Digital Operational Resilience Act (DORA)

🇧🇪Digital Operational Resilience Act in Belgium

A comprehensive guide to Digital Operational Resilience Act compliance for organisations operating in Belgium. Understand local enforcement, the national data protection authority, key focus areas, and notable enforcement actions.

About Digital Operational Resilience Act

The EU regulation establishing a comprehensive framework for digital operational resilience in the financial sector, covering ICT risk management, incident reporting, testing, and third-party risk.

Effective: 17 January 2025Max penalty: €5,000,000 for entities; €500,000 for individuals or 2% of total annual worldwide turnover for critical ICT third-party providers
Full Digital Operational Resilience Act overview

Digital Operational Resilience Act Enforcement in Belgium

Belgium's APD/GBA is a bilingual authority (French/Dutch) that has gained prominence through its scrutiny of the online advertising ecosystem. The APD issued a landmark decision against IAB Europe regarding the Transparency and Consent Framework (TCF) used by the programmatic advertising industry, finding it violated GDPR — a decision upheld by the Belgian Market Court and later referenced by the CJEU. Belgium supplemented the GDPR through the Law of 30 July 2018, which addresses processing of genetic, biometric, and health data, journalistic exemptions, and the processing of judicial data. The APD has also focused on political campaigns, airport biometric systems, and public sector compliance.

Data Protection Authority

Autorité de protection des données / Gegevensbeschermingsautoriteit (APD/GBA)

Key Enforcement Focus Areas in Belgium

  • Online advertising and consent frameworks (IAB TCF)
  • Programmatic advertising ecosystem compliance
  • Biometric data at airports and public spaces
  • Political campaign data processing
  • Public sector and government data sharing

Notable Enforcement Actions in Belgium

IAB Europe

€250,000(2022)

GDPR violations in Transparency and Consent Framework used by programmatic ad industry — upheld on appeal

Google Belgium

€600,000(2022)

Failure to comply with right to erasure and right to be forgotten requests from Belgian citizens

Brussels Airport Company

€200,000(2023)

Processing passenger biometric data through facial recognition boarding system without adequate legal basis

Proximus SA

€50,000(2021)

Continuing direct marketing communications after customers exercised right to object

Check Your Compliance Status

Take our free assessment to evaluate your organisation's compliance posture. Get a personalised report with actionable recommendations in minutes — no sign-up required.

Start Free Assessment

Disclaimer: The information on this page is for educational purposes and does not constitute legal advice. For specific compliance guidance, consult a qualified legal professional in your jurisdiction.

Other Regulations Affecting Belgium