BE — Country Profile

Belgium

21TOTAL
21OFFICIAL SOURCES
4TOPIC AREAS
Law / Act6
National Strategy3
Standard / Framework1
Working Paper1
Court Case1
Report1
Other8
05 OCT 2025 · Other

Safeguards for "consent or pay" models in the updated Recommendation (01/2020) on direct marketing

On 10 May 2025, the Data Protection Authority (APD) closes its consultation on the updated recommendation on direct marketing. The update builds on Recommendation 01/2020 and takes into account developments in case law, regulatory decisions and guidance from the European Data Protection Board (EDPB). An addition to the updated Recommendation is the assessment of "consent or pay" models, where users must either consent to data processing for targeted advertising or pay a fee for an ad-free exp...

Official materialNational StrategyOfficial source · autoriteprotectiondonnees.be ↗
17 SEP 2025 · Standard / Framework

Data protection authorities adopted joint statement on building trustworthy data governance frameworks to encourage development of innovative and privacy-protecting AI

Primary source (pcpd.org.hk) dated 17 September 2025 in BE. See linked source for full text.

Official materialData Privacy & Protection ·SandboxOfficial source · pcpd.org.hk ↗
26 JUN 2025 · Other

Data Protection Authority investigation into NOYB complaints

On 26 June 2025, the Litigation Chamber of the Belgian Data Protection Authority (APD) dismissed 16 complaints across five cases filed by NOYB, an Austrian privacy advocacy group, on procedural grounds under the General Data Protection Regulation (GDPR). The APD clarified that Belgian law permits associations to lodge complaints only as representatives of identifiable data subjects, not in their own name. The APD noted that NOYB’s complaints involved automated identification of alleged violat...

Official materialNational StrategyOfficial source · autoriteprotectiondonnees.be ↗
14 MAY 2025 · Law / Act

APD investigation into IAB Transparency and Consent Framework regarding GDPR compliance

On 14 May 2025, the Belgian Market Court ruled in the case between the Belgian Data Protection Authority (DPA) and Interactive Advertising Bureau (IAB) Europe regarding the Transparency and Consent Framework (TCF). The ruling followed the Court of Justice of the European Union's (CJEU) judgment of 7 March 2024 (case C-604/22), which confirmed that the TC String constitutes personal data under the General Data Protection Regulation (GDPR) and designated IAB Europe as a joint data controller. T...

Primary legal sourceNational StrategyOfficial source · dataprotectionauthority.be ↗
10 MAY 2025 · Other

Data protection requirements in the updated Recommendation (01/2020) on direct marketing

On 10 May 2025, the Data Protection Authority (APD) closes its consultation on the updated recommendation on direct marketing. The update is based on Recommendation 01/2020 and takes into account developments in case law, regulatory decisions, and guidance from the European Data Protection Board (EDPB). The revised Recommendation defines terms related to direct marketing, describes the legal basis for processing prospective customer data under the legitimate interest framework, and outlines d...

Official materialNational StrategyOfficial source · autoriteprotectiondonnees.be ↗
10 NOV 2024 · Other

Data Protection Authority investigation into RTL Belgium's cookie banner

On 11 October 2024, The Data Protection Authority issued a decision in case no. 131/2024 regarding a complaint against RTL Belgium’s cookie banner. This complaint was lodged by a representative from Noyb (European Center for Digital Rights), alleging that RTL's cookie banner contravened both the General Data Protection Regulation (GDPR) and Belgian law. The complaint specifically highlighted that RTL's banner did not offer equal choices for users to "Accept All" and "Refuse All" cookies at th...

