🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
BE v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing21 sources retrieved model claude-sonnet-5 · 2026-08-03

Belgium

BE schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: AIC

Last updated · 10 categories · 37 claims · 34 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
37Claimsbaseline..claims[]
9Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 17 sub-modules are flagged red.

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

The Belgian Data Protection Authority (APD/GBA) has adopted a 2026-2028 Strategic Plan that reorients its enforcement posture from individual complaint-handling toward proactive, sector-targeted audits -- described as Systemic Impact Enforcement -- concentrated on healthcare, finance and minors' data processing. This structural shift arrives alongside a materially rising complaint caseload, with 1,394 complaints received in 2025 compared to 837 in 2024, and against a backdrop of a notably high annulment rate on appeals to the Brussels Market Court: 13 of 25 rulings in 2025 either wholly or partially annulled a Litigation Chamber decision. Read together, these three data points describe a regulator entering a more assertive enforcement phase even as its existing enforcement output faces meaningful appellate friction.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Full GDPR-aligned statutory framework in force with an operational, active supervisory authority; only narrow public-sector carve-outs from administrative fines.

Primary frameworkGeneral Data Protection Regulation (EU) 2016/679, as implemented by the Belgian Act of 30 July 2018 on the Protection of Natural Persons with Regard to the Processing of Personal Data and the Act of 3 December 2017 Establishing the Data Protection Authority
Traffic-light rationale — GreenFull GDPR-aligned statutory framework in force with an operational, active supervisory authority; only narrow public-sector carve-outs from administrative fines.

Sub-modules (5)

Regulator And AuthorityGreen

The APD-GBA is the sole Belgian supervisory authority for GDPR matters, headquartered in Brussels.

Claims (1):

  • The Belgian Data Protection Authority (APD-GBA), based in Brussels, is the national supervisory authority responsible for GDPR enforcement in Belgium.

Act And InstrumentsGreen

The GDPR is implemented domestically via two founding Acts: the 2017 Act creating the DPA and the 2018 Act on personal data protection.

Claims (1):

  • Belgium implemented the GDPR through the Act of 30 July 2018 on the Protection of Natural Persons with Regard to the Processing of Personal Data, together with the Act of 3 December 2017 Establishing the Data Protection Authority.

Material ScopeAmber

The Act applies broadly to private and public controllers/processors, with a narrow carve-out excluding most public authorities from GDPR Article 83 administrative fines.

Claims (1):

  • The Belgian Data Protection Act applies to both private and public controllers and processors, except that public authorities (other than public-law legal persons offering goods or services on a market) are excluded from GDPR Article 83 administrative fines.

Territorial ScopeGreen

The Act mirrors GDPR establishment-based territorial scope, applying regardless of where the actual processing occurs.

Claims (1):

  • The Belgian Data Protection Act applies to processing carried out in the context of the activities of an establishment of a controller or processor on Belgian territory, regardless of whether the processing itself takes place in Belgium.

Regulator Registration And FilingAmber

Belgium has no general controller-registration regime (abolished under GDPR); the principal filing obligation is communication of DPO contact details to the Belgian DPA.

Claims (1):

  • Controllers and processors appointing a DPO under GDPR Article 37 must publish the DPO's contact details and communicate them to the Belgian DPA, constituting the principal filing obligation under the Belgian regime.

Key findings (11)

  • Belgian DPA and dual founding Acts (2017/2018) confirmed in force; narrow public-authority carve-out from Article 83 fines. — source on file
  • Belgian DPA and dual founding Acts (2017/2018) confirmed in force; narrow public-authority carve-out from Article 83 fines. — source on file
  • Belgian DPA and dual founding Acts (2017/2018) confirmed in force; narrow public-authority carve-out from Article 83 fines. — source on file
  • Belgian DPA and dual founding Acts (2017/2018) confirmed in force; narrow public-authority carve-out from Article 83 fines. — source on file
  • Belgian DPA and dual founding Acts (2017/2018) confirmed in force; narrow public-authority carve-out from Article 83 fines. — source on file
  • Belgian DPA and dual founding Acts (2017/2018) confirmed in force; narrow public-authority carve-out from Article 83 fines. — source on file
  • Belgian DPA and dual founding Acts (2017/2018) confirmed in force; narrow public-authority carve-out from Article 83 fines. — source on file
  • Belgian DPA and dual founding Acts (2017/2018) confirmed in force; narrow public-authority carve-out from Article 83 fines. — source on file
  • Belgian DPA and dual founding Acts (2017/2018) confirmed in force; narrow public-authority carve-out from Article 83 fines. — source on file
  • Belgian DPA and dual founding Acts (2017/2018) confirmed in force; narrow public-authority carve-out from Article 83 fines. — source on file
  • Belgian DPA and dual founding Acts (2017/2018) confirmed in force; narrow public-authority carve-out from Article 83 fines. — source on file
Category narrative83 words

Belgium is an EU Member State operating under the GDPR (Regulation (EU) 2016/679) as the omnibus instrument, implemented domestically through the Act of 3 December 2017 Establishing the Data Protection Authority and the Act of 30 July 2018 on the Protection of Natural Persons with Regard to the Processing of Personal Data. The Belgian Data Protection Authority (APD-GBA) is the single national supervisory authority, based in Brussels, with a Litigation Chamber acting as its administrative enforcement/sanctioning body and an Inspection Service handling investigations.

Periodic update · new data 2026-09-28

Regulator & Framework

The Belgian Data Protection Authority, the APD/GBA, is organised around an Executive Committee plus five operational bodies, including the Litigation Chamber and the Knowledge Centre. Its statutory basis rests on the Law of 30 July 2018 implementing the GDPR domestically and the Law of 3 December 2017 establishing the DPA itself -- a stable, standing legislative baseline that was not disturbed this cycle. Registration activity continues at a steady pace: as at 31 December 2025, the APD/GBA reports 1,161 DPO notifications received and 8,533 organisations with an active registered Data Protection Officer, figures that reflect ongoing compliance engagement across the regulated population rather than a new development in themselves.

The material development this cycle is institutional rather than legislative: the APD/GBA has adopted a 2026-2028 Strategic Plan that reorients the regulator's operating posture from individual complaint-handling toward proactive, sector-targeted audits described internally as Systemic Impact Enforcement, with healthcare, finance and minors' data processing named as priority areas. This is a confirmed structural shift in regulatory strategy, though it is a plan rather than a binding instrument, and its practical effect will depend on how the named priority audits are actually conducted and resourced over the plan's multi-year horizon.

Outlook

The Strategic Plan's translation into concrete audit activity in the named priority sectors is the central item to watch over the coming cycles. Whether the DPA's institutional structure or resourcing changes to support the shift toward proactive Systemic Impact Enforcement, as distinct from reactive complaint-handling, will be a useful marker of how seriously the plan is being operationalised.

1 earlier distinct update(s)
Periodic update · new data 2026-09-14

Regulator & Framework

The APD/GBA is organised into five operational bodies plus an Executive Committee, including a Litigation Chamber, known formally as the Chambre Contentieuse, and an Inspection Service. This organisational structure underpins the regulator's dual capacity to investigate and to adjudicate. The most significant development this cycle concerns the regulator's own stated direction rather than a fresh case: the APD's 2026-2028 Strategic Plan is understood to shift enforcement focus away from individual complaint-handling and toward proactive, large-scale Systemic Impact Enforcement, concentrating audits in healthcare, finance, and the processing of minors' data.

This represents a probable, materially significant reorientation of how the regulator allocates its resources. Rather than responding primarily to complaints as they arrive, the APD would initiate its own systemic audits in prioritised sectors. Separately, the Litigation Chamber has previously addressed its own competence under GDPR Article 3 over complaints filed against defendants located outside the European Economic Area, in Decision 13/2024, a confirmed and in-force precedent establishing the territorial reach of the regulator's jurisdiction.

Outlook

The practical test of the Strategic Plan's proactive enforcement shift will be whether the APD produces concrete Systemic Impact Enforcement audit outputs in its named priority sectors within the plan's 2026-2028 window. Confirmation of a first such audit, particularly in healthcare or finance, would be the clearest signal that the shift from complaint-driven to proactive enforcement is materialising in practice rather than remaining a stated policy direction.

