Pursuant to Articles 12–14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter: GDPR), BKK Centre for Budapest Transport (hereinafter: the Data Controller or BKK) provides the following information to data subjects regarding the processing of personal data carried out by BKK in connection with the Budapest Card.
I. Details and contact information of the data controller; definitions of ‘personal data’ and ‘data subject’
Name of the data controller: BKK Centre for Budapest Transport (BKK Budapesti Közlekedési Központ Zártkörűen Működő Részvénytársaság, short name: BKK Zrt. or BKK))
Registered office: 1075 Budapest, Rumbach Sebestyén utca 19–21.
Contact details of the data protection officer: [email protected]
Telephone number (customer service): +36-1-3-255-255
For the purposes of this privacy policy (hereinafter: Privacy Policy), personal data means any information relating to an identified or identifiable natural person (hereinafter: Data Subject). A natural person is considered identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier (such as a name, number, location data, online identifier or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person).
The Data Subjects of the personal data processing operations described in this Privacy Policy are those natural persons who purchase a Budapest Card via the BKK online shop (‘purchasers’) or who use the Budapest Card (‘cardholders’).
II. Description of the data processing procedure and the legislation forming the basis for data processing
Pursuant to Local Government Regulation No. 14/2025 (15 May) of the General Assembly of the Municipality of Budapest, BKK has been responsible for the sale of the Budapest Card since the Regulation came into force on 1 July 2025. To facilitate online sales, a web shop has been set up on its website, which enables the purchase of combined fare products known as the Budapest Card, aimed at tourists visiting Budapest and entitling holders to discounts and other services. The platform allows users to purchase a voucher entitling them to collect the purchased product from a designated location. To simplify the purchase process, the platform can be used without registration; only the information required for invoicing and delivering the product is needed. In addition to unlimited travel on public transport during its period of validity, the Budapest Card also provides access to free or discounted services from our contracted partners.
The Data Subject selects the product on the ‘Tickets and Passes’ subpage of the BKK website. The product information page provides details of the product’s features, as well as its possible uses and methods of use. The information page for products available for online purchase allows the Data Subject to initiate the purchase process by specifying the desired quantity. Although there is no user account management on the online platform, providing billing and contact details is mandatory for the process to be completed successfully. After entering your personal or company billing details and confirming the purchase summary, the site will redirect you to the SimplePay payment system, to which it will forward the information required for payment. A payment confirmation, the voucher for the purchased product (hereinafter: voucher) and the issued invoice will be sent to the contact email address provided. Should any error occur during the process, we will investigate and resolve the issue based on the information provided and that generated during the purchase. We will contact the Data Subject using the contact details they have provided.
Following the successful purchase of the Budapest Card, the Data Subject will receive a voucher by email that can be redeemed for the purchased card(s) and will receive an electronic invoice within a maximum of eight (8) calendar days from the date of purchase. To collect the Budapest Card, the voucher can be exchanged for a Budapest Card at designated BKK customer service centres. After collecting the Budapest Cards, the cardholder must write the start date and time of validity (date, hour, minute) on the card and validate it by providing an identification number (photo ID card number or passport number). Based on the above, it is mandatory to indicate the start time of validity and the identification number on the Budapest Card. The number of the relevant identity document is not recorded in the Budapest Card’s electronic back-end system.
For the purpose of verifying the entitlement to free travel provided by the Budapest Card, BKK ticket inspectors and passenger coordinators may ask you to present your Budapest Card. In order to verify eligibility for free or discounted use of services, or to enable the holder to exercise that entitlement, the relevant service provider may ask the holder to present the Budapest Card when purchasing a ticket or gaining entry. During the above checks, if the date of first use has not previously been recorded on the card, this date will be recorded on the card upon first use; furthermore, the person carrying out the check may view the document number shown on the Budapest Card.
The main legislation governing data processing in accordance with this Data Protection Notice and the abbreviations used in this Data Protection Notice are as follows:
Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (GDPR)
Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information (Privacy Act)
Act CVIII of 2001 on Electronic Commerce and on Information Society Services (E-Commerce Act);
Act V of 2013 on the Civil Code (Hungarian Civil Code)
the provisions of Government Decree No. 45/2014 (II. 26.) on the detailed rules governing contracts between consumers and businesses (hereinafter: the Government Decree) shall apply even in the absence of a specific provision to that effect.