Official materialNational StrategyOfficial source · gegevensbeschermingsautoriteit.be ↗
18 OCT 2024 · Law / Act

Law establishing a framework for the cybersecurity of networks and information systems of general interest for public security implementing the NIS-2 (2022/2555) Directive

On 18 October 2024, the Act establishing a framework for the cybersecurity of networks and information systems of general interest for public security, enters into force. The Act transposes the Directive (EU) 2022/2555 into national legislation. It mandates entities to register with the Centre for Cybersecurity Belgium and implement technical, operational, and organisational measures to mitigate cybersecurity risks. Finally, the Act outlines penalties for non-compliance.

Primary legal sourceNational StrategyOfficial source · ejustice.just.fgov.be ↗
22 SEP 2024 · Report

Belgium Data Protection Agency publishes report on GDPR and AI Act

Primary source (autoriteprotectiondonnees.be) dated 22 September 2024 in BE. See linked source for full text.

Official materialData Privacy & Protection ·Generative AIOfficial source · autoriteprotectiondonnees.be ↗
19 SEP 2024 · Law / Act

Brochure on Artificial Intelligence Systems and the GDPR

On 19 September 2024, the Belgian Data Protection Authority (ADP) published a Brochure on Artificial Intelligence Systems and the GDPR, which focuses on the interplay between the General Data Protection Regulation (GDPR) and the AI Act following the latter's entry into force on 1 August 2024. In particular, the Brochure highlights the importance of aligning AI systems with data protection principles while addressing challenges related to privacy, transparency, and accountability. Furthermore,...

Primary legal sourceNational StrategyOfficial source · autoriteprotectiondonnees.be ↗
06 SEP 2024 · Other

Data Protection Authority investigation into Roularta Media Group and Google for alleged illegal cross-border data transfer

On 6 September 2024, the Belgian Data Protection Authority (DPA)'s Litigation Chamber dismissed a complaint lodged under Article 80(1) GDPR against Roularta Media Group N.V., a magazine owner, and Google LLC. The complaint, brought forward by Noyb - European Center for Digital Rights, a nonprofit, alleged that personal data was illegally transferred to the US via Google Analytics embedded in the flair.be website owned by Roularta. The case was dismissed because the complaint was found to have...

Official materialNational StrategyOfficial source · autoriteprotectiondonnees.be ↗
15 MAR 2024 · Other

Data Protection Authority investigation into processing of personal information for personalised advertising

On 15 March 2024, the Disputes Chamber of the Data Protection Authority (DPA) issued a ruling in an investigation following a complaint on the processing of personal data, including the content of payment transactions, for building models to offer “personalised discounts”. The ruling states that according to Article 5 of the General Data Protection Regulation (GDPR), processing of personalised data for purposes other than those for which the personal data was initially collected is permitted...

Official materialNational StrategyOfficial source · gegevensbeschermingsautoriteit.be ↗
16 JAN 2024 · Law / Act

GBA investigation into Black Tiger Belgium for alleged GDPR violations

On 16 January 2024, the Belgian Data Protection Authority (GBA) imposed a total of EUR 174'640 in administrative fines and corrective measures on Black Tiger Belgium, a big data and data management company, for multiple breaches of the General Data Protection Regulation (GDPR). The GBA found that the company had unfairly processed personal data without proactively and transparently informing the data subjects. The company was also found to have violated the rights of data subjects and failed ...

Primary legal sourceNational StrategyOfficial source · gegevensbeschermingsautoriteit.be ↗
20 OCT 2023 · Other

Data Protection Authority Cookie Checklist

On 20 October 2023, the Belgian Data Protection Authority (APD) published a cookie checklist directed at organisations to ensure their cookies and other tracking mechanisms policies are in compliance with the law. The APD clarifies that all cookies except strictly necessary ones need consent, and consent has to be given in advance, free, specific, informed, unambiguous, and active.

