Hungary

EU member inside Europol, Schengen and Prüm data exchange whose government turned Pegasus on journalists and opposition, sealed the findings until 2050, and gave TEK “virtually unlimited” powers the ECHR later condemned

← Back to Privacy Law Directory

Overview

EU Member State: Hungary is subject to the GDPR, the Law Enforcement Directive, and the ePrivacy Directive. For the EU framework, see the EU Framework page.

Hungary deploys Pegasus spyware against investigative journalists (Direkt36), opposition politicians, lawyers, and the Bar Association president, with NAIH classifying its findings until December 31, 2050. Five security services operate under Act CXXV/1995, with TEK wielding surveillance powers so broad the ECHR found them “virtually unlimited” (Szabó and Vissy, 2016). The Sovereignty Protection Office (SPO), created by the Protection of National Sovereignty Act (2023), targets civil society and foreign-funded NGOs. NAIH independence has been questioned since a 2012 CJEU ruling that Hungary’s termination of the prior commissioner violated EU law. Article 7(1) TEU proceedings (triggered September 2018) remain ongoing. NSA CROSSHAIR partner.[1][2]

Hungary’s outward data-sharing runs through its alliances and treaties, each detailed below. It is an NSA CROSSHAIR partner and a NATO member (since 1999), and its services take part in the Club de Berne intelligence forum, its Counter-Terrorism Group, and Visegrad Group (V4) cooperation; it is a party to the 1959 Council of Europe Mutual Assistance Convention and the Budapest Convention on Cybercrime, belongs to the Schengen and Prüm frameworks and to Europol and the European Investigation Order, and holds a bilateral mutual legal assistance treaty with the United States alongside an extensive inherited bilateral treaty network. These are the channels through which the domestic protections described below are, in practice, bypassed.[12][13][14][15][16]

International Data Sharing Agreements

Mutual Legal Assistance

EU Member States (26 countries): Hungary cooperates with the other EU states through the EU Convention on Mutual Assistance in Criminal Matters (2000), the Schengen Convention, and the European Investigation Order, which enables binding cross-border evidence requests.

European Convention on Mutual Assistance in Criminal Matters (1959, ETS 30): This Council of Europe instrument and its Additional Protocols apply between Hungary and all other parties. As of July 2026 it has 51 parties: all 46 Council of Europe member states (Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom) plus five non-members (Chile, Israel, Mongolia, the Republic of Korea, and the Russian Federation).[12]

Convention on Cybercrime (the Budapest Convention, 2001, ETS 185): Hungary is a party to the Council of Europe’s cybercrime convention (opened for signature in Budapest), which governs the expedited preservation and cross-border disclosure of stored computer and subscriber data. As of July 2026 it has 82 parties: 45 Council of Europe member states (every one of the 46 except Ireland, which has signed but not ratified), namely Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom; together with 37 non-member states: Argentina, Australia, Benin, Brazil, Cabo Verde, Cameroon, Canada, Chile, Colombia, Costa Rica, Côte d’Ivoire, the Dominican Republic, Ecuador, Fiji, Ghana, Grenada, Israel, Japan, Kiribati, Mauritius, Morocco, New Zealand, Nigeria, Panama, Papua New Guinea, Paraguay, Peru, the Philippines, Rwanda, São Tomé and Príncipe, Senegal, Sierra Leone, Sri Lanka, Tonga, Tunisia, the United States, and Vanuatu.[13]

Bilateral MLAT with the United States: Signed December 1, 1994, in force March 18, 1997. Hungary also maintains bilateral MLA agreements inherited from the pre-1989 treaty network with countries including Mongolia, Bulgaria, China, Cuba, Russia, Romania, Poland, and Turkey, supplemented by newer agreements with Australia and Canada. The full set of Hungary’s bilateral treaties is searchable in the National Legislation Database (Nemzeti Jogszabálytár) at net.jogtar.hu.[9]

Intelligence Cooperation

NSA CROSSHAIR partner. NATO member since 1999. Hungary’s services participate in the Club de Berne and its Counter-Terrorism Group (CTG); the Club de Berne keeps no public roster, but it is reported to comprise the intelligence services of the 27 EU member states (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden) together with Norway and Switzerland, with the United Kingdom also reported as a member; the CTG comprises the same services plus the United Kingdom.[17] Visegrad Group (V4) intelligence cooperation with Poland, Czechia, and Slovakia. During its 2024 EU Council Presidency, Hungary blocked Chat Control mandatory scanning proposals.[10]

