You are here:
07 December 2018 / news

First status update of Belgian DPA after six months of GDPR

The Belgian Data Protection Authority (DPA) has issued a first status update six months after the GDPR became applicable. The statistics show a remarkable increase in the number of data breach notifications, complaints and requests received.

First status update of Belgian DPA after six months of GDPR

Data breaches

Since 25 May 2018, 317 data breaches have been notified to the DPA. This is an enormous increase compared to last year, when only 13 data breaches were reported. This increase is obviously due to the fact that there was no obligation to report at that time (except for telecommunication companies or financial service providers).

The top 5 industries reporting data breaches are: (1) health care, (2) insurance, (3) public administrations and defence, (4) telecom and (5) financial services.


In addition, the DPA reports to have received 148 complaints in the past six months, which comes down to almost one complaint per day.

This amount has increased compared to 2017 (when only 76 complaints were received). It is, however, negligible compared to our neighbouring countries, who reported to have received a lot more complaints in the period following 25 May. The CNIL reported that after four months it had already received 3.767 complaints. In the Netherlands, the first six months of the new privacy law yielded more than 7.000 complaints. In both cases, the number of complaints in relation to the number of residents is much higher than in Belgium.

Other figures

The DPA has released some other noteworthy figures. Since 25 May, the DPA has received:

  • 3.599 information requests (compared to 2.145 information requests in 2017);
  • 137 requests for advice (compared to 44 requests for advice in 2017);
  • 2.551 notifications of the appointment of a DPO (compared to 989 notifications before May 2018).

Furthermore, the DPA announced that the number of cases has increased exponentially under the application of the GDPR. In 2017, the Authority handled just under 5.000 core cases, while for 2018 this number will exceed 7.000.

First investigations

Lastly, the DPA announced that it has meanwhile started its first investigations. No cases have yet been transferred to the Dispute Chamber in order to be dealt with on the merits (fore more information on the different bodies within the DPA, see our previous newsflash). Unlike Germany, Portugal and Austria, no fines have been issued yet.

On this point, the DPA is running a bit behind our neighbouring countries, who have started their first systematic inspections already at the beginning of the summer and who have already imposed a large number of warnings and sanctions.

It now looks like the DPA is getting up to speed, although it should be remembered that the members of the DPA still have to be formally appointed by the Parliament. As soon as the DPA will be fully operational, it will undoubtedly increase its advisory, inspection and sanctioning activities.

Data Protection Summer Dive

Data Protection Summer Dive

The Loyens & Loeff Data Protection & Privacy Team has prepared updates throughout summer to help you keep up with the latest decisions of the Belgian Data Protection... read more

Legal considerations for businesses during the coronavirus outbreak in Belgium

As the coronavirus (COVID-19) continues to impact the daily lives of people around the world, the priority for companies remains, of course, the safety of their... read more
Belgium’s Governmental declaration of intent

Belgium’s Governmental declaration of intent

After 493 days, Belgian politicians managed to form a so-called Vivaldi government. read more
Stay informed

Don't miss out. Stay up to date about our latest news and events.

Stay informed