What Is Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data?
Belgium’s governing federal statute is the Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data. It was promulgated on 30 July 2018 and published on 5 September 2018. Several amendments were located through 2024, but the official Justel consolidated record could not be retrieved and the 2 June 2024 amendment was identified only indirectly. Article-level currentness therefore remains an open blocker, not a confirmed finding that no later amendments exist. The Act supplements the GDPR with targeted rules for intelligence, security, judicial, police, financial-intelligence, customs, passenger-information, and joint-database processing, plus qualified expression and research derogations. Complaints involve the First Line Service, Inspection Service, and Litigation Chamber. Belgium has a 2024 Black Tiger Belgium enforcement precedent involving a data broker, but no dedicated broker-only deletion procedure was located.
At a glance
- Full name
- Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data
- Short code
- Belgian Data Protection Act
- Jurisdiction
- Belgium
- Enacted
- 2018
- Last major update
- Directly located amendments run through 16 May 2024; an Act of 2 June 2024 was identified indirectly through a later Royal Decree. The official Justel consolidated record was not retrieved, so article-level currentness and the amendment inventory remain provisional
- Regulator
- Belgian Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit)
- Private right of action
- Limited
Scope, who Belgian Data Protection Act covers
Protected data
Data subject rights
Right to transparent information and facilitated exercise of rights
Right to information at collection or where data are obtained indirectly
Right of access, normally including a free copy
Right to rectification
Right to erasure subject to exceptions
Right to restriction of processing
Right to data portability
Right to object, including an absolute objection to direct marketing
Right to withdraw consent
Right to complain to the Belgian Data Protection Authority
Right to judicial remedies under GDPR Articles 78-79
Notable features
Belgium’s complaint structure distinguishes the First Line Service, Inspection Service, and Litigation Chamber rather than treating the DPA as one undifferentiated decision-maker. The Act also contains sector-specific GDPR Article 23 restrictions, a qualified expression regime, research and archiving derogations, National Register-number controls, and a federal/community/regional competence split. The official consolidated text could not be retrieved, so currentness claims must remain qualified.
Enforcement & penalties
Penalties: The GDPR Article 83 administrative-fine framework applies through the Belgian DPA Act. Article 221(2) excludes GDPR fines for public authorities and their agents or mandataries, except public-law legal persons offering goods or services on a market; this is not a general exemption for all controllers. Separate criminal fines apply only to specified offences: €250-€15,000, €500-€30,000, €200-€10,000, €100-€10,000, or €100-€20,000 depending on the unlawful processing, disclosure, confidentiality, security, supervisory, transfer, or research violation under Articles 222-227.
Private right of action: GDPR judicial remedies under Articles 78-79 alongside the APD/GBA complaint route are the identified mechanisms. A dedicated private action for data-broker deletion was not identified; the broker-related route described is an ordinary GDPR rights request followed, where necessary, by an APD complaint.
Relevance to data brokers
No Belgium-specific data-broker registry, broker-only deletion portal, or public-record-specific complaint route was located. The ordinary route is to request access, source information, rectification, erasure, restriction, or objection and complain to the APD/GBA if necessary. The APD reported a 2024 administrative-fine decision against Black Tiger Belgium after access requests and transparency/source-access concerns; this is enforcement precedent, not a dedicated broker-specific procedure.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Is Belgium’s Act of 30 July 2018 fully current?+
The official Justel consolidated record could not be retrieved. Several amendments were located through 2024, including one identified indirectly through a later Royal Decree, so the amendment inventory remains provisional and article-level currentness is not confirmed.
Who handles a privacy complaint in Belgium?+
The First Line Service receives complaints and may mediate, the Inspection Service investigates, and the Litigation Chamber is the administrative contentious decision-maker. Complaints must be written, dated, signed, and submitted in French, Dutch, or German; anonymous complaints are exceptional.
Does Belgium have a dedicated data-broker deletion portal?+
Not located. The available route is an ordinary GDPR request for access, source information, rectification, erasure, restriction, or objection, followed where necessary by an APD/GBA complaint. The Black Tiger Belgium decision is enforcement precedent, not a dedicated broker procedure.
Official sources & citations
Other international privacy regimes
Belgian Data Protection Act sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
