Is Google Analytics Legal in Hungary? The 'Equal-Prominence' Cookie Standard and What It Demands

Is Google Analytics legal in Hungary? No ruling bans it by name. But NAIH, Hungary's privacy authority, has already ordered one popular website to remove Google Analytics for good, and it fined the country's biggest commercial broadcaster HUF 10 million over a cookie banner where rejecting took one click more than accepting. In plain English: the tool isn't banned, but the way most sites run it is. Here's the full picture, and what it means for you.
- Google Analytics has never been banned by name in Hungary, but NAIH ordered the weather site Időkép to permanently remove it in November 2022 over unlawful US data transfers.
- NAIH fined broadcaster TV2 HUF 10 million (roughly EUR 25,000) because Accept All took one click and Reject All took two. Equal prominence is the Hungarian standard.
- Hungary has no consent exemption for analytics. Under Act C of 2003, every non-essential cookie, including GA's _ga and _gid, needs prior opt-in consent.
- NAIH kept the TV2 fine low only because it was Hungary's first published cookie decision, and said so. The ceiling is EUR 20 million or 4% of global turnover.
- The EU-US Data Privacy Framework keeps GA's transfers legal for now. The EU General Court upheld it in September 2025; the appeal is pending at the CJEU.
The rules you're subject to in Hungary
Three layers of law decide what you can collect with analytics in Hungary. The GDPR applies directly, like everywhere in the EU. The Infotv, Act CXII of 2011, is Hungary's own data protection act. And your cookie banner answers to a third law entirely: Act C of 2003 on Electronic Communications.
That third law is the one you've probably never heard of. Section 155 of Act C of 2003 is Hungary's version of the EU's ePrivacy rules, the directive that gave Europe the cookie banner. It says you can't store anything on a visitor's device, or read anything from it, until the visitor has been clearly and fully informed and has agreed. Inform first, consent second, cookie third.
Notice the order there. A banner that fires trackers while you're still reading it fails the sequence before the design even matters.
If you've only ever thought about analytics through the GDPR, this is the mental shift: the cookie rule isn't about personal data at all. Section 155 protects the device. It applies before anyone gets to argue about whether an IP address is personal data, which means "we anonymize everything" doesn't get you out of the banner. Storage first, purpose later.
There's one exemption: strictly necessary cookies. A session cookie that keeps a shopping cart alive doesn't need consent, which means the login and cart mechanics of your site are safe. Analytics cookies aren't on that list. Not GA's, not anyone's.
So before you think about tools at all, ask yourself two questions about your own site. What does each script store on the visitor's device, and does anything load before your banner gets an answer? If you can't answer both from memory, open your browser's developer tools and look. That five-minute check is exactly the test NAIH ran on a popular Hungarian weather site, and I'll show you below how that ended.
That's worth a beat, because France runs a formal consent exemption for privacy-respecting audience measurement, and Italy has a similar principles-based one. Hungary doesn't have anything like that. Every analytics cookie needs prior opt-in consent before it loads. If your tool sets cookies, you need a banner, and the banner has to be honest.
Enforcement sits with a single authority: NAIH, the Nemzeti Adatvédelmi és Információszabadság Hatóság. One country, one regulator, one interpretation. That's a different world from Germany, where sixteen state authorities and a federal one share the job. And NAIH carries the standard GDPR ceiling of EUR 20 million or 4% of global turnover, whichever is higher. Which means the small fines you'll read about below are a choice, not a limit.
The TV2 fine: what "equal prominence" demands
NAIH's defining cookie decision landed on TV2 Média Csoport, the broadcaster behind tenyek.hu and tv2play.hu. The fine was HUF 10 million, roughly EUR 25,000, in a 2022 decision that reached the English-language legal press through spring 2023. (Noerr converts it to about EUR 25,000, Kapolyi to about EUR 27,000; the gap is just the exchange-rate date, so I'll use the lower figure.) That means Hungary's defining cookie ruling cost less than a small car. The headline violation was simpler still. Accepting cookies took one click. Rejecting took two.
That one-click gap now has a name. Hungarian practitioners call it the equal-prominence rule, and the consent platform Kukie summarizes NAIH's standard bluntly: an Accept All and a Reject All button must appear with equal prominence, at the same level of the banner. Same screen, same weight, same click cost. Anything less means consent wasn't freely given, which makes it no consent at all.
The banner's geometry was only the start. I read both law-firm write-ups of the decision, Noerr's and Kapolyi's, and NAIH also found:
- The cookie information sat in a cramped, hard-to-read corner of the screen. Transparency you need a magnifying glass for isn't transparency.
- The banner said "we and our partners" while quietly covering 754 advertising and data partners. That means visitors were agreeing to share data with hundreds of companies they'd never heard of, on the strength of one vague phrase.
