#
Full GDPR-aligned statutory framework in force with an operational, active supervisory authority; only narrow public-sector carve-outs from administrative fines.
Sub-modules (5)
Regulator And AuthorityGreen
The APD-GBA is the sole Belgian supervisory authority for GDPR matters, headquartered in Brussels.
Claims (1):
- The Belgian Data Protection Authority (APD-GBA), based in Brussels, is the national supervisory authority responsible for GDPR enforcement in Belgium.
Act And InstrumentsGreen
The GDPR is implemented domestically via two founding Acts: the 2017 Act creating the DPA and the 2018 Act on personal data protection.
Claims (1):
- Belgium implemented the GDPR through the Act of 30 July 2018 on the Protection of Natural Persons with Regard to the Processing of Personal Data, together with the Act of 3 December 2017 Establishing the Data Protection Authority.
Material ScopeAmber
The Act applies broadly to private and public controllers/processors, with a narrow carve-out excluding most public authorities from GDPR Article 83 administrative fines.
Claims (1):
- The Belgian Data Protection Act applies to both private and public controllers and processors, except that public authorities (other than public-law legal persons offering goods or services on a market) are excluded from GDPR Article 83 administrative fines.
Territorial ScopeGreen
The Act mirrors GDPR establishment-based territorial scope, applying regardless of where the actual processing occurs.
Claims (1):
- The Belgian Data Protection Act applies to processing carried out in the context of the activities of an establishment of a controller or processor on Belgian territory, regardless of whether the processing itself takes place in Belgium.
Regulator Registration And FilingAmber
Belgium has no general controller-registration regime (abolished under GDPR); the principal filing obligation is communication of DPO contact details to the Belgian DPA.
Claims (1):
- Controllers and processors appointing a DPO under GDPR Article 37 must publish the DPO's contact details and communicate them to the Belgian DPA, constituting the principal filing obligation under the Belgian regime.
Key findings (11)
- Belgian DPA and dual founding Acts (2017/2018) confirmed in force; narrow public-authority carve-out from Article 83 fines. — source on file
- Belgian DPA and dual founding Acts (2017/2018) confirmed in force; narrow public-authority carve-out from Article 83 fines. — source on file
- Belgian DPA and dual founding Acts (2017/2018) confirmed in force; narrow public-authority carve-out from Article 83 fines. — source on file
- Belgian DPA and dual founding Acts (2017/2018) confirmed in force; narrow public-authority carve-out from Article 83 fines. — source on file
- Belgian DPA and dual founding Acts (2017/2018) confirmed in force; narrow public-authority carve-out from Article 83 fines. — source on file
- Belgian DPA and dual founding Acts (2017/2018) confirmed in force; narrow public-authority carve-out from Article 83 fines. — source on file
- Belgian DPA and dual founding Acts (2017/2018) confirmed in force; narrow public-authority carve-out from Article 83 fines. — source on file
- Belgian DPA and dual founding Acts (2017/2018) confirmed in force; narrow public-authority carve-out from Article 83 fines. — source on file
- Belgian DPA and dual founding Acts (2017/2018) confirmed in force; narrow public-authority carve-out from Article 83 fines. — source on file
- Belgian DPA and dual founding Acts (2017/2018) confirmed in force; narrow public-authority carve-out from Article 83 fines. — source on file
- Belgian DPA and dual founding Acts (2017/2018) confirmed in force; narrow public-authority carve-out from Article 83 fines. — source on file
Regulator & Framework
The Belgian Data Protection Authority, the APD/GBA, is organised around an Executive Committee plus five operational bodies, including the Litigation Chamber and the Knowledge Centre. Its statutory basis rests on the Law of 30 July 2018 implementing the GDPR domestically and the Law of 3 December 2017 establishing the DPA itself -- a stable, standing legislative baseline that was not disturbed this cycle. Registration activity continues at a steady pace: as at 31 December 2025, the APD/GBA reports 1,161 DPO notifications received and 8,533 organisations with an active registered Data Protection Officer, figures that reflect ongoing compliance engagement across the regulated population rather than a new development in themselves.
The material development this cycle is institutional rather than legislative: the APD/GBA has adopted a 2026-2028 Strategic Plan that reorients the regulator's operating posture from individual complaint-handling toward proactive, sector-targeted audits described internally as Systemic Impact Enforcement, with healthcare, finance and minors' data processing named as priority areas. This is a confirmed structural shift in regulatory strategy, though it is a plan rather than a binding instrument, and its practical effect will depend on how the named priority audits are actually conducted and resourced over the plan's multi-year horizon.
Outlook
The Strategic Plan's translation into concrete audit activity in the named priority sectors is the central item to watch over the coming cycles. Whether the DPA's institutional structure or resourcing changes to support the shift toward proactive Systemic Impact Enforcement, as distinct from reactive complaint-handling, will be a useful marker of how seriously the plan is being operationalised.
1 earlier distinct update(s)
Regulator & Framework
The APD/GBA is organised into five operational bodies plus an Executive Committee, including a Litigation Chamber, known formally as the Chambre Contentieuse, and an Inspection Service. This organisational structure underpins the regulator's dual capacity to investigate and to adjudicate. The most significant development this cycle concerns the regulator's own stated direction rather than a fresh case: the APD's 2026-2028 Strategic Plan is understood to shift enforcement focus away from individual complaint-handling and toward proactive, large-scale Systemic Impact Enforcement, concentrating audits in healthcare, finance, and the processing of minors' data.
This represents a probable, materially significant reorientation of how the regulator allocates its resources. Rather than responding primarily to complaints as they arrive, the APD would initiate its own systemic audits in prioritised sectors. Separately, the Litigation Chamber has previously addressed its own competence under GDPR Article 3 over complaints filed against defendants located outside the European Economic Area, in Decision 13/2024, a confirmed and in-force precedent establishing the territorial reach of the regulator's jurisdiction.
Outlook
The practical test of the Strategic Plan's proactive enforcement shift will be whether the APD produces concrete Systemic Impact Enforcement audit outputs in its named priority sectors within the plan's 2026-2028 window. Confirmation of a first such audit, particularly in healthcare or finance, would be the clearest signal that the shift from complaint-driven to proactive enforcement is materialising in practice rather than remaining a stated policy direction.
Sources and claims (5)
- ConfirmedEDPB — The Belgian Data Protection Authority (APD-GBA), based in Brussels, is the national supervisory authority responsible for GDPR enforcement in Belgium.observed
- ConfirmedDataGuidance — Belgium implemented the GDPR through the Act of 30 July 2018 on the Protection of Natural Persons with Regard to the Processing of Personal Data, together with the Act of 3 December 2017 Establishing the Data Protection Authority.observed
- ConfirmedDataGuidance — The Belgian Data Protection Act applies to both private and public controllers and processors, except that public authorities (other than public-law legal persons offering goods or services on a market) are excluded from GDPR Article 83 administrative fines.observed
- ConfirmedDataGuidance — The Belgian Data Protection Act applies to processing carried out in the context of the activities of an establishment of a controller or processor on Belgian territory, regardless of whether the processing itself takes place in Belgium.observed
- ConfirmedDataGuidance — Controllers and processors appointing a DPO under GDPR Article 37 must publish the DPO's contact details and communicate them to the Belgian DPA, constituting the principal filing obligation under the Belgian regime.observed