
Introduction
Data protection has become a major strategic issue for Belgian companies. In 2026, with the continuous strengthening of the GDPR, the entry into force of the NIS2 directive, and the European Data Governance Act and Data Act, obligations around data hosting and protection have never been stricter.
In Belgium, the Data Protection Authority (APD) has stepped up its inspections: in 2025, it issued more than 120 decisions and imposed fines totalling more than EUR 8 million. Belgian companies, from micro-businesses to multinationals, must understand their obligations and put the right solutions in place.
This guide details the Belgian and European legal framework, the concrete obligations for companies, the data hosting solutions available in Belgium, and the best practices to adopt to protect your data in the cloud.
The legal framework: GDPR, Belgian law and new regulations
The GDPR: a reminder of the fundamental principles
The General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) is the cornerstone of data protection in Europe. It applies to every Belgian company that processes personal data.
The 7 principles of the GDPR:
| Principle | Description | Practical implication |
|---|---|---|
| Lawfulness, fairness, transparency | Processing based on a legal basis, clear information | Privacy policy, register of processing activities |
| Purpose limitation | Data collected for specified purposes | No reuse without a legal basis |
| Data minimisation | Only the necessary data is collected | Regular audit of collected data |
| Accuracy | Data kept up to date | Update process, right of rectification |
| Storage limitation | Data kept only as long as necessary | Retention policy, automatic deletion |
| Integrity and confidentiality | Appropriate data security | Encryption, access controls, backups |
| Accountability | The controller must demonstrate compliance | Documentation, DPIA, DPO |
The Belgian Act of 30 July 2018
Belgium transposed the GDPR via the Act of 30 July 2018 on the protection of individuals with regard to the processing of personal data. This Act adds several national clarifications:
- Digital age of consent: 13 in Belgium (versus the GDPR's default of 16)
- National register number: processing subject to strict conditions (authorisation from the Information Security Committee)
- Health data: enhanced protections, notably via the eHealth platform
- Criminal sanctions: in addition to administrative fines, criminal sanctions are possible (up to EUR 20,000 in fines and/or imprisonment)
The Data Protection Authority (APD)
The APD is Belgium's supervisory authority for the GDPR. It comprises several bodies:
- Knowledge Centre: publishes opinions and recommendations
- Inspection Service: conducts investigations, whether self-initiated or following a complaint
- Litigation Chamber: issues decisions and fines
- First-line service: answers questions from citizens and companies
APD contact: contact@apd-gba.be / +32 2 274 48 00 / Rue de la Presse 35, 1000 Brussels
Examples of APD fines in Belgium:
| Year | Company/Sector | Grounds | Fine |
|---|---|---|---|
| 2023 | Belgian bank | No legal basis for direct marketing | EUR 200,000 |
| 2024 | E-commerce site | Cookies placed without valid consent | EUR 50,000 |
| 2024 | Health insurance fund | Breach of health data security | EUR 150,000 |
| 2025 | SME | No register of processing activities and no DPO | EUR 25,000 |
| 2025 | Large company | Data transfer outside the EU without adequate safeguards | EUR 500,000 |
The new European regulations
Beyond the GDPR, several European regulations affect data hosting:
NIS2 Directive (2024-2025):
- Cybersecurity obligations for companies in essential and important sectors
- Incident notification to the CCB within 24-72 hours
- Management responsibility
Data Governance Act (DGA, 2023):
- Framework for data sharing between companies and with the public sector
- Creation of data intermediation services
- Data altruism mechanisms
Data Act (2025-2026):
- Rules on access to data generated by connected devices (IoT)
- Cloud data portability (easier provider switching)
- Protection against unfair contractual clauses from cloud providers
- Interoperability of cloud services
AI Act (2024-2026):
- Specific obligations for AI system training data
- Documentation of the datasets used
Concrete obligations for Belgian companies
1. Register of processing activities (mandatory for all companies)
Any company with more than 250 employees (or processing sensitive data, even with fewer than 250 employees) must keep a register of processing activities. In practice, the APD recommends that every company do so.
