Mihalics Law Firm (registered office: 1013 Budapest, Krisztina tér 3., Hungary; tax number: 18131103-2-41), the operator of www.mihalics.hu, applies the following data management rules when handling User data on the website and in the course of its related activities.
Purpose and scope of this Notice
What is the purpose of this Notice?
The purpose of this Notice is to set out and present the data protection and data management principles and policy applied by Mihalics Law Firm (registered office: 1013 Budapest, Krisztina tér 3., Hungary; tax number: 18131103-2-41; hereinafter: the Service Provider).
Under which legislation was this Notice adopted?
When adopting this Notice, the Service Provider took into account in particular the following legislation:
- the Fundamental Law of Hungary;
- Act V of 2013 on the Civil Code (hereinafter: Civil Code);
- Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information (hereinafter: Privacy Act);
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: GDPR).
Definitions
What is data processing?
Any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Who is the controller?
The person who, alone or jointly with others, determines the purposes and means of the processing of personal data. For the purposes of this Notice, the controller is the Service Provider named above.
Who is the data subject?
Any identified natural person, or any natural person who can be identified, directly or indirectly, on the basis of personal data.
What is personal data?
Any information relating to an identified or identifiable natural person (“data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Who is the processor?
A natural or legal person, public authority, agency or other body which processes personal data on behalf of the Service Provider as controller.
Which authority supervises the data processing carried out by the Service Provider?
The Hungarian National Authority for Data Protection and Freedom of Information (NAIH), 1055 Budapest, Falk Miksa utca 9-11., Hungary.
Scope of personal data
What personal data does the Service Provider collect?
Through the contact details indicated on the website www.mihalics.hu operated by it (hereinafter: Website), the Service Provider as controller processes the data voluntarily provided by the data subject (hereinafter: User), as follows:
- Mandatory data: surname, first name, e-mail address;
- Optional data: the User’s telephone number.
In the case of a trademark application, the telephone number and the information related to the application (e.g. type of trademark, territory of protection, trademark details) must also be provided.
The User is not obliged to provide the above mandatory data; however, without them the User cannot send an enquiry to the Service Provider via the Website or the contact details indicated on it.
The Service Provider’s data management system records the IP address of visitors to the Website.
How does the Service Provider collect personal data?
The Service Provider collects the User’s personal data through enquiries sent to the contact details indicated on the Website operated by it and, in the case of certain data, through visits to the Website.
What is a “cookie”?
In order to offer services in as personalised a manner as possible, the Service Provider places a so-called “cookie”, i.e. a small data package, on the computers of persons using its Website, the purpose of which is to enhance the user experience of the Website.
Users of the Website may, of course, configure their browser settings to block cookies, and may delete cookies already installed. If a User blocks cookies, they acknowledge and accept that the Website will not function fully, for which the Service Provider shall bear no liability.
By using cookies, the Service Provider processes only the following data: information on interests, habits and preferences (based on browsing history).
Personalised advertising
The Website uses Google advertising services. In this context, the Website uses cookies and similar technologies (such as mobile advertising identifiers) to display both personalised and non-personalised advertisements. Advertisements are personalised based on your browsing habits and interests. For more information on Google’s data processing practices, please visit Google’s business data responsibility page: https://business.safety.google/privacy/
Purpose and legal basis of data processing
For what purposes does the Service Provider process data?
- identification of the data subject;
- identification of the data subject’s entitlements;
- keeping in contact with the data subject;
- handling and processing the data subject’s individual enquiries;
- protection of the data subject’s rights;
- preparation of statistics and analyses;
- pursuit of the Service Provider’s business activities;
- enforcement of the Service Provider’s legitimate interests.
What does the pursuit of the Service Provider’s business activities mean as a purpose of data processing?
This purpose includes in particular the documentation of enquiries sent to the Service Provider, the replies and information given to them, and orders for services. The Service Provider also uses the personal data provided for the performance of its internal tasks and functions.
