Introduction

Data protection has become a major strategic issue for Belgian companies. In 2026, with the continuous strengthening of the GDPR, the entry into force of the NIS2 directive, and the European Data Governance Act and Data Act, obligations around data hosting and protection have never been stricter.

In Belgium, the Data Protection Authority (APD) has stepped up its inspections: in 2025, it issued more than 120 decisions and imposed fines totalling more than EUR 8 million. Belgian companies, from micro-businesses to multinationals, must understand their obligations and put the right solutions in place.

This guide details the Belgian and European legal framework, the concrete obligations for companies, the data hosting solutions available in Belgium, and the best practices to adopt to protect your data in the cloud.

The GDPR: a reminder of the fundamental principles

The General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) is the cornerstone of data protection in Europe. It applies to every Belgian company that processes personal data.

Principle Description Practical implication
Lawfulness, fairness, transparency Processing based on a legal basis, clear information Privacy policy, register of processing activities
Purpose limitation Data collected for specified purposes No reuse without a legal basis
Data minimisation Only the necessary data is collected Regular audit of collected data
Accuracy Data kept up to date Update process, right of rectification
Storage limitation Data kept only as long as necessary Retention policy, automatic deletion
Integrity and confidentiality Appropriate data security Encryption, access controls, backups
Accountability The controller must demonstrate compliance Documentation, DPIA, DPO

The Belgian Act of 30 July 2018

Belgium transposed the GDPR via the Act of 30 July 2018 on the protection of individuals with regard to the processing of personal data. This Act adds several national clarifications:

  • Digital age of consent: 13 in Belgium (versus the GDPR's default of 16)
  • National register number: processing subject to strict conditions (authorisation from the Information Security Committee)
  • Health data: enhanced protections, notably via the eHealth platform
  • Criminal sanctions: in addition to administrative fines, criminal sanctions are possible (up to EUR 20,000 in fines and/or imprisonment)

The Data Protection Authority (APD)

The APD is Belgium's supervisory authority for the GDPR. It comprises several bodies:

  • Knowledge Centre: publishes opinions and recommendations
  • Inspection Service: conducts investigations, whether self-initiated or following a complaint
  • Litigation Chamber: issues decisions and fines
  • First-line service: answers questions from citizens and companies

APD contact: contact@apd-gba.be / +32 2 274 48 00 / Rue de la Presse 35, 1000 Brussels

Year Company/Sector Grounds Fine
2023 Belgian bank No legal basis for direct marketing EUR 200,000
2024 E-commerce site Cookies placed without valid consent EUR 50,000
2024 Health insurance fund Breach of health data security EUR 150,000
2025 SME No register of processing activities and no DPO EUR 25,000
2025 Large company Data transfer outside the EU without adequate safeguards EUR 500,000

The new European regulations

Beyond the GDPR, several European regulations affect data hosting:

  • Cybersecurity obligations for companies in essential and important sectors
  • Incident notification to the CCB within 24-72 hours
  • Management responsibility
  • Framework for data sharing between companies and with the public sector
  • Creation of data intermediation services
  • Data altruism mechanisms
  • Rules on access to data generated by connected devices (IoT)
  • Cloud data portability (easier provider switching)
  • Protection against unfair contractual clauses from cloud providers
  • Interoperability of cloud services
  • Specific obligations for AI system training data
  • Documentation of the datasets used

Concrete obligations for Belgian companies

1. Register of processing activities (mandatory for all companies)

Any company with more than 250 employees (or processing sensitive data, even with fewer than 250 employees) must keep a register of processing activities. In practice, the APD recommends that every company do so.

  • Name and contact details of the controller
  • Purposes of each processing activity
  • Categories of data subjects and data
  • Categories of recipients
  • Transfers outside the EU (if applicable)
  • Retention periods
  • Description of security measures
  • OneTrust (free tier available for SMEs): a comprehensive compliance management platform
  • Witik (Belgian/French, from EUR 49/month): a GDPR register and compliance tool
  • Data Protection Officer (DPO) as a Service: several Belgian firms offer this service

2. Data Protection Officer (DPO)

Appointing a DPO is mandatory if your company:

  • Is a public body
  • Carries out regular and systematic large-scale monitoring of individuals
  • Processes sensitive data on a large scale (health, political opinions, biometric data, etc.)

Even where a DPO is not mandatory, it is strongly recommended. In Belgium, the DPO can be internal or external.

  • Micro/SME: EUR 200 to 800/month
  • Medium-sized company: EUR 800 to 2,500/month
  • Belgian firms offering DPO services: DPO Consult, DP-Dock Belgium, Sirius Legal, Lexing Belgium, time.lex

3. Data protection impact assessment (DPIA)

A Data Protection Impact Assessment (DPIA) is mandatory before any processing that presents a high risk to individuals' rights. In practice, it is required for:

  • Large-scale processing of sensitive data
  • Large-scale systematic monitoring
  • Automated evaluation of individuals (scoring, profiling)
  • Processing children's data
  • Use of new technologies (AI, IoT, biometrics)

The Belgian APD has published a list of processing activities that systematically require a DPIA, available on its website.

