Hungary
EU member inside Europol, Schengen and Prüm data exchange whose government turned Pegasus on journalists and opposition, sealed the findings until 2050, and gave TEK “virtually unlimited” powers the ECHR later condemned
Overview
EU Member State: Hungary is subject to the GDPR, the Law Enforcement Directive, and the ePrivacy Directive. For the EU framework, see the EU Framework page.
Hungary deploys Pegasus spyware against investigative journalists (Direkt36), opposition politicians, lawyers, and the Bar Association president, with NAIH classifying its findings until December 31, 2050. Five security services operate under Act CXXV/1995, with TEK wielding surveillance powers so broad the ECHR found them “virtually unlimited” (Szabó and Vissy, 2016). The Sovereignty Protection Office (SPO), created by the Protection of National Sovereignty Act (2023), targets civil society and foreign-funded NGOs. NAIH independence has been questioned since a 2012 CJEU ruling that Hungary’s termination of the prior commissioner violated EU law. Article 7(1) TEU proceedings (triggered September 2018) remain ongoing. NSA CROSSHAIR partner.[1][2]
Hungary’s outward data-sharing runs through its alliances and treaties, each detailed below. It is an NSA CROSSHAIR partner and a NATO member (since 1999), and its services take part in the Club de Berne intelligence forum, its Counter-Terrorism Group, and Visegrad Group (V4) cooperation; it is a party to the 1959 Council of Europe Mutual Assistance Convention and the Budapest Convention on Cybercrime, belongs to the Schengen and Prüm frameworks and to Europol and the European Investigation Order, and holds a bilateral mutual legal assistance treaty with the United States alongside an extensive inherited bilateral treaty network. These are the channels through which the domestic protections described below are, in practice, bypassed.[12][13][14][15][16]
International Data Sharing Agreements
Mutual Legal Assistance
EU Member States (26 countries): Hungary cooperates with the other EU states through the EU Convention on Mutual Assistance in Criminal Matters (2000), the Schengen Convention, and the European Investigation Order, which enables binding cross-border evidence requests.
European Convention on Mutual Assistance in Criminal Matters (1959, ETS 30): This Council of Europe instrument and its Additional Protocols apply between Hungary and all other parties. As of July 2026 it has 51 parties: all 46 Council of Europe member states (Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom) plus five non-members (Chile, Israel, Mongolia, the Republic of Korea, and the Russian Federation).[12]
Convention on Cybercrime (the Budapest Convention, 2001, ETS 185): Hungary is a party to the Council of Europe’s cybercrime convention (opened for signature in Budapest), which governs the expedited preservation and cross-border disclosure of stored computer and subscriber data. As of July 2026 it has 82 parties: 45 Council of Europe member states (every one of the 46 except Ireland, which has signed but not ratified), namely Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom; together with 37 non-member states: Argentina, Australia, Benin, Brazil, Cabo Verde, Cameroon, Canada, Chile, Colombia, Costa Rica, Côte d’Ivoire, the Dominican Republic, Ecuador, Fiji, Ghana, Grenada, Israel, Japan, Kiribati, Mauritius, Morocco, New Zealand, Nigeria, Panama, Papua New Guinea, Paraguay, Peru, the Philippines, Rwanda, São Tomé and Príncipe, Senegal, Sierra Leone, Sri Lanka, Tonga, Tunisia, the United States, and Vanuatu.[13]
Bilateral MLAT with the United States: Signed December 1, 1994, in force March 18, 1997. Hungary also maintains bilateral MLA agreements inherited from the pre-1989 treaty network with countries including Mongolia, Bulgaria, China, Cuba, Russia, Romania, Poland, and Turkey, supplemented by newer agreements with Australia and Canada. The full set of Hungary’s bilateral treaties is searchable in the National Legislation Database (Nemzeti Jogszabálytár) at net.jogtar.hu.[9]
Intelligence Cooperation
NSA CROSSHAIR partner. NATO member since 1999. Hungary’s services participate in the Club de Berne and its Counter-Terrorism Group (CTG); the Club de Berne keeps no public roster, but it is reported to comprise the intelligence services of the 27 EU member states (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden) together with Norway and Switzerland, with the United Kingdom also reported as a member; the CTG comprises the same services plus the United Kingdom.[17] Visegrad Group (V4) intelligence cooperation with Poland, Czechia, and Slovakia. During its 2024 EU Council Presidency, Hungary blocked Chat Control mandatory scanning proposals.[10]
EU and Multilateral Frameworks
SIS II: Real-time query and alert sharing across the Schengen Area (29 states: Austria, Belgium, Bulgaria, Croatia, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, the Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, and Switzerland).[14] Prüm: Automated DNA, fingerprint, and vehicle-registration exchange; the framework binds 31 states (all 27 EU members plus the non-EU Schengen associates Iceland, Liechtenstein, Norway, and Switzerland); Prüm II (2024) adds facial images and police records.[15] EU-US Umbrella Agreement, SWIFT/TFTP, PNR. Interpol I-24/7. Egmont Group.