May the Service Provider use personal data for other purposes?
The Service Provider may also use the data subject’s personal data in other ways, in which case it sends a separate notification at the time of data collection and, where necessary, requests the data subject’s consent.
What is the legal basis of the Service Provider’s data processing?
The Service Provider processes personal data only if at least one of the following conditions is met:
- the data subject has given consent to the processing of their personal data for one or more specific purposes;
- processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
- processing is necessary for compliance with a legal obligation to which the Service Provider is subject;
- processing is necessary in order to protect the vital interests of the data subject or of another natural person;
- processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Service Provider;
- processing is necessary for the purposes of the legitimate interests pursued by the Service Provider or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
What does processing based on the data subject’s consent mean?
It means that processing takes place on the basis of the data subject’s voluntary statement, made on the basis of appropriate prior information, which contains the data subject’s explicit consent to the Service Provider using and processing the personal data they have provided.
May the data subject withdraw their consent?
Where processing is based on consent, the data subject has the right to withdraw their consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
What does processing necessary for the performance of a contract mean?
If the data subject enters into a contract with the Service Provider, the Service Provider is entitled to process the personal data of the contracting data subject for the conclusion and performance of that contract.
What does it mean that processing is necessary for compliance with a legal obligation of the Service Provider?
It means that the Service Provider carries out the processing in order to fulfil its obligations laid down by law.
What does processing necessary for the legitimate interests of the Service Provider or a third party mean?
In accordance with the provisions of the GDPR, the Service Provider has carried out, and will carry out, a balancing test to determine whether the legitimate interest of the Service Provider or of a third party in the processing outweighs the interests or fundamental rights and freedoms of the data subject which require the protection of personal data.
Principles of data processing
What principles does the Service Provider apply when processing data?
With regard to personal data, the Service Provider ensures that:
- they are processed lawfully, fairly and in a transparent manner in relation to the data subject (lawfulness, fairness and transparency);
- they are collected only for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes (purpose limitation);
- they are adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (data minimisation);
- they are accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (accuracy);
- they are kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed (storage limitation);
- they are processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (integrity and confidentiality).
The Service Provider is responsible for, and able to demonstrate, compliance with the principles set out in points a) to f) (accountability).
May the Service Provider deviate from the original purpose of processing?
If the Service Provider wishes to use personal data for a purpose other than that for which they were originally collected, it must inform the data subject, obtain their prior explicit consent and, at the same time, enable them to prohibit such use.
Does the Service Provider verify the accuracy of personal data?
The Service Provider verifies the personal data provided by the data subject only where required by law. The data subject is responsible for the correctness, accuracy and adequacy of the personal data they provide.
Does the Service Provider transfer personal data to third parties?
Except as stated in this Notice, the Service Provider does not transfer personal data to third parties. If the Service Provider decides to use a processor, it transfers personal data to that processor.
The Service Provider transfers personal data to third parties that are not processors in the following exceptional cases:
- official requests from courts or the police;
- use of personal data in statistically aggregated form, which may not contain any other data suitable for identifying the data subject in any form, and the transfer of which therefore does not qualify as data processing or data transfer.
Whom does the Service Provider notify of the rectification, restriction or erasure of personal data?
The Service Provider notifies the data subject, and all persons to whom it has previously transferred the personal data, of the rectification, restriction or erasure of personal data processed by it. Such notification may be omitted if, having regard to the purpose of the processing, this does not prejudice the legitimate interests of the data subject.
Does the Service Provider have a data protection officer?
In view of the provisions of the GDPR, the Service Provider does not have a data protection officer.
Duration of data processing
The Service Provider processes personal data until any of the following conditions occurs:
- the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
- the data subject withdraws the consent on which the processing is based, and there is no other legal ground for the processing;
- the data subject objects to the processing and there are no overriding legitimate grounds for the processing;
- the personal data have been unlawfully processed by the Service Provider;
- the personal data have to be erased for compliance with a legal obligation to which the Service Provider is subject;
- the statutory period for storing the personal data has expired;
- the personal data are incomplete or incorrect and this cannot be lawfully remedied, provided that erasure is not excluded by law;
- the competent data protection authority or court has ordered the erasure of the personal data.
