# Hungary's NAIH halts a bank's AI emotion analysis of call recordings — HUF 250,000,000 fine (2022)

> On 8 February 2022 Hungary's data-protection authority (NAIH), in decision NAIH-85-3/2022, found that a bank's AI-based analysis of customer-service call recordings — which inferred callers' emotional state to rank them by likely dissatisfaction — seriously infringed the GDPR. It ordered the bank to stop analysing clients' emotions and imposed a record HUF 250,000,000 (~EUR 650,000-670,000) fine.

- Verification status: verified
- Case type: deployment
- Provider: Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH — Hungarian Data Protection Authority)
- Client: Budapest Bank Zrt., Banking (customer-service call-centre AI voice/emotion analysis) (named)
- Sector: banking / HU / customer-service
- Verified on: 2026-08-24
- Canonical URL: https://theinternetninja.com/stories/hungarian-naih-budapest-bank-250m-huf-fine-unlawful-ai-emotion-voice-analysis-2022/
- Source: The Internet Ninja (theinternetninja.com), independent verified-proof platform

## Outcomes

| Metric | Before | After |
| --- | --- | --- |
| 8 Feb 2022 (NAIH-85-3/2022): NAIH ordered the bank to modify its processing so that emotions are NOT analysed during the voice analysis, and to bring the processing into GDPR compliance |  |  |
| NAIH imposed an administrative data-protection fine of HUF 250,000,000 (two hundred fifty million forints) — approximately EUR 650,000-670,000 — the highest fine issued by the authority to date |  |  |
| NAIH found the AI's results hard to verify and potentially biased; it noted the analysis of the calls was 'not in itself unlawful' — the infringements were the missing legal basis, transparency and right to object |  |  |

## Verification method

Regulator's own decision (NAIH-85-3/2022, PDF fetched live from naih.hu and byte-tied to Wayback, Tier 1) plus NAIH's own English summary republished via the EDPB national-news page (Tier 1), corroborated by two independent measurers stating the HUF 250,000,000 figure firsthand (DLA Piper Privacy Matters; William Fry). Hungarian quotes stored byte-verbatim. Archived captures on file.

## Full case file

## The problem
Budapest Bank Zrt. recorded all of its customer-service phone calls and ran an
artificial-intelligence system over them nightly. NAIH's own English summary states that "The
software uses artificial intelligence to find keywords, and guesses the emotional state of the
client at the time of the call" ([source](https://www.edpb.europa.eu/news/national-news/2022/data-protection-issues-arising-connection-use-artificial-intelligence_en)).
The same summary describes the output as "a list of persons sorted by the likelihood of
dissatisfaction, anger based on the audio recording of the customer service phone call," on
which "designated employees mark clients to be called by customer service"
([source](https://www.edpb.europa.eu/news/national-news/2022/data-protection-issues-arising-connection-use-artificial-intelligence_en)).
An independent law-firm account describes the same deployment: the "analytical system deployed
by the bank was designed to analyse and assess callers' emotional states and keywords used on
the calls," and the results were "used to rank the calls in order of priority to determine the
order of contacting callers"
([source](https://www.williamfry.com/knowledge/hungarian-data-protection-authority-issues-largest-fine-to-date-to-a-bank-for-unlawful-use-of-ai/)).

## What was built
An AI-based speech-signal-processing deployment inside a bank's call centre: every night the
software automatically analysed new call recordings, extracted keywords and inferred the
caller's emotional state, then ranked callers by likely dissatisfaction so staff could follow
up ([source](https://www.edpb.europa.eu/news/national-news/2022/data-protection-issues-arising-connection-use-artificial-intelligence_en)).
NAIH's assessment of the technology itself was pointed: it found that "Due to its internal
working, it is difficult to confirm the results of personal data processing by artificial
intelligence, and it may be biased"
([source](https://www.edpb.europa.eu/news/national-news/2022/data-protection-issues-arising-connection-use-artificial-intelligence_en)).

## The outcome
On 8 February 2022, in decision NAIH-85-3/2022, the authority ordered the bank to change the
processing; in the decision's own Hungarian text it "utasítja az Ügyfelet, hogy akként
módosítsa adatkezelési gyakorlatát, hogy az megfeleljen az általános adatvédelmi rendeletnek,
azaz a hangelemzés során az érzelmeket ne elemezze" — ordering the client to modify its
processing to comply with the GDPR, namely not to analyse emotions during the voice analysis
([source](https://www.naih.hu/hatarozatok-vegzesek?download=517:mesterseges-intelligencia-alkalmazasanak-adatvedelmi-kerdesei)).
NAIH's English summary states that it "ordered the data controller to stop processing emotional
state of the clients, only continue the data processing if made compliant with the GDPR, and
issued an administrative fine in HUF equal to approximately EUR 650,000"
([source](https://www.edpb.europa.eu/news/national-news/2022/data-protection-issues-arising-connection-use-artificial-intelligence_en)).

