The GDPR (General Data Protection Regulation) came into force on 25 May 2018, but in 2026 many Belgian SMEs are still not fully compliant. According to a survey by the APD (Data Protection Authority), nearly 40% of Belgian SMEs have no up-to-date register of processing activities, and 55% lack a compliant privacy policy on their website. Yet the sanctions are real: the APD has issued more than 150 fines since 2019, some against small businesses. This practical guide shows you how to bring your SME into GDPR compliance, step by step, without spending weeks on it or breaking the bank.

The GDPR (EU Regulation 2016/679) is a European regulation directly applicable in all member states, including Belgium. It is supplemented in Belgian law by:

  • The Act of 30 July 2018 on the protection of individuals with regard to the processing of personal data (the Belgian framework law)
  • The Act of 5 September 2018 establishing the Data Protection Authority (APD)
  • Various sector-specific laws: the law on privacy at work, the law on electronic marketing, and others

The APD (Data Protection Authority)

The APD is Belgium's national supervisory authority. It succeeded the former Commission for the Protection of Privacy in 2019.

  • First-line service: first point of contact, complaints, information requests
  • Knowledge Centre: opinions, recommendations, guidelines
  • Inspection Service: field and online investigations
  • Litigation Chamber: the decision-making body that imposes sanctions

Contact: dataprotectionauthority.be – T. +32 (0)2 274 48 00

Year Number of sanctions Total fines
2019-2020 25 around EUR 800,000
2021 40 around EUR 1,200,000
2022 35 around EUR 1,500,000
2023 38 around EUR 2,000,000
2024 42 around EUR 2,500,000
2025 50+ around EUR 3,000,000
  • Warnings and formal notices (the most common for SMEs)
  • Administrative fines (up to EUR 20 million or 4% of worldwide turnover)
  • Compliance orders with a deadline
  • Temporary bans on processing
  • Obligation to notify data subjects
  • Google Belgium: EUR 600,000 for failing to respect the right to be forgotten
  • Proximus: EUR 20,000 for direct marketing without consent
  • A doctor: EUR 3,000 for sending unsecured medical data
  • An e-commerce SME: EUR 10,000 for having no register of processing activities and a defective privacy policy

GDPR obligations for SMEs: what concerns you

When does the GDPR apply to your SME?

The GDPR applies as soon as you process personal data. In practice, every SME is concerned, because you inevitably process personal data:

  • Customers: name, address, email, phone, purchase history
  • Employees: identification data, salary, appraisals, medical data (occupational medicine)
  • Suppliers: contact details of contact persons
  • Prospects: data collected via your website (forms, cookies, newsletter)
  • Website visitors: IP address, cookies, browsing data

The 7 fundamental principles of the GDPR

Every processing activity must respect these 7 principles:

Principle What it means in practice
Lawfulness, fairness, transparency You need a legal basis and must inform data subjects
Purpose limitation Only collect data for specific, legitimate purposes
Data minimisation Only collect data that is strictly necessary
Accuracy Keep data up to date and correct errors
Storage limitation Do not keep data longer than necessary
Integrity and confidentiality Protect data against unauthorised access
Accountability You must be able to demonstrate your compliance

You must be able to justify every processing activity on one of these 6 legal bases:

  1. Consent: the person has given explicit agreement (e.g. newsletter sign-up, marketing cookies)
  2. Contract performance: processing is necessary to perform a contract (e.g. delivering an order, managing an employment contract)
  3. Legal obligation: the law requires it (e.g. keeping invoices for 7 years, social security filings)
  4. Vital interest: protecting a person's life (rare for SMEs)
  5. Public interest task: (rare for private SMEs)
  6. Legitimate interest: your business interest justifies the processing, provided it is balanced against the individual's rights (e.g. B2B prospecting, fraud prevention, IT security)

Consent must be:

  • Freely given: no pre-ticked boxes, no forced consent
  • Specific: one consent per purpose
  • Informed: the person knows what they are consenting to
  • Unambiguous: a clear action (ticking a box, clicking "I agree")
  • Revocable: the person can withdraw consent at any time

An 8-step compliance guide

Step 1: Map your data processing activities (register of processing activities)

The register of processing activities is the central document of your GDPR compliance. It is mandatory for any company with more than 250 employees, but also for SMEs whose processing is not occasional (which is the case for almost every SME).