Sources and claims (5)
  1. ConfirmedEDPB — The Belgian Data Protection Authority (APD-GBA), based in Brussels, is the national supervisory authority responsible for GDPR enforcement in Belgium.observed
  2. ConfirmedDataGuidance — Belgium implemented the GDPR through the Act of 30 July 2018 on the Protection of Natural Persons with Regard to the Processing of Personal Data, together with the Act of 3 December 2017 Establishing the Data Protection Authority.observed
  3. ConfirmedDataGuidance — The Belgian Data Protection Act applies to both private and public controllers and processors, except that public authorities (other than public-law legal persons offering goods or services on a market) are excluded from GDPR Article 83 administrative fines.observed
  4. ConfirmedDataGuidance — The Belgian Data Protection Act applies to processing carried out in the context of the activities of an establishment of a controller or processor on Belgian territory, regardless of whether the processing itself takes place in Belgium.observed
  5. ConfirmedDataGuidance — Controllers and processors appointing a DPO under GDPR Article 37 must publish the DPO's contact details and communicate them to the Belgian DPA, constituting the principal filing obligation under the Belgian regime.observed

#

Core lawful-basis and special-category rules are GDPR-aligned and actively enforced by the Belgian DPA; pseudonymisation/anonymisation guidance is thin.

Primary frameworkGDPR Articles 6, 7 and 9, read with Belgian Act of 30 July 2018 and CBA-based employment-data rules
Traffic-light rationale — GreenCore lawful-basis and special-category rules are GDPR-aligned and actively enforced by the Belgian DPA; pseudonymisation/anonymisation guidance is thin.

Sub-modules (4)

Lawful BasesGreen

Employment-related processing may rely on the Article 6(1)(c) Member State legal-basis route, including via collective bargaining agreements.

Claims (1):

  • Employees' personal data may be processed on the Article 6(1)(c) GDPR Member State legal-basis route where necessary for establishing, implementing, or terminating an employment relationship, including under a collective bargaining agreement.

Special CategoriesGreen

Biometric and other special-category data require an explicit Article 9 legal basis; the Belgian DPA has actively enforced this against employers using fingerprint time-registration.

Claims (1):

  • The Belgian DPA fined a company €45,000 after finding it processed employees' fingerprints (special-category biometric data) for time-registration without articulating a valid Article 9 legal basis and in breach of purpose-limitation and minimisation principles.

Pseudonymisation And AnonymisationRed

No Belgium-specific pseudonymisation/anonymisation safe-harbour distinct from the GDPR Article 4(5)/Recital 26 baseline was identified.

Absence provenance: unavailable. Searched: Belgian DPA pseudonymisation anonymisation guidance, Belgium GDPR anonymisation safe harbour.

Key findings (11)

  • Biometric special-category enforcement (Decision 114/2024, corrected) and 'consent or pay' invalidity guidance. — source on file
  • Biometric special-category enforcement (Decision 114/2024, corrected) and 'consent or pay' invalidity guidance. — source on file
  • Biometric special-category enforcement (Decision 114/2024, corrected) and 'consent or pay' invalidity guidance. — source on file
  • Biometric special-category enforcement (Decision 114/2024, corrected) and 'consent or pay' invalidity guidance. — source on file
  • Biometric special-category enforcement (Decision 114/2024, corrected) and 'consent or pay' invalidity guidance. — source on file
  • Biometric special-category enforcement (Decision 114/2024, corrected) and 'consent or pay' invalidity guidance. — source on file
  • Biometric special-category enforcement (Decision 114/2024, corrected) and 'consent or pay' invalidity guidance. — source on file
  • Biometric special-category enforcement (Decision 114/2024, corrected) and 'consent or pay' invalidity guidance. — source on file
  • Biometric special-category enforcement (Decision 114/2024, corrected) and 'consent or pay' invalidity guidance. — source on file
  • Biometric special-category enforcement (Decision 114/2024, corrected) and 'consent or pay' invalidity guidance. — source on file
  • Biometric special-category enforcement (Decision 114/2024, corrected) and 'consent or pay' invalidity guidance. — source on file
Category narrative51 words

Belgium applies the GDPR Article 6 lawful bases and Article 9 special-category regime without a comprehensive derogating statute, though Article 88-based employment rules and Belgian DPA guidance (e.g., on direct marketing and biometric processing) supplement the baseline. Pseudonymisation/anonymisation is governed by the GDPR baseline definitions with no distinct Belgian safe-harbour identified.

Periodic update · new data 2026-09-28

Lawful Processing & Special Data

The APD/GBA is understood to apply an exceptionally strict reading of Article 6 GDPR, requiring controllers to clearly choose, document and evidence application of their chosen lawful basis for processing. This supervisory-interpretation posture is reported at a Probable confidence level, resting on a single lower-tier source, and should be read as an indication of the regulator's general orientation rather than a confirmed, citable standard.

The concrete, confirmed development this cycle sits in the consent space: the APD/GBA published Recommendation 01/2026 on direct marketing, which replaces and supersedes the regulator's February 2020 recommendation on the same subject. The new recommendation clarifies the conditions for valid consent, the circumstances requiring consent renewal, and how profiling and automated decision-making should be treated when used in a direct-marketing context. This is a binding guidance instrument, in force from early 2026, and represents the DPA's most concrete lawful-processing-adjacent output this cycle.

Outlook

The practical application of Recommendation 01/2026 -- particularly how the DPA treats consent-renewal timing and profiling-related marketing practices in any subsequent enforcement activity -- is the item to watch. Whether the reported strict-reading posture toward Article 6 generally is corroborated by a primary-source APD/GBA statement in a future cycle would also strengthen that finding's confidence tier.

Sources and claims (3)
  1. ConfirmedDataGuidance — Employees' personal data may be processed on the Article 6(1)(c) GDPR Member State legal-basis route where necessary for establishing, implementing, or terminating an employment relationship, including under a collective bargaining agreement.observed
  2. ConfirmedDataGuidance — The Belgian DPA's direct marketing guidelines require that consent be free, specific, informed, and unambiguous, and state that 'consent or pay' models are generally invalid.observed
  3. ConfirmedDataGuidance — The Belgian DPA fined a company €45,000 after finding it processed employees' fingerprints (special-category biometric data) for time-registration without articulating a valid Article 9 legal basis and in breach of purpose-limitation and minimisation principles.observed

#

Rights framework is GDPR-aligned and enforced through repeated Belgian DPA decisions; portability enforcement activity specifically is thin.

Primary frameworkGDPR Articles 12-22 as applied in Belgium
Traffic-light rationale — GreenRights framework is GDPR-aligned and enforced through repeated Belgian DPA decisions; portability enforcement activity specifically is thin.

Sub-modules (5)

Access RightGreen

The Belgian DPA is particularly active in issuing enforcement decisions concerning responses to data subject access requests.

Claims (1):

  • In Decision No. 86/2026, the Belgian DPA fined an employer €8,500 after it kept a former employee's professional mailbox active and failed to respond to the employee's erasure request.

Rectification And ErasureGreen

Failure to action erasure requests has been the subject of Belgian DPA fines, including the 2026 Y.NV decision.

Claims (1):

  • In Decision No. 86/2026, the Belgian DPA fined an employer €8,500 after it kept a former employee's professional mailbox active and failed to respond to the employee's erasure request.

Restriction And ObjectionGreen

The Belgian DPA has fined controllers for failing to honour objection requests to direct-marketing processing.

Claims (1):

  • The Belgian DPA fined a controller €1,000 for not responding to a data subject's request to object to processing of his data for marketing purposes and for failing to cooperate with the authority's injunction.

Data PortabilityRed

No Belgium-specific portability enforcement decision or derogating guidance was located beyond the GDPR Article 20 baseline.

Absence provenance: unavailable. Searched: Belgian DPA data portability decision, Belgium GDPR Article 20 guidance.

Deadlines And Response WindowsGreen

The standard one-month response deadline under GDPR Article 12(3)/(4) applies in Belgium without a shortened or extended national variant identified.

Claims (1):

  • Where a controller does not act on a data subject's rights request, it must inform the data subject without delay and at the latest within one month of receipt, of the reasons for not taking action and of the possibility of lodging a complaint with a supervisory authority or seeking a judicial remedy.

Key findings (11)

  • Y.NV erasure-failure fine and standard one-month response-window baseline; one objection-fine detail escalated. — source on file
  • Y.NV erasure-failure fine and standard one-month response-window baseline; one objection-fine detail escalated. — source on file
  • Y.NV erasure-failure fine and standard one-month response-window baseline; one objection-fine detail escalated. — source on file
  • Y.NV erasure-failure fine and standard one-month response-window baseline; one objection-fine detail escalated. — source on file
  • Y.NV erasure-failure fine and standard one-month response-window baseline; one objection-fine detail escalated. — source on file
  • Y.NV erasure-failure fine and standard one-month response-window baseline; one objection-fine detail escalated. — source on file
  • Y.NV erasure-failure fine and standard one-month response-window baseline; one objection-fine detail escalated. — source on file
  • Y.NV erasure-failure fine and standard one-month response-window baseline; one objection-fine detail escalated. — source on file
  • Y.NV erasure-failure fine and standard one-month response-window baseline; one objection-fine detail escalated. — source on file
  • Y.NV erasure-failure fine and standard one-month response-window baseline; one objection-fine detail escalated. — source on file
  • Y.NV erasure-failure fine and standard one-month response-window baseline; one objection-fine detail escalated. — source on file
Category narrative33 words

Belgium follows the GDPR data-subject-rights catalogue (access, rectification/erasure, restriction/objection, portability) with the standard one-month response deadline. The Belgian DPA is particularly active in enforcement concerning access requests, erasure failures, and objection to marketing.

