
Belgium's Data Protection Authority (APD) is stepping up its inspections and sanctions. Eight years after the General Data Protection Regulation (GDPR) took effect, the grace period is definitively over. Belgian companies, whatever their size, must demonstrate effective GDPR compliance or face heavy financial penalties. This detailed guide reviews every obligation, the regulatory developments, and the concrete actions to take.
The Belgian legal framework for data protection
The founding texts
Data protection in Belgium rests on a multi-layered legal framework:
- Regulation (EU) 2016/679 (GDPR): directly applicable since 25 May 2018, it forms the common European foundation
- Law of 30 July 2018 on the protection of individuals with regard to the processing of personal data: the Belgian law implementing the GDPR
- Law of 3 December 2017 establishing the Data Protection Authority (replacing the former Privacy Commission)
- Royal Decree of 11 May 2023 on the certification of DPOs in Belgium
- ePrivacy Directive (2002/58/EC) and its Belgian transposition: specific regulation of cookies, electronic marketing and electronic communications
The Data Protection Authority (APD)
The APD is Belgium's independent supervisory authority. Its offices are at rue de la Presse 35, 1000 Brussels. It comprises several bodies:
| Body | Role |
|---|---|
| Management committee | Strategic and administrative management |
| First-line service | Handling complaints and mediation requests |
| Knowledge centre | Opinions, recommendations and studies |
| Inspection service | Investigations and on-site checks |
| Litigation Chamber | Imposes sanctions (fines, injunctions) |
| Disputes Chamber | Resolves disputes between parties |
Contact: contact@apd-gba.be — Tel.: +32 2 274 48 00 — Website: autoritéprotectiondonnees.be (or gegevensbeschermingsautoriteit.be in Dutch)
Sanctions in Belgium: the figures
The APD has considerably stepped up its enforcement activity in recent years, driving GDPR compliance across every sector:
| Year | Number of litigation decisions | Total fines | Highest individual fine |
|---|---|---|---|
| 2020 | 48 | EUR 800,000 | EUR 600,000 (Google Belgium) |
| 2021 | 65 | EUR 1,200,000 | EUR 250,000 |
| 2022 | 87 | EUR 1,800,000 | EUR 600,000 |
| 2023 | 102 | EUR 2,500,000 | EUR 750,000 |
| 2024 | 118 | EUR 4,100,000 | EUR 1,200,000 |
| 2025 | 134 | EUR 6,800,000 | EUR 2,000,000 |
| 2026 (projected) | 150+ | EUR 10,000,000+ | Tougher enforcement announced |
Notable APD decisions
Some concrete examples of sanctions imposed:
- Proximus (2023): EUR 50,000 for non-compliant direct marketing practices, sending commercial communications without valid consent
- Real estate sector (2024): EUR 75,000 for an estate agency over excessive retention of tenant data and the absence of a deletion policy
- E-commerce (2024): EUR 120,000 for no effective way to delete a customer account and dark patterns in the consent process
- Hospital (2025): EUR 200,000 for uncontrolled access to medical records by unauthorised staff
- Digital marketing company (2025): EUR 350,000 for large-scale profiling without a valid legal basis and unauthorised data transfers to the United States
The most closely monitored sectors in 2026
Digital marketing and online advertising
The APD has confirmed that digital marketing remains a priority for GDPR compliance checks. The most frequent breaches:
- Cookies and trackers: setting analytics or advertising cookies before obtaining the user's explicit consent. Simply continuing to browse does NOT constitute valid consent (APD decision 2021, confirmed by the CJEU in the Planet49 ruling)
- Newsletters and email marketing: sending commercial communications without prior opt-in consent (Article 13 of the law of 11 March 2003 on information society services)
- Marketing profiling: using behavioural data to target adverts without transparent information or a legal basis (consent or a documented legitimate interest)
- Pixel tracking: embedding Meta, Google or TikTok pixels without prior consent
- Non-freely-given consent: cookie walls that block access to content without consent — considered non-compliant by the APD
Practical tip: Your cookie banner must offer a "Reject all" button that is just as visible and accessible as the "Accept all" button. Pre-ticked boxes are prohibited.
