Data Protection & Privacy
DETAIL

Hungary Information Self-Determination and Freedom of Information Act — Act CXII of 2011

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

arrow_back
arrow_forward

Overview

The Hungary Information Self-Determination and Freedom of Information Act — Act CXII of 2011 is a national data protection and privacy regulation that governs the collection, processing, and disclosure of personal data within Hungary. Its primary purpose is to safeguard individuals’ right to informational self-determination while enabling transparency and accountability in the handling of personal data.

Enacted and enforced by the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), Act CXII applies to both public and private entities that process personal information. The Act covers areas such as data subject rights, lawful processing, data security requirements, and obligations related to freedom of information, aligning with broader European data protection principles and supporting compliance with the General Data Protection Regulation (GDPR).

Organizations typically operationalize Act CXII by establishing internal policies, implementing data protection controls, and conducting regular risk assessments. Incorporating the Act’s requirements into compliance programs helps organizations manage privacy risks, demonstrate regulatory compliance, and respond effectively to data subject requests and supervisory authority audits.

Why it Matters

Hungary’s Act CXII establishes a robust legal foundation forprotecting personal data and safeguarding individual privacy rightsacross all organizational sectors.

Key benefits include:

  • Strengthen data protection practices

Ensure systematicsafeguards are in place to prevent unauthorized access, loss, ormisuse of personal information.

  • Enhance regulatory alignment

Facilitatealignment with national and European data protection laws, supportingcross-border compliance requirements such as GDPR.

  • Support transparency and accountability

Promote trust byensuring organizations provide clear information about dataprocessing and respond to data subject requests.

  • Increase audit readiness

Enable structureddocumentation and evidence of compliance for supervisory authorityinspections and regulatory audits.

  • Reduce privacy risk exposure

Mitigatepotential reputational and financial impacts by proactivelyaddressing data handling obligations and legal requirements.

How it Works

The Hungary Information Self-Determination and Freedom of InformationAct — Act CXII of 2011 structures privacy obligations acrossgovernance domains and the data processing lifecycle. It outlinesdata subject rights, transparency duties, and controller/processorresponsibilities while prescribing technical and organizationalmeasures as security safeguards. The law emphasizes a risk managementapproach and retention, access, and accountability requirementsaligned with broader privacy principles.

Organizations implement Act CXII by translating statutoryrequirements into security controls, performing data protectionimpact assessments, and embedding privacy into vendor and recordsmanagement. Teams establish policies, appoint responsible roles,conduct compliance assessments and monitoring, and operate incidentresponse and breach notification processes. Continuous auditing andremediation ensure ongoing alignment with governance and complianceobligations.

In SmartSuite, teams map Act CXII requirements to control libraries,maintain risk registers, and manage policy governance centrally.Evidence collection and compliance tracking support audit readiness,while remediation workflows assign and track fixes. Reportingdashboards provide monitoring metrics and executive visibility tosupport security practices and demonstrate regulatory compliance.

Key Elements

  • Personal Data Processing Principles

Defines lawfulbases, fairness, minimization, and accuracy requirements guiding allpersonal data processing activities.

  • Data Subject Rights Provisions

Establishesentitlements for individuals regarding access, rectification,erasure, and objection to data processing.

  • Organizational Responsibilities and Governance

Specifiesobligations for data controllers and processors, includingaccountability, internal policies, and documentation.

  • Data Security and Safeguards

Describestechnical and organizational measures for ensuring confidentiality,integrity, and availability of personal data.

  • Freedom of Information Controls

Outlinesprocedures and requirements for the public disclosure of informationheld by covered entities.

  • Supervisory Authority Oversight

Defines roles andenforcement powers of the Hungarian Data Protection Authority forcompliance monitoring and investigation.

Framework Scope

Hungary Information Self-Determination and Freedom of Information Act— Act CXII of 2011 governs organizations processing personal datawithin Hungary, including both public and private entities. The Actregulates information systems and personal data processingactivities, and is adopted when meeting national data protectionobligations, enabling regulatory compliance, and supporting assuranceprograms.

