Full GDPR-aligned statutory framework in force with an operational, active supervisory authority; only narrow public-sector carve-outs from administrative fines.
Primary frameworkGeneral Data Protection Regulation (EU) 2016/679, as implemented by the Belgian Act of 30 July 2018 on the Protection of Natural Persons with Regard to the Processing of Personal Data and the Act of 3 December 2017 Establishing the Data Protection Authority
Traffic-light rationale — GreenFull GDPR-aligned statutory framework in force with an operational, active supervisory authority; only narrow public-sector carve-outs from administrative fines.
Sub-modules (5)
Regulator And AuthorityGreen
The APD-GBA is the sole Belgian supervisory authority for GDPR matters, headquartered in Brussels.
Claims: CLM-BE-a1b2c3d4
Act And InstrumentsGreen
The GDPR is implemented domestically via two founding Acts: the 2017 Act creating the DPA and the 2018 Act on personal data protection.
Claims: CLM-BE-b2c3d4e5
Material ScopeAmber
The Act applies broadly to private and public controllers/processors, with a narrow carve-out excluding most public authorities from GDPR Article 83 administrative fines.
Claims: CLM-BE-c3d4e5f6
Territorial ScopeGreen
The Act mirrors GDPR establishment-based territorial scope, applying regardless of where the actual processing occurs.
Claims: CLM-BE-d4e5f6a7
Regulator Registration And FilingAmber
Belgium has no general controller-registration regime (abolished under GDPR); the principal filing obligation is communication of DPO contact details to the Belgian DPA.
Claims: CLM-BE-e5f6a7b8
Category narrative83 words
Belgium is an EU Member State operating under the GDPR (Regulation (EU) 2016/679) as the omnibus instrument, implemented domestically through the Act of 3 December 2017 Establishing the Data Protection Authority and the Act of 30 July 2018 on the Protection of Natural Persons with Regard to the Processing of Personal Data. The Belgian Data Protection Authority (APD-GBA) is the single national supervisory authority, based in Brussels, with a Litigation Chamber acting as its administrative enforcement/sanctioning body and an Inspection Service handling investigations.
Sources and claims (5)
ConfirmedEDPB — The Belgian Data Protection Authority (APD-GBA), based in Brussels, is the national supervisory authority responsible for GDPR enforcement in Belgium.
ConfirmedDataGuidance — Belgium implemented the GDPR through the Act of 30 July 2018 on the Protection of Natural Persons with Regard to the Processing of Personal Data, together with the Act of 3 December 2017 Establishing the Data Protection Authority.
ConfirmedDataGuidance — The Belgian Data Protection Act applies to both private and public controllers and processors, except that public authorities (other than public-law legal persons offering goods or services on a market) are excluded from GDPR Article 83 administrative fines.
ConfirmedDataGuidance — The Belgian Data Protection Act applies to processing carried out in the context of the activities of an establishment of a controller or processor on Belgian territory, regardless of whether the processing itself takes place in Belgium.
ConfirmedDataGuidance — Controllers and processors appointing a DPO under GDPR Article 37 must publish the DPO's contact details and communicate them to the Belgian DPA, constituting the principal filing obligation under the Belgian regime.
Core lawful-basis and special-category rules are GDPR-aligned and actively enforced by the Belgian DPA; pseudonymisation/anonymisation guidance is thin.
Primary frameworkGDPR Articles 6, 7 and 9, read with Belgian Act of 30 July 2018 and CBA-based employment-data rules
Traffic-light rationale — GreenCore lawful-basis and special-category rules are GDPR-aligned and actively enforced by the Belgian DPA; pseudonymisation/anonymisation guidance is thin.
Sub-modules (4)
Lawful BasesGreen
Employment-related processing may rely on the Article 6(1)(c) Member State legal-basis route, including via collective bargaining agreements.
Claims: CLM-BE-f6a7b8c9
Consent ThresholdsGreen
The Belgian DPA requires consent to be free, specific, informed and unambiguous, and treats 'consent or pay' models as generally invalid.
Claims: CLM-BE-a7b8c9d0
Special CategoriesGreen
Biometric and other special-category data require an explicit Article 9 legal basis; the Belgian DPA has actively enforced this against employers using fingerprint time-registration.