Periodic update · new data 2026-09-28

Data Subject Rights

Data subject rights activity in Belgium rose materially in 2025. The APD/GBA reports 1,394 complaints received in 2025, up sharply from 837 in 2024 -- an increase of well over half in a single year. Information requests, by contrast, held roughly steady: 3,034 in 2025 compared to 3,051 in 2024, essentially flat year over year. This divergence between rapidly rising complaints and stable information-request volume suggests the increase in subject-rights activity is concentrated in adversarial or dispute-oriented engagement with the regulator rather than in general information-seeking, though the underlying drivers of the complaint increase were not further specified this cycle.

This rising complaint volume arrives in the same cycle as the APD/GBA's adoption of its 2026-2028 Strategic Plan reorienting toward proactive enforcement, creating a combined picture of a regulator facing increased reactive demand from data subjects at the same time it is attempting to shift resources toward proactive sector audits. How the DPA balances these two pressures -- a rising complaint caseload and a strategic pivot toward proactive audit work -- is not resolved by the evidence available this cycle.

Outlook

Whether the 2025 complaint increase continues, stabilises, or reverses in the coming cycle is the key data point to watch, as is whether the DPA's response-time performance on individual complaints changes as it reallocates resources toward the Strategic Plan's proactive audit priorities.

Sources and claims (3)
  1. ConfirmedEUR-Lex — Where a controller does not act on a data subject's rights request, it must inform the data subject without delay and at the latest within one month of receipt, of the reasons for not taking action and of the possibility of lodging a complaint with a supervisory authority or seeking a judicial remedy.observed
  2. ConfirmedEDPB / Belgian DPA — The Belgian DPA fined a controller €1,000 for not responding to a data subject's request to object to processing of his data for marketing purposes and for failing to cooperate with the authority's injunction.observed
  3. ConfirmedDataGuidance — In Decision No. 86/2026, the Belgian DPA fined an employer €8,500 after it kept a former employee's professional mailbox active and failed to respond to the employee's erasure request.observed

#

All core controller/processor duties are GDPR-aligned, actively guided by Belgian DPA published lists, and enforced through repeated fines; joint-controller arrangements lack Belgium-specific findings.

Primary frameworkGDPR Articles 24-39 as applied and supplemented by Belgian DPA guidance
Traffic-light rationale — GreenAll core controller/processor duties are GDPR-aligned, actively guided by Belgian DPA published lists, and enforced through repeated fines; joint-controller arrangements lack Belgium-specific findings.

Sub-modules (7)

Accountability And DpiaGreen

The Belgian DPA publishes a binding list of processing operations requiring a DPIA, covering biometric identification and large-scale health/behavioural data processing.

Claims (1):

  • The Belgian DPA maintains a published list of processing operations requiring a DPIA, including biometric data collected to uniquely identify data subjects in a public space or a private but publicly accessible area.

Dpo RequirementsGreen

Article 37 DPO designation, publication, and DPA-notification duties apply; the Belgian DPA issues guidance in Dutch, French and German.

Claims (1):

  • Controllers and processors meeting the GDPR Article 37 designation criteria must appoint a DPO, publish the DPO's contact details, and communicate those details to the Belgian DPA.

Ropa RequirementsGreen

The Belgian DPA has found and sanctioned Article 30(1) ROPA deficiencies in enforcement decisions.

Claims (1):

  • The Belgian DPA found a company in breach of Article 30(1)(a)-(d) GDPR for failing to maintain adequate records of processing activities relating to biometric time-registration data.

Joint Controller ArrangementsRed

No Belgium-specific joint-controller enforcement or guidance distinct from the GDPR Article 26 baseline was located.

Absence provenance: unavailable. Searched: Belgian DPA joint controller decision, Belgium Article 26 GDPR guidance.

Security MeasuresGreen

The Belgian DPA enforces Article 32 security-of-processing and data-protection-by-design obligations, including against video-surveillance system design flaws.

Claims (1):

  • The Belgian DPA fined a controller €1,500 for unlawful processing via a video-surveillance system, finding that camera positioning also infringed the data-protection-by-design principle.

Breach NotificationGreen

The standard GDPR Article 33/34 72-hour breach-notification regime applies without Belgian derogation.

Claims (1):

  • In the case of a personal data breach, controllers must notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to individuals' rights and freedoms.

Retention And DisposalGreen

The Belgian DPA actively enforces storage-limitation principles, ordering retention-period reductions where excessive.

Claims (1):

  • The Belgian DPA ordered Freedelity to ensure personal data retention does not exceed three years, having found its prior retention period excessive and in breach of the storage-limitation principle.

Key findings (11)

  • DPIA list, DPO duties, Freedelity retention order, video-surveillance security fine; ROPA claim corrected to DPIA-failure finding. — source on file
  • DPIA list, DPO duties, Freedelity retention order, video-surveillance security fine; ROPA claim corrected to DPIA-failure finding. — source on file
  • DPIA list, DPO duties, Freedelity retention order, video-surveillance security fine; ROPA claim corrected to DPIA-failure finding. — source on file
  • DPIA list, DPO duties, Freedelity retention order, video-surveillance security fine; ROPA claim corrected to DPIA-failure finding. — source on file
  • DPIA list, DPO duties, Freedelity retention order, video-surveillance security fine; ROPA claim corrected to DPIA-failure finding. — source on file
  • DPIA list, DPO duties, Freedelity retention order, video-surveillance security fine; ROPA claim corrected to DPIA-failure finding. — source on file
  • DPIA list, DPO duties, Freedelity retention order, video-surveillance security fine; ROPA claim corrected to DPIA-failure finding. — source on file
  • DPIA list, DPO duties, Freedelity retention order, video-surveillance security fine; ROPA claim corrected to DPIA-failure finding. — source on file
  • DPIA list, DPO duties, Freedelity retention order, video-surveillance security fine; ROPA claim corrected to DPIA-failure finding. — source on file
  • DPIA list, DPO duties, Freedelity retention order, video-surveillance security fine; ROPA claim corrected to DPIA-failure finding. — source on file
  • DPIA list, DPO duties, Freedelity retention order, video-surveillance security fine; ROPA claim corrected to DPIA-failure finding. — source on file
Category narrative46 words

Belgian controllers/processors are subject to the full GDPR accountability toolkit: DPIA (with a Belgian DPA-published mandatory-DPIA list), DPO appointment and registration, ROPA, breach notification within 72 hours, security-of-processing obligations, and storage-limitation/retention duties. Joint-controller arrangements follow the GDPR Article 26 baseline with no distinct Belgian overlay identified.

Periodic update · new data 2026-09-28

Controller/Processor Duties

Belgium's controller and processor accountability expectations are tightening this cycle, driven primarily by the APD/GBA's 2026-2028 Strategic Plan, which shifts the regulator's posture from individual complaint response toward proactive, sector-targeted Systemic Impact Enforcement audits in healthcare, finance and minors' data processing. This is a confirmed strategic reorientation, though it remains a plan rather than a binding legal instrument, and its accountability implications for controllers will depend on how the named audits are actually scoped and conducted.

Notably, this tightening in stated regulatory ambition coincides with a decline in reported breach-notification volume: the APD/GBA received 1,216 data breach notifications in 2025, down from 1,455 in 2024. This is a genuine divergence worth stating plainly rather than smoothing over: rising proactive-enforcement ambition and falling breach-notification volume are not contradictory on their face, but they do mean that any assessment of Belgium's controller-duty compliance environment cannot rely on breach-notification trends alone as a proxy for overall accountability performance.

Outlook

The key items to watch are whether the Strategic Plan's proactive audits surface accountability or DPIA-adequacy gaps that breach-notification data alone would not have revealed, and whether the declining breach-notification trend continues or reverses as the DPA's supervisory attention increases under the new plan.

1 earlier distinct update(s)
Periodic update · new data 2026-09-14

Controller/Processor Duties

The Belgian Market Court has confirmed that IAB Europe acts as joint data controller for the processing of user preferences via the TC String within its Transparency and Consent Framework. This confirmed, in-force ruling settles a question central to how consent-management infrastructure providers are characterised under Belgian and EU data protection law: an entity that operates the technical mechanism for recording and transmitting consent signals can itself be held to be a joint controller of the personal data processed through that mechanism, alongside the businesses that rely on it.

This controller characterisation compounds the APD's broader strategic direction toward demonstrable accountability. The APD's 2026-2028 Strategic Plan is understood to demand demonstrable accountability logs from controllers and processors as part of its proactive Systemic Impact Enforcement approach, meaning organisations relying on shared consent-management infrastructure of the kind at issue in the IAB Europe proceedings should expect scrutiny of how joint-controller responsibilities are documented and evidenced, not merely asserted.

