Do you have an incident?

Our S.O.S. line:

+49 89 262 025954

Our team of experts is ready to assist your organization in the event of a cyberattack.

details

Trainings

Background

Privacy policy for applicants to cybersecurity training and continuing training programmes

 


1. Name and contact details of the Controller

Name of the Controller: White Hat IT Security Szolgáltató és Kereskedelmi Korlátolt Felelősségű Társaság, hereinafter: White Hat or the Controller

Registered office: 1021 Budapest, Ötvös János u. 3.

Mailing address: 1021 Budapest, Ötvös János u. 3.

Tax number: 26373643-2-41

Company registration number: Cg. 01-09-326869

Representative: Sándor Fehér, CEO
Website: Home Page – White Hat IT Security

Data protection contact person:

Name: dr. Alexandra Enyedi
E-mail: privacy@whitehat.eu
Telefon: +36 20 346 9646


2. Purpose and legal basis of processing

White Hat processes personal data for the purposes of registering for the cybersecurity training and continuing training programmes organised by it, organising, conducting and documenting the training programmes, certifying participation, issuing certificates, invoicing, and fulfilling statutory data reporting obligations.

This processing relates in particular to the following training programmes:

  • mandatory cybersecurity training and continuing training for company executives, heads of organisations and senior executives;
  • mandatory cybersecurity continuing training for information security officers, persons responsible for the security of electronic information systems, and professionals acting in related roles.

The training programmes are provided as adult education activities pursuant to Ministerial Decree 17/2025 (VII. 24.) EM, related to Act LXIX of 2024 on the Cybersecurity of Hungary. In connection with the training programmes, White Hat is subject to adult education documentation, certificate issuance and data reporting obligations.

The legal basis for processing is:

  • in the case of managing applications and organising and conducting the training, Article 6(1)(b) of the GDPR, as the processing is necessary for the performance of the training service and for taking steps prior to entering into a contract;
  • in the case of adult education documentation, certificate issuance, reporting to FAR and invoicing, Article 6(1)(c) of the GDPR, as the processing is necessary for compliance with a legal obligation to which the Controller is subject;
  • in the case of processing contact details and handling any complaints, legal disputes and fee claims, Article 6(1)(f) of the GDPR, namely the legitimate interests of the Controller.

3. Categories of personal data processed

In the course of registration for and delivery of the training and compliance with statutory obligations, White Hat may process the following personal data:

  • name of the applicant;
  • name of the person participating in the training;
  • name of the contact person;
  • e-mail address;
  • telephone number;
  • name of the nominating or invoiced organisation;
  • name of the selected training programme;
  • selected training date;
  • participation and attendance data;
  • data relating to completion of the training;
  • data required for issuing the certificate;
  • data required for reporting to FAR and to be transferred pursuant to law;
  • invoicing name;
  • invoicing address;
  • tax number;
  • tax identification number, where its processing is necessary;
  • payment method;
  • data relating to a pro forma invoice, invoice or payment of fees.

Registration for the training takes place via a Microsoft Forms form. On the Microsoft Forms interface, the applicant or the contact person designated by the organisation provides the data required for registration and administration of the training.

Where the applicant or the contracting organisation provides the data of another natural person, it must ensure that the data subject receives appropriate information about the processing.


4. Source of personal data

The primary source of the personal data is the data subject, the applicant, or the contact person of the organisation registering for or ordering the training.

As a general rule, White Hat does not process personal data that has not been provided by the data subject, the applicant or the contracting organisation.


5. Reporting to FAR and adult education documentation

Pursuant to adult education legislation, White Hat is required to transfer specified data relating to the training to the Adult Education Data Reporting System (Felnőttképzési Adatszolgáltatási Rendszer), i.e. FAR.

The transfer of data to FAR is not based on consent but is carried out in order to comply with a statutory obligation. Fulfilment of the reporting obligation is a condition for conducting the training within the adult education framework.

White Hat records and retains documents relating to adult education, including in particular application, participation, attendance, completion and certificate issuance documents, for the period prescribed by law.


6. Issuance of certificates

White Hat may issue a certificate confirming completion of the training or continuing training. For the purposes of issuing and recording the certificate, White Hat processes the data required to identify the participant and the name, date, number of hours and completion of the training, as well as to identify the certificate.

The legal basis for processing in connection with the certificate is Article 6(1)(c) of the GDPR, i.e. compliance with a legal obligation to which the Controller is subject.


