Belgium
Part of the European Union, so bloc-wide rules apply here too. Checked yesterday.
The answer
For an ordinary business Belgium follows the normal European rules: data may leave the country once you have the right paperwork. Belgium adds no general permission step of its own. Three specific areas are much harder. Online gambling operators must run their servers on Belgian soil. Phone and internet companies must keep the connection records they hold for the police inside Europe. And a foreign company with a Belgian branch must keep that branch's accounting records in Belgium.
Data governance in Belgium
The eight things that decide how you handle data about people in Belgium. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. Europe's General Data Protection Regulation reaches any company anywhere in the world that offers goods or services to people in Belgium, or that monitors what they do. There is no minimum size, revenue or number of customers. If your company has no establishment anywhere in Europe you must appoint a representative inside Europe who can be contacted and, in practice, sued. Belgium adds its own layer on top of the European rules, and one Belgian choice matters early: a child can consent for themselves from the age of thirteen.
The national layer is the Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data. Article 7 fixes the digital consent age at 13, the floor the General Data Protection Regulation allows, rather than the 16-year default. Below 13 the legal representative must consent. Article 228 makes the controller, the processor or its representative in Belgium liable for paying fines imposed on their staff or agents, which is unusual drafting and matters when a foreign group relies on a thin Belgian entity. There is no separate Belgian registration, licence or filing before you may process personal data; the only routine filing is notifying your data protection officer's contact details to the regulator.
Sources
- Official sourceAutorite de protection des donnees / GegevensbeschermingsautoriteitAct of 30 July 2018 on the protection of natural persons with regard to the processing of personal data, articles 7 and 228 (official English version)
dataprotectionauthority.be
“the processing of personal data related to children in relation to the offer of information society services directly to a child is lawful where the consent has been given by children who are at least 13 years old.”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), articles 3 and 27
eur-lex.europa.eu
Link checked 18 August 2026
Where the data is allowed to live
In general, yes, with the standard European paperwork, and Belgium adds no extra approval of its own. But check your industry before you believe that. Online gambling companies must keep the servers that run their website and its data in a permanent establishment in Belgium. Telephone and internet companies must keep the subscriber and connection records they hold for the authorities inside the European Union, and must hand them over in Belgium. A foreign company with a Belgian branch must keep that branch's books and receipts in Belgium, at least as a copy. Banking, insurance, health and government work have no Belgian storage-location rule that we could find.
Sector by sector, checked 18 August 2026. GAMBLING: the strictest rule in the country. Article 43/8 of the Gambling Act of 7 May 1999 requires the Royal Decree on supervision of online games to contain, at minimum, the condition that the servers managing the website's data and structure sit in a permanent establishment on Belgian territory. This is a licence condition, so the sanction is losing the licence, not a fine. TELECOM: article 126 of the Telecommunications Act of 13 June 2005, as replaced by the Act of 20 July 2022, obliges operators to retain subscriber identification data and metadata on European Union territory and to supply requested data in Belgium. BANKING, PAYMENTS, INSURANCE, SECURITIES: no localisation rule found. The European Digital Operational Resilience Act has applied since 17 January 2025 and governs; the National Bank of Belgium's 2020 cloud outsourcing circular requires you to know and disclose where data sits and to notify material outsourcing, but does not require Belgian or European storage. The Financial Services and Markets Authority is running active supervision, including a June 2026 communication on frontier artificial intelligence systems and cyber risk. HEALTH: no Belgian equivalent of France's compulsory health-data hosting certification was found. The federal Health Data Agency, created for secondary use of health data, is operational and is Belgium's route into the European Health Data Space. GOVERNMENT: no statutory localisation found; the federal G-Cloud offers in-country hosting as a procurement choice, not a legal duty. EDUCATION, GEOSPATIAL, DEFENCE: no localisation rule found. Remember that Regulation (EU) 2018/1807 forbids member states from imposing localisation on non-personal data except on public-security grounds.
