
The GDPR (General Data Protection Regulation) came into force on 25 May 2018, but in 2026 many Belgian SMEs are still not fully compliant. According to a survey by the APD (Data Protection Authority), nearly 40% of Belgian SMEs have no up-to-date register of processing activities, and 55% lack a compliant privacy policy on their website. Yet the sanctions are real: the APD has issued more than 150 fines since 2019, some against small businesses. This practical guide shows you how to bring your SME into GDPR compliance, step by step, without spending weeks on it or breaking the bank.
GDPR in Belgium: legal framework and supervisory authority
The legal framework
The GDPR (EU Regulation 2016/679) is a European regulation directly applicable in all member states, including Belgium. It is supplemented in Belgian law by:
- The Act of 30 July 2018 on the protection of individuals with regard to the processing of personal data (the Belgian framework law)
- The Act of 5 September 2018 establishing the Data Protection Authority (APD)
- Various sector-specific laws: the law on privacy at work, the law on electronic marketing, and others
The APD (Data Protection Authority)
The APD is Belgium's national supervisory authority. It succeeded the former Commission for the Protection of Privacy in 2019.
Structure of the APD:
- First-line service: first point of contact, complaints, information requests
- Knowledge Centre: opinions, recommendations, guidelines
- Inspection Service: field and online investigations
- Litigation Chamber: the decision-making body that imposes sanctions
Contact: dataprotectionauthority.be – T. +32 (0)2 274 48 00
Sanctions in Belgium (2019–2025):
| Year | Number of sanctions | Total fines |
|---|---|---|
| 2019-2020 | 25 | around EUR 800,000 |
| 2021 | 40 | around EUR 1,200,000 |
| 2022 | 35 | around EUR 1,500,000 |
| 2023 | 38 | around EUR 2,000,000 |
| 2024 | 42 | around EUR 2,500,000 |
| 2025 | 50+ | around EUR 3,000,000 |
Types of sanctions imposed:
- Warnings and formal notices (the most common for SMEs)
- Administrative fines (up to EUR 20 million or 4% of worldwide turnover)
- Compliance orders with a deadline
- Temporary bans on processing
- Obligation to notify data subjects
Notable Belgian sanctions:
- Google Belgium: EUR 600,000 for failing to respect the right to be forgotten
- Proximus: EUR 20,000 for direct marketing without consent
- A doctor: EUR 3,000 for sending unsecured medical data
- An e-commerce SME: EUR 10,000 for having no register of processing activities and a defective privacy policy
GDPR obligations for SMEs: what concerns you
When does the GDPR apply to your SME?
The GDPR applies as soon as you process personal data. In practice, every SME is concerned, because you inevitably process personal data:
- Customers: name, address, email, phone, purchase history
- Employees: identification data, salary, appraisals, medical data (occupational medicine)
- Suppliers: contact details of contact persons
- Prospects: data collected via your website (forms, cookies, newsletter)
- Website visitors: IP address, cookies, browsing data
The 7 fundamental principles of the GDPR
Every processing activity must respect these 7 principles:
| Principle | What it means in practice |
|---|---|
| Lawfulness, fairness, transparency | You need a legal basis and must inform data subjects |
| Purpose limitation | Only collect data for specific, legitimate purposes |
| Data minimisation | Only collect data that is strictly necessary |
| Accuracy | Keep data up to date and correct errors |
| Storage limitation | Do not keep data longer than necessary |
| Integrity and confidentiality | Protect data against unauthorised access |
| Accountability | You must be able to demonstrate your compliance |
The 6 legal bases for processing data
You must be able to justify every processing activity on one of these 6 legal bases:
- Consent: the person has given explicit agreement (e.g. newsletter sign-up, marketing cookies)
- Contract performance: processing is necessary to perform a contract (e.g. delivering an order, managing an employment contract)
- Legal obligation: the law requires it (e.g. keeping invoices for 7 years, social security filings)
- Vital interest: protecting a person's life (rare for SMEs)
- Public interest task: (rare for private SMEs)
- Legitimate interest: your business interest justifies the processing, provided it is balanced against the individual's rights (e.g. B2B prospecting, fraud prevention, IT security)
Beware of consent:
Consent must be:
- Freely given: no pre-ticked boxes, no forced consent
- Specific: one consent per purpose
- Informed: the person knows what they are consenting to
- Unambiguous: a clear action (ticking a box, clicking "I agree")
- Revocable: the person can withdraw consent at any time
An 8-step compliance guide
Step 1: Map your data processing activities (register of processing activities)
The register of processing activities is the central document of your GDPR compliance. It is mandatory for any company with more than 250 employees, but also for SMEs whose processing is not occasional (which is the case for almost every SME).
