3. Performance cookies:
Information is collected about the user’s behaviour on the website they are visiting, the time spent there and their clicks. These are typically third-party applications (e.g. Google Analytics, AdWords).
Legal basis for data processing: the data subject’s consent.
Purpose of data processing: to analyse the website and send advertising offers.
CHAPTER V
INFORMATION ON THE RIGHTS OF THE DATA SUBJECT
12. A brief summary of the data subject’s rights:
- Transparent information, communication and facilitating the exercise of rights by data subjects
- Right to be informed in advance – where personal data is collected from the data subject
- Informing the data subject and the information to be provided to them where the data controller did not obtain the personal data directly from them
- The data subject’s right of access
- The right to rectification
- The right to erasure („the right to be forgotten”)
- The right to restrict processing
- The obligation to provide notice in relation to the rectification or erasure of personal data, or the restriction of processing
- The right to data portability
- The right to protest
- Automated decision-making in individual cases, including profiling
- Restrictions
- Informing the data subject of the data breach
- The right to lodge a complaint with the supervisory authority (the right to a remedy before the authority)
- The right to an effective judicial remedy against the supervisory authority
- The right to an effective judicial remedy against the data controller or data processor
13. The data subject’s rights in detail:
1. Transparent information and communication, and facilitating the exercise of data subjects’ rights
1.1. The data controller must provide the data subject with all information and notifications relating to the processing of personal data in a concise, transparent, intelligible and easily accessible form, using clear and plain language, particularly in the case of any information addressed to children. The information must be provided in writing or by other means, including, where appropriate, by electronic means. At the data subject’s request, information may also be provided orally, provided that the data subject’s identity has been verified by other means.
1.2. The data controller must facilitate the exercise of the data subject’s rights.
1.3. The data controller shall, without undue delay and in any event within one month of receipt of the request, inform the data subject of the measures taken in response to their request to exercise their rights. This time limit may be extended by a further two months under the conditions set out in the Regulation, of which the data subject must be informed.
1.4. If the data controller fails to take action in response to the data subject’s request, it shall, without delay, but no later than one month from receipt of the request, it shall inform the data subject of the reasons for failing to take action, and that the data subject may lodge a complaint with a supervisory authority and seek a judicial remedy.
1.5. The data controller shall provide the information and the information and measures relating to the data subject’s rights free of charge; however, a fee may be charged in the cases specified in the Regulation.
The detailed rules can be found in Article 12 of the Regulation.
2. Right to be informed in advance – where personal data is collected from the data subject
2.1. The data subject is entitled to be informed, prior to the commencement of data processing, of the facts and information relating to such processing. In this context, the data subject must be informed of:
- the identity and contact details of the data controller and their representative,
- the contact details of the data protection officer (if any),
- the purpose of the intended processing of personal data, and the legal basis for such processing,
- in the case of data processing based on the pursuit of a legitimate interest, the legitimate interests of the data controller or a third party,
- the recipients of the personal data – to whom the personal data is disclosed – and, where applicable, the categories of recipients;
- (e) where applicable, the fact that the data controller intends to transfer personal data to a third country or to an international organisation.
2.2. In order to ensure fair and transparent data processing, the data controller must provide the data subject with the following additional information:
- the period for which personal data will be stored, or, where this is not possible, the criteria used to determine that period;
- the data subject’s right to request from the data controller access to, rectification of, erasure of or restriction of the processing of personal data relating to them, and to object to the processing of such personal data, as well as the data subject’s right to data portability;
- in the case of data processing based on the data subject’s consent, that they have the right to withdraw their consent at any time, without this affecting the lawfulness of the data processing carried out on the basis of that consent prior to the withdrawal;
- the right to lodge a complaint with the supervisory authority;
- whether the provision of personal data is required by law or under a contractual obligation, or whether it is a prerequisite for entering into a contract, and whether the data subject is obliged to provide the personal data, as well as the possible consequences of failing to provide such data;
- the fact that automated decision-making, including profiling, is taking place, as well as, at least in such cases, the logic applied and comprehensible information as to the significance of such data processing and the likely consequences for the data subject.
2.3. Where the data controller intends to carry out further processing of personal data for a purpose other than that for which the data were collected, the data controller must inform the data subject of that different purpose and provide any relevant additional information prior to carrying out such further processing.
The detailed rules governing the right to prior information are set out in Article 13 of the Regulation.
3. Informing the data subject and the information to be provided to them where the data controller has not obtained the personal data directly from them
3.1. Where the data controller has not obtained the personal data from the data subject, the data controller shall inform the data subject no later than one month after obtaining the personal data; where the personal data are used for the purpose of communicating with the data subject, at the very least at the time of the first contact with the data subject; or if the data are likely to be disclosed to other recipients, no later than the first time the personal data are disclosed, the data controller must inform the data subject of the facts and information set out in point 2 above, as well as the categories of personal data relating to the data subject, the source of the personal data and, where applicable, whether the data are derived from publicly available sources.
3.2. Further rules are governed by the provisions set out in point 2 above (Right to prior information).
The detailed rules governing this information are set out in Article 14 of the Regulation.
