Skip to content
A short summary is enough. We reply within one working day with what we need for the next step.Request a proposal

Practice areas

Data protection

We treat data protection not as a document pack but from the direction of the actual data flow: what the company collects, where it is stored, who it goes to, and what happens if it leaks. We take part in building and maintaining GDPR compliance for all of our clients.

  • Mapping the whole data estate, data protection screening, records of processing
  • Privacy notices, consent statements and internal data protection policies in Hungarian and English
  • Processor and transfer agreements, and outsourcing to cloud service platforms
  • Handling data breaches, including notification and communication to data subjects
  • Representation before the National Authority for Data Protection and Freedom of Information and before the courts
  • Putting direct marketing, prize promotions and social media data collection on a lawful footing
Enquire about this practice area

Describe the matter in a few sentences. We reply within one working day with what we need for the next step.

We use what you send us only to answer your enquiry, and we treat its contents as confidential. No newsletter unless you ask for one.

A short summary is enough. Enquiries are treated as confidential.

Representative matters

01

Comprehensive data protection advice for a multinational company in the telecommunications sector: data leakage, outsourcing e-mail to a cloud-based service platform, incident handling and contract review.

02

Ongoing data protection advice to a major foreign-owned Hungarian bank and its investment and real estate subsidiaries: data protection review of the contract portfolio, representation in proceedings before the data protection authority, preparation of documents, and direct marketing advice.

03

Full data protection advice to a healthcare market research and medical database company, with particular focus on the processing of health data: preparation of documents in Hungarian and English, and representation during registration with the authority.

04

Full data protection representation of companies handling large volumes of personal data (direct marketing and PR, crowdfunding, fintech, online education, healthcare) in regulatory and court proceedings.

05

Mapping the entire data estate managed by multinational companies, data protection screening, and proposals for implementing processes to prevent data breaches.

06

Legal advice to businesses in the financial, FMCG and healthcare sectors on data collection through social media platforms and on running prize promotions.

Questions clients ask us

What has to be done after a data breach?

The incident has to be recorded internally and assessed for risk to the individuals concerned. If there is a risk, the authority must be notified within the short statutory deadline; where the risk is high, the individuals must be told as well. In practice what decides the outcome is whether there is a clearly assigned owner and a written procedure ready in the first hours. That is worth drafting in advance.

Do we need to appoint a data protection officer?

Size does not decide it: what the company does decides it. It is mandatory where the core activity involves regular and systematic monitoring of individuals on a large scale, or large-scale processing of special category data such as health data. Even where it is not mandatory, name someone: after an incident the authority's first question is who owned the process.

Can we send a newsletter to our existing customer list?

Only if the list has a proper legal basis behind it and you can prove it. Consent has to be freely given and demonstrable after the fact: you need to know who signed up, when and to what. Every message must also offer a one-step unsubscribe. A purchase does not by itself produce marketing consent.