The fine is stated verbatim in the decision as "250 000 000 Ft, azaz kétszázötvenmillió forint"
(HUF 250,000,000)
([source](https://www.naih.hu/hatarozatok-vegzesek?download=517:mesterseges-intelligencia-alkalmazasanak-adatvedelmi-kerdesei)).
Two independent measurers report the same figure firsthand. DLA Piper wrote that "the Authority
imposed the highest fine to date of ca. EUR 670,000 (HUF 250 million)"
([source](https://privacymatters.dlapiper.com/2022/04/hungary-record-gdpr-fine-by-the-hungarian-data-protection-authority-for-the-unlawful-use-of-artificial-intelligence/)).
William Fry reported "a fine of €670,000 (HUF 250,000,000) being imposed on a bank," which it
called the "highest imposed by the Hungarian Authority"
([source](https://www.williamfry.com/knowledge/hungarian-data-protection-authority-issues-largest-fine-to-date-to-a-bank-for-unlawful-use-of-ai/)).

This was a GDPR data-protection enforcement action, not a per-se ban on emotion AI: William Fry
notes the "analysis of the recorded calls was not in itself unlawful," the flaws being the
bank's GDPR-compliance failures — a missing legal basis, no transparency and no effective right
to object
([source](https://www.williamfry.com/knowledge/hungarian-data-protection-authority-issues-largest-fine-to-date-to-a-bank-for-unlawful-use-of-ai/)).

**Weakest load-bearing source.** The EUR conversion of the fine is not a fixed figure: the two
corroborating sources are Tier-2 law-firm client alerts summarising NAIH's annual report, and
they render the amount slightly differently ("ca. EUR 670,000" at DLA Piper, "€670,000" at
William Fry; NAIH's own English text says "approximately EUR 650,000"). The load-bearing,
non-approximate figure is the Hungarian HUF 250,000,000 stated in the Tier-1 decision itself;
the euro amounts are indicative conversions only.

## How this was verified
Method: the regulator's own decision (NAIH-85-3/2022, 8 Feb 2022) was fetched as a PDF from
naih.hu and byte-tied to its Wayback capture (Tier 1), and NAIH's own English summary was read
from the EDPB national-news page (Tier 1). The HUF 250,000,000 fine and the emotion-analysis
halt were each corroborated by two independent Tier-2 measurers (DLA Piper Privacy Matters;
William Fry). Every Hungarian quote above was re-checked byte-verbatim against the archived PDF;
every English quote was re-checked against the captured EDPB and law-firm pages. Verified
2026-08-10. This page carries a `checking` status: it is not a green `verified` badge.

## Path to green
The honest-negative event — the 8 February 2022 order to stop analysing clients' emotions and
the HUF 250,000,000 fine — rests on NAIH's own decision (Tier 1) and English summary,
corroborated by two independent measurers. Green would additionally require a recorded
confirmation of the decision's final status (whether it became final or was challenged before
the Budapest-Capital Regional Court within the 30-day window) and whether the fine was paid and
the emotion analysis discontinued.

## Sources
1. **Tier 1** — NAIH · Decision NAIH-85-3/2022, "A mesterséges intelligencia alkalmazásának adatvédelmi kérdései" (the regulator's own decision PDF) · 8 Feb 2022 · https://www.naih.hu/hatarozatok-vegzesek?download=517:mesterseges-intelligencia-alkalmazasanak-adatvedelmi-kerdesei
2. **Tier 1** — European Data Protection Board (EDPB national news) · "Data protection issues arising in connection with the use of artificial intelligence" (NAIH's own English summary) · 8 Feb 2022 · https://www.edpb.europa.eu/news/national-news/2022/data-protection-issues-arising-connection-use-artificial-intelligence_en
3. **Tier 2** — DLA Piper Privacy Matters · "Hungary: Record GDPR fine by the Hungarian Data Protection Authority for the unlawful use of artificial intelligence" · 12 Apr 2022 · https://privacymatters.dlapiper.com/2022/04/hungary-record-gdpr-fine-by-the-hungarian-data-protection-authority-for-the-unlawful-use-of-artificial-intelligence/
4. **Tier 2** — William Fry · "Hungarian Data Protection Authority Issues Largest Fine to Date to a Bank for Unlawful Use of AI" · 21 Oct 2022 · https://www.williamfry.com/knowledge/hungarian-data-protection-authority-issues-largest-fine-to-date-to-a-bank-for-unlawful-use-of-ai/

## Related case files
- [ICO ordered Serco Leisure to halt unlawful biometric monitoring — a regulator forcing a stop to a deployed AI/biometric system, the same shape as this halt](/stories/ico-orders-serco-leisure-to-halt-unlawful-facial-recognition-and-fingerprint-att/)
- [Spain's AEPD ordered Worldcoin to halt biometric iris-scanning — another DPA-forced stop of an unlawfully-deployed biometric AI](/stories/spain-aepd-orders-worldcoin-tools-for-humanity-to-halt-biometric-iris-scanning-a/)
- [Italy's Garante blocked DeepSeek over Italian users' data — a regulator limiting an AI system for the same GDPR failings of legal basis and transparency](/stories/italy-garante-blocks-deepseek-ai-limitation-processing-italian-users-data-2025/)
- [Italy's Garante fined Foodinho €2.6M over its rider-management algorithm — a DPA fine against an automated system that profiled and ranked people](/stories/italy-garante-fines-foodinho-2-6m-for-rider-management-algorithm-2021/)