Skip to content
World Watch/Belgium/Data & Privacy

Data & Privacy · Belgium

Data protection & GDPR compliance in Belgium (2026)

Comprehensive lawCountry index 93 · A+

Belgium shaded by its data & privacy status

Data protection in Belgium: comprehensive law.

FrameworkEU General Data Protection Regulation (Regulation 2016/679) as directly applicable, supplemented by the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data (Framework Act) and the Act of 3 December 2017 establishing the Data Protection Authority (as amended in 2023). Supervised by the Belgian Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit, APD/GBA).

Belgium operates a fully comprehensive, GDPR-based personal data protection regime. The directly applicable GDPR is transposed and supplemented domestically by the Framework Act of 30 July 2018 (which also implements the Law Enforcement Directive 2016/680 and consolidated a previously patchy landscape replacing the 1992 Privacy Act), while the DPA itself is constituted under the Act of 3 December 2017 (amended by Acts of 7 September and 25 December 2023 to reinforce independence and permit third-party appeals). The APD/GBA has published a 2026-2028 Strategic Plan focusing enforcement on large-scale high-risk processing (adtech, data brokers, health, banking, tax databases) and processing of minors' data.

GDPR & data protection in Belgium

In Belgium, data protection is governed by the EU General Data Protection Regulation (GDPR), which applies directly and is enforced by the Data Protection Authority (Gegevensbeschermingsautoriteit / APD).

Framework
the GDPR (Regulation (EU) 2016/679) plus the national data-protection act
Supervisory authority
the Data Protection Authority (Gegevensbeschermingsautoriteit / APD)
Applies to
any organisation processing the personal data of people in Belgium, wherever the organisation is based
Maximum fine
€20 million or 4% of global annual turnover, whichever is higher
Breach notification
within 72 hours of becoming aware, to the supervisory authority
DPO
required for large-scale monitoring or large-scale special-category processing

The GDPR is bloc-wide; Belgium supplements it with a national data-protection act and its own supervisory authority.

GDPR in Belgium: FAQ

Does the GDPR apply in Belgium?

Yes. As an EU/EEA member, Belgium applies the GDPR (Regulation (EU) 2016/679) directly, enforced by the Data Protection Authority (Gegevensbeschermingsautoriteit / APD).

Who enforces data protection law in Belgium?

The Data Protection Authority (Gegevensbeschermingsautoriteit / APD).

What are the GDPR fines in Belgium?

Up to €20 million or 4% of global annual turnover, whichever is higher.

Do you need a Data Protection Officer in Belgium?

A DPO is required where you carry out large-scale monitoring or process special-category data at scale.

How quickly must a data breach be reported in Belgium?

Personal-data breaches must be notified to the supervisory authority within 72 hours of becoming aware.

Key points

Primary national law

The Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data (published in the Belgian Official Gazette on 5 September 2018) supplements the GDPR where national law is required, and transposes Directive (EU) 2016/680 for police/criminal-justice processing. It replaced the Privacy Act of 8 December 1992.

Supervisory authority

The Belgian Data Protection Authority (APD/GBA), established by the Act of 3 December 2017, succeeded the former Commission for the Protection of Privacy on 25 May 2018. It is organized around an Executive Committee plus five operational bodies (General Secretariat, First-Line Service, Knowledge Centre, Inspection Service, and Litigation Chamber), headquartered in Brussels.

2023 reforms to the DPA

The Acts of 7 September 2023 and 25 December 2023 amended the 3 December 2017 DPA Act to strengthen the authority's independence and operational capacity, reform its internal composition, and — following a Belgian Constitutional Court ruling — allow interested third parties to challenge Litigation Chamber decisions.

Enforcement powers and penalties

The APD/GBA wields the full Article 58 GDPR toolkit — warnings, orders, temporary or definitive processing bans, and administrative fines up to €20 million or 4% of worldwide annual turnover (Art. 83 GDPR) — plus periodic penalty payments under Belgian law. A notable domestic limitation is that administrative fines generally cannot be imposed on public-sector bodies except where they offer goods/services on the open market.