Claims: CLM-BE-b8c9d0e1
Pseudonymisation And AnonymisationRed
No Belgium-specific pseudonymisation/anonymisation safe-harbour distinct from the GDPR Article 4(5)/Recital 26 baseline was identified.
Absence provenance: not recorded. Searched: Belgian DPA pseudonymisation anonymisation guidance, Belgium GDPR anonymisation safe harbour.
Category narrative51 words
Belgium applies the GDPR Article 6 lawful bases and Article 9 special-category regime without a comprehensive derogating statute, though Article 88-based employment rules and Belgian DPA guidance (e.g., on direct marketing and biometric processing) supplement the baseline. Pseudonymisation/anonymisation is governed by the GDPR baseline definitions with no distinct Belgian safe-harbour identified.
Sources and claims (3)
ConfirmedDataGuidance — Employees' personal data may be processed on the Article 6(1)(c) GDPR Member State legal-basis route where necessary for establishing, implementing, or terminating an employment relationship, including under a collective bargaining agreement.
ConfirmedDataGuidance — The Belgian DPA's direct marketing guidelines require that consent be free, specific, informed, and unambiguous, and state that 'consent or pay' models are generally invalid.
ConfirmedDataGuidance — The Belgian DPA fined a company €45,000 after finding it processed employees' fingerprints (special-category biometric data) for time-registration without articulating a valid Article 9 legal basis and in breach of purpose-limitation and minimisation principles.
Traffic-light rationale — GreenRights framework is GDPR-aligned and enforced through repeated Belgian DPA decisions; portability enforcement activity specifically is thin.
Sub-modules (5)
Access RightGreen
The Belgian DPA is particularly active in issuing enforcement decisions concerning responses to data subject access requests.
Claims: CLM-BE-e1f2a3b4
Rectification And ErasureGreen
Failure to action erasure requests has been the subject of Belgian DPA fines, including the 2026 Y.NV decision.
Claims: CLM-BE-e1f2a3b4
Restriction And ObjectionGreen
The Belgian DPA has fined controllers for failing to honour objection requests to direct-marketing processing.
Claims: CLM-BE-d0e1f2a3
Data PortabilityRed
No Belgium-specific portability enforcement decision or derogating guidance was located beyond the GDPR Article 20 baseline.
Absence provenance: not recorded. Searched: Belgian DPA data portability decision, Belgium GDPR Article 20 guidance.
Deadlines And Response WindowsGreen
The standard one-month response deadline under GDPR Article 12(3)/(4) applies in Belgium without a shortened or extended national variant identified.
Claims: CLM-BE-c9d0e1f2
Category narrative33 words
Belgium follows the GDPR data-subject-rights catalogue (access, rectification/erasure, restriction/objection, portability) with the standard one-month response deadline. The Belgian DPA is particularly active in enforcement concerning access requests, erasure failures, and objection to marketing.
Sources and claims (3)
ConfirmedEUR-Lex — Where a controller does not act on a data subject's rights request, it must inform the data subject without delay and at the latest within one month of receipt, of the reasons for not taking action and of the possibility of lodging a complaint with a supervisory authority or seeking a judicial remedy.
ConfirmedEDPB / Belgian DPA — The Belgian DPA fined a controller €1,000 for not responding to a data subject's request to object to processing of his data for marketing purposes and for failing to cooperate with the authority's injunction.
ConfirmedDataGuidance — In Decision No. 86/2026, the Belgian DPA fined an employer €8,500 after it kept a former employee's professional mailbox active and failed to respond to the employee's erasure request.
All core controller/processor duties are GDPR-aligned, actively guided by Belgian DPA published lists, and enforced through repeated fines; joint-controller arrangements lack Belgium-specific findings.
Primary frameworkGDPR Articles 24-39 as applied and supplemented by Belgian DPA guidance
Traffic-light rationale — GreenAll core controller/processor duties are GDPR-aligned, actively guided by Belgian DPA published lists, and enforced through repeated fines; joint-controller arrangements lack Belgium-specific findings.