Contents of the register:
- Name and contact details of the controller
- Purposes of each processing activity
- Categories of data subjects and data
- Categories of recipients
- Transfers outside the EU (if applicable)
- Retention periods
- Description of security measures
Tools for keeping a register of processing activities:
- OneTrust (free tier available for SMEs): a comprehensive compliance management platform
- Witik (Belgian/French, from EUR 49/month): a GDPR register and compliance tool
- Data Protection Officer (DPO) as a Service: several Belgian firms offer this service
2. Data Protection Officer (DPO)
Appointing a DPO is mandatory if your company:
- Is a public body
- Carries out regular and systematic large-scale monitoring of individuals
- Processes sensitive data on a large scale (health, political opinions, biometric data, etc.)
Even where a DPO is not mandatory, it is strongly recommended. In Belgium, the DPO can be internal or external.
Cost of an external DPO in Belgium:
- Micro/SME: EUR 200 to 800/month
- Medium-sized company: EUR 800 to 2,500/month
- Belgian firms offering DPO services: DPO Consult, DP-Dock Belgium, Sirius Legal, Lexing Belgium, time.lex
3. Data protection impact assessment (DPIA)
A Data Protection Impact Assessment (DPIA) is mandatory before any processing that presents a high risk to individuals' rights. In practice, it is required for:
- Large-scale processing of sensitive data
- Large-scale systematic monitoring
- Automated evaluation of individuals (scoring, profiling)
- Processing children's data
- Use of new technologies (AI, IoT, biometrics)
The Belgian APD has published a list of processing activities that systematically require a DPIA, available on its website.
4. Consent and cookies
Consent must be freely given, specific, informed and unambiguous. For cookies:
Belgium-specific rules:
- Strictly necessary cookies do not require consent
- All other cookies (analytics, marketing, social media) require prior consent
- The cookie banner must offer a genuine choice ("Accept" and "Reject" buttons of the same size and colour)
- the FPS Economy carries out regular checks and can impose fines
CMP (Consent Management Platform) solutions:
- Cookiebot (from EUR 12/month): very popular in Belgium, GDPR-compliant
- Axeptio (from EUR 19/month): pleasant, customisable interface
- OneTrust: for large companies
- Tarteaucitron (open source, free): a technical solution for developers
Data hosting: where should you host your data in Belgium?
Data localisation requirements
The GDPR does not require Belgian data hosting, but it imposes restrictions on transfers outside the European Economic Area (EEA). In practice:
Transfers allowed without restriction:
- To any EEA country (27 EU countries + Iceland, Liechtenstein, Norway)
- To countries covered by an adequacy decision (United Kingdom, Switzerland, Japan, South Korea, Canada, Israel, New Zealand, etc.)
- To the USA under the EU-US Data Privacy Framework (DPF) since 2023
Transfers requiring additional safeguards:
- To countries without an adequacy decision: standard contractual clauses (SCCs) from the European Commission plus supplementary measures
- A Transfer Impact Assessment is required
Sectors with stricter localisation requirements:
- Belgian public sector: data held by public administrations must generally stay within the EU, or even within Belgium
- Financial sector: the NBB (National Bank of Belgium) and the FSMA impose specific requirements for cloud outsourcing
- Health sector: health data must be hosted with enhanced safeguards (HDS hosting or equivalent)
Belgian data hosting providers
For companies that want to guarantee their data stays on Belgian territory:
| Provider | Data centre location | Certifications | Services |
|---|---|---|---|
| NRB | Herstal (Liège), Villers-le-Bouillet | ISO 27001, ISO 9001 | Private cloud, mainframe, critical infrastructure |
| Proximus EnCo | Belgium (several sites) | ISO 27001, C5 | Sovereign cloud, connectivity, SD-WAN |
| LCL Data Centers | Diegem, Aalst, Gembloux | ISO 27001, ISAE 3402 | Colocation, private cloud |
| Combell / Sentia (team.blue group) | Ghent, Zaventem | ISO 27001 | Web hosting, managed cloud |
| Nucleus | Kontich (Antwerp) | ISO 27001 | Hosting, cloud, backup |
| Kinamo | Ghent | – | Hosting, VPS, cloud |
| Openminds | Ghent | – | Managed web hosting |
International data hosting providers with Belgian regions
| Provider | Belgian region | Certifications | Strengths |
|---|---|---|---|
| Google Cloud | europe-west1 (Saint-Ghislain) | ISO 27001, SOC 1/2/3, C5 | AI/ML, Big Data, native Belgian region |
| Microsoft Azure | Belgium Central (Brussels) | ISO 27001, SOC 1/2/3, C5, ENS | Belgian region, M365 integration |
The European sovereign cloud
Several initiatives aim to create a European sovereign cloud, guaranteed free of interference from extraterritorial legislation (such as the US CLOUD Act):
- Gaia-X: a Franco-German initiative for a federated European cloud ecosystem, involving Belgian players (NRB, Proximus, Smals)
- EUCLIDIA: an association of European cloud providers promoting digital sovereignty
- S3NS (Thales/Google Cloud) and Bleu (Orange/Capgemini/Microsoft): trusted cloud offerings in France, potentially accessible from Belgium
Protecting data in the cloud: best practices
Whichever data hosting provider you choose, the following practices apply.
