Skip to the content
Global Data RulesData governance rules, country by country

Belgium

Part of the European Union, so bloc-wide rules apply here too. Checked yesterday.

The answer

Depends on your industryWork: HighEnforcement: Active

For an ordinary business Belgium follows the normal European rules: data may leave the country once you have the right paperwork. Belgium adds no general permission step of its own. Three specific areas are much harder. Online gambling operators must run their servers on Belgian soil. Phone and internet companies must keep the connection records they hold for the police inside Europe. And a foreign company with a Belgian branch must keep that branch's accounting records in Belgium.

Data governance in Belgium

The eight things that decide how you handle data about people in Belgium. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. Europe's General Data Protection Regulation reaches any company anywhere in the world that offers goods or services to people in Belgium, or that monitors what they do. There is no minimum size, revenue or number of customers. If your company has no establishment anywhere in Europe you must appoint a representative inside Europe who can be contacted and, in practice, sued. Belgium adds its own layer on top of the European rules, and one Belgian choice matters early: a child can consent for themselves from the age of thirteen.

High confidenceNational rulesAppoint a local representativeGet a parent's consent for children

Where the data is allowed to live

In general, yes, with the standard European paperwork, and Belgium adds no extra approval of its own. But check your industry before you believe that. Online gambling companies must keep the servers that run their website and its data in a permanent establishment in Belgium. Telephone and internet companies must keep the subscriber and connection records they hold for the authorities inside the European Union, and must hand them over in Belgium. A foreign company with a Belgian branch must keep that branch's books and receipts in Belgium, at least as a copy. Banking, insurance, health and government work have no Belgian storage-location rule that we could find.

High confidenceDepends on your industryAllowlistKeep the data in the country

Sending data out of the country

Use the ordinary European toolkit. If the destination country is on Europe's approved list, nothing more is needed. If it is not, you sign Europe's standard contract clauses and check whether local surveillance law undermines them. Large corporate groups can instead get their own internal rules approved, and the Belgian regulator does approve them: it signed off one multinational's group rules in May 2026. Belgium adds no national filing, translation or approval step on top.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesCertification schemeApproved code of conductExplicit consentNeeded for a contractLegal claimsPut a transfer safeguard in place

The regulator, and whether it actually acts

The Data Protection Authority, and it is genuinely working. It has a president, five internal bodies and a published register of 1,242 decisions, of which 224 were issued in 2025 and 111 in the first seven and a half months of 2026. Its most recent published opinions are dated 17 August 2026, the day before this record was written. Appeals go to the Market Court, a chamber of the Brussels Court of Appeal, which has published 99 judgments in these cases. Several other regulators enforce alongside it, and they are all staffed.

High confidenceActive

How long you must keep it — and when to delete it

There is a floor and a ceiling, and they point in opposite directions. Business records must be kept seven years, counted from the first of January after the year you close the books; receipts that will never be used as proof against an outsider can go after three. Phone and internet companies must keep subscriber records for twelve months after the service ends. In the other direction, security camera footage must normally be deleted within one month, and everything else must go once you no longer need it. When a keeping duty and a deletion duty collide, the keeping duty wins, because European law expressly allows you to refuse an erasure request where a legal obligation requires you to hold the data.

High confidenceKeep data for a minimum periodDelete data after a periodKeep records of processing

If something goes wrong

Count three clocks, not one. For a personal data breach you have 72 hours to tell the privacy regulator. For a significant cybersecurity incident, if you fall under Belgium's network and information security law, you have 24 hours for a first warning, 72 hours for the full report, and one month for the final report. Trust service providers get 24 hours for that middle step, not 72. Financial firms report separately under Europe's operational resilience rules. Missing the 24-hour warning while you are still assembling the 72-hour privacy notification is the most common failure.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What catches people out

Five things that are not in the summary. One: sending personal data abroad without the right safeguards is a crime in Belgium, not just a regulator's fine, and a court can order the judgment printed in newspapers at your expense. Two: if a public prosecutor picks up the same facts within two months, the privacy regulator loses the power to punish you, so your risk moves from an administrative file to a criminal one. Three: government bodies in Belgium generally cannot be fined at all under the European rules, so a complaint against a public body ends in orders, not money. Four: you may not use the Belgian national identity number without permission from the Interior Minister. Five: security cameras need a notification, an internal register and a one-month deletion rule of their own.

High confidenceCriminal liabilityFixed maximum fineRegister or notifyKeep records of processingDelete data after a period

What's changing next

The biggest change is a change of style, not of law. The privacy regulator published a three-year plan in December 2025 saying it will stop being driven mainly by complaints and start picking its own targets, with two named priorities: very large data operations that put people at real risk, and anything involving children. Europe adds two dates: from the twelfth of January 2027 cloud providers may no longer charge you to move your data out, and the approval that lets data flow to self-certified American companies is under formal challenge. Watch the quiet levers too: Belgium's telephone-record retention map can be redrawn by a ministerial decree with no consultation.