7. Data retention period

White Hat processes personal data only for as long as is necessary to achieve the purpose of the processing or until the end of the retention period prescribed by law.

White Hat processes data relating to registration and contact until completion of the training and for as long as claims arising from the contractual relationship may be enforced, as a general rule until the end of the five-year limitation period under the Hungarian Civil Code.

White Hat retains data relating to adult education documentation, participation, completion, certificate issuance and reporting to FAR for the period specified in sectoral legislation, as a general rule until the last day of the eighth year following the year in which the data were generated.

White Hat processes data relating to invoices and accounting records until the end of the eight-year retention period prescribed by accounting legislation.

White Hat may process data relating to any complaints, legal disputes or fee claims until the case is closed or until the end of the limitation period available for enforcing the claim.


8. Recipients and processors

Personal data may be accessed by those employees and contributors of White Hat who need to know the data in order to organise, conduct, administer, invoice and document the training, issue certificates, or comply with a statutory obligation.

White Hat may transfer personal data to the following recipients or categories of recipients:

  • Adult Education Data Reporting System (FAR);
  • the body operating the FAR system;
  • the competent adult education authority, in particular the Government Office of Pest County;
  • the competent cybersecurity authority, where required by law or by a request from an authority;
  • the National Tax and Customs Administration of Hungary (NAV), in cases prescribed by law;
  • accountant;
  • invoicing software service provider;
  • account-holding bank;
  • legal representative, authority or court, where necessary for the establishment, exercise or defence of legal claims.

White Hat may use processors for its data processing operations.

In particular, the following is a processor:

Microsoft Corporation
Registered office: Redmond, Washington, United States of America
Task: supporting Microsoft Forms, Microsoft 365, cloud services, hosting services, electronic communications and technical data processing.

Microsoft Forms is used for the structured collection and technical handling of registration data.


9. Access and data transfers

Access to personal data is granted exclusively to authorised persons.

White Hat transfers personal data to third parties only where this is necessary to comply with a statutory obligation, perform a contract, pursue a legitimate interest, comply with a request from an authority or court, or where the data subject has given consent based on an appropriate legal basis.

White Hat does not sell personal data to third parties for marketing purposes or otherwise disclose it for such purposes.


10. Automated decision-making

White Hat does not use automated decision-making or profiling in the course of the processing activities covered by this Privacy Policy.


11. Rights of data subjects

Under the GDPR, the data subject has the following rights:

  • the right to withdraw consent, where the processing is based on consent;
  • the right of access;
  • the right to rectification;
  • the right to erasure;
  • the right to restriction of processing;
  • the right to object, where the processing is based on a legitimate interest;
  • the right to data portability, where the statutory conditions for exercising that right are met.

In the case of processing based on a statutory obligation—including, in particular, reporting to FAR, adult education documentation, certificate issuance and the retention of accounting records—the right to erasure may not be exercised in a manner that would prevent or render impossible White Hat’s compliance with its statutory obligations.

The data subject may submit a request to exercise their rights using the following contact details:

privacy@whitehat.eu


12. Time limit

White Hat shall comply with or respond to a data subject request without undue delay and, in any event, no later than one month after receipt of the request.

Where necessary, taking into account the complexity and number of requests, this period may be extended by a further two months. White Hat shall inform the data subject of any such extension within one month of receipt of the request, together with the reasons for the delay.


13. Remedies

If the data subject believes that White Hat is processing their personal data unlawfully, they are advised in the first instance to contact White Hat directly with their complaint or question:

privacy@whitehat.eu

Az érintett jogosult panaszt tenni a Nemzeti Adatvédelmi és Információszabadság Hatóságnál is.

Hungarian National Authority for Data Protection and Freedom of Information
Registered office: 1055 Budapest, Falk Miksa utca 9-11.
Postal address: 1363 Budapest, P.O. Box 9.
Telephone: +36 1 391 1400
E-mail: ugyfelszolgalat@naih.hu
Website: About the Authority

The data subject is also entitled to bring proceedings before a court. At the data subject’s discretion, proceedings may also be brought before the regional court having jurisdiction over their place of residence or temporary residence.


14. Amendment of this Privacy Policy

White Hat reserves the right to amend this Privacy Notice, in particular in the event of changes in legislation, changes in regulatory practice, modifications to the training process, changes in data processing processes, or modifications to the technical solutions used.

The Privacy Notice in force at any given time is available on White Hat’s website or on the interface specified during registration for the training.

Effective date of this Privacy Policy: 06 August 2026.