Hungary Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Info Act)
HU Infotv Chap5 - NAIH

Hungary Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Info Act) HU-INFOTV-Chap5-NAIH-Authority-Powers-Enforcement-Fines: HU Infotv Chap V - NAIH Authority Powers + Investigation + Enforcement + Administrative Fines + Penal Code Sec 219 (Sections 38-71)

Chapter V establishes Nemzeti Adatvedelmi es Informacioszabadsag Hatosag (NAIH) - National Authority for Data Protection and Freedom of Information. Independent autonomous central public body. President appointed by Hungarian President on Prime Minister proposal for 9-year non-renewable term. Functions (Section 38): supervise + advise + register + cooperate. Section 51 onwards (Powers) - investigation (own-motion or complaint) + inspection + access to data + access to systems + audit; Section 55-61 (Procedure) - data subject complaint + remedy 60 days NAIH + court appeal; Section 56 NAIH may order: cease processing + restriction + blocking + erasure + correction + fine. Administrative fines (Section 59A added GDPR alignment): up to EUR 20 million or 4 percent global turnover (tier 2 GDPR Article 83(5)) for serious violations; up to EUR 10 million or 2 percent global turnover (tier 1 Article 83(4)) for less serious. NAIH may also pursue Hungarian-specific compliance order under Government Decree 217/2018 on data protection administrative procedure. Section 62-71 (Court Appeal) Hungarian administrative court route. Criminal exposure: Hungarian Penal Code Section 219 (Misuse of Personal Data) - up to 1 year imprisonment + up to 2 years if involving special category + up to 3 years if causing significant harm. Section 218 (Misuse of Public Interest Data). NAIH publishes Annual Report + Investigation Reports + GDPR fines register + decisions. Recent significant fines: DIGI 248K EUR (2020) + numerous SME breach fines. HU Infotv NAIH + investigation + fines + Penal Code + Section 219 + court appeal applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 72 controls across 27 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CH-FADP-19 Transparency and proactive information
  • CH-FADP-21 Data protection impact assessments
  • FADP-16 FDPIC Independence and Functions
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • FADP-9 Data Protection Advisor (Articles 14-15)
  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority

GDPR · 3 controls

ISO/IEC 27011:2024 · 3 controls

  • 27011-5.2 Information Security Roles in Telecoms
  • 27011-6.3 Awareness and Training
  • 27011-8.6 Data protection and backup
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection

Bahrain PDPL · 2 controls

  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-4 Section 4 - Principles Relating to Processing
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)

ISO/IEC 27400:2022 · 2 controls

  • 27400-7.1 Network Security for IoT
  • 27400-7.4 Data retention and deletion
  • ItalyCodice-Garante-Enforcement-AdministrativeSanctions-Criminal-Art166-167-170-20MEUR-Coord-EDPB Italy Codice Garante Authority + Article 140-bis + Article 144 Complaints + Article 166 Administrative Sanctions up to EUR 20M/4% + Article 167 Criminal Offences + Article 170 Failure to Comply with Garante Orders + EDPB Coordination
  • ItalyCodice-ePrivacy-Cookies-ElectronicCommunications-Telemarketing-PublicOpposition-TrafficDataRetention-Art121-122-130-132 Italy Codice ePrivacy - Article 121 Electronic Communications + Article 122 Cookies and Tracking + Article 130 Unsolicited Direct Marketing + Article 132 Traffic Data Retention + Italian Public Opposition Register (Registro delle Opposizioni)
  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure
  • ASD37-27 Outbound data loss prevention (Very Good)
  • AL-DPA-14 Direct Marketing
  • LOPDP-EC-Governance-DPO-ROPA-DPIA-Privacy-by-Design-Training-Articles-46-58-Compliance-Monitoring Ecuador LOPDP Governance + DPO + ROPA + DPIA + Privacy by Design + Training
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)

India DPDP Act · 1 control

  • DOM172-Supervisory-Authority-Cooperation-Sanctions-Penalties-Articles-77-79-Awareness-Training-Retention-DPO-Designation Dominican Republic Law 172-13 Supervisory Authority + Sanctions + Articles 77-79 + DPO + Awareness
  • RUSPD-4 Special Categories, Biometric Data
  • CPSC-CS.3 Data Protection for Safety Systems
  • VIETNAMCYBER-4 Incident Reporting and Cooperation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 72 it maps to, and the evidence behind each claim, over MCP and REST.