Official materialNational StrategyOfficial source · autoriteprotectiondonnees.be ↗
24 MAY 2023 · Law / Act

DPA investigation into the transfer of tax data from Belgium to US under Foreign Account Tax Compliance Act compliance with GDPR

On 24 May 2023, the Belgian Data Protection Authority (DPA) Litigation Chamber issued its ruling in the investigation into the transfer of tax data from Belgium to the United States under the Foreign Account Tax Compliance Act (FATCA) compliance with the General Data Protection Regulation (GDPR). The DPA ruled that the FATCA agreement doesn't comply with the GDPR, noting that the transfer of tax data violates the principles principle of purpose, data minimisation and proportionality of GDPR. ...

Primary legal sourceNational StrategyOfficial source · dataprotectionauthority.be ↗
25 MAY 2022 · Other

Data protection investigation regarding cookie use of Roularta Media Group

On 25 May 2022, the Belgian Data Protection Authority (DPA) concluded its investigation of Roularta Media Group for GDPR-compliance by imposing a fine of EUR 50'000. The DPA found that the news websites knack.be and levif.be, which are run by Roularta, violated the GDPR in their cookie use. Specifically, the websites did not comply with the requirement of obtaining prior consent for cookie use from users. Cookies that were not strictly necessary were applied before consent was obtained, viola...

Official materialNational StrategyOfficial source · gegevensbeschermingsautoriteit.be ↗
27 APR 2022 · Court Case

Lawsuit concerning Data Sharing Requirements for Financial Transactions (Airbnb v Brussels-Capital Region)

On 27 April 2022, the Court of Justice of the European Union (CJEU) ruled on Case C-674/20, where the involved parties are Airbnb Ireland and the City of Brussels. Airbnb Ireland alleged that it is illegal for Belgian tax authorities to request tourist accommodation transactions. The CJEU ruled that the request is legal because the data-sharing requirements for the field of taxation differ from requirements that fall under the scope of the e-Commerce Directive.

Court recordNational StrategyOfficial source · curia.europa.eu ↗
01 SEP 2021 · Working Paper

Consultation regarding the recommendations on the processing of biometric data

The Belgian Supervisory Authority (SA) closes its consultation on recommendations regarding the processing of biometric data on September 1, 2021. The consultation period opened on July 15, 2021. The recommendation's stated goal is to instruct data controllers on how to interpret data protection law and in particular the General Data Protection Regulation (GDPR). Specifically, the scope of Art. 9 GDPR is addressed. Finally, the SA recommends a general prohibition of secondary use of biometric...

Official materialNational StrategyOfficial source · autoriteprotectiondonnees.be ↗
20 MAY 2021 · Law / Act

Belgian data protection agency approves transnational GDPR code of conduct

The Code aims to create comparability between different data processing practices in the cloud industry and to improve upon the state of the art for data protection by cloud service providers. It includes data subject rights as well as minimum security and transparency requirements.

Primary legal sourceNational StrategyOfficial source · dataprotectionauthority.be ↗
National Strategy

AI4Belgium (Belgian national AI coalition / roadmap)

AI law in Belgium: AI4Belgium is a national coalition and strategic roadmap initiated to coordinate Belgium’s public-private-academic AI ecosystem, promote responsible adoption, and create an observatory for monitoring AI uptake and ethics. Led by the Federal Public Service for Policy and Support together with regional hubs, industry and research partners, the initiative focuses on skills, trustworthiness, data infrastructures, and alignment with EU AI priorities....

Official materialNational StrategyOfficial source · eur-lex.europa.eu ↗
National Strategy

FARI AI for the Common Good Institute

AI law in Belgium: A Brussels-based institute leveraging AI and robotics for urban common good and public interest through academic-government collaboration.

Official materialNational StrategyOfficial source · digitalskillsjobs.europa.eu ↗
National Strategy

Wallonia DigitalWallonia4.ai Program 2020-2024

AI law in Belgium: The Wallonia DigitalWallonia4.ai Program 2020-2024 is a regional initiative in Belgium accelerating AI adoption and fostering its local AI ecosystem.

Official materialNational StrategyOfficial source · digital-strategy.ec.europa.eu ↗