1. Data encryption
Encryption is the fundamental technical measure for protecting your data in the cloud:
Encryption at rest:
- All major cloud providers encrypt data at rest by default (AES-256)
- Use your own encryption key (BYOK – Bring Your Own Key) for maximum control
- Key management solutions: Azure Key Vault, AWS KMS, Google Cloud KMS, HashiCorp Vault
Encryption in transit:
- Enforce TLS 1.3 for all communications
- Use site-to-site VPNs for connections between your network and the cloud
- Check the SSL certificates of your web applications
Client-side encryption:
- Encrypt data before sending it to the cloud
- You alone hold the decryption key
- Solutions: Boxcryptor, Cryptomator (open source, free), Tresorit (Swiss, GDPR-compliant)
2. Identity and access management (IAM)
- Apply the least-privilege principle: each user only accesses the data they need
- Implement MFA (multi-factor authentication) on all accounts
- Use SSO (Single Sign-On) to centralise identity management
- Carry out quarterly access reviews
- Remove access for departing employees on the same day they leave
3. Backups and disaster recovery plan (DRP)
- Apply the 3-2-1-1-0 rule (3 copies, 2 media types, 1 off-site, 1 offline, 0 errors)
- Test your backup restoration at least quarterly
- Document your disaster recovery plan with defined RTOs (Recovery Time Objective) and RPOs (Recovery Point Objective)
Recommended RTO and RPO by data type:
| Data type | Recommended RTO | Recommended RPO |
|---|---|---|
| Critical data (ERP, CRM, production) | 4 hours | 1 hour |
| Messaging and collaboration | 8 hours | 4 hours |
| Archives and documents | 24 hours | 24 hours |
| Development/test data | 48 hours | 24 hours |
4. Logging and monitoring
- Enable logging of all access to sensitive data
- Set up alerts for suspicious activity (unusual access, mass downloads)
- Keep logs for at least 12 months (a legal obligation in some cases)
- Use a SIEM (Security Information and Event Management) to centralise logs
5. Data classification
Classify your data to apply the appropriate level of protection:
| Level | Description | Examples | Protection measures |
|---|---|---|---|
| Public | Information that can be shared freely | Website, brochures | Standard protection |
| Internal | Information intended for employees | Procedures, org chart | Access control, encryption in transit |
| Confidential | Sensitive information with restricted distribution | Financial data, contracts | Encryption at rest and in transit, restricted access, logging |
| Strictly confidential | Very high-risk information | Health data, banking data, trade secrets | End-to-end encryption, BYOK, minimal access, enhanced logging, DPIA |
The cloud contract: points to watch
Before signing any data hosting contract, review the following clauses carefully.
The Data Processing Agreement (DPA)
Any contract with a cloud provider processing personal data on your behalf must include a DPA compliant with Article 28 of the GDPR.