Outlook

The joint-controller finding's practical consequences will become clearer once the APD completes its required re-validation of IAB Europe's corrective action plan following the Market Court's annulment of the prior validation. Organisations using the Transparency and Consent Framework, or comparable shared consent-management infrastructure, should watch for how the re-validated plan allocates joint-controller obligations in practice.

Sources and claims (6)
  1. ConfirmedDataGuidance — The Belgian DPA maintains a published list of processing operations requiring a DPIA, including biometric data collected to uniquely identify data subjects in a public space or a private but publicly accessible area.observed
  2. ConfirmedDataGuidance — Controllers and processors meeting the GDPR Article 37 designation criteria must appoint a DPO, publish the DPO's contact details, and communicate those details to the Belgian DPA.observed
  3. ConfirmedDataGuidance — The Belgian DPA found a company in breach of Article 30(1)(a)-(d) GDPR for failing to maintain adequate records of processing activities relating to biometric time-registration data.observed
  4. ConfirmedEUR-Lex — In the case of a personal data breach, controllers must notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to individuals' rights and freedoms.observed
  5. ConfirmedEDPB / Belgian DPA — The Belgian DPA fined a controller €1,500 for unlawful processing via a video-surveillance system, finding that camera positioning also infringed the data-protection-by-design principle.observed
  6. ConfirmedDataGuidance — The Belgian DPA ordered Freedelity to ensure personal data retention does not exceed three years, having found its prior retention period excessive and in breach of the storage-limitation principle.observed

#

Transfer mechanisms are fully operative and actively used (BCR lead-authority role, Schrems II guidance); adequacy grant/receipt is not a Member-State-level competence.

Primary frameworkGDPR Chapter V (Articles 44-49)
Traffic-light rationale — GreenTransfer mechanisms are fully operative and actively used (BCR lead-authority role, Schrems II guidance); adequacy grant/receipt is not a Member-State-level competence.

Sub-modules (6)

Transfer MechanismsGreen

Adequacy decisions, SCCs, BCRs and Article 49 derogations are available under the GDPR baseline as applied in Belgium.

Claims (1):

  • Under GDPR Chapter V as applied in Belgium, transfers to third countries may take place on the basis of a European Commission adequacy decision or, absent one, on appropriate safeguards providing enforceable rights and effective legal remedies for data subjects.

Adequacy ReceivedAmber

Adequacy decisions are adopted by the European Commission on behalf of the EU/EEA as a bloc; this is not a Belgium-specific competence.

Absence provenance: unavailable. Searched: Belgium adequacy decision received, Belgium GDPR Article 45 adequacy.

Adequacy GrantedAmber

Belgium does not independently grant adequacy; this is exercised at EU Commission level.

Absence provenance: unavailable. Searched: Belgium adequacy decision granted third country.

Sccs And BcrsGreen

The Belgian DPA acts as lead supervisory authority for Belgian-headquartered groups' Binding Corporate Rules submissions to the EDPB.

Claims (1):

  • The Belgian DPA, acting as lead supervisory authority, has submitted draft Binding Corporate Rules decisions for EDPB Article 64 opinion, including for Oregon Tool, Inc. (formerly Blount).

Transfer Impact AssessmentGreen

Following Schrems II, the Belgian DPA issued guidance on the need for supplementary-measures assessments for third-country transfers.

Claims (1):

  • Following the Schrems II judgment, the Belgian DPA published a statement on 31 August 2020 noting consequences for controllers and processors transferring personal data to third countries.

Data LocalisationRed

No Belgium-specific data-localisation mandate beyond the GDPR Chapter V baseline was identified.

Absence provenance: unavailable. Searched: Belgium data localisation law, Belgium data residency requirement personal data.

Key findings (11)

  • BCR lead-authority role and post-Schrems II transfer-impact guidance; adequacy correctly scoped to EU Commission. — source on file
  • BCR lead-authority role and post-Schrems II transfer-impact guidance; adequacy correctly scoped to EU Commission. — source on file
  • BCR lead-authority role and post-Schrems II transfer-impact guidance; adequacy correctly scoped to EU Commission. — source on file
  • BCR lead-authority role and post-Schrems II transfer-impact guidance; adequacy correctly scoped to EU Commission. — source on file
  • BCR lead-authority role and post-Schrems II transfer-impact guidance; adequacy correctly scoped to EU Commission. — source on file
  • BCR lead-authority role and post-Schrems II transfer-impact guidance; adequacy correctly scoped to EU Commission. — source on file
  • BCR lead-authority role and post-Schrems II transfer-impact guidance; adequacy correctly scoped to EU Commission. — source on file
  • BCR lead-authority role and post-Schrems II transfer-impact guidance; adequacy correctly scoped to EU Commission. — source on file
  • BCR lead-authority role and post-Schrems II transfer-impact guidance; adequacy correctly scoped to EU Commission. — source on file
  • BCR lead-authority role and post-Schrems II transfer-impact guidance; adequacy correctly scoped to EU Commission. — source on file
  • BCR lead-authority role and post-Schrems II transfer-impact guidance; adequacy correctly scoped to EU Commission. — source on file
Category narrative64 words

As an EU Member State, Belgium relies on the EU-level GDPR Chapter V transfer regime: European Commission adequacy decisions, SCCs, BCRs, and Article 49 derogations. Adequacy decisions are granted/received at EU Commission level, not by Belgium individually, and Belgium has no additional data-localisation mandate beyond GDPR baseline. The Belgian DPA has acted as lead authority in BCR approvals and issued post-Schrems II transfer guidance.

Periodic update · new data 2026-09-14

Cross-Border & Adequacy

The Belgian Market Court referred thirteen preliminary questions to the Court of Justice of the European Union concerning the material scope of GDPR Article 96 and the framework governing third-country transfers, following the APD Litigation Chamber's Decision 79/2025 finding that FPS Finance's FATCA-related transfers of personal data to the United States were unlawful. This is a confirmed, in-force development of high materiality: it places directly before the CJEU the question of how the GDPR's transfer framework interacts with pre-existing international agreements concluded before the Regulation's entry into force, of which FATCA, the US Foreign Account Tax Compliance Act cooperation framework, is a prominent example.

The stakes of this referral extend well beyond the specific FATCA context. A CJEU ruling clarifying Article 96's scope would have implications for any pre-GDPR international agreement involving cross-border transfers of personal data from Belgium, and by extension from other member states facing comparable disputes, to third countries. Until the CJEU rules, the practical transfer framework for FATCA-related and comparable pre-GDPR-agreement transfers from Belgium remains unsettled.

Outlook

The CJEU's ruling on the Market Court's thirteen preliminary questions is the central item to watch in this domain, though it is not expected imminently given the scale and complexity of the referral. In the interim, entities relying on pre-GDPR international agreements for cross-border transfers from Belgium should treat the underlying legal basis as contested rather than settled.

Sources and claims (3)
  1. ConfirmedEDPB — Under GDPR Chapter V as applied in Belgium, transfers to third countries may take place on the basis of a European Commission adequacy decision or, absent one, on appropriate safeguards providing enforceable rights and effective legal remedies for data subjects.observed
  2. ConfirmedEDPB — The Belgian DPA, acting as lead supervisory authority, has submitted draft Binding Corporate Rules decisions for EDPB Article 64 opinion, including for Oregon Tool, Inc. (formerly Blount).observed
  3. ConfirmedDataGuidance — Following the Schrems II judgment, the Belgian DPA published a statement on 31 August 2020 noting consequences for controllers and processors transferring personal data to third countries.observed

#

Strong, sourced coverage of telecoms and employment overlays; other sectors carry an evidentiary gap requiring escalation.

Primary frameworkGDPR plus Belgian Electronic Communications Act (LCE) and CBA No. 81
Traffic-light rationale — AmberStrong, sourced coverage of telecoms and employment overlays; other sectors carry an evidentiary gap requiring escalation.

Sub-modules (7)

Financial Sector OverlayRed

No Belgium-specific financial-sector (FSMA/NBB) data-protection overlay distinct from the GDPR baseline was substantiated.

Absence provenance: unavailable. Searched: Belgium FSMA data protection banking secrecy GDPR, Belgium NBB personal data financial sector.

Health Sector OverlayRed

No Belgium-specific health-sector data-protection overlay distinct from GDPR Article 9 baseline was substantiated.

Absence provenance: unavailable. Searched: Belgium health data law patient rights GDPR, Belgium eHealth platform data protection.

Telecoms And EprivacyGreen

The Belgian DPA jointly enforces GDPR and the Belgian Electronic Communications Act (LCE) against telecoms-adjacent processing such as call recording.