4. The data subject’s right of access
4.1. The data subject has the right to receive confirmation from the data controller as to whether their personal data is being processed and, if such processing is taking place, has the right to access their personal data and any related information. (Article 15 of the Regulation).
4.2. Where personal data are transferred to a third country or to an international organisation, the data subject has the right to be informed of the appropriate safeguards relating to the transfer in accordance with Article 46 of the Regulation.
4.3. The data controller must provide the data subject with a copy of the personal data being processed. The data controller may charge a reasonable fee, based on administrative costs, for any further copies requested by the data subject.
Detailed rules concerning the data subject’s right of access are set out in Article 15 of the Decree.
5. The right to rectification
5.1. The data subject has the right to have the Data Controller rectify any inaccurate personal data concerning them without undue delay upon request.
5.2. Taking into account the purpose of the data processing, the data subject is entitled to request that incomplete personal data be supplemented, including, amongst other things, by means of a supplementary statement.
These rules are set out in Article 16 of the Regulation.
6. The right to erasure („the right to be forgotten”)
6.1. The data subject has the right to request that the data controller erase personal data relating to them without undue delay, and the data controller is obliged to erase personal data relating to the data subject without undue delay if
- the personal data are no longer necessary for the purpose for which they were collected or otherwise processed;
- the data subject withdraws their consent, which forms the basis for the data processing, and there is no other legal basis for the data processing;
- the data subject objects to the processing of their data, and there are no legitimate grounds for the processing that take precedence,
- personal data was processed unlawfully;
- personal data must be erased in order to comply with a legal obligation under Union or Member State law applicable to the data controller;
- The collection of personal data took place in connection with the provision of information society services offered directly to children.
6.2. The right to erasure may not be exercised where the processing is necessary
- for the purpose of exercising the freedom of expression and the right to information;
- for the purposes of compliance with a legal obligation under EU or Member State law to which the data controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller;
- on the grounds of public interest relating to the field of public health;
- for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes, in so far as the right to erasure is likely to render such processing impossible or seriously jeopardise it; or
- to bring, enforce and defend legal claims.
The detailed rules on the right to erasure are set out in Article 17 of the Regulation.
7. The right to restriction of processing
7.1. Where data processing is restricted, such personal data may, apart from storage, only be processed with the data subject’s consent, or for the purpose of establishing, enforce or defend legal claims, or to protect the rights of another natural or legal person, or for reasons of substantial public interest of the Union or of a Member State.
7.2. The data subject has the right to request that the Data Controller restrict the processing of their data if any of the following conditions are met:
- the data subject disputes the accuracy of the personal data; in this case, the restriction shall apply for a period enabling the Data Controller to verify the accuracy of the personal data;
- the processing is unlawful, and the data subject objects to the erasure of the data and requests, instead, that its use be restricted;
- the Data Controller no longer requires the personal data for the purposes of data processing, but the data subject requires it for the establishment, exercise or defence of legal claims; or
- the data subject has objected to the processing; in this case, the restriction shall apply for as long as it has not been established whether the data controller’s legitimate grounds override those of the data subject.
7.3. The data subject must be informed in advance of the lifting of the restriction on data processing.
The relevant rules are set out in Article 18 of the Regulation.
8. The obligation to notify in relation to the rectification or erasure of personal data, or the restriction of processing
The data controller shall inform any recipient to whom the personal data have been disclosed of any rectification, erasure or restriction of processing, unless this proves impossible or involves a disproportionate effort. At the data subject’s request, the data controller shall provide information about these recipients.
These rules are set out in Article 19 of the Regulation.
9. The right to data portability
9.1. Subject to the conditions set out in the Regulation, the data subject is entitled to receive the personal data concerning them, which they have provided to a data controller, in a structured, commonly used and machine-readable format, and is also entitled to transmit those data to another data controller without hindrance from the data controller to whom the personal data were provided, provided that
- the processing of personal data is based on consent or a contract; and
- Data processing is carried out automatically.
9.2. The data subject may also request the direct transfer of personal data between data controllers.
9.3. The exercise of the right to data portability must not infringe Article 17 of the Regulation (The right to erasure („the right to be forgotten”)). The right to data portability shall not apply where the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. This right shall not adversely affect the rights and freedoms of others.
The detailed rules are set out in Article 20 of the Regulation.
10. The right to protest
10.1. The data subject has the right to object at any time, on grounds relating to their particular situation, to the processing of their personal data carried out in the public interest or in the performance of a public task (Article 6 (1) ) or a legitimate interest (Article 6(f))—including profiling based on those provisions. In such a case, the data controller may no longer process the personal data unless the data controller demonstrates that the processing is justified by compelling legitimate grounds which override the data subject’s interests, rights and freedoms, or which relate to the establishment, exercise or defence of legal claims.
10.2. Where personal data are processed for the purposes of direct marketing, the data subject has the right to object at any time to the processing of personal data relating to them for this purpose, including profiling, insofar as it is related to direct marketing. If the data subject objects to the processing of personal data for the purposes of direct marketing, the personal data may no longer be processed for that purpose.
