Law / Belgium

Belgium

privacy

Belgium's private-sector personal-data regime is the General Data Protection Regulation (GDPR) as given domestic effect by the Act of 30 July 2018, with the supervisory structure sitting in a separate Act of 3 December 2017.

Reading the Act of 30 July 2018 end to end in the official bilingual gazette confirms three Belgium-specific additions: a criminal-offense chapter at Title 6, Chapter II, an Article 9 access-designation and confidentiality duty for genetic, biometric, and health data, and a switch turning off GDPR Article 83 fines for most public authorities.

On biometrics the GBA/APD has a dedicated recommendation and one Litigation Chamber decision on the merits, which fined an employer 45,000 EUR for fingerprint-based workplace time registration; it has nothing at all on voiceprints.

16 instruments named 10 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Biometric privacy

Act of 30 July 2018 Article 9 and GBA/APD Biometric Recommendation and Enforcement

cite Loi du 30 juillet 2018, Art. 9; GBA/APD Aanbeveling nr. 01/2021; GBA/APD Beslissing ten gronde nr. 114/2024 stage In effect since 2018-09-05 source GBA/APD Aanbeveling nr. 01/2021 (direct read, full text)

Belgium has no dedicated biometric-identifier statute; a biometric identifier is General Data Protection Regulation (GDPR) Article 9(1) special-category data, plus Act Article 9's access-designation and confidentiality duties. GBA/APD Recommendation 01/2021, read in full, concludes there is at present a lacuna in Belgian law such that any biometric authentication processing lacking explicit consent, other than eID and passport processing, has no legal basis.

Litigation Chamber Decision 114/2024, read in full, fined an employer 45,000 EUR for fingerprint-based workplace time registration, holding that employee consent failed the power-imbalance analysis and that record-keeping and DPIA duties were also breached.

The GBA/APD's own publication search returns zero results for voice recognition and 16 results for facial recognition, none of them a decision, so Belgium has no facial-recognition Litigation Chamber decision and no voiceprint guidance at all, established from the regulator's own index rather than an inference.

What it asks of an app

Breach notification

GDPR Articles 33-34, Breach Notification

cite Regulation (EU) 2016/679, Arts. 33-34 stage In effect since 2018-05-25 source GDPR Arts. 33-34

A controller must notify the GBA/APD within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. No Belgium-specific derogation from this timeline or threshold was found in the Act of 30 July 2018.

A related but distinct power, Act of 3 December 2017 Article 100, 7, lets the Litigation Chamber order that a data subject be informed of a security problem, a corrective power over an Article 34 failure rather than a separate notification duty.

What it asks of an app

Comprehensive regime

Act of 30 July 2018 on the Protection of Natural Persons with regard to Personal Data

cite Loi du 30 juillet 2018 relative a la protection des personnes physiques a l'egard des traitements de donnees a caractere personnel (numac 2018040581) stage In effect since 2018-09-05 source Moniteur belge, 5 September 2018, and the consolidated Justel text (both direct read)

Belgium gives the General Data Protection Regulation (GDPR) domestic effect through the Act of 30 July 2018, published in the Moniteur belge 5 September 2018, read end to end in the official bilingual gazette text. Article 6 states Title 1 executes the Regulation; the Act sets the digital-consent age at 13 (Art. 7), designates public-interest processing categories under GDPR Article 9(2)(g) (Art. 8), and adds criminal-conviction-data grounds (Art. 10).

The supervisory structure sits in a separate statute, the Act of 3 December 2017. The Act has been amended four times on the Justel record, most recently in 2024.

What it asks of an app

Cross border transfer

GDPR Chapter V and Act Article 222, 4, Cross-Border Transfer Restrictions

cite Regulation (EU) 2016/679, Arts. 44-49, 83(5); Loi du 30 juillet 2018, Art. 222, 4 stage In effect since 2018-09-05 source Moniteur belge, 5 September 2018, Art. 222, 4 (direct read, verbatim)

A transfer of personal data outside the EEA requires an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier.

Belgium adds a criminal offense for the same conduct: Article 222, 4, read verbatim, fines a controller, processor, employee, agent, or competent authority 250 to 15,000 EUR for a Chapter V breach carried out by gross negligence or malicious intent, and the Act of 3 December 2017 Article 100, 14 lets the Litigation Chamber order the suspension of cross-border data flows. No localization mandate was found.

What it asks of an app

Data subject rights

Act of 30 July 2018 Title 5, Action en Cessation, and GDPR Article 22

cite Loi du 30 juillet 2018, Arts. 11-17, 209-211, 220; Regulation (EU) 2016/679, Art. 22 stage In effect since 2018-09-05 source Moniteur belge, 5 September 2018, Arts. 11-17, 209-211, 220 (direct read, verbatim)

General Data Protection Regulation (GDPR) Articles 12-23 govern access, rectification, erasure, restriction, portability, objection, and the Article 22 right against solely automated decision-making; Belgium adds no sector-specific automated-decision rule beyond that baseline.

