Cybersecurity 2026

BELGIUM Law and Practice Contributed by: Wim Nauwelaerts, Alston & Bird LLP

Security Requirements for Processing Personal Data General obligations Controllers and processors must implement appropri - ate technical and organisational measures to ensure a level of security appropriate to the risk associated with the processing of personal data. This requirement obliges organisations to consider: • the nature, scope, context and purposes of pro - cessing; • the likelihood and severity of risks for individuals; and • industry-appropriate security norms and state of the art protections. Typical measures expected in Belgium While Belgian law remains technology-neutral, the DPA generally expects measures such as: • identity and access management, including role- based access, multi-factor authentication and least privilege principles; • the encryption of personal data in transit and at rest, especially for sensitive or high-risk data cat - egories; • logging and continuous monitoring, including proactive detection of unauthorised or anomalous activities; • robust incident response procedures, with pre - defined roles, communication lines and decision- making protocols; • business continuity and disaster recovery proce - dures capable of restoring access to personal data in a timely manner after a physical or technical incident; and • vendor and supply chain diligence, ensuring pro - cessors maintain security standards equivalent to those of the controller. Where appropriate, Belgium also expects regular test - ing and evaluation of security measures (eg, penetra - tion tests, audits, tabletop exercises). Definition and Assessment of a Personal Data Breach Belgium applies the GDPR definition of a personal data breach, under which a personal data breach

is “a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data”. The Bel - gian DPA emphasises that not every security incident amounts to a breach; however, controllers must con - duct a prompt and documented assessment of every

incident involving personal data. Notification to the Belgian DPA Threshold for notification

Controllers must notify the DPA unless the personal data breach is unlikely to result in a risk to the rights and freedoms of individuals. Risk indicators include: • sensitive or financial data; • large volumes of data or high numbers of individu - als; • child or vulnerable-person data; and • indicators of malicious intent (eg, hacking, exfiltra - tion). Deadline The DPA launched a new, centralised online portal for data breach notifications in June 2025 that intro - duces a structured, mandatory two-stage notification process. • Part 1 (initial notification): must be submitted within the GDPR-mandated 72-hour window after discov - ering a breach. Completing this part generates an official Data Breach Notification (DBN) case refer - ence number. • Part 2 (detailed follow-up): requires additional, in-depth information about the scope, cause and impact of the breach. Organisations have a maxi - mum of 21 calendar days to complete this part. Failure to complete the second part within 21 days results in the initial submission (Part 1) being treated as the final submission. Required content The notification to the DPA must include at least the following: • a description of the breach, including categories and approximate numbers of impacted data sub - jects and records; • likely consequences of the breach;

48 CHAMBERS.COM

Powered by