Belgium Data Protection Act (Wet van 30 juli 2018, Loi du 30 juillet 2018)
Evidence request list. 21 controls, 21 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Belgium DPA Title 1: GDPR Implementation - General Provisions and Principles
Scope and application. Article 2 provides that the Act applies to wholly or partly automated processing of personal data and to non-automated processing of data forming part of a filing system, in implementation of the GDPR.
- Record of processing activities showing systems in scope
- Determination of automated vs non-automated processing
- Analysis of which Title (1 GDPR, 2 LED, 3 police/intelligence) applies
- Processing wrongly scoped out of the Act
- Non-automated filing systems overlooked
- Wrong Title applied to law-enforcement processing
Definitions. Article 5 provides that the definitions of the GDPR apply and defines additional terms for the Act, including 'public authority' (overheid / autorite publique).
- Mapping of GDPR definitions to internal terminology
- Identification of whether the entity is a 'public authority' under the Act
- GDPR definitions not adopted consistently
- Public-authority status misclassified, changing applicable obligations
Implementation of the GDPR. Article 6 provides that, without prejudice to specific provisions, Title 1 of the Act gives effect to the GDPR in Belgian law.
- Documentation that GDPR obligations are operationalised under Title 1
- Register of Belgian specific provisions supplementing the GDPR
- Reliance on the GDPR alone without applying Belgian specific provisions
- Belgian derogations not identified
Processing of a child's personal data. Article 7 implements GDPR Article 8.1, setting the age below which parental consent is required for information society services offered directly to a child (13 years in Belgium).
- Age-verification and parental-consent mechanism for information society services
- Records of consent for child data processing
- Privacy notices written in clear, child-appropriate language
- No age gate or parental consent for under-13s
- Consent not verifiable
- Notices not adapted for children
Special categories of data for substantial public interest. Article 8 implements GDPR Article 9.2.g, designating processing of special-category data necessary for reasons of substantial public interest and the safeguards that apply.
- Register of special-category processing and the substantial-public-interest basis relied on
- Documented appropriate safeguards (access restriction, designation of authorised persons, confidentiality)
- List of categories of persons with access
- Substantial-public-interest basis asserted without the required safeguards
- No list of authorised persons
- Safeguards under Article 9 not documented
Genetic, biometric and health data. Article 9 implements GDPR Article 9.4: when processing genetic, biometric or health data, the controller must designate the categories of persons with access and keep a list of those persons available to the supervisory authority.
- List of categories of persons with access to genetic/biometric/health data
- Confidentiality obligations for authorised persons
- Records demonstrating the list is available to the supervisory authority
- No documented list of authorised persons
- Access not restricted by role
- Confidentiality undertakings missing
Criminal conviction and offence data. Article 10 implements GDPR Article 10, restricting processing of personal data relating to criminal convictions and offences to specified controllers and purposes with safeguards.
- Authority/legal basis for processing criminal-conviction data
- List of categories of persons with access and confidentiality obligations
- Register of criminal-data processing operations
- Processing criminal data without a permitted basis
- No access restriction or authorised-persons list
- Purpose creep beyond the permitted basis
Belgium DPA Title 1: Rights, Restrictions, Impact Assessment and DPO
Processing for journalistic, academic, artistic and literary purposes. Article 24 sets the exemptions and special regime (implementing GDPR Article 85) reconciling data protection with freedom of expression and information.
- Documentation of reliance on the journalistic/academic/artistic/literary exemption
- Assessment that exempted processing is necessary for freedom of expression
- Editorial/internal safeguards applied
- Exemption claimed for processing not serving expression purposes
- No assessment of necessity
- Blanket exemption applied to all processing
Designation of a data protection officer. Article 190 requires the controller to designate a data protection officer where the processing may entail a high risk, with the position and tasks set out in the Act.
- DPO appointment record and published contact details
- DPO independence, resources and reporting line
- Records of DPO involvement in processing decisions and DPIAs
- No DPO where high-risk processing occurs
- DPO lacks independence or resources
- DPO not involved in key processing decisions
Prior consultation and high-risk processing. Article 22 addresses processing that may entail a high risk under GDPR Article 35, requiring impact assessment and, where applicable, prior consultation of the supervisory authority.
- High-risk DPIA records
- Evidence of prior consultation of the supervisory authority where residual high risk remains
- Mitigation measures adopted following the DPIA
- High-risk processing without a DPIA
- Prior consultation skipped despite residual high risk
- Mitigations not implemented
Representation of data subjects. Article 220 implements GDPR Article 80, allowing a data subject to mandate a body, organisation or not-for-profit association to lodge complaints and exercise rights and remedies on their behalf.