High confidenceIn forceActive

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Online gaming

Loi du 7 mai 1999 sur les jeux de hasard, les paris, les etablissements de jeux de hasard et la protection des joueurs, article 43/8

Act of parliament · Gambling Act of 7 May 1999, article 43/8, paragraph 2, 3, inserted by the Act of 10 January 2010

In forceA copy must stay

Belgium's hardest storage rule. To hold an online gambling licence, the servers running your website and its data must be in a permanent establishment in Belgium. The penalty is losing the licence, which for an operator is worse than any fine.

In force since 1 January 2011

Enforced by Gaming Commission

Transfer model: Not allowed

High confidence
Telecoms

Loi du 20 juillet 2022 relative a la collecte et a la conservation des donnees d'identification et des metadonnees dans le secteur des communications electroniques et a la fourniture de ces donnees aux autorites

Act of parliament · Act of 20 July 2022, amending articles 126 to 126/3 of the Telecommunications Act of 13 June 2005

In forceNo — it stays put

Belgium's telephone and internet operators must keep subscriber and connection records for the authorities inside the European Union and produce them in Belgium. Retention is targeted by geography: a ministerial decree names which judicial districts and police zones are covered, and for how long.

In force since 8 August 2022But only enforceable from 30 March 2023

Enforced by Belgian Institute for Postal Services and Telecommunications

Transfer model: Allowlist · Accepted routes: Nothing required

Medium confidence

Loi du 26 avril 2024 etablissant un cadre pour la cybersecurite des reseaux et des systemes d'information d'interet general pour la securite publique / Wet van 26 april 2024

Act of parliament · Act of 26 April 2024 transposing Directive (EU) 2022/2555 (NIS2)

In forceYes — store it anywhere

Belgium was the first European Union country to transpose the second network and information security directive. It imposes no storage-location rule, but it adds a 24-hour cyber alarm on top of the 72-hour privacy breach clock, and the two run at the same time.

In force since 18 October 2024

Enforced by Centre for Cybersecurity Belgium

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Loi du 30 juillet 2018 relative a la protection des personnes physiques a l'egard des traitements de donnees a caractere personnel / Wet van 30 juli 2018

Act of parliament · Act of 30 July 2018, Belgian Official Journal 5 September 2018

In forceYes, with paperwork

Belgium's national data protection act. It fixes the digital consent age for children at thirteen, turns several data protection failures into criminal offences, and shields public authorities from European-level fines. It imposes no storage-location requirement of its own.

In force since 5 September 2018

Enforced by Data Protection Authority

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

High confidence

Loi comptable du 17 juillet 1975, article 1er, alinea 2, recodifiee dans le Code de droit economique

Act of parliament · Accounting Act of 17 July 1975, article 1, second paragraph, as read by Accounting Standards Commission Opinion 2010/14

In forceA copy must stay

A quiet but real Belgian storage rule that has nothing to do with privacy. If a foreign company runs a Belgian branch, that branch's accounting records must be kept in Belgium, at least as a copy. A Belgian company may centralise its records abroad only if the Belgian office has full online access to them.

In force since 1 January 1976

Enforced by Accounting Standards Commission

Transfer model: No restriction · Accepted routes: Nothing required

Medium confidence

Applies across the European Union1 rule

Written once for the whole bloc, and in force in every member country.

Reglement general sur la protection des donnees / Algemene verordening gegevensbescherming

Directly binding regulation · Regulation (EU) 2016/679

In forceYes, with paperwork

Europe's data protection rules apply in Belgium directly. They do not require data to stay in Europe; they set conditions on it leaving. The list of pre-approved destination countries is populated, and everything else needs a standard contract or approved group rules.

In force since 25 May 2018

Enforced by Data Protection Authority

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk, Important public interest

High confidence

Who you would hear from

  • Autorite de protection des donnees / Gegevensbeschermingsautoriteit (APD/GBA)

    General data protection supervision across all sectors, public and private.

    Fully constituted and busy. President Koen Gorissen. Five internal bodies plus a management committee. 1,242 published decisions to date: 202 in 2024, 224 in 2025 and 111 in the first seven and a half months of 2026. Opinions 179/2026 and 180/2026 are dated 17 August 2026, the day before this record was verified. Rated active rather than aggressive: high decision volume, modest fines by European standards, and enforcement still largely complaint-driven, although the 2026-2028 strategic plan commits to changing that.

  • Centre pour la Cybersecurite Belgique / Centrum voor Cybersecurity Belgie (CCB)

    National cybersecurity authority and computer security incident response team; supervises the Act of 26 April 2024 transposing the second network and information security directive.