EU and Multilateral Frameworks

SIS II: Real-time query and alert sharing across the Schengen Area (29 states: Austria, Belgium, Bulgaria, Croatia, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, the Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, and Switzerland).[14] Prüm: Automated DNA, fingerprint, and vehicle-registration exchange; the framework binds 31 states (all 27 EU members plus the non-EU Schengen associates Iceland, Liechtenstein, Norway, and Switzerland); Prüm II (2024) adds facial images and police records.[15] EU-US Umbrella Agreement, SWIFT/TFTP, PNR. Interpol I-24/7. Egmont Group.

Europol

As an EU member state, Hungary is one of the 27 EU members that constitute Europol, the EU Agency for Law Enforcement Cooperation (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden). Europol also holds operational agreements permitting personal-data exchange with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, and the United States) and cooperates with US law enforcement including the FBI, so Hungarian person data flowing through Europol is reachable onward.[16]

The Privacy Backdoor Effect

Despite formal GDPR compliance, systemic alternative access exists:

Surveillance and Intelligence

Five Security Services

AH (Alkotmányvédelmi Hivatal): Domestic counterintelligence. IH (Információs Hivatal): Foreign intelligence. KNBSZ (Katonai Nemzetbiztonsági Szolgálat): Military intelligence/counterintelligence. NBSZ (Nemzetbiztonsági Szakszolgálat): Technical surveillance capabilities. TEK (Terrorelhárítási Központ): Counter-terrorism with surveillance powers the ECHR found “virtually unlimited” and subject to ministerial (not judicial) authorisation.[5]

Pegasus Spyware (2021)

The Pegasus Project revealed Hungary purchased NSO Group’s Pegasus, deployed against investigative journalists at Direkt36, opposition politicians, lawyers, and the president of the Budapest Bar Association. The government admitted the purchase, claiming all use was lawful. NAIH classified its findings until 2050. Pegasus targets are now pursuing ECHR applications. The PEGA Committee mission to Budapest (February 2023) found systemic oversight failures.[2][6]

Hungary’s commercial surveillance toolkit extends beyond Pegasus. A VSquare and Citizen Lab investigation documented the Orbán government’s use of Cobwebs Technologies’ web-intelligence tool “Webloc” (an Israeli-origin platform combined with Hungarian-developed technology), with a fresh round of license renewals completed in March 2026, weeks before the April 12, 2026 parliamentary elections. The disclosure deepened concern that surveillance capacity is being expanded in an electoral context while NAIH continues to issue findings clearing the government’s spyware use.[11]

Szabó and Vissy v. Hungary (ECHR, 2016)

The Court found TEK’s surveillance regime violated Article 8 ECHR: authorisation by the Justice Minister (not a judge) was insufficiently independent, and the virtually unlimited scope of secret intelligence gathering lacked adequate safeguards. Still not remedied as of early 2026.[5]

Internet Infrastructure and Transit Exposure

BIX (Budapest Internet Exchange): Over 260 connected networks. As a landlocked country, all international traffic transits through Austria and Germany, both with intelligence infrastructure (HNA Königswarte; BND/DE-CIX cable interception). Hungarian traffic through DE-CIX Frankfurt is subject to BND bulk monitoring.[7]

Recent Developments

Sovereignty Protection Office Constitutional Challenge: Constitutional Court upheld SPO Act (November 2024). CJEU referral under accelerated procedure. New draft NGO targeting law proposed May 2025.[4]

EU Rule of Law Report 2025 (July 8): Documents ongoing judicial independence failures and systemic concerns.[3]

European Parliament Rule-of-Law Alarm (November 2025): Deepened concerns over democratic backsliding and surveillance abuse.[3]

Chat Control Blocked (2024): Hungary blocked mandatory scanning as Council president, contributing to failure to reach qualified majority.[10]

Pegasus ECHR Applications: Targets now pursuing Strasbourg applications. PEGA Committee found Hungary failed to conduct adequate investigation.[6]