- Identical processing purposes ran under consent in one place and legitimate interest in another. Legitimate interest is the GDPR basis that lets a company process data without asking, when its interests genuinely outweigh yours. Running the same purpose under both bases at once is having it both ways, and NAIH said no.
- Objecting to that legitimate-interest processing took at least three clicks. One click to accept everything. Three or more to fully refuse.
Two more details matter if you run a banner yourself.
First, TV2 pointed to its participation in the IAB's Transparency and Consent Framework, the standardized consent system much of the ad industry runs on. NAIH's answer, as Kapolyi reports it: taking part in the framework doesn't itself prove GDPR compliance. An off-the-shelf banner doesn't settle anything for you.
Second, and this is the part I'd underline twice: NAIH wrote down why the fine stayed small. Hungary didn't have a published cookie-management precedent yet, so the first offender got a discount. In the same breath, the authority said widespread non-compliance doesn't make a practice lawful. Read those two together and you get the message. The warning shot is fired.
Kapolyi cites the decision as case NAIH-3195/2022, brought under the GDPR's core articles on lawfulness, transparency, and the duty to inform. In practice, that's the citation you'd hand your lawyer.
Here's how I'd turn the decision into a five-minute audit of your own banner. Count the clicks it takes to accept everything, then count the clicks to refuse everything, including any legitimate-interest toggles hiding on a second screen. If the second number is bigger, you're running the pattern NAIH fined. Then read your cookie text at arm's length and ask whether a visitor could name who gets their data. "We and our partners" didn't survive that test with 754 partners behind it, and your version won't either.
The case where NAIH ordered a site to delete Google Analytics
In November 2022, NAIH ruled that Időkép, one of Hungary's most popular weather sites, didn't have a lawful basis for sending visitor data to Google's US servers, and ordered it to remove Google Analytics permanently. NAIH didn't fine the site at all, which means the remedy was the removal itself.
The case started with noyb, the privacy group founded by Max Schrems. In August 2020, one month after the EU's top court struck down the Privacy Shield transfer deal in the Schrems II ruling, noyb filed 101 near-identical complaints across Europe against sites running Google Analytics and Facebook Connect. One targeted Időkép over a visit on 12 August 2020; the complaint went in five days later.
Schrems II, in plain English: the court found US surveillance law reaches data held by US companies, so sending Europeans' personal data to the US needed protections the Privacy Shield didn't deliver. Google Analytics sends visitor data to Google LLC in the US. That wasn't a technicality, it was the whole complaint.
Here's the detail that should make you pause. Időkép told NAIH it had removed Google Analytics on 24 August 2020, one week after the complaint. NAIH tested the live site on 27 May 2022 and found three cookies from a Google advertising service package still sending data to the US. In plain English, the site said gone, and the regulator found it still running. The removal claim didn't survive contact with the evidence.
So on 4 November 2022, NAIH ruled the transfers unlawful and ordered Időkép to permanently remove the Google Analytics code and stop the transfers. noyb logs it as case C029-79, marked won. Won, in practice, means the code came out and stayed out.
Notice the timeline, too. More than two years passed between the complaint and the decision. If you're doing the math, that's a regulator that moves slowly and then moves completely. The lesson I take from it isn't about speed. It's that a complaint filed against you today can surface as an order long after you've stopped thinking about it, and that "we removed it" only counts if the network tab agrees with you.
Hungary wasn't first to this conclusion. Austria's DSB ruled against Google Analytics transfers in January 2022, and France's CNIL followed a month later. Hungary's decision arrived later and quieter, with no fine and no press blitz. But the order itself was harder than most. Not "fix your configuration". Delete the tool.
So is Google Analytics legal in Hungary today?
Conditionally, yes. No Hungarian decision declares Google Analytics unlawful as a product, and NAIH has published no GA-specific guidance at all. But GA's cookies need prior opt-in consent before they load, and its US transfers lean on the EU-US Data Privacy Framework, a deal that's now under appeal at the EU's highest court.
Start with what doesn't exist. There's no NAIH position paper on Google Analytics, nothing like Austria's ruling series or CNIL's formal notices in France. The closest thing Hungary has is the Időkép order, which condemned one site's GA setup rather than the product. If you're hunting for a sentence that says "Google Analytics is illegal in Hungary", you won't find one. I looked.
What you will find is a consent regime with no analytics carve-out. Kukie's compliance guide states it directly: GA's own cookies, _ga and _gid, count as non-essential under Act C of 2003 and the GDPR, so they need opt-in consent before they're set. In practice, that's a compliance vendor's reading, not a NAIH quote. But it puts GA's cookies in the same category NAIH already fined a broadcaster over, and if you run a business on GA, I wouldn't bet it on the distinction. For how this question plays out across the rest of Europe, the full legality picture is here.