Sources
- Official sourceCommission des jeux de hasard / KansspelcommissieGambling Act of 7 May 1999, article 43/8, paragraph 2, 3 (consolidated text published by the Gaming Commission)
gamingcommission.be
“les modalites de surveillance et de controle des jeux de hasard exploites, qui portent au minimum sur la condition selon laquelle les serveurs sur lesquels les donnees et la structure du site web sont gerees se trouvent dans un etablissement permanent sur le territoire belge”
Link checked 18 August 2026
- Official sourceInstitut belge des services postaux et des telecommunications (BIPT/IBPT)Supply of electronic evidence to the authorities - legal framework for operator data retention (articles 126 to 126/3 of the Telecommunications Act)
ibpt.be
Link checked 18 August 2026
- Official sourceCommission des normes comptables / Commissie voor Boekhoudkundige NormenOpinion CNC 2010/14 - Retention of books and supporting documents, section on place of retention
cnc-cbn.be
“les livres, comptes et pieces justificatives relatifs aux sieges et succursales en Belgique d'entreprises etrangeres doivent etre conserves en Belgique”
Link checked 18 August 2026
- Official sourceFinancial Services and Markets AuthorityThe Digital Operational Resilience Act - Belgian supervisory page, including communication FSMA_2026_15 of 15 June 2026
fsma.be
Link checked 18 August 2026
- Official sourceHealth Data AgencyBelgian Health Data Agency - about us
hda.belgium.be
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2018/1807 on a framework for the free flow of non-personal data
eur-lex.europa.eu
Link checked 18 August 2026
Sending data out of the country
Use the ordinary European toolkit. If the destination country is on Europe's approved list, nothing more is needed. If it is not, you sign Europe's standard contract clauses and check whether local surveillance law undermines them. Large corporate groups can instead get their own internal rules approved, and the Belgian regulator does approve them: it signed off one multinational's group rules in May 2026. Belgium adds no national filing, translation or approval step on top.
The approved-destination list is populated and currently runs to sixteen countries and territories plus the European Patent Organisation. The United States counts only for organisations that have self-certified under the European Union-United States Data Privacy Framework, and that framework is under legal and political pressure: the European Data Protection Board formally wrote to the Commission on 31 July 2026 asking it to examine whether the decision is still valid. It has not been suspended. Treat it as usable but never as your only route. The 2021 standard contractual clauses remain the operative set; the promised new clauses for importers already directly caught by the General Data Protection Regulation are still not adopted. Belgium's own contribution is the sting in the tail: transferring personal data abroad in breach of the European safeguards is a criminal offence under the Act of 30 July 2018, punishable by a fine, and the court may order the judgment printed in newspapers at your expense.
Sources
- Official sourceAutorite de protection des donneesBelgian Data Protection Authority decisions register - including decision 01/2026 of 13 May 2026 approving Kuwait Petroleum controller Binding Corporate Rules, and 11 international transfer decisions
autoriteprotectiondonnees.be
Link checked 18 August 2026
- Official sourceAutorite de protection des donneesAct of 30 July 2018, articles 222 (4) and 225 - criminal fine for unlawful international transfer, and publication of the judgment
dataprotectionauthority.be
“the transfer of personal data to a recipient in a third country or to an international organisation is made in contravention of the safeguards, conditions or exceptions provided for in articles 44 to 49 of the Regulation”
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions - the European Commission's own list of approved destinations
commission.europa.eu
Link checked 18 August 2026
- Official sourceEuropean Data Protection BoardEuropean Data Protection Board letter of 31 July 2026 to Commissioner McGrath on the European Union-United States Data Privacy Framework
edpb.europa.eu
Link checked 18 August 2026
The regulator, and whether it actually acts
The Data Protection Authority, and it is genuinely working. It has a president, five internal bodies and a published register of 1,242 decisions, of which 224 were issued in 2025 and 111 in the first seven and a half months of 2026. Its most recent published opinions are dated 17 August 2026, the day before this record was written. Appeals go to the Market Court, a chamber of the Brussels Court of Appeal, which has published 99 judgments in these cases. Several other regulators enforce alongside it, and they are all staffed.