The Service Provider is obliged to keep the record of any complaint submitted by the data subject and the related reply for 5 (five) years.
Rights of the data subject and their enforcement
What rights does the data subject have in relation to data processing?
The data subject has the following rights in relation to data processing:
- right to information (Articles 13 and 14 GDPR);
- right of access to personal data (Article 15 GDPR);
- right to rectification and completion of personal data (Article 16 GDPR);
- right to erasure of personal data (Article 17 GDPR);
- right to restriction of processing (Article 18 GDPR);
- right to data portability (Article 20 GDPR); and
- right to object to the processing of personal data (Article 21 GDPR).
What does the right to information mean?
During the period of processing, the data subject may request information from the Service Provider about the processing of their personal data.
The data subject may at any time request information in writing about the processing of their personal data by registered letter or letter with acknowledgement of receipt sent to the Service Provider’s registered office, or by e-mail sent to the Service Provider’s contact address indicated in this Notice.
The Service Provider considers a request for information authentic and executable if (i) in the case of a letter sent by post, the data subject can be clearly identified, and (ii) in the case of an e-mail, it was sent from the e-mail address previously provided by the data subject. The Service Provider reserves the right to identify the data subject in other ways before fulfilling the request for information.
The information provided by the Service Provider covers the information regulated in the GDPR, in particular: the details of the Service Provider (including the name and contact details of its representative), the purpose and legal basis of the processing, the source of the data, the period for which the personal data will be stored (or the criteria used to determine it), the rights of the data subject (access to personal data, requesting their rectification, erasure or restriction of processing, objecting to the processing of personal data, and the right to data portability), the right to withdraw consent, the right to legal remedy (complaint, judicial remedy), the legitimate interest of the Service Provider as controller or of a third party (if the processing is based on it), the recipients of the personal data (if any), and the fact that the Service Provider as controller intends to transfer personal data to a third country or an international organisation (if applicable).
What does the right of access to personal data mean?
The data subject has the right to obtain confirmation from the Service Provider as to whether or not their personal data are being processed. Where that is the case, the data subject has the right to access the personal data and the information detailed in the previous point.
What does the right to rectification and completion of personal data mean?
The data subject has the right to obtain from the Service Provider without undue delay the rectification of inaccurate personal data concerning them.
Taking into account the purposes of the processing, the data subject has the right to have incomplete personal data completed, including by means of providing a supplementary statement.
If the Service Provider becomes aware that personal data processed by it are incorrect, it rectifies the data on the basis of the available documents or public registers or, where necessary, after consultation with the data subject.
If rectification is not possible, the Service Provider erases the data. If there is any obstacle to rectification or erasure, the data must be permanently blocked, with an indication of the rectification.
What does the right to erasure of personal data mean?
Following appropriate identification, the data subject has the right to obtain from the Service Provider the erasure of personal data concerning them without undue delay. The Service Provider may refuse to comply with the data subject’s request for erasure if processing is necessary:
- for exercising the right of freedom of expression and information;
- for compliance with a legal obligation under the law applicable to the Service Provider which requires processing, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
- for reasons of public interest in the area of public health;
- for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, insofar as the right to erasure is likely to render impossible or seriously impair the achievement of the objectives of that processing; or
- for the establishment, exercise or defence of legal claims.
If the Service Provider refuses to comply with the data subject’s request for erasure, it always informs the data subject of the reasons for the refusal and of the available legal remedies.
When a request for erasure is fulfilled, the personal data must be erased in such a way that they can no longer be restored.
In what cases is personal data blocked instead of erased?
Personal data must be blocked instead of erased if the data subject so requests, or if, on the basis of the information available, it can be assumed that erasure would harm the legitimate interests of the data subject.