Register template:
For each processing activity, document:
| Field | Example (customer management) | Example (newsletter) |
|---|---|---|
| Name of processing activity | Customer relationship management | Sending the newsletter |
| Controller | Manager of the SRL | Marketing department |
| Purpose | Invoicing, order tracking | Commercial information |
| Categories of data subjects | Customers | Newsletter subscribers |
| Categories of data | Name, address, email, VAT number, purchases | Email, first name |
| Legal basis | Contract performance | Consent |
| Recipients | Accountant, invoicing software | Mailchimp (processor) |
| Transfer outside the EU | No | Yes (Mailchimp in the USA) |
| Retention period | 7 years after the last invoice | Until unsubscription |
| Security measures | Restricted access, encryption | Double opt-in, unsubscribe link |
Free tools for the register:
- APD template: the Belgian APD offers a free Excel template on its website (dataprotectionauthority.be)
- CNIL template: the French CNIL also offers a GDPR-compatible template
- GDPR Register (gdprregister.eu): a free online tool for SMEs
Step 2: Draft your privacy policy
Your privacy policy (or privacy statement) must be accessible on your website and on your premises. It must inform people clearly and comprehensibly.
Mandatory content:
- Identity and contact details of the controller (your company)
- Contact details of the DPO (if you have one)
- Purposes and legal bases for each processing activity
- Categories of data processed
- Recipients or categories of recipients
- Transfers to third countries (outside the EU) and safeguards
- Retention periods
- Data subjects' rights (access, rectification, erasure, portability, objection, restriction)
- The right to lodge a complaint with the APD
- Whether providing the data is mandatory or optional
Common mistakes in privacy policies:
- Copy-pasting a generic template without adapting it to your situation
- Using incomprehensible legal jargon
- Not mentioning processors (host, CRM, email tool)
- Forgetting transfers outside the EU (Mailchimp, Google Analytics, Facebook)
- Not stating retention periods
Step 3: Manage your website's cookies
Cookies are a sensitive topic in Belgium. The APD and the ePrivacy Directive impose strict rules:
Cookie classification:
| Type | Examples | Consent required? |
|---|---|---|
| Strictly necessary | Shopping cart, session, security | No |
| Functional | Language preferences, login | Depends (recommended: yes) |
| Analytics | Google Analytics, Matomo | Yes |
| Marketing / advertising | Facebook Pixel, Google Ads, retargeting | Yes |
Obligations:
- Cookie banner: display a banner on first visit, allowing users to accept or reject each cookie category
- No pre-ticked boxes: boxes must be unticked by default (Planet49 ruling, CJEU 2019)
- Rejection as easy as acceptance: the "Reject" button must be as visible as the "Accept" button
- No "cookie wall": you cannot block access to the site if the user refuses cookies (APD's position)
Technical solutions:
- Cookiebot: a popular, GDPR-compliant CMP (Consent Management Platform). Free for 1 page, paid from EUR 9/month
- Tarteaucitron.js: an open-source, free solution, widely used in the French-speaking world
- Complianz: a WordPress plugin, from EUR 5/month
- Axeptio: a French solution with a polished interface, from EUR 19/month
Step 4: Secure personal data
GDPR compliance requires "appropriate technical and organisational measures" to protect data. For an SME, this means in practice:
Technical measures:
- Passwords: a strong password policy (minimum 12 characters, complex, unique). Use a password manager (Bitwarden, 1Password, KeePass)
- Two-factor authentication (2FA): enable it on all critical accounts (email, CRM, bank, cloud)
- Encryption: encrypt laptop hard drives (BitLocker on Windows, FileVault on Mac)
- Antivirus and firewall: keep them up to date
- Updates: systematically apply security updates for software and operating systems
- Backups: back up your data regularly (daily), on external media or in the cloud, and test the restoration process
- Restricted access: each employee should only access the data needed for their role (least-privilege principle)
- Secure Wi-Fi: WPA3, a complex password, a separate guest network
Organisational measures:
- Employee awareness: train your employees in good practice (phishing, passwords, incident reporting)
- Written procedures: a procedure for data breaches, for exercising data subjects' rights, for deletion
- Contracts with processors: mandatory GDPR clauses (Article 28)
- Clean desk policy: no documents containing personal data left unattended
Step 5: Manage your processors (Article 28)
Managing processors correctly is a core part of GDPR compliance. Any processor that processes personal data on your behalf must sign a Data Processing Agreement (DPA) compliant with Article 28 of the GDPR.