The Authority was created inside the Chamber of Representatives by the Act of 3 December 2017 and succeeded the old Privacy Commission. Its president is Koen Gorissen. Structurally it has a General Secretariat, a First Line Service, a Knowledge Centre, an Inspection Service and a Litigation Chamber, plus a management committee. Volume is high but individual fines are modest by European standards, which is why the honest rating is active rather than aggressive: this is a regulator that decides a lot of complaints rather than one that hunts large penalties. Its most-cited case, against a digital advertising standards body, was decided in 2022, upheld in substance and annulled on a procedural defect by the Market Court, and remains the reference point for online advertising consent in Europe. Other enforcers: the Centre for Cybersecurity Belgium for the network and information security law, the Belgian Institute for Postal Services and Telecommunications for operators, the Gaming Commission for gambling licences, the National Bank of Belgium and the Financial Services and Markets Authority for financial firms.
Sources
- Official sourceAutorite de protection des donneesDecisions register - 1,242 published decisions, 111 in 2026, 224 in 2025, 202 in 2024, plus 99 Market Court judgments
autoriteprotectiondonnees.be
Link checked 18 August 2026
- Official sourceAutorite de protection des donneesOrganisation of the Data Protection Authority - five bodies, management committee, president Koen Gorissen
autoriteprotectiondonnees.be
Link checked 18 August 2026
- Official sourceAutorite de protection des donneesPublications page showing opinions 179/2026 and 180/2026 of 17 August 2026 - evidence the authority is issuing output today
autoriteprotectiondonnees.be
Link checked 18 August 2026
- Official sourceAutorite de protection des donneesThe Market Court rules in the IAB Europe case - the authority's own announcement
autoriteprotectiondonnees.be
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a floor and a ceiling, and they point in opposite directions. Business records must be kept seven years, counted from the first of January after the year you close the books; receipts that will never be used as proof against an outsider can go after three. Phone and internet companies must keep subscriber records for twelve months after the service ends. In the other direction, security camera footage must normally be deleted within one month, and everything else must go once you no longer need it. When a keeping duty and a deletion duty collide, the keeping duty wins, because European law expressly allows you to refuse an erasure request where a legal obligation requires you to hold the data.
Accounting floor: seven years from 1 January of the year following the closing of the books, three years for supporting documents not intended to serve as evidence against third parties, per the Accounting Act as read by the Accounting Standards Commission. Telecom floors under the Act of 20 July 2022: subscriber identification data for as long as the service is used plus twelve months after it ends; certain traffic data for twelve months from the date of an incoming communication so the sender can be identified; a shorter four-month period for some traffic data of interpersonal communications services; and a reduced six-month period for one category of session data where the operator keeps an alternative identifier. Ceiling: the Camera Act sets a maximum retention of one month in principle for surveillance footage, extendable only in defined cases, alongside a duty to notify the cameras and keep an internal register. A separate value-added-tax retention period for invoices also applies and is longer than the accounting period; we could not verify its current length against an official source and have flagged it.
Sources
- Official sourceCommission des normes comptablesOpinion CNC 2010/14 - seven-year retention of books, three years for documents not serving as proof against third parties
cnc-cbn.be
“Les entreprises belges sont tenues de conserver leurs livres pendant sept ans a partir du premier janvier de l'annee qui suit leur cloture.”
Link checked 18 August 2026
- Official sourceAutorite de protection des donneesSurveillance cameras - one-month maximum retention, notification duty and internal register
autoriteprotectiondonnees.be
“Ici aussi, un delai de conservation maximal de principe d'un mois s'appliquera.”