For each processing activity, document:

Field Example (customer management) Example (newsletter)
Name of processing activity Customer relationship management Sending the newsletter
Controller Manager of the SRL Marketing department
Purpose Invoicing, order tracking Commercial information
Categories of data subjects Customers Newsletter subscribers
Categories of data Name, address, email, VAT number, purchases Email, first name
Legal basis Contract performance Consent
Recipients Accountant, invoicing software Mailchimp (processor)
Transfer outside the EU No Yes (Mailchimp in the USA)
Retention period 7 years after the last invoice Until unsubscription
Security measures Restricted access, encryption Double opt-in, unsubscribe link
  • APD template: the Belgian APD offers a free Excel template on its website (dataprotectionauthority.be)
  • CNIL template: the French CNIL also offers a GDPR-compatible template
  • GDPR Register (gdprregister.eu): a free online tool for SMEs

Step 2: Draft your privacy policy

Your privacy policy (or privacy statement) must be accessible on your website and on your premises. It must inform people clearly and comprehensibly.

  • Identity and contact details of the controller (your company)
  • Contact details of the DPO (if you have one)
  • Purposes and legal bases for each processing activity
  • Categories of data processed
  • Recipients or categories of recipients
  • Transfers to third countries (outside the EU) and safeguards
  • Retention periods
  • Data subjects' rights (access, rectification, erasure, portability, objection, restriction)
  • The right to lodge a complaint with the APD
  • Whether providing the data is mandatory or optional
  • Copy-pasting a generic template without adapting it to your situation
  • Using incomprehensible legal jargon
  • Not mentioning processors (host, CRM, email tool)
  • Forgetting transfers outside the EU (Mailchimp, Google Analytics, Facebook)
  • Not stating retention periods

Step 3: Manage your website's cookies

Cookies are a sensitive topic in Belgium. The APD and the ePrivacy Directive impose strict rules:

Type Examples Consent required?
Strictly necessary Shopping cart, session, security No
Functional Language preferences, login Depends (recommended: yes)
Analytics Google Analytics, Matomo Yes
Marketing / advertising Facebook Pixel, Google Ads, retargeting Yes
  • Cookie banner: display a banner on first visit, allowing users to accept or reject each cookie category
  • No pre-ticked boxes: boxes must be unticked by default (Planet49 ruling, CJEU 2019)
  • Rejection as easy as acceptance: the "Reject" button must be as visible as the "Accept" button
  • No "cookie wall": you cannot block access to the site if the user refuses cookies (APD's position)
  • Cookiebot: a popular, GDPR-compliant CMP (Consent Management Platform). Free for 1 page, paid from EUR 9/month
  • Tarteaucitron.js: an open-source, free solution, widely used in the French-speaking world
  • Complianz: a WordPress plugin, from EUR 5/month
  • Axeptio: a French solution with a polished interface, from EUR 19/month

Step 4: Secure personal data

GDPR compliance requires "appropriate technical and organisational measures" to protect data. For an SME, this means in practice:

  • Passwords: a strong password policy (minimum 12 characters, complex, unique). Use a password manager (Bitwarden, 1Password, KeePass)
  • Two-factor authentication (2FA): enable it on all critical accounts (email, CRM, bank, cloud)
  • Encryption: encrypt laptop hard drives (BitLocker on Windows, FileVault on Mac)
  • Antivirus and firewall: keep them up to date
  • Updates: systematically apply security updates for software and operating systems
  • Backups: back up your data regularly (daily), on external media or in the cloud, and test the restoration process
  • Restricted access: each employee should only access the data needed for their role (least-privilege principle)
  • Secure Wi-Fi: WPA3, a complex password, a separate guest network
  • Employee awareness: train your employees in good practice (phishing, passwords, incident reporting)
  • Written procedures: a procedure for data breaches, for exercising data subjects' rights, for deletion
  • Contracts with processors: mandatory GDPR clauses (Article 28)
  • Clean desk policy: no documents containing personal data left unattended

Step 5: Manage your processors (Article 28)

Managing processors correctly is a core part of GDPR compliance. Any processor that processes personal data on your behalf must sign a Data Processing Agreement (DPA) compliant with Article 28 of the GDPR.