Then there's the transfer question, and I'll be honest, this is where the ground moves.
In July 2023, the European Commission adopted the EU-US Data Privacy Framework, the DPF, a new adequacy deal giving transfers to certified US companies a legal basis. Google is certified, which means the exact hole the Időkép order was built on is patched. GA's transfers to the US are legal today because the DPF says so.
"Because the DPF says so" carries a lot of weight, though. On 3 September 2025, the EU General Court dismissed the first challenge to the DPF, brought by French politician Philippe Latombe, and upheld the adequacy decision at first instance. That means the framework survived round one. Latombe appealed to the CJEU in October 2025, per the law firm WilmerHale's case tracking, and the appeal is pending with no hearing date. noyb, the group whose complaints killed the last two frameworks, considers the Latombe case too narrow and is weighing broader challenges of its own.
That history should worry you. Safe Harbor fell in 2015. Privacy Shield fell in 2020. Put another way, the same bridge has already collapsed twice. The DPF is the third attempt, and Hungary's own precedent, Időkép, shows you exactly what NAIH orders when the bridge is out.
What would I do with that if I ran GA on a Hungarian site today? I'd treat the DPF as weather, not climate. Operating under it while it holds is fine, but I'd want my measurement to survive the day it doesn't. The certification is Google's to maintain and Brussels' to defend, and you control neither. And the Hungarian precedent tells you the cost of being on the wrong side isn't a warning letter. It's the tool itself, ordered out.
What NAIH enforcement actually looks like
One cookie fine, one removal order, and a written promise of more. NAIH's cookie record is far thinner than CNIL's, and you might be tempted to read that as safety. I'd read it as a loaded precedent instead, because the authority has said, in a published decision, that the first-mover discount is spent.
The single-regulator setup cuts both ways, by the way. In Germany you might reasonably wonder which of seventeen authorities' readings applies to you. In Hungary there's no such ambiguity and no forum to shop: one authority, one published cookie decision, and every future case measured against it. When NAIH moves again, you won't be able to argue you didn't know the standard.
For scale: Kapolyi, the Budapest law firm, counts 67 NAIH fines under the GDPR between 2018 and 2023, totalling about EUR 2.3 million, an average of EUR 34,535 per case, with amounts rising year over year. In plain English, five years of Hungarian GDPR enforcement adds up to a rounding error next to the ceiling. Which means the real deterrent isn't the historical average, it's the EUR 20 million maximum and the direction of travel.
And 2024? An analysis of NAIH's major fined cases that year by the Hungarian firm DMP found banking AI, data breaches, workplace surveillance, health records, covert recordings, and not a single cookie or analytics case. In practice, that means the TV2 decision still stands alone. NAIH hasn't made a second example yet.
That's less comforting than it sounds. NAIH wrote in the TV2 decision that widespread non-compliance doesn't make a practice lawful, and that the fine stayed low for lack of precedent. Both halves of that sentence now point the same way. The precedent exists. You don't want to be the case that proves it.
The traffic your cookie banner is hiding
Here's what I can't give you: a Hungary-specific cookie accept-rate study. None exists, so I won't invent one. What I can give you is Hungary's digital context, the European pattern, and the awkward arithmetic of a law that forces your banner to make rejecting effortless.
Hungary is a thoroughly online country. DataReportal's Digital 2025 report counts 9.09 million internet users, 94.1% of the population. Put another way, nearly everyone you could want to reach is online, and nearly all of them meet your cookie banner before they meet your content.
The rest of DataReportal's numbers point the same way. 95% of Hungarian households have broadband, nine in ten people aged 16 to 74 are online daily, and 7.04 million Hungarians, 72.9% of the population, use social media. This isn't a market where you can shrug off digital measurement. It's one where the measurement question decides how well you understand most of your customers.
European studies of compliant banners point the same way over and over: when accepting and rejecting cost the same single click, a large share of visitors reject, often the majority. Hungary now mandates exactly the banner design those studies measured. NAIH's equal-prominence rule makes refusal a one-click act with the same visual weight as acceptance, which means a compliant Hungarian banner is engineered to raise your rejection rate. The better your banner, the less your cookie-based analytics see. Compliance and completeness pull in opposite directions.
Ad blockers take another slice. An NMHH survey reported by Statista found 14% of Hungarians used an ad blocker on some device in 2022, and 39% of 16 to 29 year olds did. Even among the over-60s it was 26%. In plain English, one visitor in seven blocks your scripts outright, and among the young it's nearly four in ten. The survey is from 2022, the newest Hungary-specific figure I could find, but blocker use hasn't been trending down anywhere. Which means among the visitors you most want to understand, your analytics script often never loads at all.