Link checked 18 August 2026
- Official sourceBIPT/IBPTRetention of subscriber data and metadata - legal framework and implementing decrees
ibpt.be
Link checked 18 August 2026
If something goes wrong
Count three clocks, not one. For a personal data breach you have 72 hours to tell the privacy regulator. For a significant cybersecurity incident, if you fall under Belgium's network and information security law, you have 24 hours for a first warning, 72 hours for the full report, and one month for the final report. Trust service providers get 24 hours for that middle step, not 72. Financial firms report separately under Europe's operational resilience rules. Missing the 24-hour warning while you are still assembling the 72-hour privacy notification is the most common failure.
Belgium was the first European Union member state to transpose the second network and information security directive: the Act of 26 April 2024, in force 18 October 2024. The Centre for Cybersecurity Belgium's own notification guide sets the clocks: early warning within 24 hours of becoming aware of the significant incident; incident notification within 72 hours, or 24 hours for trust service providers; an intermediate report on request of the national computer security incident response team or the sectoral authority; and a final report no later than one month after the incident notification. If the incident is still running, you send progress reports and then a final report within one month of the incident being dealt with. The guide stresses that all these are outer limits: the duty is to notify without undue delay, and the full period is available only in duly justified special circumstances.
Sources
- Official sourceCentre for Cybersecurity BelgiumNIS2 Notification Guide, version 1.3 of August 2025 - 24 hour early warning, 72 hour notification, one month final report
ccb.belgium.be
“within 24 hours of becoming aware of the significant incident”
Link checked 18 August 2026
- Official sourceCentre for Cybersecurity BelgiumNIS2 in Belgium - the Centre for Cybersecurity Belgium's regulatory page
ccb.belgium.be
Link checked 18 August 2026
- Official sourceFinancial Services and Markets AuthorityDigital Operational Resilience Act - separate major incident reporting for financial entities
fsma.be
Link checked 18 August 2026
What catches people out
Five things that are not in the summary. One: sending personal data abroad without the right safeguards is a crime in Belgium, not just a regulator's fine, and a court can order the judgment printed in newspapers at your expense. Two: if a public prosecutor picks up the same facts within two months, the privacy regulator loses the power to punish you, so your risk moves from an administrative file to a criminal one. Three: government bodies in Belgium generally cannot be fined at all under the European rules, so a complaint against a public body ends in orders, not money. Four: you may not use the Belgian national identity number without permission from the Interior Minister. Five: security cameras need a notification, an internal register and a one-month deletion rule of their own.
(1) Article 222 of the Act of 30 July 2018 makes unlawful international transfer, processing without a legal basis, ignoring a regulator's order and obstructing an inspection punishable by a criminal fine of 250 to 15,000 euro, before the statutory multipliers that Belgian criminal law applies to all fines. Article 225 allows publication of the judgment. Article 230 applies Book I of the Criminal Code, which brings corporate criminal liability into play. (2) Article 229, paragraph 2: absent a protocol between the regulator and the prosecution service, the public prosecutor has two months from receiving the report to say a criminal investigation has started; that notification removes the regulator's power to use its corrective powers. (3) Article 221, paragraph 2 disapplies the European fining article to public authorities and their staff, unless the body is a legal person governed by public law that offers products or services on a market. (4) Access to National Register data and use of the National Register number is authorised by the minister responsible for the Interior under the Act of 8 August 1983 as amended in 2018; the old sectoral committee's general authorisations survive but new users must apply. (5) A further trap for telecom operators: article 107/5 of the Telecommunications Act says a foreign operator's use of encryption cannot prevent a Belgian authority's targeted request being executed, and any contract clause obstructing that is void by operation of law.
Sources
- Official sourceAutorite de protection des donneesAct of 30 July 2018, articles 221, 222, 225, 229 and 230 - criminal penalties, publication of judgment, prosecutor pre-emption, public authority carve-out
dataprotectionauthority.be
“Article 83 of the Regulation does not apply to the public authorities or their attendants or authorised representatives, unless it concerns legal persons governed by public law who offer products and services on a market.”