Framework Objectives

The Hungary Information Self-Determination and Freedom of InformationAct — Act CXII of 2011 sets out comprehensive requirements for dataprotection, privacy, and regulatory compliance within Hungary.

Safeguard the right to informational self-determination and privacyfor individuals

Strengthen organizational governance and oversight of personal dataprocessing

Ensure compliance with data protection and cybersecurity regulatoryobligations

Enhance risk management through robust security controls and datahandling practices

Support transparency and accountability in information management anddisclosure

Improve audit readiness and responsiveness to supervisory authorityrequirements The Hungarian Information Self‑Determination andFreedom of Information Act (Act CXII of 2011) complements andoperationalizes GDPR obligations and is often interpreted alongsideCouncil of Europe Convention 108 and the ePrivacy Directive.Organizations implement it for regulatory compliance, local privacygovernance, data subject access handling, and managing cross‑bordertransfers or certification efforts.

Framework in Context

The HungarianInformation Self‑Determination and Freedom of Information Act(Act CXII of 2011) complements and operationalizes GDPR obligationsand is often interpreted alongside Council of Europe Convention 108and the ePrivacy Directive. Organizations implement it for regulatorycompliance, local privacy governance, data subject access handling,and managing cross‑border transfers or certification efforts.

Common Framework Mappings

Organizations map Act CXII to major privacy, security, andinternational standards to harmonize obligations, enable cross-borderdata handling, and streamline audits across regulatory andcertification programs.

Mapped frameworks include:

APEC Privacy Framework

Council of Europe Convention 108

EU ePrivacy Directive (Directive 2002/58/EC)

General Data Protection Regulation (GDPR) — Regulation (EU)2016/679

ISO/IEC 27001

ISO/IEC 27701

ISO/IEC 29100

NIST Privacy Framework

At a Glance
Hungary Information Self‑Determination and Freedom of Information Act (Act CXII of 2011)
  • checklist
    Classification
    Category
    info
    Data Protection & Privacy
    Domain
    info
    Privacy
    Framework Family
    info
    Global Privacy Regulations
  • info
    Regulatory Context
    Type
    info
    Regulation
    Legal Instrument
    info
    Law
    Sector
    info
    Cross-Sector
    Industry
    info
    Cross-Industry
  • arrow_upload_ready
    Region / Publisher
    Region
    info
    Europe
    Region Detail
    info
    Hungary
    Publisher
    info
    National Authority for Data Protection and Freedom of Information (NAIH)
  • published_with_changes
    Versioning
    Version
    info
    Act CXII of 2011 — Information Self-Determination and Freedom of Information
    Effective Date
    info
    January 1, 2012
    Issue Date
    info
    2011
  • graph_3
    Adoption
    Adoption Model
    info
    Regulatory Compliance
    Implementation Complexity
    info
    High
  • captive_portal
    Official Reference
License Information

License included / downloadable: Yes

Hungary's Information Self-Determination and Freedom of Information Act is publicly available through official Hungarian government legal resources.

Official Resources
Hungary Information Self-Determination and Freedom of Information Act – Act CXII of 2011
Provides the full legal text of Hungary's data protection and privacy regulation.
chevron_forward
NAIH Guidance on Data Protection Compliance
Outlines compliance requirements and best practices for organizations under the Act.
chevron_forward
Data Protection Impact Assessment Guide
Describes the process for conducting impact assessments under Hungarian data protection law.
chevron_forward
SMARTSUITE

How SmartSuite Supports Hungary Data Protection Act

Manage privacy governance, personal data protection controls, and regulatory compliance through connected workflows aligned with GDPR and Hungarian privacy requirements.

Personal Data Inventory and Mapping

Track personal data assets, systems, and data flows across the organization.

Records of Processing and Legal Basis Tracking

Maintain documentation of processing activities and legal bases for processing personal data.