Human resources and staff management
HR is an area of growing scrutiny:
- Monitoring remote workers: installing monitoring software (keyloggers, screenshots, webcam surveillance) — ruled disproportionate by the APD in several decisions. Monitoring must comply with Collective Labour Agreement No. 81 of the National Labour Council and the law of 26 December 2022 on the right to disconnect
- Retaining CVs: unsuccessful candidates' CVs must be deleted within a reasonable period. The APD recommends a maximum of two years after the last contact, with the candidate's explicit consent to be kept in a recruitment pool
- Geolocation data: company vehicles fitted with GPS must be the subject of clear information to employees and proportionate use
- HR data transfers: using SaaS HR software (Workday, BambooHR, and so on) hosted outside the EU requires appropriate safeguards (standard contractual clauses, a transfer impact assessment)
- CCTV: governed by Collective Labour Agreement No. 68 and the Camera Act of 21 March 2007 — requiring prior notice, registration and proportionality
E-commerce and online sales
Checks are multiplying in the e-commerce sector, where GDPR compliance gaps are easy for the APD to spot:
- Account deletion: customers must be able to delete their account and have their data erased easily (the right to erasure, Article 17 GDPR). A deletion button must be accessible in the account settings
- Payment data: card numbers cannot be retained without explicit consent, and retention must be time-limited. Using tokenisation is recommended
- Privacy policy: it must be written in clear, accessible language, in the languages matching the target audience (French, Dutch, German for Belgium). It must contain all the information required under Articles 13 and 14 GDPR
- International transfers: hosting customer data on US servers (AWS US, Google Cloud US) requires additional safeguards post-Schrems II
Health and medical data
The healthcare sector receives particular attention given the sensitivity of the data:
- Health data: a special category under Article 9 GDPR, requiring enhanced protection measures
- Patient consent: must be specific, informed and documented
- eHealth platform: the federal eHealth platform imposes strict security standards for exchanging health data
- Information Security Committee: prior authorisation is required for certain health data processing
For hospitals and clinics, GDPR compliance starts with strict access controls around patient records.
Detailed GDPR compliance obligations for businesses in 2026
1. Record of processing activities (Article 30 GDPR)
Any company processing personal data must keep a record of processing activities. In 2026, the APD requires an enhanced record covering:
| Element | Description | Mandatory |
|---|---|---|
| Name and contact details of the controller | Full identification of the company | Yes |
| Purposes of processing | Why the data is processed (e.g. payroll management, marketing) | Yes |
| Categories of data subjects | Employees, customers, prospects, suppliers | Yes |
| Categories of data | Name, email, address, financial data, and so on | Yes |
| Legal basis | Consent, contract, legal obligation, legitimate interest, and so on | Yes |
| Recipients of the data | Processors, partners, authorities | Yes |
| Transfers outside the EU | Destination countries and appropriate safeguards | Yes |
| Retention periods | Precise period for each category of data | Yes |
| Technical security measures | Encryption, pseudonymisation, access control | Yes (new) |
| Risk assessment | Risk level for each processing activity | Yes (new) |
| DPIA outcomes | Summary of the impact assessments carried out | Yes (new) |
Concrete example for an SME with 15 employees selling online:
Your record should contain at least the following processing activities:
- Customer order management (basis: contract)
- Sending newsletters (basis: consent)
- Accounting management (basis: legal obligation)
- HR management (basis: contract + legal obligation)
- Analytics cookies on the website (basis: consent)
- CCTV of the premises (basis: legitimate interest)
2. Data breach notification (Articles 33 and 34 GDPR)
In the event of a personal data breach (leak, hack, loss, unauthorised access), the obligations are as follows:
Notification to the APD
- Deadline: 72 hours after becoming aware of the breach (the GDPR maintains this deadline; any future reduction would come through an amendment to the regulation or sector-specific recommendations)
- Form: online notification via the APD's portal (databreachnotification.be)
- Content: nature of the breach, categories and number of data subjects affected, likely consequences, measures taken or proposed
Notification to data subjects
- When: when the breach is likely to result in a high risk to individuals' rights and freedoms
- How: direct communication (email, letter), in clear language
- Content: description of the breach, recommendations to protect themselves (changing passwords, monitoring bank accounts)
Concrete example: A Walloon SME suffers a ransomware attack that encrypts its customer database (5,000 contacts with names, emails and purchase history). It must:
- Notify the APD within 72 hours via the online form
- Inform the 5,000 customers of the breach by email
- Document the incident in its internal breach register
- Take corrective action (strengthening security, backups, an audit)
3. Data Protection Officer (DPO)
Appointing the right person is often the linchpin of GDPR compliance for larger organisations.
When is a DPO mandatory?
The GDPR (Article 37) requires a DPO to be appointed in three cases:
- Public authorities or bodies (except courts acting in their judicial capacity)
- Core activities involving regular and systematic large-scale monitoring of data subjects
- Large-scale processing of sensitive data (health, judicial, biometric data, and so on)
The APD has clarified in its recommendations that this notably applies to:
- Digital marketing companies carrying out profiling
- Security companies using large-scale CCTV
- Healthcare providers
- Companies systematically processing data on more than 5,000 people
DPO profile
- Expertise: in-depth knowledge of data protection law and IT security
- Independence: the DPO cannot receive instructions on how to carry out their duties, and cannot be penalised for performing them
- Resources: the company must give the DPO the resources they need (time, budget, ongoing training)
- Registration: the DPO's contact details must be communicated to the APD
In-house vs external DPO
| Criterion | In-house DPO | External DPO |
|---|---|---|
| Estimated annual cost | EUR 60,000 – 90,000 (gross salary) | EUR 5,000 – 25,000 (fee) |
| Availability | Full-time or part-time | Per contract (fixed fee or on demand) |
| Knowledge of the company | Excellent | Needs building up |
| Independence | Risk of conflicts of interest | Guaranteed by nature |
| Best suited to | Large companies (250+ employees) | SMEs and mid-sized companies |
4. Data Protection Impact Assessment (DPIA)
When is a DPIA mandatory?