Processor Type of data Based in the EU?
Accountant / accounting firm Financial data, employee data Yes (generally)
Web host (Combell, OVH, Hostinger) Website data, emails Depends
CRM software (HubSpot, Salesforce, Teamleader) Customer data Depends (often USA)
Email tool (Mailchimp, Brevo, ActiveCampaign) Subscriber emails Depends (often USA)
Accounting software (Exact, Yuki, Octopus, BOB50) Financial data Yes (generally)
Cloud service (Google Workspace, Microsoft 365) All data USA (standard contractual clauses)
Payroll agency (Securex, Partena, Liantis, Acerta) Employee data Yes
Payroll software Salary data Yes

Since the Schrems II ruling (2020) and the EU-US Data Privacy Framework (2023):

  • Transfers to US companies certified under the Data Privacy Framework are permitted
  • For others, you must use standard contractual clauses (SCCs) adopted by the European Commission
  • Check whether your US processor is certified: dataprivacyframework.gov

Step 6: Respect data subjects' rights

GDPR compliance also means respecting individual rights. The GDPR grants 8 rights to the people whose data you process:

Right What it means Response deadline
Access The person may request a copy of their data 1 month
Rectification Correcting inaccurate data 1 month
Erasure (right to be forgotten) Deleting data (unless there is a legal retention obligation) 1 month
Restriction Temporarily limiting processing 1 month
Portability Receiving their data in a machine-readable format 1 month
Objection Objecting to processing (legitimate interest, direct marketing) Immediately (direct marketing)
No automated decision-making Not being subject to an automated decision 1 month
Withdrawal of consent Withdrawing consent at any time Immediately
  1. Appoint someone responsible for handling requests (the DPO if you have one, otherwise the manager)
  2. Create a dedicated email address (e.g. privacy@yourcompany.be)
  3. Verify the requester's identity before responding
  4. Respond within the 1-month deadline (extendable by 2 months for complex requests)
  5. Document every request and your response (proof of compliance)

Step 7: Prepare for data breaches

A data breach is any security incident leading to the destruction, loss, alteration or unauthorised disclosure of personal data.

  • An employee mistakenly sends a customer file to the wrong person
  • A laptop containing customer data is stolen
  • Your website is hacked and user data is exposed
  • Ransomware encrypts your data (and potentially exfiltrates it)
  • A phishing email lets an attacker access your CRM
  1. Document the incident (nature, data involved, number of people, consequences)
  2. Assess the risk to the people concerned
  3. Notify the APD within 72 hours if the risk is not negligible (online form at dataprotectionauthority.be)
  4. Notify the people concerned "without undue delay" if the risk is high (e.g. financial data, health data exposed)
  5. Take corrective measures to limit the damage and prevent recurrence

Even if a breach does not require notification to the APD, you must document it in an internal register (obligation under Article 33(5) of the GDPR).

Step 8: Appoint a DPO if necessary

A DPO (Data Protection Officer) is mandatory in 3 cases:

  1. You are a public body
  2. Your core activities involve regular and systematic large-scale monitoring of individuals
  3. Your core activities involve large-scale processing of sensitive data (health, biometrics, criminal convictions)

In practice, a DPO is not mandatory for most Belgian SMEs. However, it is strongly recommended to appoint someone within the company responsible for day-to-day GDPR compliance.

