Belgian Privacy Commission Issues Priorities and Thematic Dossier to Prepare for GDPR
Time 3 Minute Read

On September 16, 2016, the Belgian Data Protection Authority (the “Privacy Commission”) published a 13-step guidance document (in French and Dutch) to help organizations prepare for the EU General Data Protection Regulation (“GDPR”).

The 13 steps recommended by the Privacy Commission are summarized below.

  • Awareness. Inform key persons and decision makers about the upcoming changes in order to assess the consequences of the GDPR on the company or organization.
  • Internal Records. Document what personal data is stored, where it came from and with whom it is shared. Record data processing activities and consider undertaking an information audit.
  • Privacy Notice. Review existing privacy notices and update them to comply with the GDPR.
  • Individuals’ Rights. Review current procedures to comply with individuals’ rights, including any procedures to delete or transfer personal data electronically.
  • Access Requests. Update existing procedures to address access requests and plan how individuals’ access requests will be handled within the new time limits imposed by the GDPR.
  • Legal Basis. Document data processing activities and identify the appropriate legal basis to carry out each type of data processing activity.
  • Consent. Review how consent is sought, collected and recorded, and ensure that procedures comply with the new requirements of the GDPR.
  • Children’s Personal Data. Develop mechanisms to verify the ages of individuals and gather parental or legal guardian consent for processing activities that involve children’s data.
  • Data Breach. Ensure appropriate procedures are in place to detect, investigate and report data breaches.
  • Data Protection by Design and Data Protection Impact Assessments. Become familiar with the concepts of Data Protection by Design and Data Protection Impact Assessment, and determine how to implement them within the organization.
  • Data Protection Officer. Appoint a Data Protection Officer (“DPO”), if required, or someone to take responsibility for data protection compliance. Review the position within the organization’s structure and governance arrangements.
  • International. Determine which data protection supervisory authority will be responsible for supervising your organization’s compliance with the GDPR.
  • Existing Contracts. Review existing contracts, in particular with data processors, and make the necessary changes to comply with the GDPR.

In addition, the Privacy Commission also published a thematic dossier on the GDPR (in French and in Dutch), split into three categories: (1) for data controllers, (2) for data processors, and (3) for individuals (to be published soon). For each category, the Privacy Commission offers a detailed overview of the GDPR’s fundamental principles and main concepts, including sanctions, scope of application, individuals’ rights, one-stop-shop mechanism, data transfers, accountability, appointment of a DPO, data security and data breach notifications. In addition, the thematic dossier will also include a FAQ section that collates the most frequently asked questions submitted by individuals and stakeholders via an online form.

You May Also Be Interested In

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 2 Minute Read

On February 23, 2026, a Joint Statement on AI-Generated Imagery was published by 61 data protection authorities. The Joint Statement addresses concerns regarding AI systems capable of generating realistic images and videos depicting identifiable individuals without their knowledge or consent.

Time 6 Minute Read

On February 9, 2026, trade association NetChoice filed a lawsuit challenging South Carolina’s newly passed Age-Appropriate Code Design (“SC AACD”) on First and Fourteenth Amendment grounds. The SC AACD was signed into law on February 5, 2026, making South Carolina the fifth U.S. state to enact such a law, following California, Maryland, Nebraska and Vermont.

Time 2 Minute Read

Congress has extended the Cybersecurity Information Sharing Act of 2015 through September 30, 2026 as part of the Consolidated Appropriations Act, a government funding package enacted in early February 2026.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page