Link checked 18 August 2026
- Official sourceSPF Strategie et Appui (BOSA)General National Register authorisations - access and use of the National Register number authorised by the Minister of the Interior
bosa.belgium.be
“l'acces aux donnees du Registre national est autorise par le ministre ayant l'Interieur dans ses attributions”
Link checked 18 August 2026
- Official sourceAutorite de protection des donneesSurveillance cameras - notification, internal register and one-month retention ceiling
autoriteprotectiondonnees.be
Link checked 18 August 2026
- Official sourceBIPT/IBPTArticle 107/5 of the Telecommunications Act - encryption may not obstruct an authority's request; obstructing contract clauses are void
ibpt.be
“Toute clause contractuelle prise par les operateurs faisant obstacle a l'execution de l'alinea 1er est interdite et nulle de plein droit.”
Link checked 18 August 2026
What's changing next
The biggest change is a change of style, not of law. The privacy regulator published a three-year plan in December 2025 saying it will stop being driven mainly by complaints and start picking its own targets, with two named priorities: very large data operations that put people at real risk, and anything involving children. Europe adds two dates: from the twelfth of January 2027 cloud providers may no longer charge you to move your data out, and the approval that lets data flow to self-certified American companies is under formal challenge. Watch the quiet levers too: Belgium's telephone-record retention map can be redrawn by a ministerial decree with no consultation.
Confirmed and dated: the Data Protection Authority's Strategic Plan 2026-2028 was published on 23 December 2025 and commits to more own-initiative supervision, faster and more accessible dispute handling, and two thematic priorities, large-scale high-risk processing and the personal data of minors. From Europe: the Data Act's hard deadline of 12 January 2027 for zero cloud switching and egress charges; the European Union-United States Data Privacy Framework remains in force but the European Data Protection Board asked the Commission on 31 July 2026 to examine its continued validity, and an appeal against the General Court's Latombe judgment is pending. The Digital Omnibus proposal of 19 November 2025 is not adopted and has no legal effect. DORMANT SWITCHES that can move overnight with no consultation: first, the ministerial decree that names which judicial districts and police zones are subject to telecom data retention and for how long, last remade on 28 March 2024 after an earlier version of 30 March 2023; second, the Royal Decree confirming the threat level across the whole territory, which is the mechanism that widens targeted retention into general nationwide retention; third, the Royal Decree setting online gambling licence conditions, which is where the Belgian server requirement actually lives and can be tightened without primary legislation.
Sources
- Official sourceAutorite de protection des donneesStrategic Plan 2026-2028 - proactive supervision and two priority themes
autoriteprotectiondonnees.be
“L'APD s'efforce egalement d'evoluer vers une politique plus proactive de controle du respect de la reglementation qui soit moins dictee par les plaintes.”
Link checked 18 August 2026
- Official sourceAutorite de protection des donneesThe Data Protection Authority publishes its Strategic Plan 2026-2028, 23 December 2025
autoriteprotectiondonnees.be
Link checked 18 August 2026
- Official sourceBIPT/IBPTImplementing decrees for telecom retention, including the ministerial decree of 28 March 2024 and the Royal Decree of 16 November 2023 confirming the nationwide threat level
ibpt.be
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2023/2854 (Data Act) - cloud switching charges to reach zero on 12 January 2027
eur-lex.europa.eu
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Loi du 7 mai 1999 sur les jeux de hasard, les paris, les etablissements de jeux de hasard et la protection des joueurs, article 43/8
Act of parliament · Gambling Act of 7 May 1999, article 43/8, paragraph 2, 3, inserted by the Act of 10 January 2010
Belgium's hardest storage rule. To hold an online gambling licence, the servers running your website and its data must be in a permanent establishment in Belgium. The penalty is losing the licence, which for an operator is worse than any fine.
Enforced by Gaming Commission
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryThe servers managing the website's data and structure must sit in a permanent establishment on Belgian territory. The law does not expressly ban an additional copy abroad, which is why this is rated as a copy-must-stay rule rather than an absolute ban.
- Register or notifyAn online licence (A+, B+ or F1+) can only be held by the holder of a matching land-based Belgian licence.
