Data Protection and Privacy 2025

BELGIUM Trends and Developments Contributed by: Benjamin Docquir and Margo Cornette, Osborne Clarke

Penalties Both the GDPR and the AI Act provide for admin - istrative fines, the extent of which depend on the severity of the infringement. Under the GDPR, minor infringements can result in fines up to EUR10 million or 2% of the total annual global turnover, whichever is higher. Examples of such infringements include violating the GDPR’s prin - ciple of privacy by design and default. For more serious breaches, fines can escalate to EUR20 million or 4% of the total annual global turno - ver, for example for breaches of the GDPR’s provisions on processing principles and data subjects’ rights. With regard to the AIA, penal - ties are outlined in Article 99 of the AIA. Seri - ous breaches, such as non-compliance with prohibited AI practices or failure to meet quality requirements for high-risk AI systems, can lead to fines up to EUR35 million or 7% of worldwide annual turnover. For less serious breaches, like providing incorrect, incomplete or misleading information to notified bodies or national com - petent authorities, the fine is EUR7.5 million or 1% of worldwide annual turnover, whichever is higher. Conclusion The integration of AI technologies into healthcare offers a potentially transformative opportunity, but also presents complex legal and regulatory challenges, particularly under the AIA, GDPR and MDR. With the coming into force of the AIA, healthcare professionals will need to navigate a rigorous compliance landscape resulting from the broad definition of “deployer” and extensive obligations on those who use high-risk AI sys - tems. This requires adopting a proactive and strategic approach: assessing AI systems (with a focus on high-risk categories), developing robust com - pliance frameworks and understanding compli -

and organisational measures to ensure that the system is used in accordance with its instruc - tions of use, including with respect to human oversight. If a certain level of human oversight is lacking, for example because the human decision-makers are not properly trained, the AI system might not be considered partially automated, thus falling under the automated decision-making frame - work of Article 22 of the GDPR. Reporting incidents Reporting obligations relating to serious inci - dents or the malfunctioning of AI systems may partially overlap with GDPR reporting obligations when personal data is involved. In the section headed “Roles under the GDPR and AIA”, a brief discussion was provided of the obligation of a healthcare professional using AI systems for remote patient monitoring to inform the pro - vider and, where legally required, also the dis - tributor and/or the relevant market surveillance authorities if they identify a significant risk or a serious incident. If such an incident results in a data breach (ie, compromises the confidential - ity, availability or integrity of the data processed by the AI system), healthcare professionals may also need to notify the relevant data protec - tion authority and, in some cases, the affected data subjects. The incident should be reported to the relevant supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach, unless the breach is unlikely to put the data sub - jects’ rights and freedoms at risk, and to affected data subjects if the breach is likely to result in a high risk to the rights and freedoms of the data subjects.

36

CHAMBERS.COM

Powered by