Sub-modules (7)
Accountability And DpiaGreen
The Belgian DPA publishes a binding list of processing operations requiring a DPIA, covering biometric identification and large-scale health/behavioural data processing.
Claims: CLM-BE-f2a3b4c5
Dpo RequirementsGreen
Article 37 DPO designation, publication, and DPA-notification duties apply; the Belgian DPA issues guidance in Dutch, French and German.
Claims: CLM-BE-a3b4c5d6
Ropa RequirementsGreen
The Belgian DPA has found and sanctioned Article 30(1) ROPA deficiencies in enforcement decisions.
Claims: CLM-BE-b4c5d6e7
Joint Controller ArrangementsRed
No Belgium-specific joint-controller enforcement or guidance distinct from the GDPR Article 26 baseline was located.
Absence provenance: not recorded. Searched: Belgian DPA joint controller decision, Belgium Article 26 GDPR guidance.
Security MeasuresGreen
The Belgian DPA enforces Article 32 security-of-processing and data-protection-by-design obligations, including against video-surveillance system design flaws.
Claims: CLM-BE-d6e7f8a9
Breach NotificationGreen
The standard GDPR Article 33/34 72-hour breach-notification regime applies without Belgian derogation.
Claims: CLM-BE-c5d6e7f8
Retention And DisposalGreen
The Belgian DPA actively enforces storage-limitation principles, ordering retention-period reductions where excessive.
Claims: CLM-BE-e7f8a9b0
Category narrative46 words
Belgian controllers/processors are subject to the full GDPR accountability toolkit: DPIA (with a Belgian DPA-published mandatory-DPIA list), DPO appointment and registration, ROPA, breach notification within 72 hours, security-of-processing obligations, and storage-limitation/retention duties. Joint-controller arrangements follow the GDPR Article 26 baseline with no distinct Belgian overlay identified.
Sources and claims (6)
ConfirmedDataGuidance — The Belgian DPA maintains a published list of processing operations requiring a DPIA, including biometric data collected to uniquely identify data subjects in a public space or a private but publicly accessible area.
ConfirmedDataGuidance — Controllers and processors meeting the GDPR Article 37 designation criteria must appoint a DPO, publish the DPO's contact details, and communicate those details to the Belgian DPA.
ConfirmedDataGuidance — The Belgian DPA found a company in breach of Article 30(1)(a)-(d) GDPR for failing to maintain adequate records of processing activities relating to biometric time-registration data.
ConfirmedEUR-Lex — In the case of a personal data breach, controllers must notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to individuals' rights and freedoms.
ConfirmedEDPB / Belgian DPA — The Belgian DPA fined a controller €1,500 for unlawful processing via a video-surveillance system, finding that camera positioning also infringed the data-protection-by-design principle.
ConfirmedDataGuidance — The Belgian DPA ordered Freedelity to ensure personal data retention does not exceed three years, having found its prior retention period excessive and in breach of the storage-limitation principle.
Transfer mechanisms are fully operative and actively used (BCR lead-authority role, Schrems II guidance); adequacy grant/receipt is not a Member-State-level competence.
Traffic-light rationale — GreenTransfer mechanisms are fully operative and actively used (BCR lead-authority role, Schrems II guidance); adequacy grant/receipt is not a Member-State-level competence.
Sub-modules (6)
Transfer MechanismsGreen
Adequacy decisions, SCCs, BCRs and Article 49 derogations are available under the GDPR baseline as applied in Belgium.
Claims: CLM-BE-f8a9b0c1
Adequacy ReceivedAmber
Adequacy decisions are adopted by the European Commission on behalf of the EU/EEA as a bloc; this is not a Belgium-specific competence.
Belgium does not independently grant adequacy; this is exercised at EU Commission level.
Absence provenance: not recorded. Searched: Belgium adequacy decision granted third country.
Sccs And BcrsGreen
The Belgian DPA acts as lead supervisory authority for Belgian-headquartered groups' Binding Corporate Rules submissions to the EDPB.
Claims: CLM-BE-a9b0c1d2
Transfer Impact AssessmentGreen
Following Schrems II, the Belgian DPA issued guidance on the need for supplementary-measures assessments for third-country transfers.