Act C of 2000 on Accounting (Accounting Act)
III. Description of the purposes of data processing, the legal basis for data processing, the scope of the data processed, and the duration of data processing
Source of personal data: the Data Subject provides some of the personal data processed to the Data Controller themselves during the purchase, the issue of the Budapest Card, the exercise of the right of withdrawal, or the handling of complaints, whilst the log data generated during the use of the Budapest Card by the cardholder are generated during the use of the Budapest Card (scanning at the venue offering the discount).
| Description and purpose of data processing |
Legal basis for data processing (for GDPR Article 6(1)(c) or (e), the exact legal provision is specified)
| Scope of personal data processed |
Duration of data processing |
| 1) On its website, the Data Controller enables its customers to create a shopping basket, order services at (Budapest Card), and pay for goods and services. |
Article 6(1)(b) of the GDPR: taking steps at the data subject’s request prior to entering into a contract, and the performance of a contract | Billing name, billing address, billing email address, invoice number, type and quantity of Budapest Card |
We do not store personal data for this purpose after the purchase |
| 2) Payment of consideration, keeping a record of customers, distinguishing between them, and documenting the purchase and payment |
Article 6(1)(b) of the GDPR, performance of a contract | Billing name, billing address, billing email address, invoice number, telephone number, type and quantity of Budapest Cards, voucher number, the 32-character identifier and transaction identifier required for SimplePay payment | 5 years from the expiry date of the Budapest Card, pursuant to Section 6:22 of the Civil Code |
| 3) Issuing invoices and fulfilling the obligation to retain accounting records: | Article 6(1)(c) of the GDPR; compliance with a legal obligation under Section 169(2) of the Accounting Act | Billing name, billing address, invoice number, type and quantity of Budapest Cards | For 8 years following the issue of the last accounting document relating to the purchase of / withdrawal from the Budapest Card |
|
4) Customer contact in the event of a failed purchase or other error | Article 6(1)(b) of the GDPR, performance of a contract |
Billing name, billing address, billing email address, telephone number | In the case of a purchase made before 1 May of the current year, until 5 May of the current year; in the case of a purchase made on or after 1 May of the current year, until 5 May of the following year. |
| 5) Redemption of vouchers and issuance of the Budapest Card | Article 6(1)(b) of the GDPR, performance of a contract | Voucher number, name of voucher purchaser (for online purchases), date of purchase, start of validity, end of validity, redeemed cards (virtual card, physical card), whether fully redeemed, redeemed, ‘ ’ status, redeemed card/voucher number, redeeming user’s name, redeeming user’s email address, name of redeeming partner, cardholder’s name (for online purchases), which partner the voucher was generated for in the system, card type (e.g. 24-hour), card type category (e.g. physical), card number, QR identification number, current issuing location, current activation point. Access/paper-based data recording: identity document number. | Pursuant to Section 6:22 of the Civil Code, for a period of 5 years from the expiry of the Budapest Card |
|
6) Verification of entitlement to free travel and to the free or discounted use of services; exercise of such entitlement; logging of transactions | Article 6(1)(b) of the GDPR, performance of a contract |
Redeemed cards (virtual card, physical card), number of the redeemed card/voucher, name of the redeeming user, email address of the redeeming user, redeeming partner, name of the cardholder (in the case of online purchases), the partner for whom the voucher was generated in the system, card type (e.g. 24-hour), card type category (e.g. physical), card number, QR identification number, current issuing location, current activation point, active, lost, revoked, invalid, date of redemption, ‘ ’ partner (redemption location visited), discount (type, amount), number of people allowed entry, type of card purchased, validity. Access: identity document number. | 5 years from the expiry date of the Budapest Card, pursuant to Section 6:22 of the Civil Code |
| 7) Refund of payment in connection with the exercise of the right of withdrawal: processing of the notice of withdrawal, issuing an invoice, making the payment | Article 6(1)(c) of the GDPR; compliance with a legal obligation pursuant to Section 20 of Government Decree No. 45/2014 (II. 26.) |
Date and time of submission of the notice of withdrawal, name of the person concerned, billing name, email address, date of purchase, time of purchase, voucher number, SimplePay transaction ID, external reference number, amount paid (HUF), number of products purchased, number of products affected by the withdrawal, e-invoice reference number, card type (e.g. 24-hour), card type category (e.g. physical) |
For 8 years following the issue of the last accounting document relating to the purchase of or cancellation of the Budapest Card |
| 8) Sending out pre- and post-purchase customer satisfaction questionnaires, and following up on customer feedback | Article 6(1)(a) of the GDPR, consent of the data subject | Cardholder’s name, card number, card type (e.g. 24-hour), active, lost, cancelled, faulty, date of redemption, partner (i.e. redemption location visited), discount (type, amount), number of persons eligible for entry, planned redemption locations to be visited, suggested new redemption locations, factors motivating the purchase of the Budapest Card, satisfaction with the purchasing and redemption process, customer service channels and staff, the cardholder’s gender, age, country of residence, email address, and name of the sales channel | For a period of 1 year from the expiry date of the Budapest Card used |
IV. The fact of automated decision-making, including profiling, as well as, at least in these cases, the logic applied and comprehensible information regarding the significance of such data processing and the expected consequences for the data subject
No automated decision-making or profiling takes place in the processing of personal data as detailed in this Privacy Policy.
V. Data security measures
The Data Controller undertakes to ensure the security of the personal data it processes. Taking into account the state of the art, the cost of implementation, the nature, scope, context and purposes of the processing, as well as the risks of varying likelihood and severity to the rights and freedoms of natural persons, shall take such technical and organisational measures and establish such procedural rules as are necessary to ensure that the data collected, stored or processed are protected, and to prevent their destruction, unauthorised use and unauthorised alteration.
The Data Controller also undertakes to require any third party to whom it transfers or discloses data on any legal basis to comply with data security requirements.
The Data Controller guarantees a level of data security commensurate with the level of risk, including, amongst other things, where applicable:
- the pseudonymisation and encryption of personal data,
- ensuring the ongoing confidentiality, integrity, availability and resilience of the systems and services used to process personal data (operational and development security, protection against and detection of intrusions, and prevention of unauthorised access),
- in the event of a physical or technical incident, the ability to restore access to personal data and the availability of such data in a timely manner (prevention of data breaches; vulnerability and incident management),
- a procedure for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures taken to ensure the security of data processing (maintaining business continuity, protection against malicious code, the secure storage, transmission and processing of data, and security training for our employees).
When determining the appropriate level of security, particular consideration must be given to the risks arising from data processing, specifically those resulting from the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data that is transmitted, stored or otherwise processed.
The Data Subject’s data is stored on the Data Controller’s secure internal servers, the protection of which complies with the highest standards of IT security. Remote access is permitted only to a limited group of authorised persons, exclusively via a virtual private network and following authentication. All operations carried out by Users and the Service Provider relating to data processing involving any changes are logged. The data is not copied onto any other physical data storage media.
The Data Controller operates the IT tools used for the processing of recorded personal data as follows:
- To ensure the protection of physical devices containing data relating to BKK.
- To ensure that only approved and authorised Users have access to the data used by the Data Controller.
- To ensure that only persons authorised to use the systems have access to the Data Controller’s data.
- To ensure that unauthorised persons cannot transmit, read, modify or delete the Data Controller’s data during data transmission or storage. The data being processed may only be accessed by the Data Controller, its employees and any data processor(s) engaged by it, in accordance with their respective authorisation levels; the Data Controller shall not disclose such data to any third party who is not authorised to access it. Employees of the Data Controller and the Data Processor may access personal data in a specified manner, in accordance with access levels, as assigned to the roles defined by the Data Controller and the Data Processor.
- To ensure that the Data Controller’s data is protected against accidental destruction or loss, and that, in the event of incidents causing such consequences, the Data Controller’s data can be accessed and restored in a timely manner.
- To ensure that the Data Controller’s data is processed separately from that of other clients. The Data Controller and the Data Processor shall classify and treat personal data as confidential. In order to protect the data files processed electronically in the various registers, the Data Controller shall ensure that the data stored in the registers – subject to the exceptions specified by law – cannot be directly linked to or attributed to the Data Subject.
