Monsiegesocial Logo

GDPR for SMEs in Belgium: obligations and penalties

GDPR in Belgium: what a small business must do (records of processing, DPO, security), what fines the DPA can impose, and how to reach compliance.

L

L'équipe Monsiegesocial

Published on 29 septembre 20269 min read
Verified official sources
Safes fitted with keys and locks, symbolising the protection of personal data

Key takeaways

  • The GDPR (Regulation (EU) 2016/679, applicable since 25 May 2018) applies to any Belgian SME that processes personal data, with no headcount or turnover threshold.
  • The Belgian law of 30 July 2018 complements the regulation and organises the powers of the Data Protection Authority (DPA), which is competent to control and sanction.
  • The record of processing activities (Art. 30 GDPR) remains mandatory for nearly every SME: the exemption under 250 employees falls away as soon as processing is not occasional or presents a risk.
  • The Data Protection Officer (DPO) is only mandatory in specific cases (Art. 37 GDPR): large-scale monitoring of individuals, or large-scale processing of sensitive data.
  • Sanctions can reach 20 million euros or 4% of worldwide turnover (Art. 83 GDPR), and any risky data breach must be notified to the DPA within 72 hours.

GDPR for SMEs in Belgium is not reserved for large companies or digital businesses. Since it came into application on 25 May 2018, Regulation (EU) 2016/679 applies to any organisation, including an SME with only a few employees, as soon as it manages a customer file, payroll, or a CCTV camera at the entrance of its premises. Many owners still believe their size shields them from checks: this guide covers the concrete obligations, the cases where a record or a DPO are genuinely required, and the sanctions the Data Protection Authority can impose.

The GDPR is a European regulation, therefore directly applicable in all member states without needing a substantive transposition law. Belgium nevertheless adopted the law of 30 July 2018 on the protection of individuals with regard to the processing of personal data, which settles the points left to member states: national margins of manoeuvre, special regimes (health, research), and the organisation of the supervisory authority.

That authority is the Data Protection Authority (DPA), created by the law of 3 December 2017, replacing the former Commission for the Protection of Privacy. The DPA receives complaints, conducts investigations, and can impose sanctions ranging from a warning to an administrative fine.

Which SMEs are covered, and for which processing activities

No Belgian SME escapes the GDPR because of its size. The trigger is not headcount or turnover, but the existence of processing of personal data, a broad concept covering the collection, storage, consultation, or deletion of any information relating to an identified or identifiable natural person.

A typical Belgian SME processes personal data under several headings at once: its customers and prospects (invoicing, newsletter, after-sales service), its staff (contract, payroll, appraisal), its suppliers and partners (professional contacts), and sometimes visitors or the public (CCTV, a contact form on a website). The scale of activity affects the extent of the measures to take, never their principle: an SME with no employees that only manages a customer file remains subject to the same substantive obligations as an SME with staff, from the very first processing activity.

The concrete obligations of a GDPR-compliant SME

Complying with the GDPR is not a single box to tick, but the durable organisation of several obligations that fit together.

A legal basis for each processing activity. Article 6 of the GDPR requires justifying each processing activity on one of six exhaustively listed grounds: consent, performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a task carried out in the public interest, or the legitimate interests of the controller. For a customer file, this is generally performance of the contract; for a newsletter, consent.

Informing the data subjects. Articles 13 and 14 require informing, at the point of collection, of the identity of the controller, the purposes, the legal basis, any recipients, and the retention period. A privacy policy accessible on the SME's website generally covers this obligation.

Respecting individuals' rights. Access, rectification, erasure, restriction, objection, and portability (Articles 15 to 22) must be exercisable through a simple request, with a response within one month.

  1. 1

    Map out the processing activities

    Step 1

    List all the company's personal data processing: customers, HR, marketing, CCTV, IT subcontractors.

  2. 2

    Identify the legal basis of each processing activity

    Step 2

    Document why each processing activity is lawful under Article 6 of the GDPR.

  3. 3

    Build the record of processing activities

    Step 3

    Formalise, for each processing activity, the purposes, categories of data, recipients, and retention periods (Art. 30 GDPR).

  4. 4

    Secure the data and plan for breaches

    Step 4

    Put in place proportionate technical and organisational measures (Art. 32) and a 72-hour notification procedure in case of an incident.

  5. 5

    Draft the information notices and processor contracts

    Step 5

    Update the privacy policy, the wording on forms, and contractually secure the providers who process data on behalf of the SME (Art. 28).

Record of processing and DPO: what actually applies to an SME

Two obligations come up most often in questions from SME owners, because the regulation provides exemptions for them whose real scope is often misunderstood.

The record of processing activities (Article 30 of the GDPR) is in principle required of every controller. An exemption exists for organisations with fewer than 250 employees, but it disappears as soon as the processing presents a risk to individuals' rights and freedoms, is not occasional, or concerns special categories of data (health, origin, opinions) or criminal data. An SME that manages its staff's payroll carries out non-occasional processing: it therefore remains subject to the record requirement, regardless of its headcount.

