Hungary's data protection authority has a reputation for active, formal enforcement rather than a light touch, and Hungarian legal and procurement reviewers tend to expect precise answers rather than boilerplate. This page sets out the legal framework that applies to a Hungarian site, what a rigorous review typically checks, and how lead.box's documentation is built to hold up under it.
At a glance
- Framework
- GDPR + Act CXII of 2011 (Infotv.)
- Supervision
- NAIH (Nemzeti Adatvédelmi és Információszabadság Hatóság)
- Usual legal basis
- Legitimate interest, Art. 6(1)(f) GDPR, with a documented balancing test
- Processing location
- ISO-certified EU data centres
The legal framework in Hungary
Regulation at a glance
- FrameworkGDPR + Act CXII of 2011 (Infotv.)
- SupervisionNAIH (Nemzeti Adatvédelmi és Információszabadság Hatóság)
- Usual legal basisLegitimate interest, Art. 6(1)(f) GDPR, with a documented balancing test
- Processing locationISO-certified EU data centres
The GDPR sets the substantive rules, and Hungary's Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information — universally referred to as the Infotv. — predates the GDPR and was amended to sit alongside it, adding national detail on matters such as data protection officer appointment, criminal-liability provisions for certain violations and the procedural powers of the supervisory authority. For a B2B site this means a lawful basis that can be explained on request, a record of processing activities that matches what the site actually does, and a processor agreement signed before any identification script goes live.
NAIH (Nemzeti Adatvédelmi és Információszabadság Hatóság) is known among practitioners for a comparatively active enforcement posture: it issues formal resolutions, publishes case summaries in detail, and has repeatedly fined companies for record-keeping that did not match actual processing rather than only for headline breaches. That practice makes it a poor market to treat documentation as decorative — a controller operating in Hungary should expect that its record of processing activities, legitimate interest assessment and vendor list could genuinely be requested and reviewed.
Cookie and similar-technology rules stem from the ePrivacy Directive as implemented through Hungary's Electronic Communications Act, which governs storing and accessing information on a visitor's terminal equipment and requires consent for anything beyond what is strictly necessary. Identification that resolves a visit to a company without setting advertising identifiers or cross-site tracking cookies sits outside that specific consent trigger, though everything else running on a Hungarian site remains the controller's own assessment.
What the Hungarian market expects
Given NAIH's formal enforcement track record, Hungarian legal and IT security teams commonly run a more structured vendor check than a quick policy read: a data processing agreement under Art. 28 GDPR, a named and versioned sub-processor list, an explicit statement of where data is processed, and language confirming that the vendor's entry can be reflected accurately in the customer's own record of processing activities are all standard requests, not exceptions.
Hungarian-language documentation matters here in a way that goes beyond courtesy: many procurement and works-council reviews in Hungary are conducted in Hungarian, and a vendor unable to produce at least a Hungarian-language summary of its data processing practices adds friction to what would otherwise be a straightforward sign-off.
As anywhere in the EU, claims that a tool removes the need for legal review do not survive a Hungarian check grounded in NAIH's own guidance. What holds up is a specific, checkable account of what is resolved to a company, what is discarded, and where the customer's responsibility as controller begins.
Start free
Install the snippet and see the first named companies on your own traffic.
What you actually see
Named companies in your dashboard, with industry, size and the pages they read.
Where identification pays off here
Automotive and electronics suppliers around Győr, Kecskemét and the wider industrial belt run B2B sites aimed at procurement engineers who evaluate component and tooling vendors over weeks, comparing technical documentation without ever reaching out directly. Seeing that a named manufacturer has returned to a specifications page is a concrete trigger for outbound contact while the sourcing decision is still open.
Budapest's role as a shared service centre and back-office hub for multinational finance, IT and business-process operations adds a second pattern: buyers there frequently research software and outsourcing partners on behalf of a parent company headquartered elsewhere, and identifying that research early lets a vendor engage the actual decision path rather than waiting for a generic inbound enquiry.
How lead.box works here
GDPR-compliant visitor identification: the 5 rules
1. Company level only
Identification resolves the organisation behind a visit through network and IP-to-company matching. Individual people are never identified, and a visit that cannot be matched to a company stays anonymous.
2. Legal basis: legitimate interest, Art. 6(1)(f) GDPR
Company-level identification is commonly based on legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test. Consent is not required where no personal identifiers are processed; the final assessment stays with you as the controller.
3. No personal identifiers
No names, personal e-mail addresses, device fingerprints or cross-site profiles are created. Raw network addresses are not available in the interface, exports or API — only the resolved company is stored.
4. EU data processing
Personal and visitor data concerning the EU is processed in ISO-certified data centres in the European Union. EU visitor data is not moved outside the EU for this purpose.