- Procedure for handling complaints/requests lodged by a mandated body on behalf of data subjects
- Verification of the mandate
- Records of representative actions and outcomes
- Mandated-body requests not accepted or handled
- No mandate verification
- Representative complaints not tracked
Restrictions on data subject rights. Article 11 implements GDPR Article 23, restricting the application of GDPR Articles 12 to 22 and 34 in defined circumstances (e.g. certain public-authority processing) subject to safeguards.
- Documented legal basis and necessity/proportionality assessment for each restriction
- Records of how and when restrictions are applied and lifted
- Information to data subjects about restrictions where required
- Restrictions applied without a necessity/proportionality assessment
- Restrictions broader than permitted
- Data subjects not informed where required
Specific data protection impact assessment. Article 23 implements GDPR Article 35.10, requiring a specific DPIA for processing carried out under a legal obligation or public-interest task where the law has not already assessed the impact.
- DPIA records for processing under a legal/public-interest basis
- Assessment of necessity and proportionality and of risks to data subjects
- Evidence the DPIA informed the design of the processing
- No DPIA where the general legal assessment did not cover the processing
- DPIA not addressing necessity/proportionality
- DPIA not revisited when processing changes
Belgium DPA Title 2: Law Enforcement Directive Implementation
Transposition of the Law Enforcement Directive. Article 25 opens Title 2, transposing Directive (EU) 2016/680 on the processing of personal data by competent authorities for the prevention, investigation, detection or prosecution of criminal offences.
- Identification of competent authorities and law-enforcement processing within scope of Title 2
- Mapping of LED obligations to internal procedures
- Distinction maintained between Title 1 (GDPR) and Title 2 (LED) processing
- Law-enforcement processing handled under the GDPR Title instead of Title 2
- Competent-authority status not established
- LED-specific obligations omitted
Definitions for law enforcement processing. Article 26 sets the definitions applicable to Title 2 (law-enforcement processing), including personal data, processing, competent authority and related terms.
- Mapping of Title 2 definitions to internal law-enforcement processing terminology
- Identification of competent authorities within scope
- Title 2 definitions not applied to law-enforcement processing
- Competent authority not identified
Information to the data subject (law enforcement). Article 36 requires the competent authority to take appropriate measures to make general information available to data subjects about law-enforcement processing, subject to permitted restrictions.
- General information made available to data subjects about law-enforcement processing
- Documented restrictions on information and their legal basis
- Procedure for specific-case information provision
- No general transparency information for law-enforcement processing
- Restrictions applied without legal basis
- Specific-case information not handled
Personal data in judicial decisions and files. Article 44 governs the processing of personal data contained in judicial decisions and court files within the law-enforcement Title.
- Procedures governing access to and use of personal data in judicial decisions/files
- Restrictions on further processing of such data
- Judicial-file data reused beyond permitted purposes
- No access controls over court-file personal data
Belgium DPA Title 3: Police and Intelligence Oversight
Supervisory authority for police information. Article 71 establishes, within the Chamber of Representatives, the independent Supervisory Body for Police Information (Controleorgaan op de politionele informatie / Organe de controle de l'information policiere) overseeing police and certain intelligence processing.
- Recognition of the competent supervisory body for police/intelligence processing
- Records of cooperation with and reporting to the Supervisory Body for Police Information
- Responses to its inspections and recommendations
- Police processing treated as subject only to the DPA (APD/GBA)
- No engagement with the police-information supervisory body
- Inspection findings not remediated
Belgium DPA: Remedies and Penalties
Corrective powers and administrative fines. Article 221 extends the corrective powers of the supervisory authority under GDPR Article 58.2 (including administrative fines under Article 83) to the additional provisions of the Act.
- Records of supervisory authority corrective measures and any administrative fines
- Evidence of remediation of identified infringements
- Internal tracking of regulator correspondence and orders
- Corrective orders not remediated
- Fine exposure not assessed
- Regulator correspondence not tracked to closure
Criminal penalties. Article 222 provides criminal sanctions (fines, and in defined cases imprisonment) for controllers, processors and their agents for specified infringements of the Act.
- Awareness of criminal-offence provisions among accountable staff
- Controls preventing the conduct criminalised by the Act
- Legal review of potential criminal exposure
- Accountable persons unaware of criminal exposure
- No controls against criminalised conduct
- Criminal-risk not assessed in the compliance programme
Belgium DPA: Research and Archiving Exemptions
Exemptions for archiving, scientific or historical research and statistics. Article 186 sets the exemption regime for data-subject rights (GDPR Article 89) for processing for archiving in the public interest, scientific or historical research, or statistical purposes, subject to appropriate safeguards.
- Documented reliance on the archiving/research/statistics regime
- Appropriate safeguards (minimisation, pseudonymisation) for research/archiving
- Assessment of which data-subject rights are derogated and why
- Research exemption claimed without safeguards
- No minimisation/pseudonymisation
- Derogations broader than necessary
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Belgium Data Protection Act (Wet van 30 juli 2018, Loi du 30 juillet 2018) framework page.