Consent must be freely given, specific, informed and unambiguous. For cookies:

  • Strictly necessary cookies do not require consent
  • All other cookies (analytics, marketing, social media) require prior consent
  • The cookie banner must offer a genuine choice ("Accept" and "Reject" buttons of the same size and colour)
  • the FPS Economy carries out regular checks and can impose fines
  • Cookiebot (from EUR 12/month): very popular in Belgium, GDPR-compliant
  • Axeptio (from EUR 19/month): pleasant, customisable interface
  • OneTrust: for large companies
  • Tarteaucitron (open source, free): a technical solution for developers

Data hosting: where should you host your data in Belgium?

Data localisation requirements

The GDPR does not require Belgian data hosting, but it imposes restrictions on transfers outside the European Economic Area (EEA). In practice:

  • To any EEA country (27 EU countries + Iceland, Liechtenstein, Norway)
  • To countries covered by an adequacy decision (United Kingdom, Switzerland, Japan, South Korea, Canada, Israel, New Zealand, etc.)
  • To the USA under the EU-US Data Privacy Framework (DPF) since 2023
  • To countries without an adequacy decision: standard contractual clauses (SCCs) from the European Commission plus supplementary measures
  • A Transfer Impact Assessment is required
  • Belgian public sector: data held by public administrations must generally stay within the EU, or even within Belgium
  • Financial sector: the NBB (National Bank of Belgium) and the FSMA impose specific requirements for cloud outsourcing
  • Health sector: health data must be hosted with enhanced safeguards (HDS hosting or equivalent)

Belgian data hosting providers

For companies that want to guarantee their data stays on Belgian territory:

Provider Data centre location Certifications Services
NRB Herstal (Liège), Villers-le-Bouillet ISO 27001, ISO 9001 Private cloud, mainframe, critical infrastructure
Proximus EnCo Belgium (several sites) ISO 27001, C5 Sovereign cloud, connectivity, SD-WAN
LCL Data Centers Diegem, Aalst, Gembloux ISO 27001, ISAE 3402 Colocation, private cloud
Combell / Sentia (team.blue group) Ghent, Zaventem ISO 27001 Web hosting, managed cloud
Nucleus Kontich (Antwerp) ISO 27001 Hosting, cloud, backup
Kinamo Ghent – Hosting, VPS, cloud
Openminds Ghent – Managed web hosting

International data hosting providers with Belgian regions

Provider Belgian region Certifications Strengths
Google Cloud europe-west1 (Saint-Ghislain) ISO 27001, SOC 1/2/3, C5 AI/ML, Big Data, native Belgian region
Microsoft Azure Belgium Central (Brussels) ISO 27001, SOC 1/2/3, C5, ENS Belgian region, M365 integration

The European sovereign cloud

Several initiatives aim to create a European sovereign cloud, guaranteed free of interference from extraterritorial legislation (such as the US CLOUD Act):

  • Gaia-X: a Franco-German initiative for a federated European cloud ecosystem, involving Belgian players (NRB, Proximus, Smals)
  • EUCLIDIA: an association of European cloud providers promoting digital sovereignty
  • S3NS (Thales/Google Cloud) and Bleu (Orange/Capgemini/Microsoft): trusted cloud offerings in France, potentially accessible from Belgium

Protecting data in the cloud: best practices

Whichever data hosting provider you choose, the following practices apply.

1. Data encryption

Encryption is the fundamental technical measure for protecting your data in the cloud:

  • All major cloud providers encrypt data at rest by default (AES-256)
  • Use your own encryption key (BYOK – Bring Your Own Key) for maximum control
  • Key management solutions: Azure Key Vault, AWS KMS, Google Cloud KMS, HashiCorp Vault
  • Enforce TLS 1.3 for all communications
  • Use site-to-site VPNs for connections between your network and the cloud
  • Check the SSL certificates of your web applications
  • Encrypt data before sending it to the cloud
  • You alone hold the decryption key
  • Solutions: Boxcryptor, Cryptomator (open source, free), Tresorit (Swiss, GDPR-compliant)

2. Identity and access management (IAM)

  • Apply the least-privilege principle: each user only accesses the data they need
  • Implement MFA (multi-factor authentication) on all accounts
  • Use SSO (Single Sign-On) to centralise identity management
  • Carry out quarterly access reviews
  • Remove access for departing employees on the same day they leave

3. Backups and disaster recovery plan (DRP)

  • Apply the 3-2-1-1-0 rule (3 copies, 2 media types, 1 off-site, 1 offline, 0 errors)
  • Test your backup restoration at least quarterly
  • Document your disaster recovery plan with defined RTOs (Recovery Time Objective) and RPOs (Recovery Point Objective)
Data type Recommended RTO Recommended RPO
Critical data (ERP, CRM, production) 4 hours 1 hour
Messaging and collaboration 8 hours 4 hours
Archives and documents 24 hours 24 hours
Development/test data 48 hours 24 hours

4. Logging and monitoring

  • Enable logging of all access to sensitive data
  • Set up alerts for suspicious activity (unusual access, mass downloads)
  • Keep logs for at least 12 months (a legal obligation in some cases)
  • Use a SIEM (Security Information and Event Management) to centralise logs

5. Data classification

Classify your data to apply the appropriate level of protection:

Level Description Examples Protection measures
Public Information that can be shared freely Website, brochures Standard protection
Internal Information intended for employees Procedures, org chart Access control, encryption in transit
Confidential Sensitive information with restricted distribution Financial data, contracts Encryption at rest and in transit, restricted access, logging
Strictly confidential Very high-risk information Health data, banking data, trade secrets End-to-end encryption, BYOK, minimal access, enhanced logging, DPIA

The cloud contract: points to watch

Before signing any data hosting contract, review the following clauses carefully.