Europol
As an EU member state, Hungary is one of the 27 EU members that constitute Europol, the EU Agency for Law Enforcement Cooperation (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden). Europol also holds operational agreements permitting personal-data exchange with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, and the United States) and cooperates with US law enforcement including the FBI, so Hungarian person data flowing through Europol is reachable onward.[16]
The Privacy Backdoor Effect
Despite formal GDPR compliance, systemic alternative access exists:
- Pegasus: Government-deployed spyware against journalists and opposition, findings classified until 2050
- TEK: “Virtually unlimited” surveillance with ministerial authorisation, ECHR violation unremedied
- Sovereignty Protection Office: Investigates foreign-funded civil society outside GDPR oversight
- NSA CROSSHAIR: Bilateral SIGINT partnership
- EU Framework: Hungarian data in SIS II, Prüm, EIO accessible to 27 EU states
- MLAT/CoE Conventions: the US, the 51 parties to the 1959 Convention and the 82 parties to the Budapest Convention can request data through MLA channels
- Article 7: Ongoing proceedings confirm systemic rule-of-law concerns affecting enforcement credibility
Surveillance and Intelligence
Five Security Services
AH (Alkotmányvédelmi Hivatal): Domestic counterintelligence. IH (Információs Hivatal): Foreign intelligence. KNBSZ (Katonai Nemzetbiztonsági Szolgálat): Military intelligence/counterintelligence. NBSZ (Nemzetbiztonsági Szakszolgálat): Technical surveillance capabilities. TEK (Terrorelhárítási Központ): Counter-terrorism with surveillance powers the ECHR found “virtually unlimited” and subject to ministerial (not judicial) authorisation.[5]
Pegasus Spyware (2021)
The Pegasus Project revealed Hungary purchased NSO Group’s Pegasus, deployed against investigative journalists at Direkt36, opposition politicians, lawyers, and the president of the Budapest Bar Association. The government admitted the purchase, claiming all use was lawful. NAIH classified its findings until 2050. Pegasus targets are now pursuing ECHR applications. The PEGA Committee mission to Budapest (February 2023) found systemic oversight failures.[2][6]
Hungary’s commercial surveillance toolkit extends beyond Pegasus. A VSquare and Citizen Lab investigation documented the Orbán government’s use of Cobwebs Technologies’ web-intelligence tool “Webloc” (an Israeli-origin platform combined with Hungarian-developed technology), with a fresh round of license renewals completed in March 2026, weeks before the April 12, 2026 parliamentary elections. The disclosure deepened concern that surveillance capacity is being expanded in an electoral context while NAIH continues to issue findings clearing the government’s spyware use.[11]
Szabó and Vissy v. Hungary (ECHR, 2016)
The Court found TEK’s surveillance regime violated Article 8 ECHR: authorisation by the Justice Minister (not a judge) was insufficiently independent, and the virtually unlimited scope of secret intelligence gathering lacked adequate safeguards. Still not remedied as of early 2026.[5]
Internet Infrastructure and Transit Exposure
BIX (Budapest Internet Exchange): Over 260 connected networks. As a landlocked country, all international traffic transits through Austria and Germany, both with intelligence infrastructure (HNA Königswarte; BND/DE-CIX cable interception). Hungarian traffic through DE-CIX Frankfurt is subject to BND bulk monitoring.[7]
Recent Developments
Sovereignty Protection Office Constitutional Challenge: Constitutional Court upheld SPO Act (November 2024). CJEU referral under accelerated procedure. New draft NGO targeting law proposed May 2025.[4]
EU Rule of Law Report 2025 (July 8): Documents ongoing judicial independence failures and systemic concerns.[3]
European Parliament Rule-of-Law Alarm (November 2025): Deepened concerns over democratic backsliding and surveillance abuse.[3]
Chat Control Blocked (2024): Hungary blocked mandatory scanning as Council president, contributing to failure to reach qualified majority.[10]
Pegasus ECHR Applications: Targets now pursuing Strasbourg applications. PEGA Committee found Hungary failed to conduct adequate investigation.[6]
Privacy Framework
The NAIH (led by President Attila Péterfalvi since 2012) enforces Act CXII of 2011 (Info Act, amended 2018 for GDPR). The EU Rule of Law Report 2025 (July 8) documents ongoing judicial independence failures. The Act on the Protection of National Sovereignty (2023) created the SPO with powers to investigate individuals and organisations receiving foreign funding: Constitutional Court upheld it (November 2024); CJEU referral under accelerated procedure; new draft NGO targeting law proposed May 2025.[3][4]
Data Retention
1-year mandatory metadata retention under Act C of 2003 (Electronic Communications Act). Five security services can access metadata with ministerial (not judicial) authorisation. The ECHR Szabó ruling found this authorisation model insufficient, but reforms have not been enacted.[8]
Pending Legislation
Hungary’s legislative pipeline on privacy and surveillance is dominated by enacted measures expanding state power (the 2023 Sovereignty Protection Act; broad TEK surveillance authority) rather than reform bills. The notable pending items are:
- EU AI Act national implementation: Hungary must designate AI market-surveillance authorities and adopt implementing rules; legislation is pending.
- NIS2 implementation: national cybersecurity-supervision measures continue to be developed following transposition.
- Surveillance oversight reform: despite the ECHR Szabó and Vissy (2016) ruling that TEK’s “virtually unlimited” powers violate Article 8, no remedial legislation has been introduced; reform remains a pending obligation rather than an active bill.[6]
- Sovereignty Protection Act: the EU Commission’s infringement action and an expected CJEU challenge may force amendments to the 2023 Act, but Hungary has not proposed changes.
