EnglishNederlands
Belgium flag

Belgium

Belgium Data Privacy Laws: GDPR Implementation Guide (2026)

Independently fact-checked against primary sources (last audited September 9, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 9, 2026. · 10 primary sources cited on this page. How we verify our legal content

Belgium Data Privacy Laws: GDPR Implementation Guide (2026)

Frequently Asked Questions

Does Belgium have its own data privacy law separate from the GDPR?

Yes. While the GDPR applies directly in Belgium as an EU member state, Belgium also enacted the Law of 30 July 2018 on the protection of natural persons with regard to the processing of personal data. This national law addresses areas where the GDPR allows member state discretion: the age of digital consent (set at 13 in Belgium), additional safeguards for special categories of data including access logs, criminal sanctions for data protection violations, and the establishment and powers of the Belgian Data Protection Authority. Belgium's constitutional right to privacy under Article 22, inserted in 1994, provides an additional domestic legal foundation independent of EU law.

What is the maximum GDPR fine in Belgium?

Administrative fines under the GDPR can reach 20 million euros or 4% of the organization's total worldwide annual turnover, whichever is higher, for the most serious violations. These include breaches of data processing principles, unlawful processing, and violations of data subject rights. Belgian national law also sets criminal fines by offence in Title 6, Chapter II of the Law of 30 July 2018, from 100 euros up to 30,000 euros before the statutory surcharge on criminal fines is applied. Belgian public authorities are generally exempt from administrative fines. The APD is moving toward adopting the EDPB's published five-step fining methodology, which is expected to produce higher fines than Belgium's historically moderate penalty levels.

How do I report a data breach to the Belgian Data Protection Authority?

Data controllers must notify the APD within 72 hours of becoming aware of a personal data breach that poses a risk to individuals' rights and freedoms. Since June 10, 2025, notifications must be submitted through the APD's new unified portal. Organizations must create a company account authenticated via Belgium's Federal Authentication Service (FAS) using Belgian eID or itsme. Only one company account is permitted per data controller. Notifications must describe the nature of the breach, the categories and approximate number of individuals affected, the DPO's contact details, likely consequences, and remedial measures taken or planned.

At what age can children consent to data processing in Belgium?

Belgium set the age of digital consent at 13 years under Article 7 of the Law of 30 July 2018. This is the lowest threshold the GDPR permits for member states. It applies specifically to information society services offered directly to children where processing relies on consent. For children under 13, the child's legal representative must provide consent. For processing outside information society services, Belgian civil law rules on legal capacity apply, and parental involvement may be required even for children aged 13 and above depending on the nature of the legal act.

Can the Belgian DPA fine government agencies for GDPR violations?

Generally, no. Belgian law exempts public authorities and public bodies from administrative fines under the GDPR, except when those bodies offer goods or services on the open market in competition with private enterprises. The Constitutional Court rejected an action to annul that provision in judgment 3/2021 of January 14, 2021, holding that the distinction rests on an objective criterion and is not without reasonable justification. However, the APD can still issue warnings, reprimands, and compliance orders against public sector entities, and criminal sanctions under the Law of 30 July 2018 may apply to individual public officials who commit data protection offenses.

What is the APD/GBA strategic enforcement focus for 2026 to 2028?

The APD's 2026-2028 Strategic Plan shifts from reactive complaint processing to systemic-impact enforcement. It sets two content priorities: large-scale processing, public or private, that carries a high risk to individuals' rights and freedoms, and the processing of minors' personal data. The plan's examples of large-scale processing include health data held by hospitals and care networks, profiling in banking and insurance, tax databases, and advertising technology and data brokers. The APD will proactively initiate inspections rather than waiting for complaints, and will no longer provide individual guidance to DPOs, instead publishing sector-specific FAQs and checklists. Complaints suited to it are routed to mediation by the Front Office. Due to a hiring freeze through 2029, its 96 staff will be deployed on high-impact investigations.

How does the EU AI Act apply in Belgium?

The EU AI Act (Regulation (EU) 2024/1689) applies directly in Belgium. The 2025-2029 Federal Government Agreement of January 31, 2025 announced that BIPT (the Belgian Institute for Postal Services and Telecommunications) would take the lead as Belgium's AI Act market surveillance authority, but the European Commission's list of single points of contact, last updated September 7, 2026, still shows no entry for Belgium, so the formal designation under Article 70 is outstanding. The APD retains oversight of AI systems that process personal data. Prohibited AI practices have been banned since February 2, 2025. Regulation (EU) 2026/1744 of July 8, 2026 moved the high-risk deadlines to December 2, 2027 for Annex III systems and to August 2, 2028 for high-risk AI embedded in regulated products, the date from which the AI Act is fully applicable. Organizations deploying AI systems in Belgium should assess whether their systems qualify as high-risk and which authority, BIPT or APD, will be the primary supervisor.

What are Belgium's rules for employee monitoring and workplace privacy?

Belgium regulates workplace privacy primarily through National Labour Council collective agreements (CCTs) rather than standalone statutes. CCT No. 68 governs CCTV surveillance in the workplace. CCT No. 81 regulates employer monitoring of employee email and internet usage. CCT No. 38 governs data processing during recruitment. The APD has consistently held that employee consent cannot serve as the lawful basis for employment-related processing due to the power imbalance inherent in the employment relationship. Employers must rely on legal obligation (including the CCTs themselves, once adopted by royal decree) or a carefully documented legitimate interest.