- To ensure that the Data Processor regularly tests, reviews and evaluates the effectiveness of the technical and organisational measures outlined above.
- To ensure the security of its IT systems, the Data Controller protects them with a firewall and uses antivirus and anti-malware software to prevent both external and internal data loss. The Data Controller has also ensured that all incoming and outgoing communications, in whatever form, are properly monitored to prevent misuse.
VI. Data processors, data transfer
| Name and registered office of the data processor |
Activities carried out by the data processor | Personal data processed by the data processor |
|
Innostart Informatikai Fejlesztő Kft. 1115 Budapest, Thallóczy Lajos utca 27. | Carrying out operational and development tasks relating to the online shop, and identifying malfunctions |
Billing name, billing address, email address, telephone number |
| Chrome-Soft Kft. 9700 Szombathely, Semmelweis Ignác utca 4-6. 1. em. 103. ajtó |
Provision of the system for recording Budapest Card transactions | Voucher number, name of voucher purchaser, date of purchase, start of validity, end of validity, redeemed cards (virtual card, physical card), fully redeemed, redeemed, status, redeemed card/voucher number, issued card number, redeeming user’s name, redeeming user’s email address, redeeming partner, cardholder’s name (for online shop purchases), which partner the voucher was generated for in the system, card type (e.g. 24-hour), card type category (e.g. physical), card number, QR identification number, current issuing location, current activation point, status (active, lost, revoked, invalid), date of card use, partner (redemption location), discount (type, amount), number of persons permitted entry |
In the event of a request from a regulatory authority, the data requested by the authority will be forwarded to that authority.
The data controller informs the customer that, when redirected to the SimplePay website during a bankcard payment (32-digit identifier, transaction identifier, customer’s email address, billing details: name, address), this data will be transferred to SimplePay Zrt. as an independent data controller. The nature and purpose of the data processing carried out by SimplePay Zrt. can be viewed in the SimplePay Data Protection Notice at the following link: https://simplepay.hu/adatkezelesi-tajekoztatok/
The operator of a service available free of charge or at a discount with the Budapest Card may request that the Budapest Card be presented when purchasing a ticket or gaining entry, for the purposes of verifying eligibility for free or discounted use of the services, exercising that eligibility, and logging the transaction. In this context, the service provider has access to the customer data associated with the relevant Budapest Card, and the IT back-end system logs the operations carried out by the service provider. When verifying and processing eligibility, the service provider does not process data on behalf of BKK but verifies eligibility and records its use in the manner necessary for the provision of its own service; therefore, it is to be regarded as an independent data controller in this context. If not previously indicated, the card will show the date of activation, i.e. the date of first use; this is an administrative procedure necessary to claim the discount, which in itself does not constitute the status of a data processor. During the inspection, the service provider carries out the inspection and data recording; however, the log data relating to the operation is generated in the system operated by BKK.
VII. Your (the data subject’s) rights and the procedure for exercising them
The Data Controller shall, without undue delay but within one month of receiving the request, inform the data subject, via the contact details provided by them, of the measures taken in response to the request as set out below. If necessary, taking into account the complexity of the request and the number of requests, this time limit may be extended by a further two months. The Data Controller shall inform the data subject of any extension of the time limit within one month of receiving the request, stating the reasons for the delay.
As a data subject, you may exercise your rights listed below using the contact details provided:
In person:
At BKK customer service centres.
In writing:
- by post: to the customer service address, 1075 Budapest, Rumbach Sebestyén u. 19-21.
- by email: to the customer service email address bkkbkk.hu
Your right to information
The Data Controller is obliged – provided that the personal data originates from the Data Subject at the time of collection – to make the following information regarding data processing available to Data Subjects:
- the Data Controller’s name, contact details and representative;
- the contact details of the data protection officer;
- the purposes of the intended processing of personal data and the legal basis for the processing;
- in the case of data processing based on legitimate interests, the legitimate interests of the Data Controller or a third party;
- the recipients of the personal data;
- the period for which the personal data will be stored;
- whether the Data Controller intends to transfer the personal data to a third country or to an international organisation;
- information on the rights to which the Data Subject is entitled;
- in the case of data processing based on consent, the right to withdraw consent;
- the right to lodge a complaint with the supervisory authority;
- whether the provision of personal data is required by law or under a contractual obligation, or whether it is a prerequisite for entering into a contract;
- the fact of automated decision-making, including profiling.