Claims: CLM-BE-b0c1d2e3
Data LocalisationRed
No Belgium-specific data-localisation mandate beyond the GDPR Chapter V baseline was identified.
Absence provenance: not recorded. Searched: Belgium data localisation law, Belgium data residency requirement personal data.
Category narrative64 words
As an EU Member State, Belgium relies on the EU-level GDPR Chapter V transfer regime: European Commission adequacy decisions, SCCs, BCRs, and Article 49 derogations. Adequacy decisions are granted/received at EU Commission level, not by Belgium individually, and Belgium has no additional data-localisation mandate beyond GDPR baseline. The Belgian DPA has acted as lead authority in BCR approvals and issued post-Schrems II transfer guidance.
Sources and claims (3)
ConfirmedEDPB — Under GDPR Chapter V as applied in Belgium, transfers to third countries may take place on the basis of a European Commission adequacy decision or, absent one, on appropriate safeguards providing enforceable rights and effective legal remedies for data subjects.
ConfirmedEDPB — The Belgian DPA, acting as lead supervisory authority, has submitted draft Binding Corporate Rules decisions for EDPB Article 64 opinion, including for Oregon Tool, Inc. (formerly Blount).
ConfirmedDataGuidance — Following the Schrems II judgment, the Belgian DPA published a statement on 31 August 2020 noting consequences for controllers and processors transferring personal data to third countries.
Traffic-light rationale — AmberStrong, sourced coverage of telecoms and employment overlays; other sectors carry an evidentiary gap requiring escalation.
Sub-modules (7)
Financial Sector OverlayRed
No Belgium-specific financial-sector (FSMA/NBB) data-protection overlay distinct from the GDPR baseline was substantiated.
Absence provenance: not recorded. Searched: Belgium FSMA data protection banking secrecy GDPR, Belgium NBB personal data financial sector.
Health Sector OverlayRed
No Belgium-specific health-sector data-protection overlay distinct from GDPR Article 9 baseline was substantiated.
Absence provenance: not recorded. Searched: Belgium health data law patient rights GDPR, Belgium eHealth platform data protection.
Telecoms And EprivacyGreen
The Belgian DPA jointly enforces GDPR and the Belgian Electronic Communications Act (LCE) against telecoms-adjacent processing such as call recording.
Claims: CLM-BE-c1d2e3f4
Employment DataGreen
Employer monitoring of employee e-communications is governed by CBA No. 81 alongside GDPR, with Belgian DPA guidance on finality, transparency and proportionality.
Claims: CLM-BE-d2e3f4a5
Credit And ScoringRed
No Belgium-specific credit-scoring overlay was substantiated in this pass.
Absence provenance: not recorded. Searched: Belgium credit scoring data protection law.
EducationRed
No Belgium-specific education-sector overlay was substantiated in this pass.
Absence provenance: not recorded. Searched: Belgium education sector student data protection law.
InsuranceRed
No Belgium-specific insurance-sector overlay was substantiated in this pass.
Absence provenance: not recorded. Searched: Belgium insurance sector data protection law.
Category narrative49 words
Sectoral overlays confirmed for Belgium are strongest in telecoms/electronic-communications (Belgian Electronic Communications Act, LCE, applied alongside GDPR) and employment (CBA No. 81 governing employer access to employee e-communications). Financial-sector, health-sector, credit-scoring, education and insurance overlays specific to Belgium were not substantiated in this research pass beyond the GDPR baseline.
Sources and claims (2)
ConfirmedDataGuidance — The Belgian DPA fined water utility SWDE €86,000 (Decision No. 102/2026) for violations of the GDPR and the Belgian Electronic Communications Act (LCE) relating to systematic call recording without valid consent and inadequate transparency to callers and employees.
ConfirmedIAPP — Belgian employers' access to employees' professional e-communications is governed by Collective Bargaining Agreement (CBA) No. 81, which the Belgian DPA has interpreted as requiring compliance with finality, transparency, and proportionality principles rather than reliance on individual employee consent.
Strong enforcement record across cookies, dark patterns, cross-context advertising (TCF) and direct marketing; opt-out-signal and clean-room specifics are thin.