Essential elements of the DPA:
- Subject matter, duration, nature and purpose of the processing
- Type of personal data processed
- Categories of data subjects
- Processor obligations (security, confidentiality, cooperation)
- Audit right for the controller
- Conditions for using sub-processors
- Fate of the data at the end of the contract (return or deletion)
- Location of processing
- Technical and organisational security measures
Clauses to check in the cloud contract
- Data location: where is your data physically stored? Are transfers outside the EU possible?
- Sub-processors: can the provider use sub-processors? Which ones? Are you informed of any change?
- Portability: can you retrieve your data easily (in a standard format) if you switch providers?
- Egress fees: what are the costs of transferring your data to another provider? The European Data Act limits these fees.
- SLA (Service Level Agreement): what availability is guaranteed? What compensation applies in the event of an outage?
- Incident notification: how quickly does the provider inform you of a data breach?
- Audit right: can you audit the provider or access independent audit reports (SOC 2, ISO 27001)?
What to do in the event of a data breach?
Notification procedure in Belgium
In the event of a personal data breach, you must:
1. Notify the APD within 72 hours (unless the breach is unlikely to result in a risk to individuals):
- Via the online form on the APD website (dataprotectionauthority.be)
- Information to provide: nature of the breach, categories and number of people affected, likely consequences, measures taken
2. Notify the people affected "without undue delay" if the breach is likely to result in a high risk:
- Clear communication in plain language
- Description of the nature of the breach
- Contact details of the DPO or point of contact
- Likely consequences
- Measures taken and recommended
3. Document every breach in an internal breach register, even where notification to the APD is not required.
4. If subject to NIS2: also notify the CCB within 24 hours (early warning) and 72 hours (full notification).
Immediate actions in the event of a breach
- Contain the breach (isolate compromised systems, block access)
- Assess the scope of the breach (what data, how many people)
- Activate the incident response plan
- Notify the competent authorities (APD, CCB if NIS2 applies)
- Notify the people affected if necessary
- Document the incident and the actions taken
- Analyse the causes and put corrective measures in place
Budget and compliance costs
Estimate for a Belgian SME with 30 employees
| Item | Estimated cost |
|---|---|
| External DPO (part-time) | EUR 4,800 – 12,000/year |
| Register of processing activities (tool + setup) | EUR 1,000 – 3,000 (one-off) |
| Privacy policy and legal notices | EUR 1,500 – 3,000 (lawyer) |
| Cookie CMP (Cookiebot or equivalent) | EUR 144 – 500/year |
| GDPR training for employees | EUR 1,000 – 3,000/year |
| Annual security audit | EUR 3,000 – 8,000 |
| Secure data hosting (Belgian or EU) | EUR 3,000 – 12,000/year |
| Encryption and backup solution | EUR 1,200 – 3,600/year |
| Total for the first year | EUR 15,644 – 45,100 |
| Total for subsequent years | EUR 13,144 – 39,100 |
This budget should be weighed against the risk of an APD fine (up to EUR 20 million or 4% of worldwide turnover) and the average cost of a data breach in Belgium (estimated by IBM at EUR 3.5 million for large companies).
Support available in Belgium
- "Cybersecurity" business vouchers (Wallonia): cover up to 75% of the cost of data protection and cybersecurity advice (cap of EUR 60,000/year)
- KMO-portefeuille (Flanders): 20-30% support for GDPR advisory and training costs
- Hub.brussels: free support for Brussels-based companies
- Digital vouchers (Brussels): grants for digital transformation, including compliance
Conclusion
Data protection is not just a legal obligation for Belgian companies: it is a competitive advantage. Customers and partners are increasingly attentive to how their data is handled, and exemplary data protection strengthens trust in, and the reputation of, your company.
The regulatory landscape is becoming more complex as the GDPR, NIS2, the Data Governance Act, the Data Act and the AI Act stack up. But the basic principles remain the same: know what data you collect, why, how you protect it, and where it is hosted.
Invest in compliance today: prevention costs are always lower than remediation costs after a data breach. And take advantage of Belgian regional support schemes to fund your efforts.
This article was written by the Espero-Soft team for the blog dedicated to entrepreneurs in Belgium. For a GDPR compliance audit or support with protecting your data, contact our experts.


