Belgian DPA annual report 2025

Belgian DPA annual report 2025

Belgian DPA annual report 2025

Privacy compliance

The Belgian Data Protection Authority’s (DPA) 2025 Annual Report offers a useful snapshot of where Belgian privacy enforcement is heading. For in-house counsel, DPOs and compliance professionals, the report is less about isolated enforcement figures and more about regulatory direction: more structured case handling, continued scrutiny of data-intensive business models, and a clear expectation that organisations can evidence GDPR compliance in complex technological environments.

In 2025, the DPA launched a new case-management platform with a customer portal, initially covering DPO management and data-breach notifications, with further functionalities still being rolled out.

2025 in figures

  • The Litigation Chamber issued 214 decisions, which led to a range of sanctions and corrective measures, including reprimands, orders and administrative fines.
  • The DPA also played an active role in cross-border GDPR cooperation. It was involved as a concerned supervisory authority in 286 international complaints where the processing was considered to have a significant impact on Belgian data subjects. . In one case, part of a website operated by an Asian controller was taken offline due to GDPR issues. In another investigation concerning a conversational mobile app using AI and large language models, it convinced a US company to implement privacy changes and appoint a permanent EU representative.
  • Appeals were also significant: 20 appeals were brought before the Market Court against Litigation Chamber decisions, and the Market Court ruled in 25 appeal proceedings, with 13 decisions annulled in whole or in part
  • The DPA continued to function as a high-volume contact point for individuals and organisations. It received 3,034 information requests, with main topics including image processing and cameras, indirect access, and commercial practices such as direct marketing.
  • It also received 1,394 complaints and opened 263 mediation files. The most common complaint areas were image processing and cameras, privacy in the workplace, and telecommunications, including cookies and social media.
  • The General Secretariat processed 1,078 data-breach files. Of these, only 215 were assessed in extenso, while the remaining notifications received a prima facie assessment; 4 files were referred to the Inspection Service. Hence, lots of notifications will not lead to full enforcement escalation.

Data brokers

One of the clearest commercial themes in the 2025 report is the DPA’s focus on data brokers and data-trading ecosystems. Transparency and the demonstrability of the lawful basis were recurring issues in these files. The report stresses that complex networks involving data brokers, customers and suppliers do not excuse failures to comply with basic GDPR principles. The Inspection Service also indicated that it will continue to monitor the data-trading sector closely, given its statutory task to follow technological and commercial developments affecting personal-data protection .

Direct marketing

Direct marketing is also highlighted as an area requiring continued attention. The Inspection Service describes direct marketing as resembling an iceberg: the visible impact may not always appear severe, but less transparent elements such as profiling and prospecting sources remain important areas of scrutiny .

Artificial intelligence

The Inspection Service continued investigations into AI-based systems and confirmed a trend already visible in 2024: AI applications do not necessarily require a different legal framework, but they make the application of existing GDPR principles more complex. The investigated AI processing activities often arose in research and development contexts, where organisations train algorithmic models on existing datasets for prediction or decision-support purposes. These projects tend to involve scale, data-quality dependencies and technical design choices that directly affect GDPR compliance.

The DPA identified recurring concerns around:

  • lawful basis, particularly the need to properly document legitimate-interest assessments
  • DPIAs that are too generic, late or insufficiently tailored to predictive-model risks, including bias and residual risks
  • transparency notices that are too general to allow data subjects to understand the processing or exercise their rights effectively
  • reliance on anonymisation without sufficient documentation of the methods and residual risks

The Inspection Service concludes that AI projects often act as a stress test for GDPR compliance, bringing lawful basis, transparency, data minimisation and risk assessment sharply into focus.

Cookies, tracking and website compliance

Websites are continued to be seen as an important first point of contact between organisations and individuals. The report notes that privacy notices, privacy governance, cookies and tracking remain areas of attention.
Cookie banners should not be treated as a one-off design issue. Consent validity, interface neutrality, cookie categorisation, vendor lists and proof of consent should be periodically reviewed.

The 2025 Annual Report suggests a number of priorities for legal and compliance teams:
1. Document lawful basis in data-intensive projects.
2. Treat DPIAs as operational risk tools, not formalities.
3. Review transparency across the data lifecycle.
4. Audit third-party data supply chains.
5. Refresh cookie and tracking governance.
6. Prepare for selective but sophisticated enforcement.

Share on XShare via emailShare on LinkedIn

Go to
Offices

Go to Offices