What does the right to restriction of processing mean?
The data subject has the right to obtain from the Service Provider restriction of processing where:
- the accuracy of the personal data is contested by the data subject (in this case, the restriction applies for a period enabling the controller to verify the accuracy of the personal data); or
- the processing is unlawful and the data subject opposes the erasure of the data and requests the restriction of their use instead; or
- the purpose of the processing has been achieved, but the data subject requires the data for the establishment, exercise or defence of legal claims; or
- the data subject has objected to processing (in this case, the restriction applies pending the verification of whether the legitimate grounds of the Service Provider override those of the data subject).
What does the right to data portability mean?
The data subject has the right to receive the personal data concerning them, which they have provided to the Service Provider, in a structured, commonly used and machine-readable format, and has the right to transmit those data to another controller without hindrance from the Service Provider, where:
- the processing is based on the data subject’s consent or on a contract to which the data subject is party, or the processing is necessary in order to take steps at the request of the data subject prior to entering into a contract; and
- the processing is carried out by automated means.
The data subject’s right to data portability includes the right to request, where technically feasible, that the Service Provider transmit the personal data directly to another controller.
What does the right to object to the processing of personal data mean?
The data subject has the right to object at any time to the processing of their personal data, including profiling, where:
- the processing of personal data is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Service Provider; or
- the processing is necessary for the purposes of the legitimate interests pursued by the Service Provider or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data; or
- the processing or transfer of personal data is necessary solely for compliance with a legal obligation of the Service Provider, except in the case of mandatory processing; or
- the personal data are processed for direct marketing, public opinion polling or scientific research purposes; in this case, the data subject has the right to object at any time to the processing of personal data concerning them for such purposes, including profiling to the extent that it is related to direct marketing.
If the Service Provider accepts the data subject’s objection, it terminates the processing (including further data collection and transfer), blocks the data, and notifies the objection and the measures taken on its basis to all those to whom it previously transferred the personal data concerned and who are obliged to take action to enforce the right to object.
How does the Service Provider proceed when the data subject exercises the above rights?
The Service Provider informs the data subject of the action taken on their request without undue delay, but no later than 1 (one) month from receipt of the request. Depending on the complexity of the request and the number of requests received, the Service Provider may extend this deadline by a maximum of 2 (two) months, of which it informs the data subject within the original deadline, stating the reasons for the delay. If the request is submitted electronically, the Service Provider provides the information electronically, unless the data subject requests otherwise.
If the Service Provider fails to meet the above obligation within the deadline, the data subject may use the legal remedies described in this Notice.
The Service Provider provides the information to the data subject free of charge.
Rules concerning data subjects under the age of 18
Persons under the age of 18 may provide their personal data only with the written permission of the person exercising parental responsibility.
This means that a person under the age of 18 is not entitled to provide their personal data independently and must obtain the consent of their legal representative. In the absence of such consent, the personal data of a person under the age of 18 may only be processed on a legal basis other than consent.
If a person under the age of 18 does not come into personal contact with the Service Provider when providing their personal data, the data subject is obliged to ensure compliance with this section, and the Service Provider bears no liability for any failure to do so. The Service Provider considers the provision of personal data as a declaration by the data subject that they are not subject to any restriction regarding the provision of personal data.
However, the Service Provider reserves the right to verify the lawfulness of the processing and the existence of its legal basis, including the existence of the consent of the person exercising parental responsibility.
The Service Provider will, of course, take all necessary measures to erase the personal data of persons under the age of 18 that have been provided to it without authorisation, and will ensure that such data are neither transferred nor processed.
Profiling
What does profiling mean?
Profiling means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a user, in particular to analyse or predict aspects concerning that person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
At the time of adoption of this Notice, the Service Provider does not carry out profiling.
Data processing by processors
At the time of adoption of this Notice, the Service Provider does not use any processors.