Primary frameworkGDPR plus ePrivacy Directive as transposed via the Belgian Electronic Communications Act (LCE)
Traffic-light rationale — GreenStrong enforcement record across cookies, dark patterns, cross-context advertising (TCF) and direct marketing; opt-out-signal and clean-room specifics are thin.
Sub-modules (6)
Cookies And TrackersGreen
The Belgian DPA acts as lead supervisory authority for major cookie-banner complaints, subject to EDPB oversight on procedural handling.
Claims: CLM-BE-e3f4a5b6
Dark PatternsGreen
The Belgian DPA has sanctioned loyalty-card schemes for coercive consent mechanisms and excessive data collection.
Claims: CLM-BE-a5b6c7d8
Opt Out SignalsRed
No Belgium-specific Global Privacy Control/DAA opt-out-signal enforcement or guidance was located.
Absence provenance: not recorded. Searched: Belgium Global Privacy Control GDPR, Belgian DPA opt-out signal guidance.
Clean Rooms And DcrRed
No Belgium-specific clean-room/data-collaboration-room guidance was located.
Absence provenance: not recorded. Searched: Belgium data clean room guidance GDPR.
Cross Context AdvertisingGreen
The Belgian DPA led the EU-wide finding that IAB Europe's Transparency and Consent Framework violates the GDPR.
Claims: CLM-BE-f4a5b6c7
Direct MarketingGreen
The Belgian DPA's updated Recommendation No. 1/2025 governs lawful bases, consent standards and minors' protections for direct marketing.
Claims: CLM-BE-b6c7d8e9
Category narrative46 words
The Belgian DPA is one of the most active EU regulators in adtech enforcement, having fined IAB Europe over its Transparency and Consent Framework, sanctioned dark-pattern-style loyalty programmes (Freedelity), pursued cookie-banner complaints as lead authority (VRT/NOYB), and issued updated direct-marketing guidance covering consent and legitimate-interest bases.
Sources and claims (4)
ConfirmedEDPB — The EDPB required the Belgian DPA, acting as lead supervisory authority, to reconsider on the merits a NOYB complaint against Belgian public broadcaster VRT concerning cookie banners, after the Austrian DPA objected to the Belgian DPA's proposal to dismiss the complaint on procedural grounds.
ConfirmedIAPP — The Belgian DPA's Litigation Chamber fined IAB Europe €250,000 after finding its Transparency and Consent Framework (TCF) could lead to loss of control over personal information for large groups of citizens, and ordered deletion of personal data already processed within the TCF system.
ConfirmedDataGuidance — The Belgian DPA imposed corrective measures and a daily fine of €5,000 (capped at €100,000) on Freedelity for non-compliant consent mechanisms and excessive data collection via loyalty-card identity-document scanning.
ConfirmedDataGuidance — The Belgian DPA's updated Recommendation No. 1/2025 on direct marketing states that consent and legitimate interest are the primary lawful bases, requires consent to be free, specific, informed and unambiguous, and requires parental consent for marketing directed at children under 13.
Strong sourced coverage on biometric DPIA triggers and state-surveillance carve-outs; profiling/ADM-transparency and genetic-data specifics were not substantiated, and AI risk-assessment rules remain proposals.
Primary frameworkGDPR Article 22 and Title 3 of the Belgian Act of 30 July 2018; EU AI Act (interfacing, not yet Belgium-specific)
Traffic-light rationale — AmberStrong sourced coverage on biometric DPIA triggers and state-surveillance carve-outs; profiling/ADM-transparency and genetic-data specifics were not substantiated, and AI risk-assessment rules remain proposals.
Sub-modules (6)
Profiling RestrictionsRed
No Belgium-specific profiling-restriction enforcement distinct from the GDPR Article 22 baseline was located.
Absence provenance: not recorded. Searched: Belgian DPA profiling decision Article 22, Belgium automated decision-making enforcement.
Automated Decision Making TransparencyRed
No Belgium-specific ADM-transparency enforcement or guidance distinct from GDPR baseline was located.
Absence provenance: not recorded. Searched: Belgian DPA automated decision making transparency guidance.
Ai Risk AssessmentsAmber
EU-level Digital Omnibus proposals addressing GDPR/AI Act interfaces are under EDPB/EDPS review but are not yet binding Belgian or EU law.