What it costs if you get it wrong
- Loss of your licenceBreach of the qualitative and supervision conditions attached to the supplementary online licence
- Criminal liabilityOperating games of chance without a valid licence is a criminal offence under the Gambling Act
Sources
- Official sourceCommission des jeux de hasard / KansspelcommissieGambling Act of 7 May 1999, article 43/8 - consolidated text published by the regulator
gamingcommission.be
“les serveurs sur lesquels les donnees et la structure du site web sont gerees se trouvent dans un etablissement permanent sur le territoire belge”
Link checked 18 August 2026
- Official sourceCommission des jeux de hasard / KansspelcommissieRoyal Decrees under the Gambling Act, including the decrees of 21 June 2011 on online licence conditions and supervision
gamingcommission.be
Link checked 18 August 2026
Loi du 20 juillet 2022 relative a la collecte et a la conservation des donnees d'identification et des metadonnees dans le secteur des communications electroniques et a la fourniture de ces donnees aux autorites
Act of parliament · Act of 20 July 2022, amending articles 126 to 126/3 of the Telecommunications Act of 13 June 2005
Belgium's telephone and internet operators must keep subscriber and connection records for the authorities inside the European Union and produce them in Belgium. Retention is targeted by geography: a ministerial decree names which judicial districts and police zones are covered, and for how long.
Enforced by Belgian Institute for Postal Services and Telecommunications
Transfer model: Allowlist · Accepted routes: Nothing required
What it makes you do
- Keep the data in the countryRetained data must sit on European Union territory, and the operator must supply requested data in Belgium. Belgium itself is not required, but leaving Europe is.
- Keep data for a minimum period — 1 yearSubscriber identification data for as long as the service is used plus twelve months after it ends; twelve months for traffic data on incoming communications; four months for certain interpersonal communications traffic data.
- Secure the data
- Do not hand data to foreign authorities on demandRead the other way round here: a foreign operator's encryption may not obstruct a Belgian authority's targeted request, and contract clauses that obstruct it are void.
What it costs if you get it wrong
- Criminal liabilityBreaches of the Telecommunications Act obligations are criminally sanctionable and are established by the regulator's judicial police officers
- Fixed maximum fineAdministrative measures and fines imposed by the telecoms regulator's Council
Sources
- Official sourceBIPT/IBPTSupply of electronic evidence to the authorities - retention framework, implementing decrees and the encryption rule
ibpt.be
“Arrete ministeriel du 28 mars 2024 portant execution de l'article 126/3, paragraphe 1, de la loi du 13 juin 2005 relatives aux communications electroniques en vue de l'adoption de la liste des arrondissements judiciaires et des zones de police soumises a l'obligation de conservation ainsi que la duree de conservation.”
Link checked 18 August 2026
- Official sourceService public federal JusticeNew data retention law: almost complete green light - ministry statement on the Constitutional Court's ruling upholding most of the 2022 Act
justice.belgium.be
Link checked 18 August 2026
- Secondary sourceetaamb / openjustice.beAct of 20 July 2022, full Official Journal text (private mirror), article 126 paragraph 3
etaamb.openjustice.be
“conservent les donnees sur le territoire de l'Union europeenne et fournissent en Belgique les donnees demandees par une autorite belge”
Link checked 18 August 2026
Loi du 26 avril 2024 etablissant un cadre pour la cybersecurite des reseaux et des systemes d'information d'interet general pour la securite publique / Wet van 26 april 2024
Act of parliament · Act of 26 April 2024 transposing Directive (EU) 2022/2555 (NIS2)
Belgium was the first European Union country to transpose the second network and information security directive. It imposes no storage-location rule, but it adds a 24-hour cyber alarm on top of the 72-hour privacy breach clock, and the two run at the same time.
Enforced by Centre for Cybersecurity Belgium
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — within 24 hoursEarly warning within 24 hours of becoming aware of a significant incident.
- Report cyber incidents — within 72 hoursFull incident notification within 72 hours, reduced to 24 hours for trust service providers.
