Data Protection Atlas

Belgium

Tier 2 Comprehensive law Europe

Principal framework: GDPR + Data Protection Framework Act 2018 (2018). Regulator: APD / GBA. Framework Act splits oversight between the APD and sectoral bodies; intelligence-service carve-outs.

At a glance

Criminal offences
Criminal fines only — no custody
Public-sector fines
Effectively no — only public-law bodies operating on the market
Principal law
Loi du 30 juillet 2018 relative à la protection des personnes physiques à l'égard des traitements de données à caractère personnel / Wet van 30 juli 2018 [Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data]
Regulator
Autorité de la protection des données / Gegevensbeschermingsautoriteit (APD-GBA)
Breach notification
72 hours to the supervisory authority (Art 33); undue-delay notice to individuals at high risk
Maximum penalty
Up to €20m or 4% of global annual turnover
DPO required
Public authorities; large-scale regular monitoring or special-category processing (Art 37)
Digital consent age
13
Extraterritorial reach
Yes — targeting or monitoring people in the EU (Art 3(2))
National implementing act
Data Protection Framework Act 2018

Structure

Structural pattern
Not assessed
Sub-jurisdictions
None — no sub-national axis
ISO code
BE

A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.

Transfers and adequacy

EU member
Yes
EEA member
Yes
Holds EU adequacy
Yes

EU/EEA member — intra-EEA transfers need no adequacy decision.

Instruments

No instrument profiled yet.

Also applies here

Directly applicable as EU law, without national transposition. The national act supplements it rather than replacing it.

Sources

Never independently verified — seeded from the prototype.