NIS2 compliance and data processing: new challenges in practice

The introduction of the NIS2 Directive brings not only cyber security and IT controls into the life of organisations, but also has significant consequences for data processing. During compliance, a number of new or strengthened measures are introduced that directly affect the processing of employees’ personal data. In many cases, these measures appear as mandatory, audited requirements, meaning that companies must reconsider certain aspects of their operations not only from a technical perspective, but also from a legal and data protection perspective.

Soft opt-in for registered users – what does the Inteligo Media judgment really say, and why is Hungary in default?

On 13 November 2025, the Court of Justice of the European Union delivered its long-awaited judgment in the Inteligo Media case (C-654/23), providing important guidance on the lawfulness of email marketing under the ePrivacy Directive. The decision is of particular significance for businesses operating registration-based or freemium business models that send regular email communications to their existing users.

Occupational health examinations

On 26 September 2024, regulations regarding occupational health examinations were announced, which will come into effect two days after their announcement, i.e., on 28 September 2024. The current issue of …

Occupational health examinations to change from 1 September 2024 – new data protection authority guidelines

From 1 September 2024, the regime for mandatory occupational health examinations will change: the obligation to undergo an occupational health examination will no longer be comprehensive, as

(i) legislation will specify the specific jobs for which an occupational health examination is mandatory, and

(ii) in other cases, it will be up to the employer to decide whether to require an occupational health examination

Noyb Report on Cookie Banners

In July 2024, the noyb organization, led by Austrian data protection activist and lawyer Max Schrems, published a detailed report examining the decisions and recommendations issued by national data protection authorities regarding website cookie management.

HUF 40 million fine for passing on data security obligations

According to the NAIH’s report on the year 2023, the data protection authority imposed a HUF 40,000,000 data protection fine on a data controller for trying to pass on data security obligations to data subjects [NAIH-109/2023].The data controller required data subjects to send documents containing bank data to it in a password-protected, secure manner, instead of the data controller itself setting up the conditions for secure data sharing.

Sweden’s IMY fines bank over tracking pixel

In a decision published in June 2024, Sweden’s data protection authority, Integritetsskyddsmyndigheten (IMY), fined Avanza Bank SEK15 million (EUR 1.3 m) for its alleged use of a tracking pixel to send excessive personal data (information about, for example, customers’ securities holdings and account numbers) to the social media company Meta. The IMY said the bank did not take appropriate security measures under the EU General Data Protection Regulation (GDPR) to prevent the transfer of personal data.