The DPO requirement in Belgium is governed directly by the EU General Data Protection Regulation (GDPR), which applies uniformly across all EU member states, including Belgium. Whether your organisation must appoint a Data Protection Officer depends on the nature of your activities, the type of data you process, and whether you are a public body. This guide walks through the mandatory criteria, the voluntary appointment option, the DPO';s role and qualifications, and the practical steps Belgian organisations should take to stay compliant.
When the DPO requirement in Belgium applies
The GDPR, specifically Article 37, sets out three situations in which appointing a DPO is mandatory. These rules apply equally to organisations established in Belgium and to foreign organisations that process the personal data of Belgian residents as part of their main activities.
The first trigger is public authority or public body status. Any Belgian public authority or body - whether a federal ministry, a regional government agency, a municipality, or a public university - must appoint a DPO. The only exception carved out by the GDPR is for courts acting in their judicial capacity.
The second trigger is large-scale, regular, and systematic monitoring of individuals. If your core business activities involve tracking people';s behaviour, location, or online activity at scale - think behavioural advertising platforms, telematics insurers, or large loyalty programme operators - you are required to appoint a DPO. The key phrase is "large scale": a small retailer running a basic loyalty card scheme is unlikely to meet this threshold, while a national e-commerce platform tracking millions of users almost certainly does.
The third trigger is large-scale processing of special categories of data or data relating to criminal convictions. Special categories under GDPR Article 9 include health data, genetic data, biometric data used for identification, racial or ethnic origin, political opinions, religious beliefs, trade union membership, and sexual orientation. Belgian healthcare providers, HR platforms handling medical records, and financial institutions processing fraud-related criminal data are typical examples of organisations that fall into this category.
In practice, Belgian organisations often struggle with the "large scale" threshold because neither the GDPR nor the Belgian Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit, commonly referred to as the APD/GBA) has published a precise employee or data-subject count that triggers the obligation. The Article 29 Working Party guidelines - now continued under the European Data Protection Board (EDPB) - suggest considering the number of data subjects, the volume of data, the geographic scope, and the duration of processing. A common mistake is assuming that because a company is small, it automatically falls outside the mandatory scope; a small but highly specialised medical data processor may still be required to appoint a DPO.
What counts as "large scale" processing in Belgium
Belgian organisations frequently ask where the line is between routine processing and large-scale processing. The APD/GBA has not issued a binding numerical threshold, so organisations must apply a qualitative assessment based on EDPB guidance.
Factors that point toward large-scale processing include:
- Processing data of a significant proportion of the Belgian population or a large regional segment.
- Processing data continuously or over extended periods rather than on an occasional basis.
- Processing data across multiple geographic locations or business units simultaneously.
- Processing data that generates detailed profiles or enables significant decisions about individuals.
A general practitioner processing patient records in a single clinic is explicitly cited in EDPB guidance as not constituting large-scale processing. By contrast, a hospital network covering several Belgian provinces, or a health insurance platform serving hundreds of thousands of policyholders, would almost certainly qualify.
For systematic monitoring, the concept covers not only online tracking but also CCTV networks covering public or semi-public spaces, employee monitoring systems, and connected device ecosystems that continuously collect location or behavioural data. A Belgian logistics company operating GPS tracking across a large fleet and workforce should assess carefully whether this activity triggers the DPO obligation.
A non-obvious requirement is that the assessment must be documented. Even if you conclude that a DPO is not required, Belgian data protection practice - consistent with the GDPR';s accountability principle under Article 5(2) - expects you to record that reasoning in your records of processing activities (ROPA). The APD/GBA can request this documentation during an investigation.
Voluntary DPO appointment and its advantages
Even when the mandatory criteria are not met, Belgian organisations may appoint a DPO voluntarily. This is explicitly permitted under GDPR Article 37(4). Many mid-sized Belgian companies, particularly those in fintech, HR technology, and professional services, choose this route to signal accountability to clients and regulators.
A voluntary DPO carries the same legal status and protections as a mandatory one. This means the DPO must be given the resources to perform their tasks, must not be penalised for performing their duties, and must report directly to the highest management level. Organisations sometimes appoint a "privacy officer" or "data manager" informally without granting these protections, which creates a gap between the de jure title and the de facto role.
In practice, founders should consider whether their sector or client base effectively makes a DPO appointment commercially necessary even if it is not legally mandatory. Belgian public procurement contracts, financial sector partnerships, and healthcare data-sharing agreements increasingly require counterparties to demonstrate robust data governance, which a formally appointed DPO supports.
If you are uncertain whether your processing activities cross the mandatory threshold, contact info@vlolawfirm.com. We can help structure the assessment correctly the first time.
Who can serve as DPO in Belgium
The GDPR requires that a DPO be appointed on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices. Belgian organisations have three structural options.
The first is an internal employee. The DPO can be an existing staff member provided there is no conflict of interest. A common mistake is appointing a Chief Information Officer, General Counsel, or HR Director as DPO when those roles involve making decisions about the purposes and means of processing - precisely the decisions the DPO is supposed to oversee independently. The APD/GBA has flagged this conflict-of-interest issue in its published guidance.
The second option is an external DPO. Belgian law and GDPR Article 37(6) explicitly allow organisations to fulfil the DPO obligation through a service contract with an external provider. This is particularly practical for small and medium-sized enterprises (SMEs) that cannot justify a full-time specialist. External DPOs typically operate on a retainer basis, covering a defined number of hours per month for monitoring, advice, and regulatory liaison.