What the Act adds, read verbatim, is a domestic enforcement route: Title 5's action en cessation lets the president of the court of first instance, sitting as in summary proceedings, order the cessation of processing that violates the data-protection rules, with standing confined to the data subject and the supervisory authority (Art. 211).

Article 220 implements GDPR Article 80, letting a data subject mandate a qualifying body active in data protection for at least three years to lodge a complaint on their behalf.

What it asks of an app

Enforcement supervision

Act of 30 July 2018 Title 6 Chapter II, Criminal Sanctions

cite Loi du 30 juillet 2018, Arts. 222-230 stage In effect since 2018-09-05 source Moniteur belge, 5 September 2018, Title 6, Chapter II, Arts. 222-230 (direct read, verbatim)

Title 6, Chapter II, read verbatim article by article, is Belgium's criminal chapter for data-protection violations, distinct from the Act of 3 December 2017's supervisory structure: Article 222 fines a controller, processor, employee, agent, or competent authority 250 to 15,000 EUR on fourteen enumerated grounds including processing without a legal basis and obstructing the supervisory authority; Article 224 fines a member or staffer of the supervisory authority 200 to 10,000 EUR for breaching confidentiality; Article 227 fines 100 to 20,000 EUR on five grounds including using assault, violence, or threats to compel a person's processing authorization; and Article 229 governs the overlap between administrative and criminal routes.

What it asks of an app

Act of 3 December 2017, GBA/APD and Litigation Chamber

cite Loi du 3 decembre 2017 portant creation de l'Autorite de protection des donnees (numac 2017031916) stage In effect since 2018-05-25 source Act of 3 December 2017, Arts. 32, 33, 100 (direct read, verbatim)

The Act of 3 December 2017, enacted 3 December 2017 and in force 25 May 2018, creates the Gegevensbeschermingsautoriteit / Autorite de Protection des Donnees (GBA/APD) and its Chambre Contentieuse / Geschillenkamer (Litigation Chamber, Art. 32). Article 100, read verbatim, lists sixteen measures the Chamber may take, from dismissing a complaint to imposing administrative fines, suspending cross-border data flows, and transferring a file to the public prosecutor. Appeal lies to the Marktenhof.

What it asks of an app

Code de Droit Economique Article XVII.37, 10 degrees/1, Collective Redress for GDPR Claims

cite Code de droit economique, Art. XVII.37, 10 degrees/1, as inserted by the Loi du 30 juillet 2018 portant dispositions diverses en matiere d'Economie (numac 2018031589), Art. 43 stage In effect since 2018-05-25 source Act of 30 July 2018 on various economic provisions, Arts. 43, 104 (direct read, verbatim)

General Data Protection Regulation (GDPR) Article 82 arms an individual data subject to claim damages directly.

Belgium separately added the GDPR to the Code of Economic Law's collective redress action, Book XVII, Title 2: Article 43(a) of the Act of 30 July 2018 on various economic provisions, read verbatim, inserted point 10 degrees/1 naming Regulation (EU) 2016/679 into Article XVII.37's list of instruments whose breach can found a collective redress action, and Article 104 of the same act gives that insertion retroactive effect from 25 May 2018.

This session could not read Article XVII.37's complete current list directly (the Code's own consolidated text truncates before Book XVII), so confidence is high on the GDPR's inclusion and low on the article's present overall shape.

What it asks of an app

Sensitive categories

Act of 30 July 2018 Article 10/1, Recorded Commercial Communications

cite Loi du 30 juillet 2018, Art. 10/1, as inserted by the Act of 21 December 2021, article 255 stage In effect since 2022-01-10 source Moniteur belge, 5 September 2018, Art. 10/1 (direct read, verbatim)

Article 10/1, read verbatim, permits recording an electronic communication and its traffic data in lawful commercial transactions as proof, on condition the parties are informed of the recording, its precise purposes, and the storage period before the recording, with data erased at the latest when the transaction can no longer be challenged in court.

Paragraph 2 separately permits listening to and recording calls solely to monitor service quality in call centres, on prior information to staff, with a maximum retention of one month. This is the Belgian provision most likely to bind a voice-recording product, distinct from the biometric rules above.

What it asks of an app

Act of 30 July 2018 Articles 8-10, Special-Category Processing Grounds

cite Loi du 30 juillet 2018, Arts. 8-10 stage In effect since 2018-09-05 source Moniteur belge, 5 September 2018, Arts. 8-10 (direct read, verbatim)

General Data Protection Regulation (GDPR) Article 9(1) lists biometric data processed for unique identification as a special category. Article 9 of the Act, read verbatim, requires every controller processing genetic, biometric, or health data to designate the categories of staff with access, keep that list available to the supervisory authority, and bind those staff to confidentiality.

Article 8, paragraph 1's final subparagraph outright prohibits genetic and biometric processing for unique identification by the specific associations and foundations it authorizes under Article 9(2)(g), absent particular legal provisions. Article 10, paragraph 1, point 6 makes processing of criminal-conviction data manifestly made public by the data subject a lawful-basis ground, not a scope exclusion.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.