Claims (1):

  • The Belgian DPA fined water utility SWDE €86,000 (Decision No. 102/2026) for violations of the GDPR and the Belgian Electronic Communications Act (LCE) relating to systematic call recording without valid consent and inadequate transparency to callers and employees.

Employment DataGreen

Employer monitoring of employee e-communications is governed by CBA No. 81 alongside GDPR, with Belgian DPA guidance on finality, transparency and proportionality.

Claims (1):

  • Belgian employers' access to employees' professional e-communications is governed by Collective Bargaining Agreement (CBA) No. 81, which the Belgian DPA has interpreted as requiring compliance with finality, transparency, and proportionality principles rather than reliance on individual employee consent.

Credit And ScoringRed

No Belgium-specific credit-scoring overlay was substantiated in this pass.

Absence provenance: unavailable. Searched: Belgium credit scoring data protection law.

EducationRed

No Belgium-specific education-sector overlay was substantiated in this pass.

Absence provenance: unavailable. Searched: Belgium education sector student data protection law.

InsuranceRed

No Belgium-specific insurance-sector overlay was substantiated in this pass.

Absence provenance: unavailable. Searched: Belgium insurance sector data protection law.

Key findings (11)

  • SWDE telecoms/eprivacy fine and CBA No. 81 employment overlay; financial/health/credit/education/insurance overlays unresearched. — source on file
  • SWDE telecoms/eprivacy fine and CBA No. 81 employment overlay; financial/health/credit/education/insurance overlays unresearched. — source on file
  • SWDE telecoms/eprivacy fine and CBA No. 81 employment overlay; financial/health/credit/education/insurance overlays unresearched. — source on file
  • SWDE telecoms/eprivacy fine and CBA No. 81 employment overlay; financial/health/credit/education/insurance overlays unresearched. — source on file
  • SWDE telecoms/eprivacy fine and CBA No. 81 employment overlay; financial/health/credit/education/insurance overlays unresearched. — source on file
  • SWDE telecoms/eprivacy fine and CBA No. 81 employment overlay; financial/health/credit/education/insurance overlays unresearched. — source on file
  • SWDE telecoms/eprivacy fine and CBA No. 81 employment overlay; financial/health/credit/education/insurance overlays unresearched. — source on file
  • SWDE telecoms/eprivacy fine and CBA No. 81 employment overlay; financial/health/credit/education/insurance overlays unresearched. — source on file
  • SWDE telecoms/eprivacy fine and CBA No. 81 employment overlay; financial/health/credit/education/insurance overlays unresearched. — source on file
  • SWDE telecoms/eprivacy fine and CBA No. 81 employment overlay; financial/health/credit/education/insurance overlays unresearched. — source on file
  • SWDE telecoms/eprivacy fine and CBA No. 81 employment overlay; financial/health/credit/education/insurance overlays unresearched. — source on file
Category narrative49 words

Sectoral overlays confirmed for Belgium are strongest in telecoms/electronic-communications (Belgian Electronic Communications Act, LCE, applied alongside GDPR) and employment (CBA No. 81 governing employer access to employee e-communications). Financial-sector, health-sector, credit-scoring, education and insurance overlays specific to Belgium were not substantiated in this research pass beyond the GDPR baseline.

Periodic update · new data 2026-09-28

Sectoral Watch

The APD/GBA's 2026-2028 Strategic Plan designates healthcare and finance as tailored priority-workflow sectors for large-scale profiling and health-data audits. This sectoral designation is assessed as probable, resting on the Strategic Plan's own stated priorities as reported by secondary sources, rather than on a confirmed primary-source audit programme document. The designation nonetheless represents a meaningful signal for entities in either sector: it indicates that generic, complaint-driven regulatory attention is being supplemented, and in the plan's stated intent partially superseded, by sector-specific proactive audit activity.

No further sector-specific instrument, guidance, or audit finding beyond this Strategic Plan designation was located this cycle. The designation should therefore be read as a forward-looking prioritisation signal rather than an account of any completed or in-progress sectoral audit.

Outlook

Whether the Strategic Plan's healthcare and finance prioritisation translates into a published audit programme, timeline, or set of sector-specific guidance documents in the coming cycles is the principal item to watch. Any concrete healthcare or finance audit finding arising from this prioritisation would represent a material escalation from the current planning-stage signal.

Sources and claims (2)
  1. ConfirmedDataGuidance — The Belgian DPA fined water utility SWDE €86,000 (Decision No. 102/2026) for violations of the GDPR and the Belgian Electronic Communications Act (LCE) relating to systematic call recording without valid consent and inadequate transparency to callers and employees.observed
  2. ConfirmedIAPP — Belgian employers' access to employees' professional e-communications is governed by Collective Bargaining Agreement (CBA) No. 81, which the Belgian DPA has interpreted as requiring compliance with finality, transparency, and proportionality principles rather than reliance on individual employee consent.observed

#

Strong enforcement record across cookies, dark patterns, cross-context advertising (TCF) and direct marketing; opt-out-signal and clean-room specifics are thin.

Primary frameworkGDPR plus ePrivacy Directive as transposed via the Belgian Electronic Communications Act (LCE)
Traffic-light rationale — GreenStrong enforcement record across cookies, dark patterns, cross-context advertising (TCF) and direct marketing; opt-out-signal and clean-room specifics are thin.

Sub-modules (6)

Cookies And TrackersGreen

The Belgian DPA acts as lead supervisory authority for major cookie-banner complaints, subject to EDPB oversight on procedural handling.

Claims (1):

  • The EDPB required the Belgian DPA, acting as lead supervisory authority, to reconsider on the merits a NOYB complaint against Belgian public broadcaster VRT concerning cookie banners, after the Austrian DPA objected to the Belgian DPA's proposal to dismiss the complaint on procedural grounds.

Dark PatternsGreen

The Belgian DPA has sanctioned loyalty-card schemes for coercive consent mechanisms and excessive data collection.

Claims (1):

  • The Belgian DPA imposed corrective measures and a daily fine of €5,000 (capped at €100,000) on Freedelity for non-compliant consent mechanisms and excessive data collection via loyalty-card identity-document scanning.

Opt Out SignalsRed

No Belgium-specific Global Privacy Control/DAA opt-out-signal enforcement or guidance was located.

Absence provenance: unavailable. Searched: Belgium Global Privacy Control GDPR, Belgian DPA opt-out signal guidance.

Clean Rooms And DcrRed

No Belgium-specific clean-room/data-collaboration-room guidance was located.

Absence provenance: unavailable. Searched: Belgium data clean room guidance GDPR.

Cross Context AdvertisingGreen

The Belgian DPA led the EU-wide finding that IAB Europe's Transparency and Consent Framework violates the GDPR.

Claims (1):

  • The Belgian DPA's Litigation Chamber fined IAB Europe €250,000 after finding its Transparency and Consent Framework (TCF) could lead to loss of control over personal information for large groups of citizens, and ordered deletion of personal data already processed within the TCF system.

Direct MarketingGreen

The Belgian DPA's updated Recommendation No. 1/2025 governs lawful bases, consent standards and minors' protections for direct marketing.

Claims (1):

  • The Belgian DPA's updated Recommendation No. 1/2025 on direct marketing states that consent and legitimate interest are the primary lawful bases, requires consent to be free, specific, informed and unambiguous, and requires parental consent for marketing directed at children under 13.

Key findings (11)

  • IAB Europe TCF EUR 250,000 fine, VRT cookie-banner EDPB reconsideration order, Freedelity dark-pattern fine, updated direct-marketing recommendation. — source on file
  • IAB Europe TCF EUR 250,000 fine, VRT cookie-banner EDPB reconsideration order, Freedelity dark-pattern fine, updated direct-marketing recommendation. — source on file
  • IAB Europe TCF EUR 250,000 fine, VRT cookie-banner EDPB reconsideration order, Freedelity dark-pattern fine, updated direct-marketing recommendation. — source on file
  • IAB Europe TCF EUR 250,000 fine, VRT cookie-banner EDPB reconsideration order, Freedelity dark-pattern fine, updated direct-marketing recommendation. — source on file
  • IAB Europe TCF EUR 250,000 fine, VRT cookie-banner EDPB reconsideration order, Freedelity dark-pattern fine, updated direct-marketing recommendation. — source on file
  • IAB Europe TCF EUR 250,000 fine, VRT cookie-banner EDPB reconsideration order, Freedelity dark-pattern fine, updated direct-marketing recommendation. — source on file
  • IAB Europe TCF EUR 250,000 fine, VRT cookie-banner EDPB reconsideration order, Freedelity dark-pattern fine, updated direct-marketing recommendation. — source on file
  • IAB Europe TCF EUR 250,000 fine, VRT cookie-banner EDPB reconsideration order, Freedelity dark-pattern fine, updated direct-marketing recommendation. — source on file
  • IAB Europe TCF EUR 250,000 fine, VRT cookie-banner EDPB reconsideration order, Freedelity dark-pattern fine, updated direct-marketing recommendation. — source on file
  • IAB Europe TCF EUR 250,000 fine, VRT cookie-banner EDPB reconsideration order, Freedelity dark-pattern fine, updated direct-marketing recommendation. — source on file
  • IAB Europe TCF EUR 250,000 fine, VRT cookie-banner EDPB reconsideration order, Freedelity dark-pattern fine, updated direct-marketing recommendation. — source on file
Category narrative46 words

The Belgian DPA is one of the most active EU regulators in adtech enforcement, having fined IAB Europe over its Transparency and Consent Framework, sanctioned dark-pattern-style loyalty programmes (Freedelity), pursued cookie-banner complaints as lead authority (VRT/NOYB), and issued updated direct-marketing guidance covering consent and legitimate-interest bases.