  • Internal DPO: an employee trained in GDPR (2 to 5 days of training, cost: EUR 1,000 to 3,000)
  • External DPO: a specialised consultant or firm. Cost: EUR 300 to 800/month for an SME
  • Reference person: without the official DPO title, appoint an internal GDPR contact

GDPR compliance budget for a Belgian SME

Estimated compliance costs

Item SME with 1-5 people SME with 5-50 people
Initial audit (consultant) EUR 1,000 to 3,000 EUR 3,000 to 8,000
Drafting a privacy policy EUR 500 to 1,500 EUR 1,500 to 3,000
Register of processing activities Free (APD template) to EUR 1,000 EUR 1,000 to 3,000
Cookie management solution EUR 0 to 200/year EUR 200 to 600/year
Processor contracts (DPAs) EUR 500 to 2,000 EUR 2,000 to 5,000
Employee training EUR 500 to 1,500 EUR 1,500 to 5,000
External DPO (if needed) EUR 300 to 500/month EUR 500 to 1,000/month
Total compliance cost EUR 2,500 to 8,000 EUR 8,000 to 25,000
Annual maintenance cost EUR 500 to 2,000/year EUR 2,000 to 10,000/year

Hiring a GDPR consultant in Belgium

If you would rather outsource the work, several firms and consultants specialise in GDPR compliance for Belgian SMEs, and can run your entire GDPR compliance project for you:

  • DPO-as-a-Service: several providers offer a part-time outsourced DPO
  • Law firms: many Belgian firms have a "privacy" department (Stibbe, Linklaters, Lydian, Simont Braun, and others)
  • Sector organisations: UCM, Unizo and trade federations often offer sector-specific GDPR guides and training

Practical cases by sector

GDPR compliance needs differ by sector. Below are the main challenges for four typical Belgian businesses.

Belgian e-commerce

  • Cookies and tracking (Google Analytics, Facebook Pixel, retargeting)
  • Newsletter and direct marketing (consent, unsubscribe link)
  • Retention of order data (7 years for accounting obligations, but not marketing data)
  • Multiple processors (e-commerce platform, payment, delivery, CRM, emailing)
  • Customer reviews (legal basis, right to deletion)

Medical / paramedical practice

  • Health data = sensitive data (Article 9 GDPR): enhanced protection
  • DPO potentially mandatory for large-scale processing
  • Electronic medical records: enhanced security measures
  • Transferring records between professionals: patient consent required
  • Retention: 30 years for medical records in Belgium

Hospitality (Horeca)

  • CCTV: declaration to the police, signage, register
  • Free Wi-Fi: retention of connection logs (1 year, telecom law)
  • Online booking: limited retention, no marketing reuse without consent
  • Loyalty programme: consent for profiling and personalised marketing

Liberal professions (lawyer, accountant, consultant)

  • Professional secrecy and GDPR: reconciling both obligations
  • Possible sensitive data (legal files, financial data)
  • Transferring files between professionals
  • Secure archiving (professional-body and legal obligations)

GDPR compliance checklist for SMEs

Use this GDPR compliance checklist as a final check before you consider the job done.

  • Register of data processing activities drafted and up to date
  • Privacy policy published on the website
  • Compliant cookie banner (no pre-ticked boxes, easy refusal)
  • Compliant contact and sign-up forms (information notice, consent)
  • Processor contracts (DPAs) signed with all processors
  • Technical security measures in place (passwords, 2FA, encryption, backups)
  • Procedure for exercising data subjects' rights documented
  • Data breach procedure documented
  • Employee training/awareness carried out
  • DPO appointed or reference person identified
  • Retention periods defined for each processing activity
  • Transfers outside the EU identified and governed (SCCs or Data Privacy Framework)

Conclusion

GDPR compliance is not a one-off project but an ongoing process. For a Belgian SME, initial compliance represents an investment of a few thousand euros and a few weeks of work, but it protects you against sanctions that can reach hundreds of thousands of euros, not to mention reputational damage. Start with the basics: the register of processing activities, the privacy policy and cookies. Then gradually improve your compliance level. The Belgian APD takes an educational approach towards SMEs acting in good faith that make efforts to comply, but it does not hesitate to sanction companies that completely ignore their obligations.