2026-2028 enforcement priorities

The APD/GBA's Strategic Plan 2026-2028 targets two priority themes: (i) large-scale high-risk processing — explicitly including advertising technology, cross-border sharing among data brokers, profiling in banking/insurance, health data at hospitals, and tax-authority databases; and (ii) processing of minors' data, backed by specialised DPIA templates. The DPA is also restructuring complaint-handling toward mediation and selective investigation.

Scope and application

The 2018 Framework Act applies to controllers and processors established in Belgium (regardless of where actual processing occurs), and to non-EU controllers/processors that offer goods or services to individuals in Belgium or monitor their behaviour in Belgium, mirroring the GDPR's Article 3 extra-territorial reach.

Timeline - major decisions & events

Nov 1, 2025guidance
Belgian DPA sets 2026-2028 enforcement strategy targeting adtech and minors

Following a November 2025 public consultation, the DPA published its 2026-2028 strategic framework prioritising large-scale high-risk processing (adtech, data brokers, profiling) and the protection of minors' data. It signals where proactive audits will focus.

Chambers Global Practice Guides
Jun 1, 2025guidance
DPA launches centralised data-breach notification portal

The authority introduced a new online portal in June 2025 with a mandatory two-stage process: an initial notification within the GDPR 72-hour window and a detailed follow-up within 21 calendar days. It standardises how controllers report breaches in Belgium.

DLA Piper Data Protection Laws of the World
May 14, 2025decisionofficial
Brussels Market Court issues final ruling in IAB Europe / TCF case

The Market Court annulled the DPA's 2022 decision on procedural grounds but confirmed the substantive findings, that the TC String is personal data and that IAB Europe is a joint controller for TCF processing. The ruling cements GDPR exposure for the online-advertising consent framework.

Belgian Data Protection Authority (APD/GBA)
Mar 7, 2024decision
CJEU rules on IAB Europe's Transparency & Consent Framework (C-604/22)

The Court of Justice of the EU held that a TC String can constitute personal data and that IAB Europe acts as a joint controller for TCF processing. The preliminary ruling, prompted by the Belgian DPA case, reshaped adtech consent practices across the EU.

Hunton (reporting CJEU C-604/22)
Feb 2, 2022enforcementofficial
Belgian DPA fines IAB Europe €250,000 over the TCF

In Decision 21/2022, agreed with 27 other EU authorities, the Litigation Chamber found IAB Europe was a controller lacking a valid legal basis, DPO, DPIA and processing register for its Transparency & Consent Framework, and ordered a compliance action plan. It was a landmark adtech enforcement case.

European Data Protection Board / Belgian DPA
Jul 14, 2020enforcementofficial
DPA imposes record €600,000 fine on Google Belgium

The Litigation Chamber fined Google Belgium for failing to respect a citizen's right to be forgotten and for an opaque delisting request form, the DPA's largest fine at the time. It established the authority's willingness to act against major tech platforms.

European Data Protection Board / Belgian DPA
Sep 5, 2018law
Data Protection Act of 30 July 2018 enters into force

Belgium's framework law implementing GDPR open clauses (derogations and additional requirements) took effect, repealing the 1992 privacy law and ending the coexistence of the old regime with the directly applicable GDPR.

Jones Day
May 25, 2018lawofficial
GDPR becomes enforceable; APD/GBA replaces the Privacy Commission

On the day GDPR became enforceable, the new Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit) succeeded the former Commission for the Protection of Privacy as Belgium's supervisory authority.

Belgian Data Protection Authority (APD/GBA)
Dec 8, 1992law
Law of 8 December 1992 on privacy and processing of personal data

Belgium's foundational data-protection statute (implementing the European data-protection regime of the era) governed personal-data processing for nearly 26 years until it was repealed by the 2018 Act. It established the original privacy-protection framework and the Privacy Commission.

Digital Evidence and Electronic Signature Law Review (translation)

Belgium - other topics

Data & Privacy in other countries

Last verified 8/6/2026 · Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite · State of Technology Regulation 2026 · Explore the full world map →