What happened in the IAB Europe TCF case in Belgium?

The IAB Europe case spans multiple proceedings. The APD fined IAB Europe 250,000 euros in February 2022 and ordered it to bring its Transparency and Consent Framework (TCF) into compliance with the GDPR. On May 14, 2025, the Belgian Market Court endorsed the APD's reasoning, confirmed the infringements and confirmed the 250,000 euro fine, annulling decision 21/2022 formally and only for procedural reasons. It rejected joint controllership only for processing occurring entirely within the OpenRTB protocol, consistent with the Court of Justice of the EU in Case C-604/22 of March 7, 2024, which held that a TC String is personal data. On January 9, 2026, the Market Court annulled the APD's January 2023 approval of the corrective action plan, sending the implementation plan back to the Litigation Chamber. The fine and the underlying findings stand.

How does Belgium handle international data transfers?

Belgium follows the GDPR's international transfer framework. Transfers within the EEA proceed freely. Transfers to countries with European Commission adequacy decisions require no additional safeguards; adequate countries and territories include Andorra, Argentina, Brazil, Canada (for PIPEDA-covered processing), the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, South Korea, Switzerland, the United Kingdom, Uruguay, and the United States (for EU-US Data Privacy Framework participants), with Brazil added in January 2026 and the United Kingdom decisions renewed in December 2025. Transfers to all other countries require Standard Contractual Clauses, Binding Corporate Rules, or another GDPR Article 46 safeguard, accompanied by a Transfer Impact Assessment to verify the receiving country's legal framework does not undermine the contractual protections.

Updates

Second-round corrections: BIPT is the intended, not yet designated, AI Act market surveillance authority; Decision 114/2024 re-dated to September 6, 2024; Strategic Plan priorities and the direct marketing recommendation number stated precisely.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Major expansion: added constitutional basis (Article 22 Belgian Constitution), lawful bases for processing, data subject rights, EU AI Act overlay (BIPT / AI Act authorities), recent 2025-2026 APD decisions (hospital 200k fine, data broker Decision 72/2025), updated IAB Europe/TCF appeal timeline (May 14 2025 and January 9 2026 Market Court rulings), new APD breach notification portal (June 2025), [GDPR](/world-laws/world-data-privacy-laws) Procedural Regulation (EU) 2025/2518, business compliance checklist. Title and meta retained. Word count: ~6,400 words.

Reviewed and approved by an editor

Sources and References

  1. Law of 30 July 2018 on the protection of natural persons with regard to the processing of personal data (Belgian Data Protection Act)(dataprotectionauthority.be).gov
  2. Belgian Data Protection Authority (APD/GBA): Official Website(dataprotectionauthority.be).gov
  3. EU General Data Protection Regulation (GDPR), Regulation (EU) 2016/679(eur-lex.europa.eu).gov
  4. Belgian Constitution, Article 22 (right to respect for private and family life), coordinated text on the Justel database(ejustice.just.fgov.be)
  5. Belgian Data Protection Authority, Litigation Chamber Decision 37/2020 of 14 July 2020 (Google, right to be forgotten; annulled by Market Court judgment 2020/AR/1111 of 30 June 2021)(autoriteprotectiondonnees.be)
  6. Belgian Data Protection Authority, Litigation Chamber Decision 42/2020 of 30 July 2020 (Proximus, public directories; administrative fine replaced by a reprimand by Market Court judgment 2020/AR/1160 of 6 September 2023)(autoriteprotectiondonnees.be)
  7. European Commission: Adequacy Decisions for International Data Transfers(commission.europa.eu).gov
  8. European Data Protection Board: International Data Transfers Guidelines(edpb.europa.eu).gov
  9. EU AI Act: Regulation (EU) 2024/1689 of the European Parliament and of the Council(eur-lex.europa.eu).gov
  10. BIPT: Application of the AI Act in Belgium(bipt.be).gov
  11. European Commission: Market Surveillance Authorities under the AI Act(digital-strategy.ec.europa.eu).gov
  12. Regulation (EU) 2025/2518: Additional Procedural Rules for GDPR Cross-Border Enforcement(eur-lex.europa.eu).gov
  13. Belgian Data Protection Authority, Annual Report 2025 (Market Court confirms the 250,000 euro IAB Europe fine, May 2025; 2025 staffing, breach and data-broker figures)(autoriteprotectiondonnees.be)
  14. IAB Europe: Wins Appeal Against APD Action Plan Decision (January 9, 2026)(iabeurope.eu)
  15. Stibbe: Belgian DPA Fines Hospital After Data Breach (December 2024)(stibbe.com)
  16. CMS Law: Launch of New APD Portal for Data Breach Notification (June 2025)(cms.law)
  17. Federal Public Service Foreign Affairs Belgium: Protection of Personal Data(unitedkingdom.diplomatie.belgium.be).gov
  18. CMS Law: AI Regulation Scanner for Belgium(cms.law)
Share: