Belgium's Data Protection Authority (APD) is stepping up its inspections and sanctions. Eight years after the General Data Protection Regulation (GDPR) took effect, the grace period is definitively over. Belgian companies, whatever their size, must demonstrate effective GDPR compliance or face heavy financial penalties. This detailed guide reviews every obligation, the regulatory developments, and the concrete actions to take.

The founding texts

Data protection in Belgium rests on a multi-layered legal framework:

  • Regulation (EU) 2016/679 (GDPR): directly applicable since 25 May 2018, it forms the common European foundation
  • Law of 30 July 2018 on the protection of individuals with regard to the processing of personal data: the Belgian law implementing the GDPR
  • Law of 3 December 2017 establishing the Data Protection Authority (replacing the former Privacy Commission)
  • Royal Decree of 11 May 2023 on the certification of DPOs in Belgium
  • ePrivacy Directive (2002/58/EC) and its Belgian transposition: specific regulation of cookies, electronic marketing and electronic communications

The Data Protection Authority (APD)

The APD is Belgium's independent supervisory authority. Its offices are at rue de la Presse 35, 1000 Brussels. It comprises several bodies:

Body Role
Management committee Strategic and administrative management
First-line service Handling complaints and mediation requests
Knowledge centre Opinions, recommendations and studies
Inspection service Investigations and on-site checks
Litigation Chamber Imposes sanctions (fines, injunctions)
Disputes Chamber Resolves disputes between parties

Contact: contact@apd-gba.be — Tel.: +32 2 274 48 00 — Website: autoritéprotectiondonnees.be (or gegevensbeschermingsautoriteit.be in Dutch)

Sanctions in Belgium: the figures

The APD has considerably stepped up its enforcement activity in recent years, driving GDPR compliance across every sector:

Year Number of litigation decisions Total fines Highest individual fine
2020 48 EUR 800,000 EUR 600,000 (Google Belgium)
2021 65 EUR 1,200,000 EUR 250,000
2022 87 EUR 1,800,000 EUR 600,000
2023 102 EUR 2,500,000 EUR 750,000
2024 118 EUR 4,100,000 EUR 1,200,000
2025 134 EUR 6,800,000 EUR 2,000,000
2026 (projected) 150+ EUR 10,000,000+ Tougher enforcement announced

Notable APD decisions

  • Proximus (2023): EUR 50,000 for non-compliant direct marketing practices, sending commercial communications without valid consent
  • Real estate sector (2024): EUR 75,000 for an estate agency over excessive retention of tenant data and the absence of a deletion policy
  • E-commerce (2024): EUR 120,000 for no effective way to delete a customer account and dark patterns in the consent process
  • Hospital (2025): EUR 200,000 for uncontrolled access to medical records by unauthorised staff
  • Digital marketing company (2025): EUR 350,000 for large-scale profiling without a valid legal basis and unauthorised data transfers to the United States

The most closely monitored sectors in 2026

Digital marketing and online advertising

The APD has confirmed that digital marketing remains a priority for GDPR compliance checks. The most frequent breaches:

  • Cookies and trackers: setting analytics or advertising cookies before obtaining the user's explicit consent. Simply continuing to browse does NOT constitute valid consent (APD decision 2021, confirmed by the CJEU in the Planet49 ruling)
  • Newsletters and email marketing: sending commercial communications without prior opt-in consent (Article 13 of the law of 11 March 2003 on information society services)
  • Marketing profiling: using behavioural data to target adverts without transparent information or a legal basis (consent or a documented legitimate interest)
  • Pixel tracking: embedding Meta, Google or TikTok pixels without prior consent
  • Non-freely-given consent: cookie walls that block access to content without consent — considered non-compliant by the APD

Practical tip: Your cookie banner must offer a "Reject all" button that is just as visible and accessible as the "Accept all" button. Pre-ticked boxes are prohibited.

Human resources and staff management

HR is an area of growing scrutiny:

  • Monitoring remote workers: installing monitoring software (keyloggers, screenshots, webcam surveillance) — ruled disproportionate by the APD in several decisions. Monitoring must comply with Collective Labour Agreement No. 81 of the National Labour Council and the law of 26 December 2022 on the right to disconnect
  • Retaining CVs: unsuccessful candidates' CVs must be deleted within a reasonable period. The APD recommends a maximum of two years after the last contact, with the candidate's explicit consent to be kept in a recruitment pool
  • Geolocation data: company vehicles fitted with GPS must be the subject of clear information to employees and proportionate use
  • HR data transfers: using SaaS HR software (Workday, BambooHR, and so on) hosted outside the EU requires appropriate safeguards (standard contractual clauses, a transfer impact assessment)
  • CCTV: governed by Collective Labour Agreement No. 68 and the Camera Act of 21 March 2007 — requiring prior notice, registration and proportionality