The Data Protection Officer (DPO, Article 37) follows a different logic: it is only mandatory for public authorities, or for organisations whose core activity involves regular and systematic monitoring of individuals on a large scale, or large-scale processing of sensitive or criminal data. An SME providing standard services (retail, craft trades, consulting) generally does not fall under these criteria and has no legal obligation to appoint a DPO, without this exempting it from the other substantive obligations.

€20M

or 4% of worldwide turnover

Fine ceiling for breaches of the fundamental principles (Art. 83.5 GDPR)

€10M

or 2% of worldwide turnover

Fine ceiling for other breaches, including records and security (Art. 83.4 GDPR)

72h

notification window

Maximum window to notify a risky data breach to the DPA (Art. 33 GDPR)

Sanctions: what the Data Protection Authority can do

The Data Protection Authority does not only hold the power to fine. Article 58 of the GDPR gives it a range of corrective powers: a warning, a formal notice to comply within a given period, an order to satisfy data subjects' requests, temporary or permanent limitation of processing, and even suspension of data flows to a third country.

The administrative fine, provided for by Article 83, is added to these measures in the most serious cases or in the event of persistent non-compliance. The ceilings (20 million euros or 4% of worldwide annual turnover, or 10 million euros or 2%, depending on the nature of the breach) are legal maximums: the DPA takes into account, when setting the actual amount, the gravity, duration, intentional character, mitigating measures taken, and the size of the company. A sanctioned SME is not fined at the same level as a large group for a comparable breach, but it remains exposed to the principle of the sanction itself.

Priorities for an SME starting its compliance work

  • Keep a record of processing activities up to date

    Even as a simple table: purposes, categories of data, recipients, retention periods for each processing activity.

  • Publish a clear privacy policy

    Accessible on the website and given to staff, covering the points required by Articles 13 and 14.

  • Secure access to data

    Passwords, encryption, access limited to what is strictly necessary, regular backups.

  • Frame IT subcontractors contractually

    A processing agreement compliant with Article 28 with every provider that hosts or processes data on behalf of the SME.

  • Plan a breach management procedure

    Who to alert, how to document the incident, how to meet the 72-hour deadline towards the DPA when the risk requires it.

A project to build in from the start of the company's structure

GDPR compliance is easier to build when it is thought through from the creation of the company, at the moment when invoicing, HR management, and customer relationship processes are being set up, rather than bolted onto practices already in place. A clearly identified registered office and a structured administrative organisation also make it easier to keep the record of processing up to date and to respond to requests from the DPA or from data subjects.

Structure your company on solid foundations from the start

Monsiegesocial supports company creation and domiciliation in Belgium, with an administrative organisation ready to integrate your regulatory obligations.

Going further

Frequently asked questions

What is the GDPR and since when has it applied in Belgium?

The GDPR is Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, directly applicable in all member states since 25 May 2018. In Belgium, it is complemented by the law of 30 July 2018 on the protection of individuals with regard to the processing of personal data, which notably organises the powers of the Data Protection Authority.

Are all Belgian SMEs covered by the GDPR?

Yes. The GDPR applies to any organisation, regardless of size, as soon as it processes personal data: a customer file, staff management, commercial prospecting, or CCTV. There is no headcount or turnover threshold below which an SME would be exempt from the regulation's substantive obligations.

Must an SME appoint a Data Protection Officer (DPO)?

Not systematically. Article 37 of the GDPR requires a DPO for public authorities, and for organisations whose core activity involves either regular and systematic monitoring of individuals on a large scale, or large-scale processing of special categories of data or data relating to criminal convictions. An SME outside these cases may appoint a DPO voluntarily, or assign the function internally or to an external provider without a legal obligation to do so.

Is the record of processing activities mandatory for an SME with fewer than 250 employees?

Article 30(5) of the GDPR provides an exemption for organisations with fewer than 250 employees, but it is narrow: it no longer applies as soon as the processing is likely to result in a risk to the rights and freedoms of the data subjects, is not occasional, or concerns special categories of data or data relating to criminal convictions. In practice, almost every SME (staff management, regular customers) falls outside the exemption and must keep a record.

What does an SME risk in case of GDPR non-compliance?

Article 83 of the GDPR sets two ceilings for administrative fines. For breaches of the most structural obligations (legal bases, data subject rights, international transfers), the fine can reach 20 million euros or 4% of total worldwide annual turnover of the preceding financial year, whichever is higher. For other breaches (records, security, breach notification), the ceiling is 10 million euros or 2% of worldwide turnover. The Belgian Data Protection Authority also has non-financial corrective powers: warnings, formal notice, and temporary limitation of processing.

What should be done in case of a personal data breach (leak, hacking)?

Article 33 of the GDPR requires notifying any personal data breach to the Data Protection Authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of the data subjects. When the risk is high, Article 34 additionally requires informing the data subjects directly, without undue delay.

You might also like