What’s NAIH (Hungarian DPA) + GDPR cookie banner compliance for HU?

NAIH (Nemzeti Adatvédelmi és Információszabadság Hatóság) is the Hungarian Data Protection Authority, the body that enforces GDPR in Hungary, on top of 2011. évi CXII. törvény (Hungarian Information Act). NAIH is moderately strict but more pragmatic than France’s CNIL or Germany’s DSK.

Concrete Magento checklist:

  • Cookie consent, granular, per-purpose opt-in. Pre-ticked checkboxes prohibited. “Reject all” button must be as accessible as “Accept all”.
  • Hungarian-language banner, legally required to be in Hungarian for HU-targeted sites. Tools: Cookiebot, Axeptio, CookieFirst, or NAIH-vetted local providers.
  • Privacy policy, in Hungarian, naming NAIH as supervisory authority, including the controller’s Adószám.
  • DSAR routing, right-to-access, right-to-erasure, right-to-portability per GDPR Art. 15-20. We wire Magento’s native GDPR module (or extend) so HU customers can self-serve in Hungarian.
  • Breach notification, NAIH expects notification within 72 hours of a breach, in Hungarian, via their portal.
  • Data localisation, not strictly required for HU, but NAIH prefers EU-region hosting (Cloud99 / Maxer / OVHcloud / AWS Frankfurt all qualify).

NAIH fines have been moderate compared to CNIL (largest ~HUF 100M / ~€250k), but they trigger reputational damage with HU media.

Kishan Savaliya
Kishan Savaliya
Adobe Certified Magento Commerce Developer
Ahmedabad [IN]working hours, replies within four hours
When do you need it

Read personally. Never shared. Or email the brief.

More on magento developer hungary

Need it fixed, not just explained?

Send the brief with your store URL; the written quote comes back within 24 hours.