Periodic update · new data 2026-09-28

AdTech & Commercial Privacy

The APD/GBA published Recommendation 01/2026 on direct marketing this cycle, replacing and superseding its February 2020 recommendation on the same subject. The new recommendation clarifies the conditions for valid consent in a direct-marketing context, the circumstances under which consent must be renewed, and how profiling and automated decision-making should be treated when deployed for marketing purposes. It also addresses the use of existing customers' contact details under a "soft opt-in" approach, providing updated guidance on when marketing to an existing customer base can proceed without fresh, explicit consent.

This is a confirmed, binding guidance instrument, in force from early 2026, and represents the most concrete and directly on-point commercial-privacy development this cycle. It supersedes six years of standing guidance under the 2020 recommendation, meaning organisations relying on the prior framework's specific consent-renewal or soft-opt-in thresholds should reassess their marketing-consent practices against the updated 2026 text.

Outlook

The practical enforcement application of Recommendation 01/2026 -- particularly whether the APD/GBA brings any enforcement action explicitly citing the new recommendation's profiling or consent-renewal provisions -- is the item to watch in the coming cycles.

1 earlier distinct update(s)
Periodic update · new data 2026-09-14

AdTech & Commercial Privacy

On 7 January 2026 the Belgian Market Court annulled the APD's January 2023 decision validating IAB Europe's Transparency and Consent Framework corrective action plan. Critically, the annulment did not disturb the underlying February 2022 finding that TC-String processing breaches the GDPR; the Market Court's ruling concerned only the adequacy of the APD's validation of the corrective action plan meant to remedy that underlying breach, requiring the APD to redo its validation with a narrower scope after a formal hearing.

This sits alongside the Market Court's separate confirmation that IAB Europe acts as joint data controller for TC String processing, reinforcing rather than undermining the substantive finding of GDPR non-compliance in the Transparency and Consent Framework's operation. Taken together, these developments indicate that while the mechanics of remedying the underlying breach remain procedurally unresolved, the underlying characterisation of the breach itself, and of IAB Europe's controller status, has been judicially confirmed rather than called into question.

Outlook

The APD's re-issued validation decision for the corrective action plan, expected following the required formal hearing, is the key item to watch. Its narrower scope, as directed by the Market Court, should clarify precisely what remedial measures the APD now considers sufficient to bring the Transparency and Consent Framework into compliance, which will be directly relevant to any organisation relying on that framework for advertising consent management.

Sources and claims (4)
  1. ConfirmedEDPB — The EDPB required the Belgian DPA, acting as lead supervisory authority, to reconsider on the merits a NOYB complaint against Belgian public broadcaster VRT concerning cookie banners, after the Austrian DPA objected to the Belgian DPA's proposal to dismiss the complaint on procedural grounds.observed
  2. ConfirmedIAPP — The Belgian DPA's Litigation Chamber fined IAB Europe €250,000 after finding its Transparency and Consent Framework (TCF) could lead to loss of control over personal information for large groups of citizens, and ordered deletion of personal data already processed within the TCF system.observed
  3. ConfirmedDataGuidance — The Belgian DPA imposed corrective measures and a daily fine of €5,000 (capped at €100,000) on Freedelity for non-compliant consent mechanisms and excessive data collection via loyalty-card identity-document scanning.observed
  4. ConfirmedDataGuidance — The Belgian DPA's updated Recommendation No. 1/2025 on direct marketing states that consent and legitimate interest are the primary lawful bases, requires consent to be free, specific, informed and unambiguous, and requires parental consent for marketing directed at children under 13.observed

#

Strong sourced coverage on biometric DPIA triggers and state-surveillance carve-outs; profiling/ADM-transparency and genetic-data specifics were not substantiated, and AI risk-assessment rules remain proposals.

Primary frameworkGDPR Article 22 and Title 3 of the Belgian Act of 30 July 2018; EU AI Act (interfacing, not yet Belgium-specific)
Traffic-light rationale — AmberStrong sourced coverage on biometric DPIA triggers and state-surveillance carve-outs; profiling/ADM-transparency and genetic-data specifics were not substantiated, and AI risk-assessment rules remain proposals.

Sub-modules (6)

Profiling RestrictionsRed

No Belgium-specific profiling-restriction enforcement distinct from the GDPR Article 22 baseline was located.

Absence provenance: unavailable. Searched: Belgian DPA profiling decision Article 22, Belgium automated decision-making enforcement.

Automated Decision Making TransparencyRed

No Belgium-specific ADM-transparency enforcement or guidance distinct from GDPR baseline was located.

Absence provenance: unavailable. Searched: Belgian DPA automated decision making transparency guidance.

Ai Risk AssessmentsAmber

EU-level Digital Omnibus proposals addressing GDPR/AI Act interfaces are under EDPB/EDPS review but are not yet binding Belgian or EU law.

Claims (1):

  • On 20 January 2026, the EDPB and EDPS adopted a Joint Opinion on the 'Digital Omnibus on AI', at the European Commission's request, addressing interfaces between the GDPR and AI-related risk-assessment obligations relevant to Member States including Belgium; this remains a legislative proposal, not yet adopted law.

Biometric RegimeGreen

The Belgian DPA requires a DPIA for biometric data collected to uniquely identify individuals in public or publicly accessible private spaces, and has enforced against unlawful biometric processing.

Claims (1):

  • The Belgian DPA's mandatory DPIA list requires a DPIA for biometric data collected to uniquely identify individuals present in a public space or a privately-owned but publicly accessible area.

Genetic DataRed

No Belgium-specific genetic-data regime distinct from the GDPR Article 9 baseline was located.

Absence provenance: unavailable. Searched: Belgium genetic data protection law GDPR.

State Surveillance CarveoutsGreen

Title 3 of the Belgian Act creates specific derogations for intelligence/security services, the armed forces, classification/security-clearance processes, the Coordination Unit for Threat Analysis, and passenger-data processing.

Claims (1):

  • Title 3 of the Belgian Data Protection Act specifically addresses processing of personal data by intelligence and security services, the armed forces, classification and security-clearance processes, the Coordination Unit for Threat Analysis, and passenger-data processing, establishing derogations from the general GDPR regime for these activities.

Key findings (11)

  • Biometric DPIA trigger, Title 3 state-surveillance carve-outs, and proposal-stage Digital Omnibus AI Joint Opinion. — source on file
  • Biometric DPIA trigger, Title 3 state-surveillance carve-outs, and proposal-stage Digital Omnibus AI Joint Opinion. — source on file
  • Biometric DPIA trigger, Title 3 state-surveillance carve-outs, and proposal-stage Digital Omnibus AI Joint Opinion. — source on file
  • Biometric DPIA trigger, Title 3 state-surveillance carve-outs, and proposal-stage Digital Omnibus AI Joint Opinion. — source on file
  • Biometric DPIA trigger, Title 3 state-surveillance carve-outs, and proposal-stage Digital Omnibus AI Joint Opinion. — source on file
  • Biometric DPIA trigger, Title 3 state-surveillance carve-outs, and proposal-stage Digital Omnibus AI Joint Opinion. — source on file
  • Biometric DPIA trigger, Title 3 state-surveillance carve-outs, and proposal-stage Digital Omnibus AI Joint Opinion. — source on file
  • Biometric DPIA trigger, Title 3 state-surveillance carve-outs, and proposal-stage Digital Omnibus AI Joint Opinion. — source on file
  • Biometric DPIA trigger, Title 3 state-surveillance carve-outs, and proposal-stage Digital Omnibus AI Joint Opinion. — source on file
  • Biometric DPIA trigger, Title 3 state-surveillance carve-outs, and proposal-stage Digital Omnibus AI Joint Opinion. — source on file
  • Biometric DPIA trigger, Title 3 state-surveillance carve-outs, and proposal-stage Digital Omnibus AI Joint Opinion. — source on file
Category narrative58 words

Belgium applies GDPR Article 22-style profiling/ADM protections at the EU baseline, with the Belgian DPA imposing a mandatory-DPIA requirement for public-space biometric identification. The Belgian Act's Title 3 creates specific carve-outs for intelligence/security services, security clearances, and passenger-data processing. AI-specific risk-assessment obligations are emerging at EU level (Digital Omnibus on AI) but are not yet Belgium-specific binding law.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. ConfirmedDataGuidance — The Belgian DPA's mandatory DPIA list requires a DPIA for biometric data collected to uniquely identify individuals present in a public space or a privately-owned but publicly accessible area.observed
  2. ConfirmedDataGuidance — Title 3 of the Belgian Data Protection Act specifically addresses processing of personal data by intelligence and security services, the armed forces, classification and security-clearance processes, the Coordination Unit for Threat Analysis, and passenger-data processing, establishing derogations from the general GDPR regime for these activities.observed
  3. ProbableEDPB/EDPS — On 20 January 2026, the EDPB and EDPS adopted a Joint Opinion on the 'Digital Omnibus on AI', at the European Commission's request, addressing interfaces between the GDPR and AI-related risk-assessment obligations relevant to Member States including Belgium; this remains a legislative proposal, not yet adopted law.observed

#

Strong sourced coverage of the age-13 threshold and parental-consent rule; education-settings and dependent-adults sub-modules carry an evidentiary gap.