The obligation to provide the information set out above need not be fulfilled if the Data Subject already possesses the information contained in these points.
Where the personal data have not been obtained from the Data Subject, the Data Controller shall provide the Data Subject with the above information, as well as the following additional information:
- the categories of the Data Subject’s personal data;
- the source of the personal data and, where applicable, whether the data originates from publicly available sources.
If the personal data were not obtained from the Data Subject, the obligation to provide information need not be fulfilled if:
- - the Data Subject already has the information,
- it proves impossible to provide the information or would require a disproportionate effort,
- the collection or disclosure of the data is expressly required by Union law or applicable Hungarian law applicable to the Data Controller, or
- the personal data must remain confidential pursuant to a professional duty of confidentiality prescribed by EU or applicable Hungarian law.
Your right of access
You have the right to receive confirmation from the Data Controller as to whether your personal data is being processed, and if such processing is taking place, you have the right to access your personal data and the following information:
- the purposes of data processing;
- the categories of personal data processed in relation to you;
- the recipients or categories of recipients to whom the Data Controller has disclosed or will disclose the personal data, including, in particular, recipients in third countries or international organisations;
- where applicable, the envisaged period for which the personal data will be stored, or, if this is not possible, the criteria used to determine that period;
- your right to request from the Data Controller the rectification, erasure or restriction of the processing of your personal data;
- the right to lodge a complaint with a supervisory authority (in Hungary, the National Authority for Data Protection and Freedom of Information);
- where the Data Controller has not collected the data from you, all available information regarding its source;
- the fact that automated decision-making, including profiling, is taking place, and, at least in such cases, the logic applied and comprehensible information as to the significance of such data processing and the likely consequences for you.
The Data Controller shall provide you with a copy of the personal data being processed. The Data Controller may charge a reasonable fee based on administrative costs for any further copies you request. If you have submitted your request electronically, the information must be provided in a commonly used electronic format, unless you request otherwise. The right to request a copy must not adversely affect the rights and freedoms of others.
Your right to rectification and completion
Upon your request, the Data Controller is obliged to rectify any inaccurate personal data concerning you without undue delay. Taking into account the purpose of the data processing, you are entitled to request that incomplete personal data be completed, including, amongst other things, by means of a supplementary statement.
Your right to erasure
You have the right to request that the Data Controller erases your personal data. The Data Controller is obliged to erase your personal data without undue delay in the following cases:
- the personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
- the personal data have been processed unlawfully;
- the personal data must be erased in order to comply with a legal obligation under Union or Member State law (Hungarian law) applicable to the Data Controller;
- the personal data were collected in connection with the offering of information society services.
A request for erasure cannot be complied with if the processing is necessary:
- for the purposes of exercising the right to freedom of expression and the right to information;
- to comply with a legal obligation under Union or Member State law to which the data controller is subject, or to carry out a task carried out in the public interest or in the exercise of official authority vested in the data controller;
- on grounds of public interest in the area of public health;
- for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, in so far as the exercise of the right to erasure would render impossible or seriously jeopardise such processing;
- for the establishment, exercise or defence of legal claims.
Your right to restriction of processing
You have the right to request that the Data Controller restrict data processing if any of the following apply:
- you contest the accuracy of the personal data; in this case, the restriction applies for a period enabling the Data Controller to verify the accuracy of the personal data;
- the processing is unlawful and you oppose the erasure of the data, requesting instead that its use be restricted;
- the Data Controller no longer needs the personal data for the purposes of processing, but you require it for the establishment, exercise or defence of legal claims.
If data processing is restricted on the basis of the above, such personal data may, apart from storage, only be processed with your consent, or for the purpose of establishing, exercising or defending legal claims, or for the protection of the rights of another natural or legal person, or for reasons of substantial public interest of the Union or of a Member State. The Data Controller shall inform you in advance – if data processing has been restricted at your request – of the lifting of the restriction on data processing. The data will remain blocked for as long as the reason you have specified necessitates the storage of the data. You may request that the data be blocked, for example, if you believe that the Data Controller has processed your data unlawfully, but it is necessary for the purposes of administrative or judicial proceedings initiated by you that the Data Controller does not erase the data.
