Skip to the content
Global Data RulesData governance rules, country by country

Belgium

Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Belgium — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Active

For an ordinary business, Belgium follows the normal European rules. Data may leave the country once you have the right paperwork. Belgium adds no general permission step of its own. Three specific areas are much harder. Online gambling operators must run their servers on Belgian soil. Phone and internet companies must keep the connection records they hold for the police inside Europe. And a foreign company with a Belgian branch must keep that branch's accounting records in Belgium.

Data governance in Belgium

The eight things that decide how you handle data about people in Belgium. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. Europe's General Data Protection Regulation reaches any company anywhere in the world that offers goods or services to people in Belgium. It also reaches any company that monitors what they do. There is no minimum size, revenue or number of customers. If your company has no office anywhere in Europe, you must appoint a representative inside Europe. That representative can be contacted and sued. Belgium adds its own layer on top of the European rules. One Belgian choice matters early: a child can consent for themselves from the age of thirteen.

What you have to do here:
Appoint a representative · Get a parent's consent for children

Where the data is allowed to live

In general, yes, with the standard European paperwork. Belgium adds no extra approval of its own. But check your industry before you rely on that. Online gambling companies must keep the servers that run their website and its data in a permanent establishment in Belgium. Telephone and internet companies must keep the subscriber and connection records they hold for the authorities inside the European Union. They must hand them over in Belgium. A foreign company with a Belgian branch must keep that branch's books and receipts in Belgium, at least as a copy. Banking, insurance, health and government work have no Belgian storage-location rule that we could find.

What you have to do here:
Keep the data in the country

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

Use the ordinary European toolkit. If the destination country is on Europe's approved list, nothing more is needed. If it is not, you sign Europe's standard contract clauses. You also check whether local surveillance law undermines them. Large corporate groups can instead get their own internal rules approved. The Belgian regulator does approve them. It signed off one multinational's group rules in May 2026. Belgium adds no national filing, translation or approval step on top.

What you have to do here:
Put a transfer safeguard in place
Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Certification scheme · Approved code of conduct · Explicit consent · Needed for a contract · Legal claims

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The Data Protection Authority, and it is really working. It has a president, five internal bodies and a published register of 1,242 decisions. Of those, 224 were issued in 2025 and 111 in the first seven and a half months of 2026. Its most recent published opinions are dated 17 August 2026, the day before this record was written. Appeals go to the Market Court, a chamber of the Brussels Court of Appeal. That court has published 99 judgments in these cases. Several other regulators enforce alongside it, and they are all staffed.

How long you must keep it — and when to delete it

Some rules make you keep data and others make you delete it. Business records must be kept seven years. You count from the first of January after the year you close the books. Receipts that will never be used as proof against an outsider can go after three years. Phone and internet companies must keep subscriber records for twelve months after the service ends. Going the other way, security camera footage must normally be deleted within one month. Everything else must go once you no longer need it. When a keeping duty and a deletion duty clash, the keeping duty wins. European law expressly lets you refuse an erasure request where the law requires you to hold the data.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep records of how you use data

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Count three deadlines, not one. For a personal data breach you have 72 hours to tell the privacy regulator. For a significant cybersecurity incident there are three steps, if you fall under Belgium's network and information security law. A first warning in 24 hours. The full report in 72 hours. The final report in one month. Trust service providers get 24 hours for that middle step, not 72. Financial firms report separately under Europe's operational resilience rules. The most common failure is missing the 24-hour warning while you are still putting together the 72-hour privacy notification.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things. One: sending personal data abroad without the right safeguards is a crime in Belgium, not just a regulator's fine. A court can order the judgment printed in newspapers at your expense. Two: if a public prosecutor picks up the same facts within two months, the privacy regulator loses the power to punish you. Your risk moves from an administrative file to a criminal one. Three: government bodies in Belgium generally cannot be fined at all under the European rules. A complaint against a public body ends in orders, not money. Four: you may not use the Belgian national identity number without permission from the Interior Minister. Five: security cameras need a notification, an internal register and a one-month deletion rule of their own.

What you have to do here:
Register or notify · Keep records of how you use data · Delete data after a period
What it costs if you get it wrong:
Criminal liability · Fixed maximum fine

What's changing next

The biggest change is a change of style, not of law. The privacy regulator published a three-year plan in December 2025. It says it will stop being driven mainly by complaints and start picking its own targets. It named two priorities: very large data operations that put people at real risk, and anything involving children. Europe adds two dates. From the twelfth of January 2027, cloud providers may no longer charge you to move your data out. And the approval that lets data flow to self-certified American companies is under formal challenge. Watch the quiet powers too. Belgium's telephone-record retention map can be redrawn by a ministerial decree with no consultation.