10.3. The data subject must be expressly informed of these rights at the latest when first contacted, and the relevant information must be presented clearly and separately from all other information.
10.4. The data subject may also exercise their right to object using automated means based on technical specifications.
10.5. Where personal data are processed for scientific or historical research purposes or for statistical purposes, the data subject shall have the right to object, on grounds relating to their particular situation, to the processing of personal data concerning them, unless the processing is necessary for the performance of a task carried out in the public interest.
The relevant rules are set out in the article of the Regulation.
11. Automated decision-making in individual cases, including profiling
11.1. The data subject has the right not to be subject to a decision based solely on automated processing – including profiling – which produces legal effects concerning him or her or similarly significantly affects him or her.
11.2. This right shall not apply where the decision:
- is necessary for the conclusion or performance of a contract between the data subject and the data controller;
- the processing is permitted by Union or Member State law applicable to the data controller, which also lays down appropriate safeguards to protect the data subject’s rights and freedoms and legitimate interests; or
- is based on the data subject’s explicit consent.
11.3. In the cases referred to in points (a) and (c) above, the data controller shall take appropriate measures to safeguard the data subject’s rights, freedoms and legitimate interests, including, at a minimum, the data subject’s right to request human intervention on the part of the data controller, to express their views, and to lodge an objection to the decision.
Further rules are set out in Article 22 of the Regulation.
12. Restrictions
EU or Member State law applicable to the data controller or data processor may, by means of legislative measures, restrict the scope of rights and obligations (Articles 12–22, Article 34, Article 5) where the restriction respects the essence of fundamental rights and freedoms.
The conditions for this restriction are set out in Article 23 of the Regulation.
13. Informing the data subject of the data breach
13.1. Where a data breach is likely to result in a high risk to the rights and freedoms of natural persons, the data controller must inform the data subject of the data breach without undue delay. This notification must describe the nature of the data breach in a clear and plain language and must include at least the following:
- the name and contact details of the data protection officer or any other contact person who can provide further information;
- the likely consequences of the data breach must be set out;
- The measures taken or planned by the data controller to remedy the data breach must be described, including, where appropriate, measures aimed at mitigating any adverse consequences arising from the data breach.
13.2. The data subject need not be informed if any of the following conditions are met:
- the data controller has implemented appropriate technical and organisational security measures, and these measures were applied to the data affected by the data breach, in particular those measures – such as the use of encryption – which render the data unintelligible to any person not authorised to access the personal data;
- following the data breach, the data controller has taken further measures to ensure that the high risk to the data subject’s rights and freedoms is unlikely to materialise in the future;
- providing such information would require a disproportionate effort. In such cases, the data subjects must be informed by means of publicly available information, or similar measures must be taken to ensure that the data subjects are informed in an equally effective manner.
Further provisions are set out in Article 34 of the Regulation.
14. The right to lodge a complaint with the supervisory authority (the right to a remedy before the supervisory authority)
The data subject has the right to lodge a complaint with a supervisory authority – in particular in the Member State of their habitual residence, their place of work or the Member State in which the alleged infringement took place – if the data subject considers that the processing of personal data relating to them infringes the Regulation. The supervisory authority to which the complaint has been lodged is obliged to inform the data subject of the progress of the proceedings relating to the complaint and of their outcome, including the fact that the data subject has the right to seek judicial redress.
These rules are set out in Article 77 of the Regulation.
15. The right to an effective judicial remedy against the supervisory authority
15.1. Without prejudice to other administrative or non-judicial remedies, every natural and legal person is entitled to an effective judicial remedy against a legally binding decision of the supervisory authority concerning them.
15.2. Without prejudice to other administrative or non-judicial remedies, every data subject shall have the right to an effective judicial remedy if the competent supervisory authority fails to deal with the complaint or fails to inform the data subject within three months of the progress or outcome of the proceedings relating to the complaint lodged.
15.3. Proceedings against the supervisory authority must be brought before the courts of the Member State in which the supervisory authority has its seat.
15.4. Where proceedings are brought against a decision of a supervisory authority in respect of which the Board has previously issued an opinion or taken a decision within the framework of the Single Supervisory Mechanism, the supervisory authority shall be obliged to forward that opinion or decision to the court.
These rules are set out in Article 78 of the Regulation.
16. The right to an effective judicial remedy against the data controller or data processor
16.1. Without prejudice to the administrative or non-judicial remedies available – including the right to lodge a complaint with the supervisory authority – every data subject shall have the right to an effective judicial remedy if they consider that their rights under this Regulation have been infringed as a result of the processing of their personal data in a manner that does not comply with this Regulation.
16.2. Proceedings against the data controller or the data processor must be brought before the courts of the Member State in which the data controller or the data processor has its place of business. Such proceedings may also be brought before the courts of the Member State in which the data subject has his or her habitual residence, unless the controller or processor is a public authority of a Member State acting in the exercise of its public powers.
These rules are set out in Article 79 of the Regulation.
Dated 31 August 2026, Budapest.