The third option is a shared DPO across a group of companies. Under GDPR Article 37(2), a group of undertakings may appoint a single DPO provided that person is easily accessible from each establishment. Belgian subsidiaries of multinational groups frequently rely on a group-level DPO, but the APD/GBA expects that the DPO is genuinely reachable and not merely a nominal appointment.
The DPO does not need to be a lawyer, but must have sufficient knowledge of Belgian and EU data protection law, the technical and organisational measures relevant to the organisation';s processing, and the sector-specific regulatory environment. For healthcare organisations, this means familiarity with Belgian health data legislation; for financial institutions, familiarity with sector-specific supervisory expectations from the National Bank of Belgium and the FSMA alongside GDPR.
Registering the DPO with the APD/GBA
Once appointed, the DPO must be registered with the APD/GBA. This is a mandatory step under GDPR Article 37(7), which requires controllers and processors to publish the DPO';s contact details and communicate them to the supervisory authority.
The APD/GBA maintains an online register of DPOs. Registration requires submitting the DPO';s name, contact details, and the identity of the organisation. The DPO';s personal address need not be published; a professional contact address or the organisation';s address is sufficient. The APD/GBA uses this register to direct data subject complaints and regulatory correspondence to the correct contact point.
A common oversight is failing to update the register when the DPO changes. If an internal DPO leaves the organisation or an external provider';s contract ends, the organisation must promptly appoint a successor and update the APD/GBA registration. Operating without a registered DPO when one is mandatory is itself a compliance failure that can attract regulatory attention.
The APD/GBA is Belgium';s independent supervisory authority established under the Belgian law of 3 December 2017 creating the Data Protection Authority. It has the power to investigate complaints, conduct audits, issue warnings, impose corrective measures, and levy administrative fines. Fines for GDPR infringements can reach up to four percent of global annual turnover or a fixed ceiling, whichever is higher, for the most serious violations.
Practical scenarios: when Belgian organisations must act
Scenario one: Belgian SaaS company processing HR data for clients. A Brussels-based software company provides a human resources platform used by corporate clients across Belgium and the Netherlands. The platform processes employee performance data, payroll information, and, for some clients, health-related absence records. Because the company processes special categories of data (health data) at scale on behalf of multiple clients, it almost certainly meets the mandatory DPO threshold as a data processor. Appointing an external DPO on a retainer is a cost-effective solution that also reassures enterprise clients during procurement due diligence.
Scenario two: Small Belgian e-commerce retailer. A Ghent-based online retailer sells artisan food products and collects standard customer data - names, delivery addresses, and purchase history - for approximately fifteen thousand customers. It does not process special categories of data and does not engage in systematic behavioural profiling. This organisation is unlikely to meet the mandatory DPO threshold. However, it should document that assessment in its ROPA and implement appropriate privacy governance. Appointing a voluntary DPO or designating a privacy contact person is advisable as the business scales.
These two scenarios illustrate that the DPO requirement in Belgium is not determined by company size alone but by the nature and scale of processing activities. A small company in a sensitive sector may be obligated; a large retailer in a low-risk sector may not be.
FAQ
Is a DPO required for all Belgian companies under GDPR?
No. The mandatory DPO requirement applies only to public authorities, organisations that carry out large-scale regular and systematic monitoring of individuals, and organisations that process special categories of personal data or criminal conviction data at large scale. Many Belgian private-sector companies, particularly SMEs with limited and routine data processing, are not legally required to appoint a DPO. However, the absence of a legal obligation does not remove the need for sound data governance. Organisations should document their assessment of whether the threshold is met and review it whenever their processing activities change significantly.
How long does it take to appoint and register a DPO in Belgium?
The internal process of selecting and appointing a DPO can take anywhere from a few days, if an external provider is engaged quickly, to several weeks if an internal candidate must be identified and conflicts of interest assessed. Once appointed, registration with the APD/GBA is straightforward and can typically be completed online within one to two business days. The more time-consuming element is ensuring the DPO has the resources, access, and organisational positioning required by GDPR before the appointment is formalised. Rushing this step and appointing a DPO in name only is a common mistake that creates compliance risk rather than resolving it.
Can a Belgian company share a DPO with its foreign parent or subsidiaries?
Yes. GDPR explicitly allows a group of undertakings to appoint a single DPO, provided that person is easily accessible from each establishment within the group. In practice, this means the DPO must be reachable by employees and data subjects in Belgium, must have sufficient capacity to handle Belgian-specific matters, and must be able to communicate with the APD/GBA in French, Dutch, or German - Belgium';s three official languages. A group-level DPO based abroad who has no practical knowledge of Belgian regulatory requirements or cannot respond promptly to APD/GBA inquiries may not satisfy the accessibility standard. Belgian subsidiaries relying on a group DPO should verify these conditions are genuinely met.
Conclusion
The DPO requirement in Belgium follows GDPR rules directly, with the APD/GBA as the competent supervisory authority. Mandatory appointment applies to public bodies, large-scale systematic monitors, and large-scale processors of sensitive data. Voluntary appointment is available to all organisations and increasingly expected in regulated sectors. Proper qualification, independence, and APD/GBA registration are essential regardless of whether the appointment is mandatory or voluntary.
VLO Law Firms advises international clients on DPO requirements and data protection compliance in Belgium. We can assist with assessing whether your organisation meets the mandatory threshold, structuring the DPO appointment, drafting the necessary documentation, and registering with the APD/GBA. To request a consultation, contact: info@vlolawfirm.com