Law note · Belgium
GDPR Chapter V and Act Article 222, 4, Cross-Border Transfer Restrictions
A transfer of personal data outside the EEA requires an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier.
Belgium adds a criminal offense for the same conduct: Article 222, 4, read verbatim, fines a controller, processor, employee, agent, or competent authority 250 to 15,000 EUR for a Chapter V breach carried out by gross negligence or malicious intent, and the Act of 3 December 2017 Article 100, 14 lets the Litigation Chamber order the suspension of cross-border data flows. No localization mandate was found.
What it asks of an app
- Rely on an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Belgium outside the EEA; a grossly negligent or malicious breach is a criminal offense under Act Article 222, 4.
When LexLint raises it
Declared activities: crawls_web, trains_models
Primary source: Moniteur belge, 5 September 2018, Art. 222, 4 (direct read, verbatim)
Act of 3 December 2017, Art. 100, 14