Skip to content
Esta es una traduccion de conveniencia. La version en ingles es la version oficial y legalmente vinculante. Ver version en ingles
HUMEDIUM coverage1 enforcement action

Hungary — NAIH + EU AI Act + Hungarian AI Strategy: AI Compliance Requirements

Hungary's National Authority for Data Protection and Freedom of Information (NAIH — Nemzeti Adatvédelmi és Információszabadság Hatóság) enforces GDPR and has published AI guidance covering automated decision-making in employment, credit scoring, and public administration. Hungary published the "Hungarian Artificial Intelligence Strategy 2020-2030" with specific governance frameworks for state-used AI. Hungary is subject to the EU AI Act.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

January 1, 2021

Enforcement Begins

August 2, 2026

Maximum Penalty

GDPR (NAIH): up to €20M or 4% global turnover. EU AI Act: €35M or 7% global turnover.

What Your Business Must Do

3 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

EU AI Act Compliance (Mandatory)

Critical

Hungary is subject to the EU AI Act. The Hungarian Intellectual Property Office (HIPO) coordinates conformity assessment for AI products. High-risk AI used in Hungarian public administration, financial services (MNB oversight), and healthcare requires conformity assessment, registration, and technical documentation before deployment. NOTE: the EU AI Act high-risk (Annex III) conformity-assessment deadline was deferred EU-wide from 2026-08-02 to 2027-12-02 by the "Digital Omnibus" amendment, Regulation (EU) 2026/1744 (in force 2026-07-27) -- Article 50 transparency obligations still apply from 2026-08-02, but conformity assessment/technical documentation/registration for stand-alone high-risk systems is not due until 2027-12-02 (2028-08-02 for Annex I product-embedded high-risk systems).

Deadline: December 2, 2027

EU AI Act Art. 6, Annex III (high-risk classification); Art. 16 (provider obligations); Art. 43 (conformity assessment); Art. 26 (deployer obligations)

NAIH GDPR Compliance for AI Systems

High Priority

NAIH requires: DPIA for AI profiling of Hungarian residents, documentation of legal basis (legitimate interest analysis), individual rights fulfilment (access, erasure, objection to automated decisions within GDPR timelines), and transparency notices for AI-assisted decisions. NAIH has investigated AI-based credit scoring and employee monitoring systems.

GDPR Art. 22 (automated decisions); Art. 35 (DPIA); Art. 13-14 (transparency/privacy-notice duty — the basis for NAIH-85-3/2022's finding)

Hungarian AI Strategy 2020-2030

Lower Priority

Hungary's AI Strategy creates public sector AI governance requirements. Organizations seeking Hungarian government AI contracts must meet strategy principles: human oversight, transparency, non-discrimination, and data governance. Hungarian AI export compliance with EU standards required for EU tender eligibility.

Who Does This Apply To?

Applies to: any organisation established in Hungary, and any organisation outside Hungary processing the personal data of Hungarian residents through AI systems — GDPR applies with extraterritorial reach (Art. 3), obligations attaching to the processing activity rather than company size, with no general small-business exemption. As an EU member state, Hungary is fully subject to the EU AI Act, with the Hungarian Intellectual Property Office (HIPO) coordinating conformity assessment: high-risk AI in public administration, financial services (MNB oversight) and healthcare requires conformity assessment, registration and technical documentation before deployment. The National Authority for Data Protection and Freedom of Information (NAIH — Nemzeti Adatvédelmi és Információszabadság Hatóság) requires a DPIA for AI profiling, a documented legitimate-interest analysis, fulfilment of individual rights within GDPR timelines, transparency notices for AI-assisted decisions, and a documented Article 22 human-review mechanism for automated credit, insurance and employment decisions. Penalties reach €20M / 4% of global turnover under GDPR and €35M / 7% under the EU AI Act.

Recent Enforcement Actions

2022Source verified· as of 2026-08-22

Against:

Recent Regulatory Guidance

guidance2024-03

NAIH AI Guidance — Lessons from the Voice/Emotion-Analysis Fine (2022-2024)

Following its largest-ever fine over undisclosed AI voice/emotion analysis of call-centre recordings, NAIH guidance for Hungarian organisations using AI on customer interactions emphasises: (1) privacy notices must specifically disclose AI-based voice, sentiment, or emotion analysis — a generic call-recording notice is insufficient; (2) a documented legitimate-interest balancing test is required before deploying AI profiling for internal efficiency/retention purposes; (3) automated credit, insurance, and employment decisions separately require a documented Art. 22 human-review mechanism; (4) DPIAs must address AI-specific risks including training-data bias and output discrimination.

Frequently Asked Questions

Does Hungary — NAIH + EU AI Act + Hungarian AI Strategy apply to my business?

Hungary's National Authority for Data Protection and Freedom of Information (NAIH — Nemzeti Adatvédelmi és Információszabadság Hatóság) enforces GDPR and has published AI guidance covering automated decision-making in employment, credit scoring, and… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Hungary — NAIH + EU AI Act + Hungarian AI Strategy is: GDPR (NAIH): up to €20M or 4% global turnover. EU AI Act: €35M or 7% global turnover.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Hungary — NAIH + EU AI Act + Hungarian AI Strategy?

The 3 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://naih.hu/en

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan