What Belgium Data Protection Act 2018 (Loi du 30 juillet 2018) - GDPR National Implementation requires
Belgium's Act of 30 July 2018 on the Protection of Natural Persons with Regard to the Processing of Personal Data (Loi du 30 juillet 2018 relative à la protection des personnes physiques à l'égard des traitements de données à caractère personnel / Wet van 30 juli 2018 betreffende de bescherming van natuurlijke personen met betrekking tot de verwerking van persoonsgegevens), published in the Belgian Official Gazette (Belgisch Staatsblad / Moniteur Belge) on 5 September 2018, is Belgium's primary national legislation supplementing the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) in Belgium. The GDPR is directly applicable Belgian law by virtue of Belgium's EU membership. Belgium's Act of 30 July 2018 provides national derogations, additions, and specifications for the Belgian GDPR implementation and repeals the prior Belgian Data Protection Act of 8 December 1992. Belgium is home to several EU institutions and international organisations whose data processing activities intersect with Belgian data protection law. Enforcement: Gegevensbeschermingsautoriteit / Autorité de protection des données (GBA/APD - Belgian Data Protection Authority) is Belgium's independent data protection supervisory authority, established by the Act of 3 December 2017. The GBA/APD is Belgium's representative on the European Data Protection Board (EDPB) and participates in the EDPB's one-stop-shop mechanism for cross-border processing. Key Belgian national provisions: (1) Age of digital consent: Belgium has set the age of consent for information society services at 13 years (GDPR Art. 8 permits member states to set between 13 and 16); data subjects under 13 require parental or guardian consent; (2) Employment context - Belgium's Act of 30 July 2018 provides significant provisions on employee data processing, which interact with Belgian labour law, the Act of 3 July 1978 on Employment Contracts, and collective bargaining agreements (CBAs); Belgium has a well-developed system of sector-level CBAs (Collective Labour Agreements / Collectieve arbeidsovereenkomsten - CAO) that govern employment data processing; (3) State security and intelligence - specific provisions for processing by Belgian state security and intelligence services (State Security Service / Veiligheid van de Staat); (4) Journalistic, scientific, and historical processing - exemptions aligned with GDPR Art. 85 and 89; (5) Criminal data - restrictions on private entity processing of criminal conviction data; (6) DPO obligations - public authorities and entities engaged in large-scale processing must appoint a DPO. Fines: GDPR administrative fines apply in Belgium - up to EUR 20 million or 4% of global annual turnover. The GBA/APD has imposed significant fines including against political parties for electoral data processing, telecommunications operators, and digital advertising companies. Belgium's courts have also considered GDPR matters including the Brussels Court of Appeal's landmark judgment on IAB Europe's Transparency and Consent Framework (TCF) and its interaction with GDPR.
Pillar: Data Protection & Privacy · Authority: Gegevensbeschermingsautoriteit / Autorité de protection des données (GBA/APD - Belgian Data Protection Authority) · Version: 1.0.0 · Last updated:
Primary source: https://www.gegevensbeschermingsautoriteit.be/
SHA-256 integrity: 7842c9f8d665a0ef37afdcbbaf3eca34c7e8f0f54f4c948b6a4dd5fccac8a023
Primary Citations — 6 traced to source
- Loi du 30 juillet 2018 relative à la protection des personnes physiques à l'égard des traitements de données à caractère personnel / Wet van 30 juli 2018 betreffende de bescherming van natuurlijke personen met betrekking tot de verwerking van persoonsgegevens (Belgium) - published Belgian Official Gazette 5 September 2018; national derogations: age of digital consent 13 years; trilingual privacy communications required; employment data processing governed additionally by NAR-CAOs No. 68 and No. 81
- EU GDPR (Regulation (EU) 2016/679) - directly applicable in Belgium; fines up to EUR 20 million or 4% of global annual turnover; GBA/APD is Belgium's supervisory authority and EDPB member; 72-hour breach notification under Art. 33; DPIA mandatory for high-risk processing under Art. 35; IAB Europe TCF decision (GBA/APD, February 2022, EUR 250,000 fine) established GDPR requirements for digital advertising consent frameworks
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/be-data-protection-act-2018.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/be-data-protection-act-2018.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/be-data-protection-act-2018
- Back to registry: Browse all 10,099 compliance nodes