Common processors for a Belgian SME:
| Processor | Type of data | Based in the EU? |
|---|---|---|
| Accountant / accounting firm | Financial data, employee data | Yes (generally) |
| Web host (Combell, OVH, Hostinger) | Website data, emails | Depends |
| CRM software (HubSpot, Salesforce, Teamleader) | Customer data | Depends (often USA) |
| Email tool (Mailchimp, Brevo, ActiveCampaign) | Subscriber emails | Depends (often USA) |
| Accounting software (Exact, Yuki, Octopus, BOB50) | Financial data | Yes (generally) |
| Cloud service (Google Workspace, Microsoft 365) | All data | USA (standard contractual clauses) |
| Payroll agency (Securex, Partena, Liantis, Acerta) | Employee data | Yes |
| Payroll software | Salary data | Yes |
Transfers outside the EU (notably to the USA):
Since the Schrems II ruling (2020) and the EU-US Data Privacy Framework (2023):
- Transfers to US companies certified under the Data Privacy Framework are permitted
- For others, you must use standard contractual clauses (SCCs) adopted by the European Commission
- Check whether your US processor is certified: dataprivacyframework.gov
Step 6: Respect data subjects' rights
GDPR compliance also means respecting individual rights. The GDPR grants 8 rights to the people whose data you process:
| Right | What it means | Response deadline |
|---|---|---|
| Access | The person may request a copy of their data | 1 month |
| Rectification | Correcting inaccurate data | 1 month |
| Erasure (right to be forgotten) | Deleting data (unless there is a legal retention obligation) | 1 month |
| Restriction | Temporarily limiting processing | 1 month |
| Portability | Receiving their data in a machine-readable format | 1 month |
| Objection | Objecting to processing (legitimate interest, direct marketing) | Immediately (direct marketing) |
| No automated decision-making | Not being subject to an automated decision | 1 month |
| Withdrawal of consent | Withdrawing consent at any time | Immediately |
Practical procedure:
- Appoint someone responsible for handling requests (the DPO if you have one, otherwise the manager)
- Create a dedicated email address (e.g. privacy@yourcompany.be)
- Verify the requester's identity before responding
- Respond within the 1-month deadline (extendable by 2 months for complex requests)
- Document every request and your response (proof of compliance)
Step 7: Prepare for data breaches
A data breach is any security incident leading to the destruction, loss, alteration or unauthorised disclosure of personal data.
Concrete examples:
- An employee mistakenly sends a customer file to the wrong person
- A laptop containing customer data is stolen
- Your website is hacked and user data is exposed
- Ransomware encrypts your data (and potentially exfiltrates it)
- A phishing email lets an attacker access your CRM
Obligations in the event of a breach:
- Document the incident (nature, data involved, number of people, consequences)
- Assess the risk to the people concerned
- Notify the APD within 72 hours if the risk is not negligible (online form at dataprotectionauthority.be)
- Notify the people concerned "without undue delay" if the risk is high (e.g. financial data, health data exposed)
- Take corrective measures to limit the damage and prevent recurrence
Breach register template:
Even if a breach does not require notification to the APD, you must document it in an internal register (obligation under Article 33(5) of the GDPR).
Step 8: Appoint a DPO if necessary
A DPO (Data Protection Officer) is mandatory in 3 cases:
- You are a public body
- Your core activities involve regular and systematic large-scale monitoring of individuals
- Your core activities involve large-scale processing of sensitive data (health, biometrics, criminal convictions)
In practice, a DPO is not mandatory for most Belgian SMEs. However, it is strongly recommended to appoint someone within the company responsible for day-to-day GDPR compliance.