Claims: CLM-BE-e9f0a1b2
Biometric RegimeGreen
The Belgian DPA requires a DPIA for biometric data collected to uniquely identify individuals in public or publicly accessible private spaces, and has enforced against unlawful biometric processing.
Claims: CLM-BE-c7d8e9f0
Genetic DataRed
No Belgium-specific genetic-data regime distinct from the GDPR Article 9 baseline was located.
Absence provenance: not recorded. Searched: Belgium genetic data protection law GDPR.
State Surveillance CarveoutsGreen
Title 3 of the Belgian Act creates specific derogations for intelligence/security services, the armed forces, classification/security-clearance processes, the Coordination Unit for Threat Analysis, and passenger-data processing.
Claims: CLM-BE-d8e9f0a1
Category narrative58 words
Belgium applies GDPR Article 22-style profiling/ADM protections at the EU baseline, with the Belgian DPA imposing a mandatory-DPIA requirement for public-space biometric identification. The Belgian Act's Title 3 creates specific carve-outs for intelligence/security services, security clearances, and passenger-data processing. AI-specific risk-assessment obligations are emerging at EU level (Digital Omnibus on AI) but are not yet Belgium-specific binding law.
Sources and claims (3)
ConfirmedDataGuidance — The Belgian DPA's mandatory DPIA list requires a DPIA for biometric data collected to uniquely identify individuals present in a public space or a privately-owned but publicly accessible area.
ConfirmedDataGuidance — Title 3 of the Belgian Data Protection Act specifically addresses processing of personal data by intelligence and security services, the armed forces, classification and security-clearance processes, the Coordination Unit for Threat Analysis, and passenger-data processing, establishing derogations from the general GDPR regime for these activities.
ProbableEDPB/EDPS — On 20 January 2026, the EDPB and EDPS adopted a Joint Opinion on the 'Digital Omnibus on AI', at the European Commission's request, addressing interfaces between the GDPR and AI-related risk-assessment obligations relevant to Member States including Belgium; this remains a legislative proposal, not yet adopted law.
Strong sourced coverage of the age-13 threshold and parental-consent rule; education-settings and dependent-adults sub-modules carry an evidentiary gap.
Primary frameworkBelgian Act of 30 July 2018, Article on children's consent (derogating from GDPR Article 8 default age of 16)
Traffic-light rationale — AmberStrong sourced coverage of the age-13 threshold and parental-consent rule; education-settings and dependent-adults sub-modules carry an evidentiary gap.
Sub-modules (5)
Age VerificationGreen
The Belgian DPA's direct-marketing guidance requires information addressed to children be adapted to the child's age and parental consent obtained below age 13.
Claims: CLM-BE-a1b2c3e4
Parental ConsentGreen
The Belgian Act sets the digital age of consent at 13, below which parental consent is required, derogating from the GDPR default of 16.
Claims: CLM-BE-f0a1b2c3
Minor Profiling BansRed
No Belgium-specific minor-profiling ban distinct from GDPR Recital 38/Article 22 baseline was located.
Absence provenance: not recorded. Searched: Belgium minor profiling ban GDPR, Belgian DPA children profiling guidance.
Education SettingsRed
No Belgium-specific education-settings data-protection rule was substantiated in this pass.
Absence provenance: not recorded. Searched: Belgium school student data protection law GDPR.
Dependent AdultsRed
No Belgium-specific dependent-adults (elderly/incapacitated) data-protection rule was substantiated in this pass.
Absence provenance: not recorded. Searched: Belgium dependent adults data protection vulnerable persons GDPR.
Category narrative41 words
Belgium derogates from the GDPR default by setting the age of digital consent at 13 (rather than 16), with corresponding parental-consent and age-appropriate-information requirements reflected in Belgian DPA direct-marketing guidance. Education-setting-specific and dependent-adult-specific rules were not substantiated in this research pass.
Sources and claims (2)
ConfirmedDataGuidance — The Belgian Data Protection Act sets the age of consent for children's data processing at 13 years, below which parental consent is required, derogating from the GDPR default age of 16.
