HomeBlogGDPR Compliance for Belgian Companies: Duties and Fines
Back to blog
Legal Services

GDPR Compliance for Belgian Companies: Duties and Fines

GDPR compliance is not optional for a Belgian company. Record of processing, privacy notices, DPO, impact assessments, data breaches and DPA fines: here is a practical action plan.

12 March 20265 min read
Share :
GDPR Compliance for Belgian Companies: Duties and Fines
Photo: Ales Nesetril on Unsplash

GDPR compliance: a duty for every company

The General Data Protection Regulation has applied since 25 May 2018. It reaches every company that processes data about individuals: clients, prospects, employees or suppliers. In Belgium, the Act of 30 July 2018 supplements it. The Data Protection Authority (DPA) supervises these rules. Solid GDPR compliance therefore avoids sanctions and reassures your clients.

This guide covers the principles, the practical duties and an eight-step action plan. For day-to-day file security, also read our guide to personal data in your business.

The seven principles

GDPR compliance rests on seven principles.

1Lawfulness, fairness and transparency: inform people clearly.
2Purpose limitation: collect for a specific goal.
3Data minimisation: keep only what you need.
4Accuracy: keep information up to date.
5Storage limitation: set a retention period.
6Integrity and confidentiality: secure the data.
7Accountability: be able to demonstrate your GDPR compliance at any time.

Each processing activity also needs a legal basis: consent, contract, legal obligation, vital interests, public interest task or legitimate interest. Without a legal basis, the processing stays unlawful.

The practical duties

Record of processing activities

The exemption for companies with fewer than 250 people stays narrow. It falls away as soon as processing becomes regular, carries a risk or involves sensitive data. In practice, almost every company therefore keeps a record. The record lists at least the following items.

  • The purposes of each processing activity.
  • The categories of data and of individuals.
  • The recipients, including outside the European Union.
  • Retention periods.
  • Security measures.

This record forms the backbone of your GDPR compliance.

Informing individuals

A clear privacy notice states the controller's identity, the purposes, the legal bases, the recipients and the retention periods. It also sets out the rights: access, rectification, erasure, portability and objection. Finally, it mentions the right to complain to the DPA.

Have you received an access request? You generally have one month to reply.

Data Protection Officer (DPO)

Appointing a DPO becomes mandatory in three cases.

  • You are a public authority or body.
  • Your core activity involves regular and systematic monitoring on a large scale.
  • You process sensitive data, such as health data, on a large scale.

In other cases, an internal or external contact person remains useful. The DPO can work in-house or as an external provider.

Data protection impact assessment (DPIA)

High-risk processing requires a prior impact assessment. This applies in particular to the following cases.

  • Profiling with significant effects on people.
  • Large-scale processing of sensitive data.
  • Systematic monitoring of a publicly accessible area.
  • New technologies that carry risk.

Processors

Your accountant, your hosting provider or your email tool process data on your behalf. The Regulation then requires a processing agreement. It sets the instructions, confidentiality, security and what happens to the data when the service ends. Our guide to commercial contracts covers this clause.

Data breaches

After a leak, a hack or a loss, notify the DPA within 72 hours if the breach creates a risk. Also inform the individuals concerned if the risk looks high. Finally, document every breach, even minor ones, in an internal log.

DPA sanctions

The Data Protection Authority holds wide powers.

  • Warnings and reprimands.
  • Orders to restore GDPR compliance within a deadline.
  • Temporary or permanent limits on processing.
  • Administrative fines.

Fines can reach €10 million or 2% of worldwide annual turnover. For the most serious breaches, the ceiling rises to €20 million or 4%. The amount depends on the seriousness, the duration and the company's cooperation.

Beyond fines, a complaint damages client trust. GDPR compliance therefore protects your reputation too.

Action plan: GDPR compliance in eight steps

1Map all your processing activities.
2Draw up the record of processing.
3Check the legal basis of each activity.
4Write or update your privacy notice.
5Sign agreements with your processors.
6Set up a procedure for requests from individuals.
7Secure the data: access, encryption, backups.
8Train your team and appoint a DPO if needed.

Review this plan every year. A new tool, a new file or a new hire changes your GDPR compliance.

Example: an online cosmetics shop

Claire runs an online shop in Ghent with three employees. First, she lists her processing: orders, newsletter, customer service and payroll. Next, she notes that the newsletter relies on consent and adds an unticked box. Then she signs processing agreements with her hosting provider and her email tool. Finally, she sets a retention period for inactive customer accounts.

Six months later, a customer asks for access to his data. Thanks to her procedure, Claire replies within a week. Her GDPR compliance fits in one clear, up-to-date file.

Common mistakes

  • Copying a privacy notice without adapting it.
  • Forgetting employee and applicant data.
  • Keeping files with no retention period.
  • Using a tool outside the European Union without checking transfers.
  • Waiting for a complaint before acting.

In summary

GDPR compliance rests on a record, clear information, processor agreements and a fast response to breaches. Start with the mapping, then move step by step. For the wider protection of your business, read our guide to legal protection for your company. The Data Protection Authority also publishes useful templates. With Juristelo, budget these actions in your financial plan.

Share :

Work with your own figures

Juristelo builds your financial plan and business plan from your answers. You get a file ready for your bank.

See the Juristelo plans