Section 25E (added by 2018 GDPR Implementation Act) establishes Data Protection Impact Assessment (DPIA) requirement for processing likely to result in high risk to rights and freedoms of natural persons. Triggers: systematic + extensive evaluation including profiling + automated decision-making with significant effects; large-scale processing of special categories or criminal data; systematic monitoring of publicly accessible area on a large scale. NAIH List of Processing Operations Requiring DPIA (NAIH-2018-2-V/2018 + updates) - includes additional Hungarian-specific triggers: large-scale biometric processing; large-scale location tracking; cross-border health data exchange; whistleblower scheme processing; combined large-scale registries. DPIA contents (mirror GDPR Article 35(7)): systematic description + necessity and proportionality + risk assessment + measures to address risks. Section 25F Prior Consultation - controller must consult NAIH before processing where DPIA indicates high residual risk that cannot be mitigated by reasonable measures. NAIH 8-week response (extendable 6 weeks for complex cases). NAIH may impose advice + ban + processing conditions. Privacy by Design + by Default (similar to GDPR Article 25) - building privacy controls into systems from design phase + default settings protecting privacy. NAIH 2022 + 2024 Guidance on Automated Decision-Making + AI + facial recognition specifically. HU Infotv Section 25E + Section 25F + DPIA + NAIH List + Prior Consultation + Privacy by Design applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.