In this case, the Data Controller will continue to store the personal data until the authority or court makes a request, after which the Data Controller will delete the data.
Your right to data portability
You have the right to receive the personal data concerning you, which you have provided to a data controller, in a structured, commonly used and machine-readable format; you also have the right to transmit this data to another data controller without hindrance from the data controller to whom you have provided the personal data, if:
- the legal basis for the processing is your consent or the performance of a contract to which you are a party, and
- the processing is carried out by automated means.
When exercising your right to data portability, you are entitled – where technically feasible – to request that your personal data be transferred directly from one data controller to another.
The exercise of the right to data portability must not infringe the right to erasure. The right to data portability does not apply where the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. The right to data portability must not adversely affect the rights and freedoms of others.
Your right to withdraw consent
You have the right to withdraw your consent to data processing at any time. Withdrawal of consent does not affect the lawfulness of data processing carried out on the basis of consent prior to withdrawal.
Your right to seek redress
Contacting the Data Controller
We recommend that, before initiating court or administrative proceedings, you send the Data Controller your enquiry or complaint regarding the processing of your personal data so that we may investigate it and resolve it to your satisfaction, or so that we may comply with any request or claim you have made under the previous point, provided it is well-founded.
The Data Controller shall, in the event of the Data Subject exercising any of their rights relating to data processing as set out in the previous point, a request for information regarding data processing, or an objection or complaint concerning data processing, the Data Controller shall investigate the matter without undue delay, within the timeframe prescribed by the applicable legislation, take appropriate action in response to the request, and provide the Data Subject with information regarding the matter. Where necessary, taking into account the complexity of the request and the number of requests, this time limit may be extended in accordance with the law.
If the Data Subject has submitted the request electronically, the Data Controller shall provide the information electronically where possible, unless the Data Subject requests otherwise. If the Data Controller does not take action in response to the Data Subject’s request without undue delay, but at the latest within the time limit specified by law, it shall inform the Data Subject of the reasons for failing to take action or for refusing to comply with the request, and that the Data Subject may initiate court or administrative proceedings in their case as set out below.
In order to exercise your rights relating to data processing, or if you have any questions or concerns regarding the data processed by the Data Controller, or if you wish to request information about your data, lodge a complaint, or exercise any of your rights as set out in the previous point, you may do so using the contact details of the Data Controller listed in point 1).
Initiating legal proceedings
The Data Subject may bring proceedings against the Data Controller or – in connection with data processing operations falling within the scope of the data processor’s activities – against the data processor, if they consider that the Data Controller, or the data processor commissioned by or acting on the instructions of the Data Controller, is processing their personal data in breach of the provisions laid down in legislation or in a binding legal act of the European Union relating to the processing of personal data.
Regional courts shall have jurisdiction to hear the case. The case may also be brought – at the Data Subject’s discretion – before the competent court in the Data Subject’s place of residence or habitual residence. You may also bring a civil action against BKK. The case may generally be brought before the Budapest-Capital Regional Court, which has jurisdiction over BKK’s registered office, or – at your discretion – before the court in the area where you are resident.
Lodging a complaint with the supervisory authority
If you believe that the Data Controller is processing your data unlawfully – without prejudice to other administrative or judicial remedies – you are entitled to lodge a complaint with the National Authority for Data Protection and Freedom of Information (NAIH) (address: 1055 Budapest, 9–11 Falk Miksa Street, postal address: 1363 Budapest, PO Box 9, email:ugyfelszolgalatnaih.hu , telephone: +36 (1) 391-1400, fax: +36 (1) 391-1410, website: www.naih.hu) – in particular in the Member State of your habitual residence, place of work or the place where the alleged infringement occurred – if you consider that the Data Controller is restricting the exercise of your rights or has rejected your request to exercise those rights (initiation of an investigation), and if, in their view, the Data Controller, or a data processor commissioned by or acting on the instructions of the Data Controller, infringes the provisions governing the processing of personal data as laid down in legislation or in a binding legal act of the European Union (request for the conduct of an administrative procedure).