Options for SMEs:
- Internal DPO: an employee trained in GDPR (2 to 5 days of training, cost: EUR 1,000 to 3,000)
- External DPO: a specialised consultant or firm. Cost: EUR 300 to 800/month for an SME
- Reference person: without the official DPO title, appoint an internal GDPR contact
GDPR compliance budget for a Belgian SME
Estimated compliance costs
| Item | SME with 1-5 people | SME with 5-50 people |
|---|---|---|
| Initial audit (consultant) | EUR 1,000 to 3,000 | EUR 3,000 to 8,000 |
| Drafting a privacy policy | EUR 500 to 1,500 | EUR 1,500 to 3,000 |
| Register of processing activities | Free (APD template) to EUR 1,000 | EUR 1,000 to 3,000 |
| Cookie management solution | EUR 0 to 200/year | EUR 200 to 600/year |
| Processor contracts (DPAs) | EUR 500 to 2,000 | EUR 2,000 to 5,000 |
| Employee training | EUR 500 to 1,500 | EUR 1,500 to 5,000 |
| External DPO (if needed) | EUR 300 to 500/month | EUR 500 to 1,000/month |
| Total compliance cost | EUR 2,500 to 8,000 | EUR 8,000 to 25,000 |
| Annual maintenance cost | EUR 500 to 2,000/year | EUR 2,000 to 10,000/year |
Hiring a GDPR consultant in Belgium
If you would rather outsource the work, several firms and consultants specialise in GDPR compliance for Belgian SMEs, and can run your entire GDPR compliance project for you:
- DPO-as-a-Service: several providers offer a part-time outsourced DPO
- Law firms: many Belgian firms have a "privacy" department (Stibbe, Linklaters, Lydian, Simont Braun, and others)
- Sector organisations: UCM, Unizo and trade federations often offer sector-specific GDPR guides and training
Practical cases by sector
GDPR compliance needs differ by sector. Below are the main challenges for four typical Belgian businesses.
Belgian e-commerce
Main GDPR challenges:
- Cookies and tracking (Google Analytics, Facebook Pixel, retargeting)
- Newsletter and direct marketing (consent, unsubscribe link)
- Retention of order data (7 years for accounting obligations, but not marketing data)
- Multiple processors (e-commerce platform, payment, delivery, CRM, emailing)
- Customer reviews (legal basis, right to deletion)
Medical / paramedical practice
Main GDPR challenges:
- Health data = sensitive data (Article 9 GDPR): enhanced protection
- DPO potentially mandatory for large-scale processing
- Electronic medical records: enhanced security measures
- Transferring records between professionals: patient consent required
- Retention: 30 years for medical records in Belgium
Hospitality (Horeca)
Main GDPR challenges:
- CCTV: declaration to the police, signage, register
- Free Wi-Fi: retention of connection logs (1 year, telecom law)
- Online booking: limited retention, no marketing reuse without consent
- Loyalty programme: consent for profiling and personalised marketing
Liberal professions (lawyer, accountant, consultant)
Main GDPR challenges:
- Professional secrecy and GDPR: reconciling both obligations
- Possible sensitive data (legal files, financial data)
- Transferring files between professionals
- Secure archiving (professional-body and legal obligations)
GDPR compliance checklist for SMEs
Use this GDPR compliance checklist as a final check before you consider the job done.
- Register of data processing activities drafted and up to date
- Privacy policy published on the website
- Compliant cookie banner (no pre-ticked boxes, easy refusal)
- Compliant contact and sign-up forms (information notice, consent)
- Processor contracts (DPAs) signed with all processors
- Technical security measures in place (passwords, 2FA, encryption, backups)
- Procedure for exercising data subjects' rights documented
- Data breach procedure documented
- Employee training/awareness carried out
- DPO appointed or reference person identified
- Retention periods defined for each processing activity
- Transfers outside the EU identified and governed (SCCs or Data Privacy Framework)
Conclusion
GDPR compliance is not a one-off project but an ongoing process. For a Belgian SME, initial compliance represents an investment of a few thousand euros and a few weeks of work, but it protects you against sanctions that can reach hundreds of thousands of euros, not to mention reputational damage. Start with the basics: the register of processing activities, the privacy policy and cookies. Then gradually improve your compliance level. The Belgian APD takes an educational approach towards SMEs acting in good faith that make efforts to comply, but it does not hesitate to sanction companies that completely ignore their obligations.