Primary frameworkBelgian Act of 30 July 2018, Article on children's consent (derogating from GDPR Article 8 default age of 16)
Traffic-light rationale — AmberStrong sourced coverage of the age-13 threshold and parental-consent rule; education-settings and dependent-adults sub-modules carry an evidentiary gap.

Sub-modules (5)

Age VerificationGreen

The Belgian DPA's direct-marketing guidance requires information addressed to children be adapted to the child's age and parental consent obtained below age 13.

Claims (1):

  • The Belgian DPA's direct marketing guidelines require that information addressed to children be adapted to the child's age and that parental consent be obtained for marketing to children under 13.

Minor Profiling BansRed

No Belgium-specific minor-profiling ban distinct from GDPR Recital 38/Article 22 baseline was located.

Absence provenance: unavailable. Searched: Belgium minor profiling ban GDPR, Belgian DPA children profiling guidance.

Education SettingsRed

No Belgium-specific education-settings data-protection rule was substantiated in this pass.

Absence provenance: unavailable. Searched: Belgium school student data protection law GDPR.

Dependent AdultsRed

No Belgium-specific dependent-adults (elderly/incapacitated) data-protection rule was substantiated in this pass.

Absence provenance: unavailable. Searched: Belgium dependent adults data protection vulnerable persons GDPR.

Key findings (11)

  • Age-13 digital-consent derogation and parental-consent marketing rule for under-13s. — source on file
  • Age-13 digital-consent derogation and parental-consent marketing rule for under-13s. — source on file
  • Age-13 digital-consent derogation and parental-consent marketing rule for under-13s. — source on file
  • Age-13 digital-consent derogation and parental-consent marketing rule for under-13s. — source on file
  • Age-13 digital-consent derogation and parental-consent marketing rule for under-13s. — source on file
  • Age-13 digital-consent derogation and parental-consent marketing rule for under-13s. — source on file
  • Age-13 digital-consent derogation and parental-consent marketing rule for under-13s. — source on file
  • Age-13 digital-consent derogation and parental-consent marketing rule for under-13s. — source on file
  • Age-13 digital-consent derogation and parental-consent marketing rule for under-13s. — source on file
  • Age-13 digital-consent derogation and parental-consent marketing rule for under-13s. — source on file
  • Age-13 digital-consent derogation and parental-consent marketing rule for under-13s. — source on file
Category narrative41 words

Belgium derogates from the GDPR default by setting the age of digital consent at 13 (rather than 16), with corresponding parental-consent and age-appropriate-information requirements reflected in Belgian DPA direct-marketing guidance. Education-setting-specific and dependent-adult-specific rules were not substantiated in this research pass.

Periodic update · new data 2026-09-28

Children & Vulnerable Groups

The APD/GBA's 2026-2028 Strategic Plan names minors' data processing as a priority area, with specialised Data Protection Impact Assessment (DPIA) templates for minors' data reportedly planned. This is assessed as probable rather than confirmed: the Strategic Plan's stated prioritisation is reported via secondary sources, and no primary-source publication of the planned specialised DPIA templates themselves was located this cycle. The distinction matters -- a stated intent to develop specialised templates is a different, and less binding, development than the templates' actual publication and entry into use.

No further children-and-vulnerable-groups-specific instrument, enforcement action, or guidance document was identified this cycle beyond this Strategic Plan prioritisation signal.

Outlook

Whether the planned specialised DPIA templates for minors' data are actually published, and what specific assessment criteria they introduce, is the key item to watch in coming cycles. Publication would represent a material escalation from the current planning-stage signal to a binding or quasi-binding compliance instrument.

Sources and claims (2)
  1. ConfirmedDataGuidance — The Belgian Data Protection Act sets the age of consent for children's data processing at 13 years, below which parental consent is required, derogating from the GDPR default age of 16.observed
  2. ConfirmedDataGuidance — The Belgian DPA's direct marketing guidelines require that information addressed to children be adapted to the child's age and that parental consent be obtained for marketing to children under 13.observed

#

Robust, judicially-tested enforcement powers with continuous 2026 enforcement activity; capacity/independence concerns are a noted but non-disqualifying risk factor.

Primary frameworkGDPR Articles 58, 77-84 as applied via the Belgian Act of 30 July 2018
Traffic-light rationale — GreenRobust, judicially-tested enforcement powers with continuous 2026 enforcement activity; capacity/independence concerns are a noted but non-disqualifying risk factor.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The Litigation Chamber may impose fines up to €20m/4% of turnover, subject to appeal before the Market Court.

Claims (1):

  • Infringements of basic GDPR principles, including Articles 5 and 6, can be subject to administrative fines of up to €20,000,000 or up to 4% of total worldwide annual turnover, imposed by the Belgian DPA's Litigation Chamber and subject to appeal before the Market Court, part of the Brussels Court of Appeal.

Enforcement Activity IndexGreen

Belgian DPA enforcement activity has been continuous through 2026, including multi-decade-old complaints finally resolved via fines.

Claims (1):

  • Between April and May 2026 the Belgian DPA issued multiple enforcement decisions, including an €8,500 fine against Y.NV (Decision 86/2026) for unlawful email retention and an €86,000 fine against SWDE (Decision 102/2026) for unlawful call recording, reflecting continued active enforcement.

Regulator Funding And CapacityAmber

The EDPB has previously flagged independence/capacity concerns regarding proposed Belgian legislative reforms affecting DPA oversight.

Claims (1):

  • The EDPB publicly expressed concern that proposed Belgian legislative reforms would strengthen parliamentary oversight over the Belgian DPA, raising independence concerns relevant to the regulator's institutional capacity.

Collective Redress And Class ActionsGreen

The Belgian Act grants both data subjects and the DPA the right to seek cease-and-desist orders, and permits class-action-type proceedings.

Claims (1):

  • The Belgian Data Protection Act grants both data subjects and the Belgian DPA the right to obtain a cease-and-desist order, enforceable under forfeiture of a penalty, against infringing controllers, and permits class-action-type proceedings.

Private Right Of ActionGreen

Data subjects may seek a judicial remedy directly before Belgian courts in addition to lodging a complaint with the Belgian DPA.

Claims (1):

  • A data subject may lodge a complaint with a supervisory authority or seek a judicial remedy directly before the competent courts where a controller fails to act on a rights request.

Recent Developments 180DGreen

Within the last 180 days, the Belgian DPA issued the Y.NV and SWDE fines, updated its direct-marketing Recommendation, and the EDPB/EDPS adopted Joint Opinions on the Digital Omnibus affecting the GDPR/ePrivacy interface.

Claims (2):

  • Between April and May 2026 the Belgian DPA issued multiple enforcement decisions, including an €8,500 fine against Y.NV (Decision 86/2026) for unlawful email retention and an €86,000 fine against SWDE (Decision 102/2026) for unlawful call recording, reflecting continued active enforcement.
  • On 11 February 2026, the EDPB and EDPS adopted a Joint Opinion raising concerns that the proposed Digital Omnibus Regulation could narrow the GDPR definition of personal data and increase the risk-notification threshold and deadline for data breaches; this remains a legislative proposal, not yet adopted law.

