1️⃣
Legal Basis for Using Cookies🇪🇺
General Data Protection Regulation (GDPR)GDPR applies if cookies process personal data, such as IP addresses, unique identifiers, or profiling data. In this case:
- A valid legal basis for processing is required (usually user consent);
- Processing must be transparent;
- Data subjects’ rights must be respected.
🇪🇺
ePrivacy DirectiveThe ePrivacy Directive specifically regulates the use of cookies.
In Hungary, it is incorporated into the electronic communications law.
It establishes that:
- Storing information on a user’s device or accessing it is allowed only with prior, informed consent.
❗
ExceptionConsent is
not required for strictly necessary (technical) cookies, which:
- Ensure basic website functionality;
- Allow login to personal accounts;
- Perform security functions;
- Are required for the website to function properly.
🇭🇺
National Legislation (Infotv.)Applies as a national supplement to GDPR, particularly regarding principles of data processing and supervision.
2️⃣
When User Consent Is RequiredConsent is required if the website uses, for example:
- Google Analytics;
- Facebook Pixel;
- Remarketing technologies;
- Marketing or statistical cookies.
👉 In such cases,
prior, active user consent is mandatory.
3️⃣
Unacceptable Ways to Obtain ConsentConsent is
not valid if it is obtained via:
- Phrasing such as “By using this site, you agree…”;
- Pre-checked checkboxes;
- Only a link to information without the possibility to choose.
4️⃣
Mandatory Elements of a Proper Cookie SolutionA proper cookie implementation should ensure:
✔️ Cookie banner is displayed on the first visit;
✔️ Cookie categories are selected separately (e.g., necessary, statistical, marketing);
✔️ Unnecessary cookies are
not loaded before consent is given;
✔️ Detailed cookie policy is available;
✔️ Users can modify or withdraw consent at any time.
5️⃣
Supervision and ResponsibilityCompliance is supervised by:
National Authority for Data Protection and Freedom of Information (NAIH)- This authority regularly imposes fines for incorrect implementation of cookie banners and consent mechanisms.