Law note · Belgium

GDPR Chapter V and Act Article 222, 4, Cross-Border Transfer Restrictions

cite Regulation (EU) 2016/679, Arts. 44-49, 83(5); Loi du 30 juillet 2018, Art. 222, 4 stage In effect since 2018-09-05 reviewed 2026-08-24

A transfer of personal data outside the EEA requires an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier.

Belgium adds a criminal offense for the same conduct: Article 222, 4, read verbatim, fines a controller, processor, employee, agent, or competent authority 250 to 15,000 EUR for a Chapter V breach carried out by gross negligence or malicious intent, and the Act of 3 December 2017 Article 100, 14 lets the Litigation Chamber order the suspension of cross-border data flows. No localization mandate was found.

What it asks of an app

  • Rely on an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Belgium outside the EEA; a grossly negligent or malicious breach is a criminal offense under Act Article 222, 4.

When LexLint raises it

Declared activities: crawls_web, trains_models

Primary source: Moniteur belge, 5 September 2018, Art. 222, 4 (direct read, verbatim)
Act of 3 December 2017, Art. 100, 14

← Back to the example  ·  Lint your app →