What to do: Diarise 12 January 2027 — that is the date this changes.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Online gaming

Online gaming data needs a copy kept in the country

Official name: Loi du 7 mai 1999 sur les jeux de hasard, les paris, les etablissements de jeux de hasard et la protection des joueurs, article 43/8 · Gambling Act of 7 May 1999, article 43/8, paragraph 2, 3, inserted by the Act of 10 January 2010 · Act of parliament

In forceA copy must stay

Belgium's hardest storage rule. To hold an online gambling licence, the servers running your website and its data must be in a permanent establishment in Belgium. The penalty is losing the licence, which for an operator is worse than any fine.

In force since 1 January 2011

Enforced by Gaming Commission

How this country controls where data goes: Not allowed

Telecoms

Telecoms data must stay in the country

Official name: Loi du 20 juillet 2022 relative a la collecte et a la conservation des donnees d'identification et des metadonnees dans le secteur des communications electroniques et a la fourniture de ces donnees aux autorites · Act of 20 July 2022, amending articles 126 to 126/3 of the Telecommunications Act of 13 June 2005 · Act of parliament

In forceNo — it stays put

Belgium's telephone and internet operators must keep subscriber and connection records for the authorities inside the European Union and produce them in Belgium. Retention is targeted by geography: a ministerial decree names which judicial districts and police zones are covered, and for how long.

In force since 8 August 2022Enforced from 30 March 2023

Enforced by Belgian Institute for Postal Services and Telecommunications

How this country controls where data goes: Only approved countries · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.

Breach reporting rules

Official name: Loi du 26 avril 2024 etablissant un cadre pour la cybersecurite des reseaux et des systemes d'information d'interet general pour la securite publique / Wet van 26 april 2024 · Act of 26 April 2024 transposing Directive (EU) 2022/2555 (NIS2) · Act of parliament

In forceYes — store it anywhere

Belgium was the first European Union country to write the second network and information security directive into national law. It has no storage-location rule. But it adds a 24-hour cyber alert on top of the 72-hour privacy breach deadline. The two run at the same time.

In force since 18 October 2024

Enforced by Centre for Cybersecurity Belgium

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Children's data rules

Official name: Loi du 30 juillet 2018 relative a la protection des personnes physiques a l'egard des traitements de donnees a caractere personnel / Wet van 30 juli 2018 · Act of 30 July 2018, Belgian Official Journal 5 September 2018 · Act of parliament

In forceYes, with paperwork

Belgium's national data protection act. It sets the digital consent age for children at thirteen. It turns several data protection failures into criminal offences. It shields public authorities from European-level fines. It has no storage-location requirement of its own.

In force since 5 September 2018

Enforced by Data Protection Authority

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

Personal data needs a copy kept in the country

Official name: Loi comptable du 17 juillet 1975, article 1er, alinea 2, recodifiee dans le Code de droit economique · Accounting Act of 17 July 1975, article 1, second paragraph, as read by Accounting Standards Commission Opinion 2010/14 · Act of parliament

In forceA copy must stay

A quiet but real Belgian storage rule that has nothing to do with privacy. If a foreign company runs a Belgian branch, that branch's accounting records must be kept in Belgium, at least as a copy. A Belgian company may centralise its records abroad only if the Belgian office has full online access to them.

In force since 1 January 1976

Enforced by Accounting Standards Commission

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.

Applies across the European Union1 rule

Written once for the whole bloc, and in force in every member country.

General data protection law

Official name: Reglement general sur la protection des donnees / Algemene verordening gegevensbescherming · Regulation (EU) 2016/679 · Directly binding regulation

In forceYes, with paperwork

Europe's data protection rules apply in Belgium directly. They do not require data to stay in Europe. They set conditions on it leaving. Some destination countries are pre-approved. Everything else needs a standard contract or approved group rules.

In force since 25 May 2018

Enforced by Data Protection Authority

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, To save someone’s life, Important public interest

Who you would hear from

  • Autorite de protection des donnees / Gegevensbeschermingsautoriteit (APD/GBA)

    General data protection supervision across all sectors, public and private.

    Fully constituted and busy. President Koen Gorissen. Five internal bodies plus a management committee. 1,242 published decisions to date: 202 in 2024, 224 in 2025 and 111 in the first seven and a half months of 2026. Opinions 179/2026 and 180/2026 are dated 17 August 2026, the day before this record was verified. Rated active rather than aggressive. It publishes many decisions, but fines are modest by European standards. Enforcement is still driven mostly by complaints, although the 2026-2028 strategic plan commits to changing that.

  • Centre pour la Cybersecurite Belgique / Centrum voor Cybersecurity Belgie (CCB)

    National cybersecurity authority and computer security incident response team; supervises the Act of 26 April 2024 transposing the second network and information security directive.

