BELGIUM Law and Practice Contributed by: Wim Nauwelaerts, Alston & Bird LLP
an expanded focus on supply chain and operational technology security. In addition to these horizontal regimes, sector-specific rules continue to play an important role. For example: • the Belgian Institute for Postal Services and Tel - ecommunications (BIPT) enforces telecom sector obligations related to network security, incident notification and the management of high-risk ven - dors in the context of 5G deployment; • for healthcare providers and medical device manufacturers, cybersecurity obligations arise under the EU Medical Devices Regulation, accom - panied by strict incident reporting duties to the Federal Agency for Medicines and Health Products (FAMHP); and • the Belgian Data Protection Authority (DPA) enforc - es security and breach notification requirements under the EU General Data Protection Regulation (GDPR), and has recently launched a dedicated national portal that introduces a structured two- stage notification process. Taken together, these developments reflect Belgium’s shift toward a more comprehensive, integrated and assurance-driven cybersecurity regulatory environ - ment. The Belgian legislature now frames cyberse - curity as a matter of both national security and eco - nomic continuity, embedding obligations directly at the organisational, sectoral and product levels. The combined effect is a regulatory model that priori - tises robust governance, verifiable risk management practices, transparent incident reporting and greater accountability across supply chains. For companies operating in Belgium, understanding the interplay between NIS 2, DORA, the CRA, the GDPR and sec - tor-specific regimes has therefore become an essen - tial element of compliance planning and a core com - ponent of overall cyber resilience strategy. 1.2 Cybersecurity Laws Principal Cybersecurity Statutes and Regulations in Belgium Belgium’s cybersecurity regulatory landscape consists of a layered system built from constitutional guaran - tees, EU level regulations and national implementing
legislation. The key instruments governing cybersecu - rity and cyber risk management are as follows. Belgian Constitution – Article 22 • Scope: protects the right to privacy, forming the constitutional basis for cybersecurity and data protection obligations. • Organisations in scope: all private and public bod - ies processing personal data in Belgium. GDPR (Regulation (EU) 2016/679) • Scope: protection and security of personal data, with breach notification and accountability obliga - tions. • Organisations in scope: controllers and processors established in Belgium or targeting individuals in Belgium. • Guidance: EDPB guidelines (eg, on breach notifica - tion and security measures) influence interpretation by the DPA and courts. Belgian data protection framework • The DPA Act (Act of 3 December 2017, amended 2023) and the Data Protection Act (Act of 30 July 2018) supplement the GDPR and clarify the role and investigative powers of the DPA. • Guidance: DPA’s decisions, recommendations and inspection reports. Belgian Criminal Code and Criminal Procedure Code • Criminalise hacking, unlawful interception, system interference, computer sabotage and computer- related fraud. • Modernised as part of Belgium’s 2024 criminal law reform (entering into force April 2026). • Apply to any individual or organisation in Belgium implicated in cybercrime. NIS 2 Act – Belgian Act of 26 April 2024 • Subject matter scope: cybersecurity of networks and information systems essential for public secu - rity and the economy. • Organisations in scope: “essential” and “important” entities in sectors listed in Annexes I and II (eg, energy, transport, digital infrastructure, healthcare, public administration, cloud providers, online mar - ketplaces).
35 CHAMBERS.COM
Powered by FlippingBook