E-commerce and online sales

Checks are multiplying in the e-commerce sector, where GDPR compliance gaps are easy for the APD to spot:

  • Account deletion: customers must be able to delete their account and have their data erased easily (the right to erasure, Article 17 GDPR). A deletion button must be accessible in the account settings
  • Payment data: card numbers cannot be retained without explicit consent, and retention must be time-limited. Using tokenisation is recommended
  • Privacy policy: it must be written in clear, accessible language, in the languages matching the target audience (French, Dutch, German for Belgium). It must contain all the information required under Articles 13 and 14 GDPR
  • International transfers: hosting customer data on US servers (AWS US, Google Cloud US) requires additional safeguards post-Schrems II

Health and medical data

The healthcare sector receives particular attention given the sensitivity of the data:

  • Health data: a special category under Article 9 GDPR, requiring enhanced protection measures
  • Patient consent: must be specific, informed and documented
  • eHealth platform: the federal eHealth platform imposes strict security standards for exchanging health data
  • Information Security Committee: prior authorisation is required for certain health data processing

For hospitals and clinics, GDPR compliance starts with strict access controls around patient records.

Detailed GDPR compliance obligations for businesses in 2026

1. Record of processing activities (Article 30 GDPR)

Any company processing personal data must keep a record of processing activities. In 2026, the APD requires an enhanced record covering:

Element Description Mandatory
Name and contact details of the controller Full identification of the company Yes
Purposes of processing Why the data is processed (e.g. payroll management, marketing) Yes
Categories of data subjects Employees, customers, prospects, suppliers Yes
Categories of data Name, email, address, financial data, and so on Yes
Legal basis Consent, contract, legal obligation, legitimate interest, and so on Yes
Recipients of the data Processors, partners, authorities Yes
Transfers outside the EU Destination countries and appropriate safeguards Yes
Retention periods Precise period for each category of data Yes
Technical security measures Encryption, pseudonymisation, access control Yes (new)
Risk assessment Risk level for each processing activity Yes (new)
DPIA outcomes Summary of the impact assessments carried out Yes (new)

Your record should contain at least the following processing activities:

  1. Customer order management (basis: contract)
  2. Sending newsletters (basis: consent)
  3. Accounting management (basis: legal obligation)
  4. HR management (basis: contract + legal obligation)
  5. Analytics cookies on the website (basis: consent)
  6. CCTV of the premises (basis: legitimate interest)

2. Data breach notification (Articles 33 and 34 GDPR)

In the event of a personal data breach (leak, hack, loss, unauthorised access), the obligations are as follows:

Notification to the APD

  • Deadline: 72 hours after becoming aware of the breach (the GDPR maintains this deadline; any future reduction would come through an amendment to the regulation or sector-specific recommendations)
  • Form: online notification via the APD's portal (databreachnotification.be)
  • Content: nature of the breach, categories and number of data subjects affected, likely consequences, measures taken or proposed

Notification to data subjects

  • When: when the breach is likely to result in a high risk to individuals' rights and freedoms
  • How: direct communication (email, letter), in clear language
  • Content: description of the breach, recommendations to protect themselves (changing passwords, monitoring bank accounts)

Concrete example: A Walloon SME suffers a ransomware attack that encrypts its customer database (5,000 contacts with names, emails and purchase history). It must:

  1. Notify the APD within 72 hours via the online form
  2. Inform the 5,000 customers of the breach by email
  3. Document the incident in its internal breach register
  4. Take corrective action (strengthening security, backups, an audit)

3. Data Protection Officer (DPO)

Appointing the right person is often the linchpin of GDPR compliance for larger organisations.

When is a DPO mandatory?

The GDPR (Article 37) requires a DPO to be appointed in three cases:

  1. Public authorities or bodies (except courts acting in their judicial capacity)
  2. Core activities involving regular and systematic large-scale monitoring of data subjects
  3. Large-scale processing of sensitive data (health, judicial, biometric data, and so on)

The APD has clarified in its recommendations that this notably applies to:

  • Digital marketing companies carrying out profiling
  • Security companies using large-scale CCTV
  • Healthcare providers
  • Companies systematically processing data on more than 5,000 people

DPO profile

  • Expertise: in-depth knowledge of data protection law and IT security
  • Independence: the DPO cannot receive instructions on how to carry out their duties, and cannot be penalised for performing them
  • Resources: the company must give the DPO the resources they need (time, budget, ongoing training)
  • Registration: the DPO's contact details must be communicated to the APD

In-house vs external DPO

Criterion In-house DPO External DPO
Estimated annual cost EUR 60,000 – 90,000 (gross salary) EUR 5,000 – 25,000 (fee)
Availability Full-time or part-time Per contract (fixed fee or on demand)
Knowledge of the company Excellent Needs building up
Independence Risk of conflicts of interest Guaranteed by nature
Best suited to Large companies (250+ employees) SMEs and mid-sized companies

4. Data Protection Impact Assessment (DPIA)

When is a DPIA mandatory?