The Data Processing Agreement (DPA)

Any contract with a cloud provider processing personal data on your behalf must include a DPA compliant with Article 28 of the GDPR.

  • Subject matter, duration, nature and purpose of the processing
  • Type of personal data processed
  • Categories of data subjects
  • Processor obligations (security, confidentiality, cooperation)
  • Audit right for the controller
  • Conditions for using sub-processors
  • Fate of the data at the end of the contract (return or deletion)
  • Location of processing
  • Technical and organisational security measures

Clauses to check in the cloud contract

  • Data location: where is your data physically stored? Are transfers outside the EU possible?
  • Sub-processors: can the provider use sub-processors? Which ones? Are you informed of any change?
  • Portability: can you retrieve your data easily (in a standard format) if you switch providers?
  • Egress fees: what are the costs of transferring your data to another provider? The European Data Act limits these fees.
  • SLA (Service Level Agreement): what availability is guaranteed? What compensation applies in the event of an outage?
  • Incident notification: how quickly does the provider inform you of a data breach?
  • Audit right: can you audit the provider or access independent audit reports (SOC 2, ISO 27001)?

What to do in the event of a data breach?

Notification procedure in Belgium

In the event of a personal data breach, you must:

1. Notify the APD within 72 hours (unless the breach is unlikely to result in a risk to individuals):

  • Via the online form on the APD website (dataprotectionauthority.be)
  • Information to provide: nature of the breach, categories and number of people affected, likely consequences, measures taken

2. Notify the people affected "without undue delay" if the breach is likely to result in a high risk:

  • Clear communication in plain language
  • Description of the nature of the breach
  • Contact details of the DPO or point of contact
  • Likely consequences
  • Measures taken and recommended

3. Document every breach in an internal breach register, even where notification to the APD is not required.

4. If subject to NIS2: also notify the CCB within 24 hours (early warning) and 72 hours (full notification).

Immediate actions in the event of a breach

  1. Contain the breach (isolate compromised systems, block access)
  2. Assess the scope of the breach (what data, how many people)
  3. Activate the incident response plan
  4. Notify the competent authorities (APD, CCB if NIS2 applies)
  5. Notify the people affected if necessary
  6. Document the incident and the actions taken
  7. Analyse the causes and put corrective measures in place

Budget and compliance costs

Estimate for a Belgian SME with 30 employees

Item Estimated cost
External DPO (part-time) EUR 4,800 – 12,000/year
Register of processing activities (tool + setup) EUR 1,000 – 3,000 (one-off)
Privacy policy and legal notices EUR 1,500 – 3,000 (lawyer)
Cookie CMP (Cookiebot or equivalent) EUR 144 – 500/year
GDPR training for employees EUR 1,000 – 3,000/year
Annual security audit EUR 3,000 – 8,000
Secure data hosting (Belgian or EU) EUR 3,000 – 12,000/year
Encryption and backup solution EUR 1,200 – 3,600/year
Total for the first year EUR 15,644 – 45,100
Total for subsequent years EUR 13,144 – 39,100

This budget should be weighed against the risk of an APD fine (up to EUR 20 million or 4% of worldwide turnover) and the average cost of a data breach in Belgium (estimated by IBM at EUR 3.5 million for large companies).

Support available in Belgium

  • "Cybersecurity" business vouchers (Wallonia): cover up to 75% of the cost of data protection and cybersecurity advice (cap of EUR 60,000/year)
  • KMO-portefeuille (Flanders): 20-30% support for GDPR advisory and training costs
  • Hub.brussels: free support for Brussels-based companies
  • Digital vouchers (Brussels): grants for digital transformation, including compliance

Conclusion

Data protection is not just a legal obligation for Belgian companies: it is a competitive advantage. Customers and partners are increasingly attentive to how their data is handled, and exemplary data protection strengthens trust in, and the reputation of, your company.

The regulatory landscape is becoming more complex as the GDPR, NIS2, the Data Governance Act, the Data Act and the AI Act stack up. But the basic principles remain the same: know what data you collect, why, how you protect it, and where it is hosted.

Invest in compliance today: prevention costs are always lower than remediation costs after a data breach. And take advantage of Belgian regional support schemes to fund your efforts.


This article was written by the Espero-Soft team for the blog dedicated to entrepreneurs in Belgium. For a GDPR compliance audit or support with protecting your data, contact our experts.