    Operational. Publishes and versions its own notification guide (version 1.3, August 2025), runs the registration portal for essential and important entities and maintains the CyberFundamentals framework.

  • Institut belge des services postaux et des telecommunications / Belgisch Instituut voor postdiensten en telecommunicatie (IBPT/BIPT)

    Telecoms regulator; supervises operator identification, retention and data-supply duties, and enforces the Data Act and Digital Services Act in its areas.

    Operational and enforcing. Maintains a published record of decisions against named operators over subscriber identification failures and authorises individual identification methods by ministerial decree, most recently for an operator in May 2026.

  • Commission des jeux de hasard / Kansspelcommissie

    Licensing and supervision of games of chance, including the online supplementary licences that carry the Belgian server requirement.

    Operational, issuing licences and publishing news and legislative updates. Its site is heavily protected against automated retrieval, so several pages must be read manually.

  • Banque nationale de Belgique / Nationale Bank van Belgie (BNB/NBB)

    Prudential supervision of banks, insurers, stockbroking firms and payment institutions, including outsourcing and cloud arrangements.

    Operational. Its 2020 circular on outsourcing to cloud service providers remains the national reference alongside the European Digital Operational Resilience Act. The Bank's website blocks automated retrieval, so the circular text could not be read directly during this run.

  • Autorite des services et marches financiers / Autoriteit voor Financiele Diensten en Markten (FSMA)

    Conduct supervision of financial markets and firms; Belgian competent authority for parts of the Digital Operational Resilience Act.

    Operational and current. Published communication FSMA_2026_15 on the impact of frontier artificial intelligence systems on cyber risk on 15 June 2026, and runs the register of information on third-party technology providers.

  • Commission des normes comptables / Commissie voor Boekhoudkundige Normen (CNC/CBN)

    Issues authoritative opinions on Belgian accounting law, including where books and supporting documents must be kept.

    Operational and publishing. Its opinions are advisory rather than binding, but courts and the tax administration treat them as the standard reading of the accounting rules.

  • Health Data Agency (HDA)

    Federal agency for the secondary use of health and health-related data; Belgium's route into the European Health Data Space.

    Operational, with a published data catalogue, a data request process and an open recruitment page. It governs access to health data for research and policy; it does not impose a hosting-location rule.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • That retained telecom data must sit on European Union territory under the current Act of 20 July 2022.

    The verbatim wording was read from a private mirror of the Belgian Official Journal, not from the government's own consolidated database. The official gazette and consolidated law site, ejustice.just.fgov.be, timed out or refused every request from this environment on 18 August 2026. The telecoms regulator's own page confirms that articles 126 to 126/3 contain the retention framework but does not reproduce the European Union territory wording.

  • The number and date of the Constitutional Court judgment that ruled on the Act of 20 July 2022.

    Media reporting places it on 26 September 2024 and the Ministry of Justice confirms the law received an almost complete green light with some questions referred to the European Court of Justice, but the judgment number could not be pinned down on the Court's own site within the search budget. Treat the partial-validation outcome as confirmed and the citation as open.

  • The current value-added-tax retention period for invoices, widely reported as ten years since 2023.

    The federal finance ministry's own retention page is protected by an anti-automation gate and could not be read. Only the seven-year accounting period is confirmed here, from the Accounting Standards Commission. Assume the tax period is longer than seven years and check before designing a deletion schedule.

  • The registration deadline and maximum fine levels under the Belgian network and information security law of 26 April 2024.

    The Centre for Cybersecurity Belgium's frequently-asked-questions document returned an access error on every attempt. The notification deadlines are confirmed from the Centre's own notification guide; the registration date and the fine ceilings are not, and have deliberately not been asserted.

  • Whether the Royal Decree implementing the online gambling server requirement has been amended since 2011.

    The requirement itself is confirmed in the Gambling Act, which obliges the Royal Decree to contain it as a minimum, so the substance is not in doubt. The Gaming Commission publishes its Royal Decrees only through pages that block automated retrieval, so the current decree version could not be read.

  • That there is no Belgian data localisation rule for public-sector cloud.

    This is a negative and is recorded as no rule found, checked 18 August 2026, not as a certainty. The federal policy and support service's cloud security guideline could not be downloaded during this run. The federal G-Cloud offers in-country hosting as a procurement option, and a procurement condition can be as binding in practice as a statute for anyone bidding for government work.

  • That the Belgian Data Protection Authority's independence dispute with the European Commission is fully resolved.

    The authority is plainly staffed, led and productive today, which is what the enforcement rating turns on. Whether the earlier European infringement procedure over its independence was formally closed was not verified in this run.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Belgium versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.