The APD has published a list of processing operations for which a DPIA is mandatory (decision No. 01/2019). Among the most frequent cases:
- Large-scale processing of geolocation data
- Systematic profiling for granting credit or insurance
- Systematic CCTV of publicly accessible areas
- Processing biometric data for identification
- Systematic monitoring of employees
- Processing health data outside individual care
- Using artificial intelligence for automated decision-making
Contents of a DPIA
- A systematic description of the envisaged processing
- An assessment of necessity and proportionality
- An assessment of the risks to individuals' rights and freedoms
- The measures envisaged to mitigate the risks
- The DPO's opinion (where applicable)
5. International data transfers
Since the CJEU's Schrems II ruling (2020) and the adoption of the EU-US Data Privacy Framework (DPF) in 2023, the transfer rules are as follows:
| Destination | Mechanism required |
|---|---|
| EU/EEA | No additional mechanism |
| Countries with an adequacy decision (Japan, United Kingdom, Switzerland, and others) | No additional mechanism |
| USA (DPF-certified company) | Transfer permitted under the DPF |
| Other third countries | Standard contractual clauses (SCCs) + a transfer impact assessment (TIA) |
Point to watch for 2026: The Data Privacy Framework is being challenged before the CJEU. Companies should have a "plan B" ready in case it is invalidated (as happened with Privacy Shield in 2020). Getting international transfers right is a core pillar of GDPR compliance.
Concrete actions to put in place
GDPR compliance checklist for 2026
Priority 1: fundamentals
- A complete, up-to-date record of processing activities (Article 30)
- A compliant privacy policy (Articles 13–14) on your website
- A compliant cookie banner with an easy "reject" option
- Data processing agreements (Article 28) signed with all your IT providers
- A procedure for handling data subject rights requests (access, erasure, portability)
Priority 2: security
- Documented technical security measures (encryption, MFA, backups)
- A data breach notification procedure
- An internal data breach register
- Regular security testing (an annual penetration test is recommended)
Priority 3: governance
- A DPO appointed (if mandatory) and registered with the APD
- DPIAs carried out for high-risk processing
- Annual staff training on data protection
- A data retention and deletion policy
Priority 4: marketing
- A clean marketing database (valid consents, a working opt-out)
- A documented opt-in consent process
- Effective unsubscribe handling within 10 working days
- Deletion of customer accounts inactive for more than 3 years (APD recommendation)
GDPR fine scale
The GDPR provides for two tiers of fines, the sharpest lever the APD has to enforce GDPR compliance:
| Tier | Maximum amount | Breaches concerned |
|---|---|---|
| Tier 1 | EUR 10 million or 2% of global turnover | Record of processing, security, DPO, DPIA |
| Tier 2 | EUR 20 million or 4% of global turnover | Core principles, data subject rights, international transfers |
For a Belgian SME with turnover of EUR 2 million:
- Maximum tier 1 fine: EUR 10 million (the absolute cap, not the percentage)
- Maximum tier 2 fine: EUR 20 million
In practice, the Belgian APD calibrates its fines according to the size of the company, the severity of the breach, whether it was intentional, and the corrective measures taken. Fines for Belgian SMEs generally range between EUR 2,000 and EUR 100,000.
Resources and support
Free APD tools
- Record of processing template: available on the APD website
- Practical guide for SMEs: a downloadable brochure
- FAQ: answers to frequently asked questions
- Online complaint form: for members of the public
Support organisations
These free resources make GDPR compliance more affordable for SMEs that lack an in-house legal team.
| Organisation | Service | Contact |
|---|---|---|
| APD | Complaints, opinions, mediation | autoritéprotectiondonnees.be |
| FPS Economy (SPF Économie) | E-commerce and data guidance | economie.fgov.be |
| CCB (Centre for Cybersecurity Belgium) | Incident reporting, security advice | ccb.belgium.be |
| safeonweb.be | Awareness-raising for citizens and SMEs | safeonweb.be |
| CNIL (France) | Useful French-language resources (not binding in Belgium) | cnil.fr |
Training and certifications
- CIPP/E certification (Certified Information Privacy Professional/Europe) — internationally recognised
- DPO certification: the APD has set up a certification scheme (the EUROCERT scheme)
- Ongoing training offered by Agoria, BELTUG, and Belgian universities (KU Leuven, ULB, UCLouvain)
Conclusion
The GDPR is no longer a future concern but a daily reality for every Belgian company. The APD now has the human and financial resources to carry out large-scale checks and impose deterrent sanctions. GDPR compliance is not just a legal obligation: it is an investment in your customers' trust, the security of your data and the long-term viability of your business. Start with the record of processing activities and the privacy policy, then progress methodically. Support from an external DPO or a specialist firm is a worthwhile investment for SMEs that lack in-house expertise.