Data Subject Rights Workflows

Automate access, correction, and deletion requests with deadlines and audit trails.

Privacy Risk and Impact Assessments

Track privacy impact assessments, approvals, mitigation tasks, and compliance evidence.

Vendor and Processor Oversight

Monitor vendors and processors that handle personal data on behalf of the organization.

Privacy Compliance Reporting and Audit Readiness

Provide dashboards and reports showing privacy program coverage and regulatory readiness.

Related frameworks

APEC PF

APEC Privacy Framework helps organizations manage cross-border privacy risks and facilitate data flows among Asia-Pacific economies.

Learn More
arrow_forward
GDPR

GDPR is an EU regulation that protects individuals' personal data and strengthens organizations' accountability for privacy.

Learn More
arrow_forward
ISO 27001:2022

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

Learn More
arrow_forward
ISO 27701

ISO/IEC 27701 extends ISO/IEC 27001 to help organizations manage privacy and protect personally identifiable information.

Learn More
arrow_forward
ISO 29100

ISO/IEC 29100 is a privacy framework that helps organizations establish governance, principles, and controls to protect personal data.

Learn More
arrow_forward
NIST Privacy Framework v1.0

NIST Privacy Framework provides voluntary guidance to help organizations identify, assess, and manage privacy risks to individuals' data.

Learn More
arrow_forward
ONBOARDING FAQS

Frequently Asked Questions For Hungary Information Self-Determination and Freedom of Information Act (Act CXII of 2011)

What is the Hungary Information Self-Determination and Freedom of Information Act (Act CXII of 2011) used for?

The Act is designed to protect individuals' personal data and ensure their right to informational self-determination. It establishes requirements for lawful collection, processing, storage, and disclosure of personal information and mandates public access to data held by public authorities.

Is compliance with Act CXII of 2011 mandatory for organizations in Hungary?

Yes, compliance with Act CXII is mandatory for any public or private entity that processes personal data in Hungary. Organizations are legally required to implement appropriate data protection measures and ensure the rights of data subjects are respected.

What is the scope of Act CXII of 2011?

Act CXII applies to all controllers and processors handling personal data in Hungary, regardless of whether the entity is public or private sector. The Act covers various categories of data, with certain exemptions for national security, law enforcement, and other specific cases as outlined in the law.

What are the key compliance requirements under Act CXII?

Key requirements include transparent data processing, honoring data subjects’ rights, implementing appropriate technical and organizational security controls, appointing responsible data protection roles, and maintaining documentation to demonstrate accountability.

How does an organization implement Act CXII requirements?

Implementation typically involves conducting data protection impact assessments, developing internal data protection policies, providing staff training, and setting up processes for managing data subject requests and breach notifications. Periodic audits and ongoing risk management are also essential.

How does Act CXII relate to the GDPR and other European data protection laws?

Act CXII aligns closely with the GDPR and other EU data protection principles, often supplementing or specifying national rules for compliance within Hungary. Organizations subject to GDPR must also comply with local requirements mandated by Act CXII.

What are the ongoing obligations for organizations under Act CXII?

Ongoing obligations include maintaining up-to-date risk assessments, continuous monitoring of security controls, prompt notification of data breaches, regular staff training, and keeping records demonstrating compliance. Organizations should also be prepared for audits by the Hungarian National Authority for Data Protection and Freedom of Information (NAIH).

How would SmartSuite support Hungary Information Self-Determination and Freedom of Information Act (Act CXII of 2011)?

SmartSuite helps organizations manage Act CXII compliance by mapping regulatory requirements to control libraries, tracking privacy and security risks, collecting audit evidence, and enabling centralized policy and documentation management. The platform supports readiness for regulatory audits through workflow-driven remediation and provides reporting dashboards for oversight and demonstration of ongoing compliance.

Operationalize Act CXII/2011 (Hungary) with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

Schedule a Demo
chevron_forward
Demo Library
chevron_forward