(3) The litigation shall be assessed within the scope of the jurisdiction of the County Court, or
Municipal Court in Budapest (hereinafter jointly referred to as county court). The legal procedure
may be launched at the county court competent in the place of residence of the data subject,
according to their choice of court.
(4) Persons normally not having the capacity to be a party to legal proceedings may also be parties
to the litigation The Authority is entitled to intervene in the proceeding in favor of the data subject.
(5) The controller shall be obliged to provide information, correct, block and delete the data, reverse
the decision made with the help of automated data processing should the court entertain the motion,
by taking account of issuing the data requested by the data recipient defined under Section 21.
(6) The controller shall be obliged to delete the personal data of the data subject within three days
following the announcement of the verdict should the court reject the motion submitted in cases
defined under Section 21. The controller shall also be obliged to delete the data should the data
recipient fail to turn to the courts within the deadline period set in Section 21 (5) and (6).
(7) The court orders the public disclosure of the verdict – by disclosing the controller’s ID data –
should this be requested in the interest of data protection and the rights of a higher number of data
subjects protected within the scope of the present Act.
17. Compensation
Section 23
(1) The controller shall be obliged to compensate for damages caused to others as an outcome of the
illegitimate control of the data of the data subject or a breach of data security requirements. The
controller shall be exempt from liability should they be able to prove that the damages were caused
by circumstances beyond their immediate control.
(2) Damages do not need to be compensated should they have ensued from the deliberate or serious
negligence of the aggrieved party.
18. Internal Data Protection Officer and Data Protection Rules
Section 24
(1) An internal data protection officer – with a higher education degree in law, economics, IT or
equivalent - under the immediate supervision of the head of the organisation must be appointed or
designated within the organisation of the controller or data processor
a. at the controller and processor controlling or processing national official, labour or criminal
files;
b. at the financial organisation;
c. at the electronic telecommunications and public service corporation.
(2) The internal data protection officer shall
a. cooperate and assist in making decisions in connection with data control and in guaranteeing
the rights of the data subjects;
b. control compliance with provisions governing the present Act and other legislation relevant
to data control, as well as rules defined in the internal data protection and data security
regulation and data security requirements;
c. assess the reports received and draw the attention of the controller or data processor to
terminating the procedure should unauthorised control be exposed;
d. compiles the internal data protection and data security regulation;
e. manages the internal data protection file;
f. organises data protection training.
(3) Controllers defined in subsection (1), as well as other state and local government controllers –
with the exception of controllers not obliged to submit reports in the data protection file - are