The APD has published a list of processing operations for which a DPIA is mandatory (decision No. 01/2019). Among the most frequent cases:

  • Large-scale processing of geolocation data
  • Systematic profiling for granting credit or insurance
  • Systematic CCTV of publicly accessible areas
  • Processing biometric data for identification
  • Systematic monitoring of employees
  • Processing health data outside individual care
  • Using artificial intelligence for automated decision-making

Contents of a DPIA

  1. A systematic description of the envisaged processing
  2. An assessment of necessity and proportionality
  3. An assessment of the risks to individuals' rights and freedoms
  4. The measures envisaged to mitigate the risks
  5. The DPO's opinion (where applicable)

5. International data transfers

Since the CJEU's Schrems II ruling (2020) and the adoption of the EU-US Data Privacy Framework (DPF) in 2023, the transfer rules are as follows:

Destination Mechanism required
EU/EEA No additional mechanism
Countries with an adequacy decision (Japan, United Kingdom, Switzerland, and others) No additional mechanism
USA (DPF-certified company) Transfer permitted under the DPF
Other third countries Standard contractual clauses (SCCs) + a transfer impact assessment (TIA)

Point to watch for 2026: The Data Privacy Framework is being challenged before the CJEU. Companies should have a "plan B" ready in case it is invalidated (as happened with Privacy Shield in 2020). Getting international transfers right is a core pillar of GDPR compliance.

Concrete actions to put in place

GDPR compliance checklist for 2026

Priority 1: fundamentals

  • A complete, up-to-date record of processing activities (Article 30)
  • A compliant privacy policy (Articles 13–14) on your website
  • A compliant cookie banner with an easy "reject" option
  • Data processing agreements (Article 28) signed with all your IT providers
  • A procedure for handling data subject rights requests (access, erasure, portability)

Priority 2: security

  • Documented technical security measures (encryption, MFA, backups)
  • A data breach notification procedure
  • An internal data breach register
  • Regular security testing (an annual penetration test is recommended)

Priority 3: governance

  • A DPO appointed (if mandatory) and registered with the APD
  • DPIAs carried out for high-risk processing
  • Annual staff training on data protection
  • A data retention and deletion policy

Priority 4: marketing

  • A clean marketing database (valid consents, a working opt-out)
  • A documented opt-in consent process
  • Effective unsubscribe handling within 10 working days
  • Deletion of customer accounts inactive for more than 3 years (APD recommendation)

GDPR fine scale

The GDPR provides for two tiers of fines, the sharpest lever the APD has to enforce GDPR compliance:

Tier Maximum amount Breaches concerned
Tier 1 EUR 10 million or 2% of global turnover Record of processing, security, DPO, DPIA
Tier 2 EUR 20 million or 4% of global turnover Core principles, data subject rights, international transfers
  • Maximum tier 1 fine: EUR 10 million (the absolute cap, not the percentage)
  • Maximum tier 2 fine: EUR 20 million

In practice, the Belgian APD calibrates its fines according to the size of the company, the severity of the breach, whether it was intentional, and the corrective measures taken. Fines for Belgian SMEs generally range between EUR 2,000 and EUR 100,000.

Resources and support

Free APD tools

  • Record of processing template: available on the APD website
  • Practical guide for SMEs: a downloadable brochure
  • FAQ: answers to frequently asked questions
  • Online complaint form: for members of the public

Support organisations

These free resources make GDPR compliance more affordable for SMEs that lack an in-house legal team.

Organisation Service Contact
APD Complaints, opinions, mediation autoritéprotectiondonnees.be
FPS Economy (SPF Économie) E-commerce and data guidance economie.fgov.be
CCB (Centre for Cybersecurity Belgium) Incident reporting, security advice ccb.belgium.be
safeonweb.be Awareness-raising for citizens and SMEs safeonweb.be
CNIL (France) Useful French-language resources (not binding in Belgium) cnil.fr

Training and certifications

  • CIPP/E certification (Certified Information Privacy Professional/Europe) — internationally recognised
  • DPO certification: the APD has set up a certification scheme (the EUROCERT scheme)
  • Ongoing training offered by Agoria, BELTUG, and Belgian universities (KU Leuven, ULB, UCLouvain)

Conclusion

The GDPR is no longer a future concern but a daily reality for every Belgian company. The APD now has the human and financial resources to carry out large-scale checks and impose deterrent sanctions. GDPR compliance is not just a legal obligation: it is an investment in your customers' trust, the security of your data and the long-term viability of your business. Start with the record of processing activities and the privacy policy, then progress methodically. Support from an external DPO or a specialist firm is a worthwhile investment for SMEs that lack in-house expertise.