- Report cyber incidentsFinal report no later than one month after the incident notification; intermediate report on request of the national incident response team or the sectoral authority.
- Secure the data
- Register or notifyEssential and important entities must register with the Centre for Cybersecurity Belgium.
What it costs if you get it wrong
- Percentage of global turnoverAdministrative fines calculated on worldwide turnover, at the levels set by the European directive
- Order to stopSupervisory measures, including temporary suspension of certification or of management functions
Sources
- Official sourceCentre for Cybersecurity BelgiumNIS2 Notification Guide v1.3, August 2025
ccb.belgium.be
“The Law of 26 April 2024 transposes the NIS2 Directive and entered into force on 18th October 2024.”
Link checked 18 August 2026
- Official sourceCentre for Cybersecurity BelgiumNIS2 - Centre for Cybersecurity Belgium
ccb.belgium.be
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Loi du 30 juillet 2018 relative a la protection des personnes physiques a l'egard des traitements de donnees a caractere personnel / Wet van 30 juli 2018
Act of parliament · Act of 30 July 2018, Belgian Official Journal 5 September 2018
Belgium's national data protection act. It fixes the digital consent age for children at thirteen, turns several data protection failures into criminal offences, and shields public authorities from European-level fines. It imposes no storage-location requirement of its own.
Enforced by Data Protection Authority
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What it makes you do
- Get a parent's consent for children — applies at: under 13Belgium chose the lowest age Europe permits. From 13 a child may consent for themselves to information society services.
- Put a transfer safeguard in placeBreaching the European transfer safeguards is a criminal offence here, not only an administrative one.
- Appoint a data protection officer
What it costs if you get it wrong
- Criminal liability: €250 to €15,000 before statutory multipliers — about $17 thousandProcessing without a legal basis, unlawful transfer abroad, ignoring a regulator order, obstructing an inspection
- Criminal liability: €500 to €30,000 before statutory multipliers — about $33 thousandFailing to inform, or wrongly informing, a person about police or intelligence-sourced data about them
- Criminal liability: €100 to €20,000 before statutory multipliers — about $22 thousandSeriously negligent or malicious transfer, or facilitating transfer, outside the European Union without the required conditions in the law-enforcement and intelligence chapters
Sources
- Official sourceAutorite de protection des donneesAct of 30 July 2018 - official English text published by the supervisory authority
dataprotectionauthority.be
“Shall be penalised by means of a fine of two hundred and fifty to fifteen thousand euro in cases where ... the transfer of personal data to a recipient in a third country or to an international organisation is made in contravention of the safeguards, conditions or exceptions provided for in articles 44 to 49 of the Regulation”
Link checked 18 August 2026
- Official sourceLink may be brokenService public federal JusticeConsolidated text of the Act of 30 July 2018 in the Justel database
ejustice.just.fgov.be
Link checked 18 August 2026
Loi comptable du 17 juillet 1975, article 1er, alinea 2, recodifiee dans le Code de droit economique
Act of parliament · Accounting Act of 17 July 1975, article 1, second paragraph, as read by Accounting Standards Commission Opinion 2010/14
A quiet but real Belgian storage rule that has nothing to do with privacy. If a foreign company runs a Belgian branch, that branch's accounting records must be kept in Belgium, at least as a copy. A Belgian company may centralise its records abroad only if the Belgian office has full online access to them.
Enforced by Accounting Standards Commission
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep the data in the countryApplies to Belgian branches and operating seats of foreign companies: the books, accounts and supporting documents must be kept in Belgium, in original or in copy. Processing and data entry may still happen on a computer abroad.
- Keep data for a minimum period — 7 yearsSeven years from 1 January of the year following the closing of the books; three years for supporting documents not intended to serve as evidence against third parties.
- Keep records of processingA Belgian company may hold its records abroad only if the Belgian seat's archives are fully accessible online.
