HUF 40 million fine for passing on data security obligations

According to the NAIH’s report on the year 2023, the data protection authority imposed a HUF 40,000,000 data protection fine on a data controller for trying to pass on data security obligations to data subjects [NAIH-109/2023].The data controller required data subjects to send documents containing bank data to it in a password-protected, secure manner, instead of the data controller itself setting up the conditions for secure data sharing.


According to the complaint lodged by the Luxembourg national, the data subject lodged a complaint with the controller’s customer service and requested reimbursement of the price of the service and other costs incurred. The data controller asked the complainant to send the invoices for the costs by email and an official bank statement containing the complainant’s bank account details in pdf format. The data controller also requested that the pdf document containing the bank details be sent in a password-protected compressed file in accordance with the data security requirements of the GDPR and that the password be sent to the customer service via a separate channel.

The complainant did not comply with the request for password protection because, in his opinion, the data security requirements of Article 32 of the GDPR apply to the controller, who cannot transfer the responsibility for data security measures to the data subject. According to the complainant, the controller should have provided a secure technical environment for the transmission of the data. The NAIH has also received complaints from other data subjects about the controller’s practices.


In its decision in the case, the NAIH found that the controller had breached Article 25(1) to (2) of the GDPR by designing the processing environment in such a way as to shift the responsibility for the application of data security measures to the data subjects. It also found that the controller had infringed Article 32(1) to (2) of the GDPR by failing to apply technical and organisational measures proportionate to the risks and appropriate to the state of the art in the reception of data subjects’ data.


The NAIH imposed a data protection fine of HUF 40,000,000 on the controller. Since, in parallel with the procedure, the controller developed a more secure online platform and a mobile application for receiving customer complaints, the NAIH did not call for further action to guarantee data security. [NAIH-109/202