Law note · Belgium
GDPR Articles 33-34, Breach Notification
A controller must notify the GBA/APD within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. No Belgium-specific derogation from this timeline or threshold was found in the Act of 30 July 2018.
A related but distinct power, Act of 3 December 2017 Article 100, 7, lets the Litigation Chamber order that a data subject be informed of a security problem, a corrective power over an Article 34 failure rather than a separate notification duty.
What it asks of an app
- Notify the GBA/APD within 72 hours of becoming aware of a personal-data breach affecting a person in Belgium, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot, processes_biometrics
Primary source: GDPR Arts. 33-34
Act of 3 December 2017, Art. 100, 7