Section 25A-25C (added by 2018 GDPR Implementation Act) establish governance obligations. Section 25A general controller obligations including appropriate technical + organisational measures + data protection policies. Section 25B Data Protection Officer (DPO) - mandatory for: public authorities and bodies (any size); core activities consisting of regular and systematic monitoring of data subjects on a large scale; core activities consisting of processing on a large scale of special categories or criminal data. DPO tasks (mirroring GDPR Article 39): inform + advise + monitor compliance + cooperate with NAIH + first point of contact for NAIH and data subjects + DPIA advice. DPO reporting line to highest management + independence + no instructions on tasks + protection from dismissal for performing tasks. Section 25C Records of Processing Activities (RoPA - similar to GDPR Article 30 with Hungarian adjustments): controller + processor must maintain records of all processing activities. Records contents: name + contact + purposes + categories + recipients + transfers + retention + security measures. Available to NAIH on request. Training: while not explicit in Section 25A, NAIH expects: annual mandatory privacy training for all staff + role-based for HR + IT + customer service + marketing + DPO + works council. Privacy Management Programme + management review + internal audit + continuous improvement. Hungarian DPO landscape: Hungarian DPO Association (Magyar Adatvedelmi Tisztviselok Egyesulete) + NAIH DPO database registration. HU Infotv Section 25A-C + DPO + RoPA + training + Hungarian specifics applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.