    Operational. It publishes and versions its own notification guide (version 1.3, August 2025). It runs the registration portal for essential and important entities and maintains the CyberFundamentals standards.

  • Institut belge des services postaux et des telecommunications / Belgisch Instituut voor postdiensten en telecommunicatie (IBPT/BIPT)

    Telecoms regulator; supervises operator identification, retention and data-supply duties, and enforces the Data Act and Digital Services Act in its areas.

    Operational and enforcing. It publishes a record of decisions against named operators over subscriber identification failures. It also approves individual identification methods by ministerial decree, most recently for an operator in May 2026.

  • Commission des jeux de hasard / Kansspelcommissie

    Licensing and supervision of games of chance, including the online supplementary licences that carry the Belgian server requirement.

    Operational, issuing licences and publishing news and legislative updates. Its site is heavily protected against automated retrieval, so several pages must be read manually.

  • Banque nationale de Belgique / Nationale Bank van Belgie (BNB/NBB)

    Prudential supervision of banks, insurers, stockbroking firms and payment institutions, including outsourcing and cloud arrangements.

    Operational. Its 2020 circular on outsourcing to cloud service providers remains the national reference, alongside the European Digital Operational Resilience Act. The Bank's website blocks automated retrieval, so we could not read the circular text directly.

  • Autorite des services et marches financiers / Autoriteit voor Financiele Diensten en Markten (FSMA)

    Conduct supervision of financial markets and firms; Belgian competent authority for parts of the Digital Operational Resilience Act.

    Operational and current. Published communication FSMA_2026_15 on the impact of frontier artificial intelligence systems on cyber risk on 15 June 2026, and runs the register of information on third-party technology providers.

  • Commission des normes comptables / Commissie voor Boekhoudkundige Normen (CNC/CBN)

    Issues authoritative opinions on Belgian accounting law, including where books and supporting documents must be kept.

    Operational and publishing. Its opinions are advisory rather than binding, but courts and the tax administration treat them as the standard reading of the accounting rules.

  • Health Data Agency (HDA)

    Federal agency for the secondary use of health and health-related data; Belgium's route into the European Health Data Space.

    Operational, with a published data catalogue, a data request process and an open recruitment page. It governs access to health data for research and policy; it does not impose a hosting-location rule.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • That retained telecom data must sit on European Union territory under the current Act of 20 July 2022.

    We could not confirm this wording against the government's own database. We read it from a private mirror of the Belgian Official Journal instead. The official gazette and consolidated law site, ejustice.just.fgov.be, would not respond on 18 August 2026. The telecoms regulator's own page confirms that articles 126 to 126/3 hold the retention rules, but it does not reproduce the European Union territory wording. Check the official text before you rely on it.

  • The number and date of the Constitutional Court judgment that ruled on the Act of 20 July 2022.

    We could not confirm the judgment number. Media reporting places the judgment on 26 September 2024. The Ministry of Justice confirms the law received an almost complete green light, with some questions sent to the European Court of Justice. Treat that outcome as confirmed and the citation as open.

  • The current value-added-tax retention period for invoices, widely reported as ten years since 2023.

    We could not confirm the current value-added-tax keeping period for invoices. The federal finance ministry's own page blocks automated reading. Only the seven-year accounting period is confirmed here, from the Accounting Standards Commission. Assume the tax period is longer than seven years, and check it before you design a deletion schedule.

  • The registration deadline and maximum fine levels under the Belgian network and information security law of 26 April 2024.

    We could not confirm the registration deadline or the maximum fines under this law. The Centre for Cybersecurity Belgium's frequently-asked-questions document would not open. The notification deadlines are confirmed from the Centre's own notification guide. The registration date and the fine limits are not, so we have not stated them. Ask the Centre if you need these.

  • Whether the Royal Decree implementing the online gambling server requirement has been amended since 2011.

    We could not confirm the current version of the Royal Decree. The requirement itself is confirmed in the Gambling Act, which forces the Royal Decree to contain it as a minimum, so the substance is not in doubt. The Gaming Commission publishes its Royal Decrees only on pages that block automated reading.

  • That there is no Belgian keeping data in the country rule for public-sector cloud.

    We found no rule forcing public-sector cloud data to stay in Belgium, checked 18 August 2026. We could not confirm this either way. We could not download the federal policy and support service's cloud security guideline. The federal G-Cloud offers in-country hosting as a buying option. A buying condition can bind you just as tightly as a law if you bid for government work. Check your tender documents.

  • That the Belgian Data Protection Authority's independence dispute with the European Commission is fully resolved.

    We could not confirm whether the earlier European infringement case about the regulator's independence was formally closed. The regulator is clearly staffed, led and productive today, and that is what our enforcement rating is based on.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.