5. Transparency and opt-out
Disclose the identification in your privacy policy — a copy-ready paragraph is on this page. Every visitor can object at any time through the public opt-out page.
lead.box applies all five rules by design.
Questions from this market
Yes, in principle it is workable under the GDPR and the Infotv. as long as identification stops at the company and never singles out an individual employee. The standard legal basis is legitimate interest under Art. 6(1)(f) GDPR, backed by a written balancing test and disclosed in your privacy policy. Hungarian legal reviewers, who are used to NAIH's formal style of enforcement, tend to ask for that balancing test as a document rather than a verbal assurance, so it should exist before the script goes live rather than be drafted after a customer asks. lead.box supplies a template balancing test and a data processing agreement so your own counsel can confirm the assessment fits your specific site, traffic and industry rather than relying on a generic statement.
NAIH, the Nemzeti Adatvédelmi és Információszabadság Hatóság, supervises GDPR and Infotv. compliance for any company running a website aimed at Hungary. Unlike some smaller EU regulators, NAIH is known for issuing detailed, published resolutions and for checking whether a company's actual record of processing activities matches what its website does in practice, not only reacting to complaints. That means a Hungarian record of processing entry describing an identification tool should be accurate and current, since it is realistic that it gets requested. lead.box keeps a versioned description of what is processed and discarded specifically so it can be dropped into that record without your team having to reverse-engineer the setup during a review.
No additional cookie banner is triggered by lead.box's own resolution step, because it does not set advertising identifiers, device fingerprints or cross-site tracking cookies on the visitor's browser. Hungary's cookie consent rule comes from the Electronic Communications Act (Eht., 2003. évi C. törvény), which implements the ePrivacy Directive and requires consent for storing or reading information on terminal equipment beyond what is strictly necessary; company-level matching against IP address does not fall into that category the way an ad pixel does. Everything else already running on your Hungarian site — analytics, retargeting, chat widgets — keeps its own separate consent assessment, which remains your responsibility as controller and is worth confirming with your own advisor.
Data concerning visits from the EU, including Hungary, is processed in ISO-certified EU data centres and is not transferred outside the EU for this purpose. That matters in a Hungarian review because NAIH pays close attention to international transfer questions, and Hungarian works-council or IT security reviewers frequently ask for a written confirmation of processing location before signing off, rather than assuming EU hosting by default. lead.box can provide that confirmation in writing alongside the Art. 28 GDPR data processing agreement and a named, versioned sub-processor list, so the location question can be closed in a single document exchange instead of a back-and-forth over email during procurement.
Expect a more structured review than a quick skim of a privacy policy, since NAIH's active enforcement record has made formal vendor checks routine among Hungarian legal and IT security teams. Typical requirements include a signed Art. 28 GDPR data processing agreement, a named and versioned sub-processor list, a clear statement of processing location, and confirmation that the vendor's entry can be reflected accurately in your own record of processing activities. Reviewers in this market tend to push back on vague answers, so having each of these documents ready before the first legal call, rather than promising to send them later, noticeably shortens the sign-off compared to a looser process elsewhere in the region.
It is not a formal GDPR requirement for the vendor itself, but in practice it helps: many Hungarian procurement and legal reviews, and works-council consultations where they apply, are conducted in Hungarian, and a vendor that can only offer English documentation adds an extra translation step to what should be a routine approval. lead.box can produce a Hungarian-language summary of the data processing description and the balancing test specifically for this purpose, which Hungarian reviewers can circulate internally without doing the translation themselves. It does not replace the underlying English contract, but it removes one common source of delay in a Hungarian sign-off process.
lead.box issues invoices against your company's VAT/tax number (adószám) so the invoice can be booked correctly under Hungarian accounting rules and reclaimed as an EU cross-border service where applicable; your finance team should confirm the reverse-charge treatment with its own accountant, since lead.box does not provide tax advice. Hungarian finance departments are typically precise about invoice formatting for NAV purposes, including company name, address and adószám matching the exact company register entry, so it is worth supplying those details accurately at signup to avoid a corrected invoice later. Contract and invoicing details can be handled separately from the technical rollout, so procurement paperwork does not have to block installing the tracking snippet.
Standard analytics tools such as page-view dashboards show anonymous session counts, not which company is behind a visit, so a Hungarian sales or marketing team typically cannot act on that data directly. lead.box resolves qualifying visits to a named company using IP-to-company matching and first-party tracking, which is the missing link between traffic numbers and an outbound list a Hungarian sales rep can actually call or email. This matters in a market where procurement engineers at automotive and electronics suppliers, or shared-service buyers in Budapest, often research vendors quietly across several sessions before making contact — company identification catches that interest while the sourcing decision is still open rather than after a competitor closes it.
See which companies are already researching you in Hungary
Install a first-party snippet, watch the first named companies appear, and hand your legal or procurement reviewer documentation that holds up under a NAIH-literate check.