Key findings (11)

  • Article 83 fine ceiling, 2026 enforcement activity (Y.NV, SWDE), Digital Omnibus Joint Opinion (11 Feb 2026), and standing 2022 independence concern. — source on file
  • Article 83 fine ceiling, 2026 enforcement activity (Y.NV, SWDE), Digital Omnibus Joint Opinion (11 Feb 2026), and standing 2022 independence concern. — source on file
  • Article 83 fine ceiling, 2026 enforcement activity (Y.NV, SWDE), Digital Omnibus Joint Opinion (11 Feb 2026), and standing 2022 independence concern. — source on file
  • Article 83 fine ceiling, 2026 enforcement activity (Y.NV, SWDE), Digital Omnibus Joint Opinion (11 Feb 2026), and standing 2022 independence concern. — source on file
  • Article 83 fine ceiling, 2026 enforcement activity (Y.NV, SWDE), Digital Omnibus Joint Opinion (11 Feb 2026), and standing 2022 independence concern. — source on file
  • Article 83 fine ceiling, 2026 enforcement activity (Y.NV, SWDE), Digital Omnibus Joint Opinion (11 Feb 2026), and standing 2022 independence concern. — source on file
  • Article 83 fine ceiling, 2026 enforcement activity (Y.NV, SWDE), Digital Omnibus Joint Opinion (11 Feb 2026), and standing 2022 independence concern. — source on file
  • Article 83 fine ceiling, 2026 enforcement activity (Y.NV, SWDE), Digital Omnibus Joint Opinion (11 Feb 2026), and standing 2022 independence concern. — source on file
  • Article 83 fine ceiling, 2026 enforcement activity (Y.NV, SWDE), Digital Omnibus Joint Opinion (11 Feb 2026), and standing 2022 independence concern. — source on file
  • Article 83 fine ceiling, 2026 enforcement activity (Y.NV, SWDE), Digital Omnibus Joint Opinion (11 Feb 2026), and standing 2022 independence concern. — source on file
  • Article 83 fine ceiling, 2026 enforcement activity (Y.NV, SWDE), Digital Omnibus Joint Opinion (11 Feb 2026), and standing 2022 independence concern. — source on file
Category narrative85 words

The Belgian DPA's Litigation Chamber exercises full GDPR Article 58 investigative and Article 83 sanctioning powers (fines up to €20m or 4% of global turnover), subject to appeal before the Market Court of the Brussels Court of Appeal, which has shown willingness to overturn DPA fines on proportionality grounds. Data subjects and the DPA can seek cease-and-desist orders and class-action-type proceedings are available. Enforcement activity has been continuous through 2026 (Y.NV, SWDE decisions), while EDPB has previously raised independence/capacity concerns over proposed Belgian legislative reforms.

Periodic update · new data 2026-09-28

Enforcement & Redress

Belgium's enforcement and redress landscape this cycle presents a mixed picture of high procedural volume alongside low aggregate financial penalties and meaningful appellate friction. The Litigation Chamber issued 214 decisions in 2025, but total fines imposed across those decisions amounted to only EUR 75,700 in aggregate -- a notably low financial total relative to the decision count, consistent with an enforcement style weighted toward corrective and procedural remedies rather than large monetary penalties.

Appellate outcomes complicate the enforcement picture further. The Brussels Market Court issued 25 rulings in 2025 (9 final, 3 interim) on 20 appeals against Litigation Chamber decisions, and 13 of those decisions were totally or partially annulled. A roughly half-to-majority annulment rate on appealed decisions is a material signal about the durability of the Litigation Chamber's enforcement output, though it should be read alongside the caveat that no primary-source confirmation of this specific statistic beyond the secondary reporting was located this cycle.

Separately, and illustrating a different enforcement tool, the APD/GBA is understood to have imposed a daily penalty of EUR 40,000 on RTL Belgium for GDPR violations related to non-compliant cookie banners -- a continuing-violation penalty structure distinct from the one-off fine amounts reflected in the EUR 75,700 aggregate figure above, and a standing precedent for how the DPA can escalate penalties for unresolved ongoing violations.

Outlook

The high Market Court annulment rate is the most consequential open question for Belgium's enforcement credibility going forward: whether this rate persists, worsens, or improves as more Litigation Chamber decisions move through the appellate pipeline will materially affect how durable the DPA's enforcement output proves to be. Primary-source confirmation of the annulment statistic itself would also strengthen this finding's evidentiary basis.

1 earlier distinct update(s)
Periodic update · new data 2026-09-14

Enforcement & Redress

Belgium's enforcement and redress landscape is escalating this cycle, driven by an active caseload centred on two major proceedings: the Market Court's 7 January 2026 annulment of the APD's IAB Europe TCF corrective action plan validation, and the Market Court's 4 December 2025 referral of thirteen preliminary questions to the CJEU following the Litigation Chamber's finding that FPS Finance's FATCA-related transfers to the United States were unlawful. Both proceedings remain active, with outcomes pending.

These two proceedings sit against a backdrop of historical enforcement precedent, including the Litigation Chamber's Decision 21/2022, which imposed an administrative fine of EUR 250,000 on IAB Europe, and a separate fine of EUR 174,640 recorded in Decision 07/2024. The confirmed, escalating trajectory this cycle reflects both the scale of the two active Market Court proceedings and the APD's own stated strategic shift toward proactive Systemic Impact Enforcement, which would, if realised, add a further category of self-initiated audit activity to the regulator's enforcement toolkit alongside its existing complaint-driven and judicial-appeal caseload.

Outlook

The resolution timelines for the two active Market Court proceedings, the TCF corrective action plan re-validation and the CJEU's ruling on the FATCA-related referral, are the primary enforcement developments to track. The APD's first concrete Systemic Impact Enforcement outputs, expected as the 2026-2028 Strategic Plan matures, will be the clearest signal of whether the proactive enforcement shift is translating into comparable or greater enforcement volume than the historical complaint-driven model.

Sources and claims (6)
  1. ConfirmedIAPP — Infringements of basic GDPR principles, including Articles 5 and 6, can be subject to administrative fines of up to €20,000,000 or up to 4% of total worldwide annual turnover, imposed by the Belgian DPA's Litigation Chamber and subject to appeal before the Market Court, part of the Brussels Court of Appeal.observed
  2. ConfirmedDataGuidance — The Belgian Data Protection Act grants both data subjects and the Belgian DPA the right to obtain a cease-and-desist order, enforceable under forfeiture of a penalty, against infringing controllers, and permits class-action-type proceedings.observed
  3. ConfirmedEUR-Lex — A data subject may lodge a complaint with a supervisory authority or seek a judicial remedy directly before the competent courts where a controller fails to act on a rights request.observed
  4. ConfirmedDataGuidance — Between April and May 2026 the Belgian DPA issued multiple enforcement decisions, including an €8,500 fine against Y.NV (Decision 86/2026) for unlawful email retention and an €86,000 fine against SWDE (Decision 102/2026) for unlawful call recording, reflecting continued active enforcement.observed
  5. ConfirmedIAPP — The EDPB publicly expressed concern that proposed Belgian legislative reforms would strengthen parliamentary oversight over the Belgian DPA, raising independence concerns relevant to the regulator's institutional capacity.observed
  6. ProbableEDPB/EDPS — On 11 February 2026, the EDPB and EDPS adopted a Joint Opinion raising concerns that the proposed Digital Omnibus Regulation could narrow the GDPR definition of personal data and increase the risk-notification threshold and deadline for data breaches; this remains a legislative proposal, not yet adopted law.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct36.36
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Belgium
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 37 claim(s) (37 category placement(s)), 34 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (35 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 15Data Subject Rightsaccess right
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer impact assessment
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties
Art. 13-14Data Subject Rightsaccess right
Art. 16-17Data Subject Rightsrectification and erasure

Self-audit

All 10 modules populated with T2/T3 evidence (EDPB official pages = T2; DataGuidance/IAPP secondary reporting = T3; EUR-Lex GDPR text = T1). Strong claim density with T1/T2 anchors for regulator_and_framework, controller_processor_duties (breach notification, DPIA), cross_border_and_adequacy (transfer mechanisms, BCR, Schrems II), adtech_and_commercial_privacy (IAB Europe, VRT cookie banner, Freedelity), and enforcement_and_redress (fines regime, 2026 decisions). Thinner, T3-only or absent-provenance coverage in: sectoral_watch (financial/health/credit/education/insurance sub-modules), algorithmic_biometric_and_surveillance_governance (profiling, ADM transparency, genetic data), children_and_vulnerable_groups (minor profiling bans, education settings, dependent adults), and cross_border_and_adequacy (data_localisation, adequacy_received/granted — correctly flagged as EU-Commission-level competence rather than Belgium-specific gaps).

Unresolved questions (5):

  • Is there a Belgium-specific financial-sector (FSMA/NBB) data-protection overlay distinct from GDPR baseline (e.g., banking secrecy interaction)?
  • Is there Belgium-specific health-sector/eHealth platform data-protection guidance beyond GDPR Article 9 baseline?
  • Does the Belgian DPA have published guidance specifically on Global Privacy Control or similar opt-out signals?
  • Is there a Belgium-specific derogation or guidance on genetic data processing beyond GDPR Article 9?
  • What is the current (2026) operational status/outcome of the EDPB's 2022 independence concerns regarding Belgian DPA governance reforms?

Escalate to primary-source review: yes