Data transfer
The Service Provider is entitled and obliged to transfer data available to it and lawfully processed by it to the competent authorities and courts if required to do so by the GDPR, applicable legislation or a final and enforceable decision. The Service Provider bears no liability for the consequences of mandatory data transfers under this section.
In the course of processing, the Service Provider does not transfer personal data to third countries or international organisations.
The Service Provider is obliged to keep a record of data transfers, covering the information specified in the GDPR and applicable legislation, in particular:
- the identification data of the data subject and the data requester;
- the purpose and legal basis of the data transfer;
- the types of data transferred; and
- the date of the data transfer.
The data subject may inspect the record with regard to their own data and request data from it, unless excluded by law.
Persons entitled to access personal data
Who has access to the personal data processed by the Service Provider?
Only the designated employees of the Service Provider with appropriate authorisation, for the purpose of performing their duties, and the recipients of data transfers have access to the data processed by the Service Provider. If the Service Provider decides to use a processor, the processor selected by the Service Provider also has access to the data processed by the Service Provider.
Data protection and data security
How does the Service Provider ensure the protection of personal data?
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Service Provider implements appropriate technical and organisational measures to ensure a level of data security appropriate to the risk.
The aim of these technical and organisational measures is to protect the personal data processed by the Service Provider and to prevent their accidental loss, unlawful destruction, unauthorised access, unauthorised use, alteration or dissemination.
To achieve the above objectives, the Service Provider uses password protection on the computers and servers used to process personal data.
The Service Provider also calls on all third parties to whom personal data processed by the Service Provider are transferred to comply, and ensure compliance, with data security requirements. In addition, the Service Provider requires its employees involved in data processing activities, and any processors it uses, to comply with data protection and data security requirements.
Personal data breach
What qualifies as a personal data breach?
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
When is the Service Provider obliged to notify the data subject of a personal data breach?
If a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the Service Provider informs the data subject of the breach without undue delay. The information provided to the data subject must clearly and plainly describe the nature of the personal data breach and communicate the most important information and measures.
In which cases is the Service Provider not obliged to notify?
The data subject does not need to be informed if any of the following conditions are met:
- the Service Provider has implemented appropriate technical and organisational protection measures, and those measures were applied to the personal data affected by the breach, in particular those that render the personal data unintelligible to any person who is not authorised to access it, such as encryption;
- the Service Provider has taken subsequent measures which ensure that the high risk to the rights and freedoms of the data subject is no longer likely to materialise;
- it would involve disproportionate effort. In such cases, the data subjects must be informed by means of publicly available information, or a similar measure must be taken whereby the data subjects are informed in an equally effective manner.
Comments and legal remedies
For any questions or comments regarding the data processing carried out by the Service Provider, the Service Provider can be contacted at the following details:
Mihalics Law Firm
Postal address: 1277 Budapest, Pf. 59, Hungary
E-mail: info@mihalics.hu
Complaints regarding data processing may be submitted directly to the Hungarian National Authority for Data Protection and Freedom of Information at the following contact details:
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address: 1055 Budapest, Falk Miksa utca 9-11., Hungary
Postal address: 1363 Budapest, Pf. 9., Hungary
Telephone: +36 (1) 391-1400; +36 (30) 683-5969; +36 (30) 549-6838
Website: www.naih.hu
E-mail: ugyfelszolgalat@naih.hu
The data subject may also apply directly to the competent court for infringement of their rights. At the choice of the data subject, the regional court (törvényszék) competent for the data subject’s place of residence or place of stay has jurisdiction to hear the claim.
Upon request, the Service Provider informs the data subject of the available legal remedies and the means thereof.
Amendment of this Notice, introduction of a new Notice
The Service Provider reserves the right to unilaterally amend or withdraw this Notice and to adopt and publish a new Notice.
By making the declaration of consent, the data subject accepts the provisions of the Notice in force at any given time.
This is an English translation of the Hungarian Privacy Notice. In the event of any discrepancy, the Hungarian version shall prevail.