What it costs if you get it wrong
- Criminal liabilityAccounting offences under Belgian company and criminal law
- Fixed maximum fineTax reassessment and administrative fines where records cannot be produced on inspection
Sources
- Official sourceCommission des normes comptables / Commissie voor Boekhoudkundige NormenOpinion CNC 2010/14 - Retention of books and supporting documents, place of retention
cnc-cbn.be
“les entreprises belges sont habilitees a conserver leurs livres, comptes et pieces justificatives a l'etranger, a condition que les archives du siege belge soient completement accessibles en ligne”
Link checked 18 August 2026
Applies across the European Union1 rule
Written once for the whole bloc, and in force in every member country.
Reglement general sur la protection des donnees / Algemene verordening gegevensbescherming
Directly binding regulation · Regulation (EU) 2016/679
Europe's data protection rules apply in Belgium directly. They do not require data to stay in Europe; they set conditions on it leaving. The list of pre-approved destination countries is populated, and everything else needs a standard contract or approved group rules.
Enforced by Data Protection Authority
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk, Important public interest
What it makes you do
- Tell people what you do
- Keep records of processing
- Secure the data
- Assess high-risk projects
- Appoint a data protection officerContact details must be notified to the Belgian Data Protection Authority through its web portal.
- Appoint a local representativeRequired where the company has no establishment in the European Union.
- Put a transfer safeguard in place
- Written vendor contract
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group annual turnoverBreach of basic principles, individual rights or the transfer rules, or defying a regulator order
- Fixed maximum fine: €20 million — about $22 millionSame, where the fixed cap is higher than the turnover figure
- Order to stopOrder to stop processing or suspend a flow of data outside Europe
- Claims by individualsIndividual compensation claims
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679, chapter V
eur-lex.europa.eu
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
That retained telecom data must sit on European Union territory under the current Act of 20 July 2022.
The verbatim wording was read from a private mirror of the Belgian Official Journal, not from the government's own consolidated database. The official gazette and consolidated law site, ejustice.just.fgov.be, timed out or refused every request from this environment on 18 August 2026. The telecoms regulator's own page confirms that articles 126 to 126/3 contain the retention framework but does not reproduce the European Union territory wording.
The number and date of the Constitutional Court judgment that ruled on the Act of 20 July 2022.
Media reporting places it on 26 September 2024 and the Ministry of Justice confirms the law received an almost complete green light with some questions referred to the European Court of Justice, but the judgment number could not be pinned down on the Court's own site within the search budget. Treat the partial-validation outcome as confirmed and the citation as open.
The current value-added-tax retention period for invoices, widely reported as ten years since 2023.
The federal finance ministry's own retention page is protected by an anti-automation gate and could not be read. Only the seven-year accounting period is confirmed here, from the Accounting Standards Commission. Assume the tax period is longer than seven years and check before designing a deletion schedule.
The registration deadline and maximum fine levels under the Belgian network and information security law of 26 April 2024.
The Centre for Cybersecurity Belgium's frequently-asked-questions document returned an access error on every attempt. The notification deadlines are confirmed from the Centre's own notification guide; the registration date and the fine ceilings are not, and have deliberately not been asserted.
Whether the Royal Decree implementing the online gambling server requirement has been amended since 2011.
The requirement itself is confirmed in the Gambling Act, which obliges the Royal Decree to contain it as a minimum, so the substance is not in doubt. The Gaming Commission publishes its Royal Decrees only through pages that block automated retrieval, so the current decree version could not be read.
That there is no Belgian data localisation rule for public-sector cloud.
This is a negative and is recorded as no rule found, checked 18 August 2026, not as a certainty. The federal policy and support service's cloud security guideline could not be downloaded during this run. The federal G-Cloud offers in-country hosting as a procurement option, and a procurement condition can be as binding in practice as a statute for anyone bidding for government work.
That the Belgian Data Protection Authority's independence dispute with the European Commission is fully resolved.
The authority is plainly staffed, led and productive today, which is what the enforcement rating turns on. Whether the earlier European infringement procedure over its independence was formally closed was not verified in this run.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
Belgium versus
Compare