Skip to content

Evidence request lists

Belgium Data Protection Act (Wet van 30 juli 2018, Loi du 30 juillet 2018)

Evidence request list. 21 controls, 21 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Belgium DPA Title 1: GDPR Implementation - General Provisions and Principles

BE-DPA-1
Scope and application of the Act

Scope and application. Article 2 provides that the Act applies to wholly or partly automated processing of personal data and to non-automated processing of data forming part of a filing system, in implementation of the GDPR.

Artefacts an auditor will ask for
  • Record of processing activities showing systems in scope
  • Determination of automated vs non-automated processing
  • Analysis of which Title (1 GDPR, 2 LED, 3 police/intelligence) applies
Where this commonly fails
  • Processing wrongly scoped out of the Act
  • Non-automated filing systems overlooked
  • Wrong Title applied to law-enforcement processing
BE-DPA-2
Definitions

Definitions. Article 5 provides that the definitions of the GDPR apply and defines additional terms for the Act, including 'public authority' (overheid / autorite publique).

Artefacts an auditor will ask for
  • Mapping of GDPR definitions to internal terminology
  • Identification of whether the entity is a 'public authority' under the Act
Where this commonly fails
  • GDPR definitions not adopted consistently
  • Public-authority status misclassified, changing applicable obligations
BE-DPA-3
Implementation of the GDPR

Implementation of the GDPR. Article 6 provides that, without prejudice to specific provisions, Title 1 of the Act gives effect to the GDPR in Belgian law.

Artefacts an auditor will ask for
  • Documentation that GDPR obligations are operationalised under Title 1
  • Register of Belgian specific provisions supplementing the GDPR
Where this commonly fails
  • Reliance on the GDPR alone without applying Belgian specific provisions
  • Belgian derogations not identified
BE-DPA-4
Processing of a child's personal data

Processing of a child's personal data. Article 7 implements GDPR Article 8.1, setting the age below which parental consent is required for information society services offered directly to a child (13 years in Belgium).

Artefacts an auditor will ask for
  • Age-verification and parental-consent mechanism for information society services
  • Records of consent for child data processing
  • Privacy notices written in clear, child-appropriate language
Where this commonly fails
  • No age gate or parental consent for under-13s
  • Consent not verifiable
  • Notices not adapted for children
BE-DPA-5
Processing of special categories for substantial public interest

Special categories of data for substantial public interest. Article 8 implements GDPR Article 9.2.g, designating processing of special-category data necessary for reasons of substantial public interest and the safeguards that apply.

Artefacts an auditor will ask for
  • Register of special-category processing and the substantial-public-interest basis relied on
  • Documented appropriate safeguards (access restriction, designation of authorised persons, confidentiality)
  • List of categories of persons with access
Where this commonly fails
  • Substantial-public-interest basis asserted without the required safeguards
  • No list of authorised persons
  • Safeguards under Article 9 not documented
BE-DPA-6
Genetic, biometric and health data safeguards

Genetic, biometric and health data. Article 9 implements GDPR Article 9.4: when processing genetic, biometric or health data, the controller must designate the categories of persons with access and keep a list of those persons available to the supervisory authority.

Artefacts an auditor will ask for
  • List of categories of persons with access to genetic/biometric/health data
  • Confidentiality obligations for authorised persons
  • Records demonstrating the list is available to the supervisory authority
Where this commonly fails
  • No documented list of authorised persons
  • Access not restricted by role
  • Confidentiality undertakings missing
BE-DPA-7
Processing of criminal conviction and offence data

Criminal conviction and offence data. Article 10 implements GDPR Article 10, restricting processing of personal data relating to criminal convictions and offences to specified controllers and purposes with safeguards.

Artefacts an auditor will ask for
  • Authority/legal basis for processing criminal-conviction data
  • List of categories of persons with access and confidentiality obligations
  • Register of criminal-data processing operations
Where this commonly fails
  • Processing criminal data without a permitted basis
  • No access restriction or authorised-persons list
  • Purpose creep beyond the permitted basis

Belgium DPA Title 1: Rights, Restrictions, Impact Assessment and DPO

BE-DPA-10
Processing for journalistic, academic, artistic and literary purposes

Processing for journalistic, academic, artistic and literary purposes. Article 24 sets the exemptions and special regime (implementing GDPR Article 85) reconciling data protection with freedom of expression and information.

Artefacts an auditor will ask for
  • Documentation of reliance on the journalistic/academic/artistic/literary exemption
  • Assessment that exempted processing is necessary for freedom of expression
  • Editorial/internal safeguards applied
Where this commonly fails
  • Exemption claimed for processing not serving expression purposes
  • No assessment of necessity
  • Blanket exemption applied to all processing
BE-DPA-12
Designation of a data protection officer

Designation of a data protection officer. Article 190 requires the controller to designate a data protection officer where the processing may entail a high risk, with the position and tasks set out in the Act.

Artefacts an auditor will ask for
  • DPO appointment record and published contact details
  • DPO independence, resources and reporting line
  • Records of DPO involvement in processing decisions and DPIAs
Where this commonly fails
  • No DPO where high-risk processing occurs
  • DPO lacks independence or resources
  • DPO not involved in key processing decisions
BE-DPA-15
Prior consultation and high-risk impact assessment

Prior consultation and high-risk processing. Article 22 addresses processing that may entail a high risk under GDPR Article 35, requiring impact assessment and, where applicable, prior consultation of the supervisory authority.

Artefacts an auditor will ask for
  • High-risk DPIA records
  • Evidence of prior consultation of the supervisory authority where residual high risk remains
  • Mitigation measures adopted following the DPIA
Where this commonly fails
  • High-risk processing without a DPIA
  • Prior consultation skipped despite residual high risk
  • Mitigations not implemented
BE-DPA-21
Representation of data subjects

Representation of data subjects. Article 220 implements GDPR Article 80, allowing a data subject to mandate a body, organisation or not-for-profit association to lodge complaints and exercise rights and remedies on their behalf.

Artefacts an auditor will ask for
  • Procedure for handling complaints/requests lodged by a mandated body on behalf of data subjects
  • Verification of the mandate
  • Records of representative actions and outcomes
Where this commonly fails
  • Mandated-body requests not accepted or handled
  • No mandate verification
  • Representative complaints not tracked
BE-DPA-8
Restrictions on data subject rights

Restrictions on data subject rights. Article 11 implements GDPR Article 23, restricting the application of GDPR Articles 12 to 22 and 34 in defined circumstances (e.g. certain public-authority processing) subject to safeguards.

Artefacts an auditor will ask for
  • Documented legal basis and necessity/proportionality assessment for each restriction
  • Records of how and when restrictions are applied and lifted
  • Information to data subjects about restrictions where required
Where this commonly fails
  • Restrictions applied without a necessity/proportionality assessment
  • Restrictions broader than permitted
  • Data subjects not informed where required
BE-DPA-9
Specific data protection impact assessment

Specific data protection impact assessment. Article 23 implements GDPR Article 35.10, requiring a specific DPIA for processing carried out under a legal obligation or public-interest task where the law has not already assessed the impact.

Artefacts an auditor will ask for
  • DPIA records for processing under a legal/public-interest basis
  • Assessment of necessity and proportionality and of risks to data subjects
  • Evidence the DPIA informed the design of the processing
Where this commonly fails
  • No DPIA where the general legal assessment did not cover the processing
  • DPIA not addressing necessity/proportionality
  • DPIA not revisited when processing changes

Belgium DPA Title 2: Law Enforcement Directive Implementation

BE-DPA-11
Transposition of the Law Enforcement Directive

Transposition of the Law Enforcement Directive. Article 25 opens Title 2, transposing Directive (EU) 2016/680 on the processing of personal data by competent authorities for the prevention, investigation, detection or prosecution of criminal offences.

Artefacts an auditor will ask for
  • Identification of competent authorities and law-enforcement processing within scope of Title 2
  • Mapping of LED obligations to internal procedures
  • Distinction maintained between Title 1 (GDPR) and Title 2 (LED) processing
Where this commonly fails
  • Law-enforcement processing handled under the GDPR Title instead of Title 2
  • Competent-authority status not established
  • LED-specific obligations omitted
BE-DPA-16
Definitions for law enforcement processing

Definitions for law enforcement processing. Article 26 sets the definitions applicable to Title 2 (law-enforcement processing), including personal data, processing, competent authority and related terms.

Artefacts an auditor will ask for
  • Mapping of Title 2 definitions to internal law-enforcement processing terminology
  • Identification of competent authorities within scope
Where this commonly fails
  • Title 2 definitions not applied to law-enforcement processing
  • Competent authority not identified
BE-DPA-17
Information to be made available to the data subject (law enforcement)

Information to the data subject (law enforcement). Article 36 requires the competent authority to take appropriate measures to make general information available to data subjects about law-enforcement processing, subject to permitted restrictions.

Artefacts an auditor will ask for
  • General information made available to data subjects about law-enforcement processing
  • Documented restrictions on information and their legal basis
  • Procedure for specific-case information provision
Where this commonly fails
  • No general transparency information for law-enforcement processing
  • Restrictions applied without legal basis
  • Specific-case information not handled
BE-DPA-18
Personal data in judicial decisions and court files

Personal data in judicial decisions and files. Article 44 governs the processing of personal data contained in judicial decisions and court files within the law-enforcement Title.

Artefacts an auditor will ask for
  • Procedures governing access to and use of personal data in judicial decisions/files
  • Restrictions on further processing of such data
Where this commonly fails
  • Judicial-file data reused beyond permitted purposes
  • No access controls over court-file personal data

Belgium DPA Title 3: Police and Intelligence Oversight

BE-DPA-19
Supervisory authority for police information

Supervisory authority for police information. Article 71 establishes, within the Chamber of Representatives, the independent Supervisory Body for Police Information (Controleorgaan op de politionele informatie / Organe de controle de l'information policiere) overseeing police and certain intelligence processing.

Artefacts an auditor will ask for
  • Recognition of the competent supervisory body for police/intelligence processing
  • Records of cooperation with and reporting to the Supervisory Body for Police Information
  • Responses to its inspections and recommendations
Where this commonly fails
  • Police processing treated as subject only to the DPA (APD/GBA)
  • No engagement with the police-information supervisory body
  • Inspection findings not remediated

Belgium DPA: Remedies and Penalties

BE-DPA-13
Corrective powers and administrative fines

Corrective powers and administrative fines. Article 221 extends the corrective powers of the supervisory authority under GDPR Article 58.2 (including administrative fines under Article 83) to the additional provisions of the Act.

Artefacts an auditor will ask for
  • Records of supervisory authority corrective measures and any administrative fines
  • Evidence of remediation of identified infringements
  • Internal tracking of regulator correspondence and orders
Where this commonly fails
  • Corrective orders not remediated
  • Fine exposure not assessed
  • Regulator correspondence not tracked to closure
BE-DPA-14
Criminal penalties

Criminal penalties. Article 222 provides criminal sanctions (fines, and in defined cases imprisonment) for controllers, processors and their agents for specified infringements of the Act.

Artefacts an auditor will ask for
  • Awareness of criminal-offence provisions among accountable staff
  • Controls preventing the conduct criminalised by the Act
  • Legal review of potential criminal exposure
Where this commonly fails
  • Accountable persons unaware of criminal exposure
  • No controls against criminalised conduct
  • Criminal-risk not assessed in the compliance programme

Belgium DPA: Research and Archiving Exemptions

BE-DPA-20
Exemptions for archiving, research and statistics

Exemptions for archiving, scientific or historical research and statistics. Article 186 sets the exemption regime for data-subject rights (GDPR Article 89) for processing for archiving in the public interest, scientific or historical research, or statistical purposes, subject to appropriate safeguards.

Artefacts an auditor will ask for
  • Documented reliance on the archiving/research/statistics regime
  • Appropriate safeguards (minimisation, pseudonymisation) for research/archiving
  • Assessment of which data-subject rights are derogated and why
Where this commonly fails
  • Research exemption claimed without safeguards
  • No minimisation/pseudonymisation
  • Derogations broader than necessary
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Belgium Data Protection Act (Wet van 30 juli 2018, Loi du 30 juillet 2018) framework page.