ConfirmedDataGuidance — The Belgian DPA's direct marketing guidelines require that information addressed to children be adapted to the child's age and that parental consent be obtained for marketing to children under 13.
Robust, judicially-tested enforcement powers with continuous 2026 enforcement activity; capacity/independence concerns are a noted but non-disqualifying risk factor.
Primary frameworkGDPR Articles 58, 77-84 as applied via the Belgian Act of 30 July 2018
Traffic-light rationale — GreenRobust, judicially-tested enforcement powers with continuous 2026 enforcement activity; capacity/independence concerns are a noted but non-disqualifying risk factor.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
The Litigation Chamber may impose fines up to €20m/4% of turnover, subject to appeal before the Market Court.
Claims: CLM-BE-b2c3e4f5
Enforcement Activity IndexGreen
Belgian DPA enforcement activity has been continuous through 2026, including multi-decade-old complaints finally resolved via fines.
Claims: CLM-BE-e5a6b7c8
Regulator Funding And CapacityAmber
The EDPB has previously flagged independence/capacity concerns regarding proposed Belgian legislative reforms affecting DPA oversight.
Claims: CLM-BE-f6a7b8d9
Collective Redress And Class ActionsGreen
The Belgian Act grants both data subjects and the DPA the right to seek cease-and-desist orders, and permits class-action-type proceedings.
Claims: CLM-BE-c3e4f5a6
Private Right Of ActionGreen
Data subjects may seek a judicial remedy directly before Belgian courts in addition to lodging a complaint with the Belgian DPA.
Claims: CLM-BE-d4f5a6b7
Recent Developments 180DGreen
Within the last 180 days, the Belgian DPA issued the Y.NV and SWDE fines, updated its direct-marketing Recommendation, and the EDPB/EDPS adopted Joint Opinions on the Digital Omnibus affecting the GDPR/ePrivacy interface.
Claims: CLM-BE-e5a6b7c8, CLM-BE-a7b8d9e0
Category narrative85 words
The Belgian DPA's Litigation Chamber exercises full GDPR Article 58 investigative and Article 83 sanctioning powers (fines up to €20m or 4% of global turnover), subject to appeal before the Market Court of the Brussels Court of Appeal, which has shown willingness to overturn DPA fines on proportionality grounds. Data subjects and the DPA can seek cease-and-desist orders and class-action-type proceedings are available. Enforcement activity has been continuous through 2026 (Y.NV, SWDE decisions), while EDPB has previously raised independence/capacity concerns over proposed Belgian legislative reforms.
Sources and claims (6)
ConfirmedIAPP — Infringements of basic GDPR principles, including Articles 5 and 6, can be subject to administrative fines of up to €20,000,000 or up to 4% of total worldwide annual turnover, imposed by the Belgian DPA's Litigation Chamber and subject to appeal before the Market Court, part of the Brussels Court of Appeal.
ConfirmedDataGuidance — The Belgian Data Protection Act grants both data subjects and the Belgian DPA the right to obtain a cease-and-desist order, enforceable under forfeiture of a penalty, against infringing controllers, and permits class-action-type proceedings.
ConfirmedEUR-Lex — A data subject may lodge a complaint with a supervisory authority or seek a judicial remedy directly before the competent courts where a controller fails to act on a rights request.
ConfirmedDataGuidance — Between April and May 2026 the Belgian DPA issued multiple enforcement decisions, including an €8,500 fine against Y.NV (Decision 86/2026) for unlawful email retention and an €86,000 fine against SWDE (Decision 102/2026) for unlawful call recording, reflecting continued active enforcement.
ConfirmedIAPP — The EDPB publicly expressed concern that proposed Belgian legislative reforms would strengthen parliamentary oversight over the Belgian DPA, raising independence concerns relevant to the regulator's institutional capacity.
ProbableEDPB/EDPS — On 11 February 2026, the EDPB and EDPS adopted a Joint Opinion raising concerns that the proposed Digital Omnibus Regulation could narrow the GDPR definition of personal data and increase the risk-notification threshold and deadline for data breaches; this remains a legislative proposal, not yet adopted law.
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Belgium
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 37 claim(s), 21 source(s) in the cumulative register.