View this page in: Hungarian
General information on our data processing activities
PricewaterhouseCoopers Hungary Ltd. (registered office: Bajcsy-Zsilinszky út 78., 1055 Budapest, Hungary, entered in the company register by the Budapest Metropolitan Court as court of registry under Cg. 01-09-063022),
PricewaterhouseCoopers Auditing Ltd. (registered office: Bajcsy-Zsilinszky út 78., 1055 Budapest, Hungary, entered in the company register by the Budapest-Metropolitan Court as court of registry under Cg. 01-09-961102), and
(hereinafter “PwC”, “we”, “us” or “our”) have prepared and updated this privacy statement to comply with the obligation to provide information on our data processing.
We divided the privacy statement into chapters, from which you can choose below depending on which of our data processing practices you would like to read in more detail.
Introduction
Personal data is any information relating to an identified or identifiable individual (“data subject”).
PwC is strongly committed to protecting and lawfully processing personal data. This privacy statement, in accordance with the provisions of the GDPR[1] and relevant Hungarian sectoral legislation, in particular Act CXII of 2011 on the Right of Informational Self-Determination and the Freedom of Information, describes for what purpose, on what legal grounds, and how we process personal data, and provides information about the rights of individuals in connection with such processing, and any other circumstances relevant to the data processing.
In all cases, our data processing will comply with the following principles:
Given its activity, PwC processes personal data for numerous purposes, and certain characteristics of the processing, such as the means of collection, the lawful basis of processing, and the retention periods may differ for each purpose. In any case, we will provide prior information on these aspects.
We have robust organisational and IT measures in place to keep the data we process secure. We adhere to internationally recognised security standards, and our information security management system relating to client data is independently certified as complying with the requirements of ISO/IEC 27001:2013. We have a framework of policies, procedures and training in place covering data protection, confidentiality, and data security, and we ensure that our staff continuously improve their privacy awareness through regular data protection training.
We consult other member firms in the PricewaterhouseCoopers network in order to improve the efficiency of our internal privacy and data security procedures, and to bring them into line with the applicable regulations.
We regularly review our internal processes, data processing practices and related documentation.
We also have a Data Protection Officer who monitors the lawfulness of data processing, and serves as a point of contact for data subjects, and for the Hungarian National Authority for Data Protection and Freedom of Information (“NAIH”).
Data Protection Officer:
Name: dr. Orsolya Hosszú, attorney-at-law, lawyer specialized in data privacy and data security.
Email: hu_dataprotection@pwc.com
Phone: +36 1 461 9100
When processing personal data, our policy is to be transparent. In order to make clear distinction between the data processing activities, this privacy statement contains the related information per processing purpose.
To find out more about our specific processing activities, please see the relevant chapters of this statement.
[1] Regulation (EU) 2016/678 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
In relation to the provision of the training services of PwC’s Academy, we may process the personal data of private individual clients or individuals associated with our corporate clients (typically individuals registered for training by a corporate client).
Training organised within the scope of the Adult Education Act
Pursuant to Section 21 (1) of Act LXXVII of 2013 on Adult Education (“Adult Education Act”), and – if applicable - Annex 11 to Government Decree 93/2002 (V. 5.) on the Registration of Accounting Service Providers, we are required to process the following information in respect of data subjects participating in trainings organised by PwC’s Academy within the scope of the Adult Education Act (e.g. state-funded training, or any additional type of training for which PwC has obtained an adult education licence):
In addition to the above, the telephone number provided by the participant during the application process will be used for contact purposes in order to ensure the successful completion of the training.
Training not covered by the Adult Education Act
Some of our training courses are not covered by the above legislation, however, depending on the subject matter of the training, we may need to process the above data in order to successfully organise the training.
Use of personal data
We use the personal data for the following purposes:
In addition, please note that PwC provides data to the Adult Education Data System pursuant to Section 15 of the Adult Education Act. By registering for the training, the participant acknowledges that when his/her personal data is transferred to the Adult Education Data System under the Adult Education Act, the participant's identification data will be compared against the data contained in the register pursuant to Act LXVI of 1992 on the Registration of Personal Data and Address of Citizens.
Legal grounds
The legal grounds for our data processing are as follows:
Data retention
We retain the personal data processed by us for as long as strictly necessary for the purpose for which it was collected.
As part of that process:
Our other data processing activities
Scope of data processed
In the context of the purposes set out in this section, we process primarily the following personal data:
Legal grounds
Transferring data
We will only share personal data with third parties when we are legally obliged to do so or where it is otherwise lawful to do so. When we share personal data with other parties, we put contractual arrangements and security mechanisms in place as appropriate to protect the data and to comply with both the legal requirements and our internal data protection, confidentiality and security standards, as well as the relevant professional standards.
We are part of PwC’s global network and in common with other professional service providers, we use third parties located in other countries to help us run our business. As a result, personal data may be transferred and become available outside the countries where we and our clients are located.
Cross-border transfers may include transfers to countries outside the European Union (“EU”) and to countries that do not have laws that provide the level of protection for personal data expected by the EU. We have taken steps to ensure all personal data are provided with adequate protection as required by the EU also in cases in which personal data is transferred outside the EU. Where we transfer personal data outside of the EU to a country not determined by the European Commission as providing an adequate level of protection for personal data, the transfers will be under an agreement which covers the EU requirements for the transfer of personal data outside the EU, such as the European Commission approved standard contractual clauses.
In certain cases, the recipient to whom the personal data are transferred will act as data controller, as it will determine the purpose of processing independently. This may be the case when our services provided to clients involve the services of other PwC member firms, where these member firms determine their own policies for providing their services.
In other cases, the recipient may act as PwC’s data processor, as it will not determine the purpose and method of processing by itself, but rather follow PwC’s documented instructions. For example, an IT services company may provide us services by processing data based on our instructions (e.g. data storage), or we may transfer data to an external event organiser for the sole purpose of facilitating the technical organisation of an event. If the recipient acts as PwC’s data processor, we will make sure that it carries out its activities in accordance with an appropriate data processing agreement that complies with GDPR requirements, ensuring that such processing is carried out lawfully.
Personal data held by us may be transferred to:
For the details of our member firm locations, please click here. We may share personal data with other PwC member firms where necessary for administrative purposes and to provide professional services to our clients (e.g. when providing services involving PwC member firms in different countries). The fact of our business contacts is visible to other PwC member firms;
For example, providers of information technology, cloud-based software infrastructure providers, identity management, website hosting and management, data analysis, data backup, security and storage services.
Changes to this privacy statement
We recognise that transparency and ensuring compliant data processing is an ongoing responsibility, thus, we will review this privacy statement on a regular basis.
We reserve the right to modify or amend this privacy statement at any time.
Data controllers and contact information
For the purposes of data processing covered by this privacy statement, the data controller is:
PricewaterhouseCoopers Hungary Ltd. (registered office: Bajcsy-Zsilinszky út 78., 1055 Budapest, Hungary, entered in the company register by the Budapest Metropolitan Court as court of registry under Cg. 01-09-063022) and
PricewaterhouseCoopers Auditing Ltd. (registered office: Bajcsy-Zsilinszky út 78., 1055 Budapest, Hungary, entered in the company register by the Budapest Metropolitan Court as court of registry under Cg. 01-09-961102)
Given the organisational structure of the PwC group in Hungary and the allocation of administrative and operative functions between the individual companies, PricewaterhouseCoopers Hungary Ltd. and PricewaterhouseCoopers Auditing Ltd. may, in certain cases, act as joint data controllers. In such cases, the data controllers will clearly agree among themselves on their obligations and responsibilities.
If you have any questions about this privacy statement or the processing of personal data, or you wish to exercise your rights detailed below, please contact us via our website or:
Email: hu_dataprotection@pwc.com
Phone: +36 1 461 9100
Data Protection Officer: dr. Orsolya Hosszú, attorney-at-law, specialized in data privacy and data security.
What rights do you have as a data subject in relation to your personal data processed by PwC?
You may request access to and rectification or erasure of your personal data or, in certain cases, restriction of the data processing, and may object to the processing of personal data. You have the right to data portability, the right to file a complaint with the supervisory authority, and the right to judicial remedy. In the case of automated individual decision-making, you have the right not to be subject to the automated decision, and the right to obtain human intervention.
Where the processing is based on your consent, you have the right to withdraw consent at any time, without affecting the lawfulness of the processing based on your consent before its withdrawal.
Right of access
You have the right to obtain information at any time about whether PwC processes personal data about you, the means and purposes for which the data are processed, the recipients to whom the personal data have been disclosed, the source from which PwC has obtained the personal data, the term for which the personal data are processed, and information on automated decision-making and profiling. In the case of data transfer to third countries and international organisations you have the right to request information on the related additional safeguards. When exercising your right of access, you also have the right to receive a copy of your personal data; in the case of a request filed electronically, unless otherwise noted, PwC will provide the requested information electronically (e.g. in PDF format).
If your right of access adversely affects the rights or freedoms of others, including trade secrets or intellectual property, PwC is entitled to refuse to act on your request to the necessary and proportionate extent. If you request the above information in additional copies, PwC will charge you a reasonable fee that is proportionate to the administrative costs incurred in preparing any additional copies.
Right to rectification
You have the right to request PwC to amend or rectify your personal data where it is inaccurate. If there is any doubt regarding the data to be amended, PwC may request you to verify the data by any appropriate means (primarily by means of an official document). If PwC has disclosed the personal data concerned to other parties (recipients such as processors), PwC will communicate any rectification of personal data to each recipient to whom the data have been disclosed, unless this proves impossible or involves disproportionate effort. PwC will inform you about such recipients if you request so.
Right to erasure (“right to be forgotten”)
If you request PwC to erase any or all of your personal data, PwC will erase the personal data concerned without undue delay if:
If PwC has disclosed the personal data concerned to other parties (recipients such as processors), PwC will communicate any erasure of personal data to each recipient to whom the data have been disclosed, unless this proves impossible or involves disproportionate effort. PwC will inform you about such recipients if you request so.
PwC’s obligation to erase the personal data will not apply to the extent that processing is necessary for the establishment, exercise or defence of legal claims.
Right to restriction of processing
You may request restriction of the processing of your personal data in the following cases:
Where processing has been restricted, PwC does not process, except for storage, the personal data subject to the restriction, or only to the extent you have consented to. Even in the absence of such consent, PwC may process data that is necessary for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or of an EU Member State.
PwC will inform you before the restriction of processing is lifted. If PwC has disclosed the personal data concerned to other parties (recipients such as processors), PwC will communicate any restriction of processing to each recipient to whom the data have been disclosed, unless this proves impossible or involves disproportionate effort. PwC will inform you about such recipients if you request so.
Right to object
If the data processing is carried out on grounds of the legitimate interests of PwC or a third party, you have the right to object to the processing. PwC may refuse to comply with the objection if PwC demonstrates
Right to lodge a complaint, and judicial remedy
You have the right to lodge a complaint with a data protection supervisory authority in the Member State of your habitual residence, place of work or place of the alleged infringement if you consider that PwC’s processing of your personal data infringes the existing data protection laws, in particular the provisions of the GDPR. In Hungary, you may turn to the Hungarian National Authority for Data Protection and Freedom of Information (“NAIH”).
You may contact NAIH at:
Website: http://naih.hu/
Address: 1055 Budapest, Falk Miksa utca 9-11.
Mailing address: 1363 Budapest, Pf. 9.
Phone: +36-1-391-1400
Fax: +36-1-391-1410
Email: ugyfelszolgalat@naih.hu
Without prejudice to your right to lodge a complaint, you have the right to judicial remedy. You have the right to judicial remedy also against a legally binding decision of a data protection supervisory authority concerning you. You also have the right to judicial remedy where the supervisory authority does not handle a complaint or does not inform you within three months on the progress or outcome of the complaint you have lodged.
If you wish to exercise any of the above rights (except for lodging a complaint with NAIH or seeking judicial remedy), please email us at hu_dataprotection@pwc.com.
Complaints relating to our use of personal data may be sent by email, with details of your complaint, to hu_dataprotection@pwc.com. We will look into and respond within one month to any complaints we receive.
If possible, please let us know of your complaint or question first before taking any further action and we will do our best to resolve it!
This privacy statement was adopted on 22 May 2018. Date of last revision: 16 January 2023.