Privacy Framework

The NAIH (led by President Attila Péterfalvi since 2012) enforces Act CXII of 2011 (Info Act, amended 2018 for GDPR). The EU Rule of Law Report 2025 (July 8) documents ongoing judicial independence failures. The Act on the Protection of National Sovereignty (2023) created the SPO with powers to investigate individuals and organisations receiving foreign funding: Constitutional Court upheld it (November 2024); CJEU referral under accelerated procedure; new draft NGO targeting law proposed May 2025.[3][4]

Data Retention

1-year mandatory metadata retention under Act C of 2003 (Electronic Communications Act). Five security services can access metadata with ministerial (not judicial) authorisation. The ECHR Szabó ruling found this authorisation model insufficient, but reforms have not been enacted.[8]

Pending Legislation

Hungary’s legislative pipeline on privacy and surveillance is dominated by enacted measures expanding state power (the 2023 Sovereignty Protection Act; broad TEK surveillance authority) rather than reform bills. The notable pending items are:

Sources

[1] NAIH: Official Website – Act CXII/2011, Péterfalvi since 2012, CJEU independence ruling
[2] Amnesty: Pegasus Project – Hungary Direkt36 journalists, opposition, Bar Association president
[3] EU Rule of Law Report 2025 – Hungary country chapter, judicial independence failures
[4] Wikipedia: Sovereignty Protection Office – Act 2023, Constitutional Court upheld, CJEU referral, NGO targeting
[5] HUDOC: Szabó and Vissy v. Hungary (2016) – TEK virtually unlimited, ministerial authorisation, Article 8 violation
[6] European Parliament: PEGA Committee – Budapest mission February 2023, NAIH classified until 2050
[7] BIX: Budapest Internet Exchange – 260+ networks, DE-CIX Frankfurt transit
[8] Library of Congress: Intelligence – Hungary – Five services, 1-year retention, ministerial access
[9] US DOJ: MLATs (April 2022) – US-Hungary MLAT signed December 1, 1994, in force March 18, 1997
[10] Wikipedia: Visegrad Group / NSA CROSSHAIR – V4, NATO since 1999, Chat Control blocked
[11] VSquare / Citizen Lab: Orbán’s Spying Kit Revealed, Cobwebs “Webloc” (2026) – Investigation into the Hungarian government’s use of Cobwebs Technologies’ Webloc web-intelligence tool (Israeli-origin, combined with Hungarian technology); license renewals completed March 2026 weeks before the April 12, 2026 parliamentary elections
[12] Council of Europe Treaty Office: European Convention on Mutual Assistance in Criminal Matters (ETS No. 30) – Chart of signatures and ratifications; 51 parties as of July 2026 (all 46 Council of Europe member states plus Chile, Israel, Mongolia, the Republic of Korea and Russia), Hungary among them
[13] Council of Europe Treaty Office: Convention on Cybercrime (ETS No. 185) – Chart of signatures and ratifications; 82 parties as of July 2026 (45 Council of Europe member states plus 37 non-member states), Hungary among them
[14] European Commission: Schengen Area – The 29 states of the Schengen Area (all EU members except Ireland and Cyprus, plus the non-EU associates Iceland, Liechtenstein, Norway and Switzerland; Bulgaria and Romania became full members January 1, 2025), Hungary among them
[15] Wikipedia: Prüm Convention – The Prüm framework for automated DNA, fingerprint and vehicle-data exchange; binds all 27 EU member states plus the non-EU Schengen associates Iceland, Liechtenstein, Norway and Switzerland (31 in all); Prüm II (2024) adds facial images and police records
[16] Europol: Operational Agreements – Europol is constituted by the 27 EU member states (Hungary among them) and maintains operational cooperation agreements permitting exchange of personal data with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, the United States) plus Denmark under a separate agreement, and with Eurojust, Frontex and Interpol
[17] about:intel: The Club de Berne – The voluntary intelligence-sharing forum (no public membership roster) reported to comprise the intelligence services of the 27 EU member states plus Norway and Switzerland, with the United Kingdom also reported; its Counter Terrorism Group (CTG) comprises the same services plus the UK; Hungary’s services are participants
← Back to Privacy Law Directory