Browsers do the rest. Per StatCounter's rolling numbers, pulled as of early August 2026, Chrome holds about 70.6% of the Hungarian market and Safari about 13.1%, with Firefox around 5% and Edge around 4%. That means roughly one Hungarian visitor in eight browses with Safari's Intelligent Tracking Prevention, which caps and deletes cookies on its own schedule. No banner interaction required.
Add it up, and a cookie-based tool on a Hungarian site is measuring a sample and calling it the population. You're making decisions on the visitors who clicked yes, ran no blocker, and used the right browser. Everyone else is a ghost.
There's one clean exit. Analytics that never stores anything on the device, no cookies, no local storage, never triggers the Section 155 consent duty in the first place. That's how Clickport works: cookieless by design, bots filtered at ingestion, data processed in the EU, and no banner needed for the analytics itself. The visitors your banner was hiding simply show up.
What's coming in 2026 and beyond
I'm watching three developments, and you should too: an EU proposal that could end the analytics consent duty entirely, a court case that could re-break Google Analytics transfers, and a regulator that has told the market its patience was a one-time offer. Any one of the three changes the math for you.
1. The Digital Omnibus. Proposed by the European Commission in November 2025, it includes a consent exemption for privacy-preserving audience measurement across the whole EU. I've broken the proposal down in a separate piece. It's still a proposal, not law, which means nothing changes for you today. But notice who'd gain most if it lands as described. Countries like Hungary, with no analytics exemption today, would jump from the strictest reading straight to consent-free measurement. France built its own exemption years ago; Hungary would get one delivered from Brussels.
2. The DPF appeal. Latombe's appeal is pending at the CJEU with no hearing date, and noyb, the group that killed the previous two frameworks, thinks his case is too narrow and is weighing broader challenges of its own. If the court overturns the framework, GA's US transfers lose their legal basis overnight, and Hungary already has a precedent for what happens next. Időkép shows you NAIH's remedy of choice. Removal, not remediation. Note the asymmetry, too: if the DPF survives, your cookie-based analytics still has to clear the equal-prominence bar. If it falls, the banner is the least of your problems.
3. NAIH's stated trajectory. The TV2 decision reads like a memo to the market: precedent now exists, industry practice is no defense, and the fine was low because it was early. It isn't early anymore. And remember the enforcement record from above. The file is thin because Hungary has published one cookie decision, not because the rules are relaxed, and in that one decision the authority went out of its way to say widespread non-compliance doesn't make a practice lawful. That's not a regulator that considers the matter closed.
If you'd rather not track any of this, the move is the same in all three futures: measurement that doesn't depend on cookies or on US transfer law. Our roundup of European analytics options maps that landscape, and our cookie banner guide helps you check what your own site strictly needs.
What this means for your website
If you run a site with Hungarian visitors, here's my honest read of where you stand. It depends less on which tool you picked and more on what your banner does in its first two clicks. That's where NAIH has looked, and that's where it fined.
If you're using Google Analytics with a cookie banner: you're likely lawful on the transfer question today, courtesy of the DPF. But your banner has to clear NAIH's bar: one click to reject, equal prominence, no legitimate-interest double-dipping, no "we and our partners" hand-waving. And every compliant rejection is a visitor your reports will never show you. You're trading completeness for compliance every single day.
If your banner accepts in one click and rejects in two: you're running the exact pattern NAIH fined TV2 for, in the country's only published cookie decision. The first-mover discount is spent, and you don't want to be the second name on the list. I wouldn't wait for the reminder.
If you want to see all your traffic and stop watching the DPF docket: switch to analytics that doesn't store anything on the visitor's device. No cookies means no Section 155 consent duty for your analytics, no banner arithmetic, and no dependency on a transfer framework that's on its third life. See how it works.
Whatever you run, here are the three questions I'd put to any analytics vendor, including us. Does your script store anything on the visitor's device? Where is the data processed, and does any of it leave the EU? And if I turn off your cookies, what exactly stops working? A vendor who can't answer those in plain language is asking you to carry their legal risk. With Clickport the answers are: nothing, in the EU, and nothing stops working, because there were no cookies to begin with.
A closing note, because this is a legal topic: I'm not a lawyer and this isn't legal advice. It's a founder's map of the terrain, built from the published decisions and the law firms that reported them, linked wherever a verified source exists. If your setup is complicated, show this to your DPO or your lawyer.
You can try Clickport free for 30 days, no credit card needed. And if you're coming from Google Analytics, switching takes one snippet: swap the tag and you're collecting within minutes. If something here doesn't match what you're seeing in Hungary, email me.

Comments
Loading comments...
Leave a comment