Skip to Content

General Data Protection Regulation (GDPR)

GDPR: what you need to know!GDPR: what you need to know!

The General Data Protection Regulation came into force on 25 May 2018.

You will find on this page a certain number of links, documents and information, which we consider useful in the context of these new regulations.

What is personal data?

  • Any information relating to an identified or identifiable natural person.

What is an identifiable natural person?

  • A natural person who can be identified, directly or indirectly, in particular by reference to an identifier, such as a name, an identification number, location data, an online identifier, or to one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity."
  • Examples of data allowing the identification of a person: surname, first name, address, date of birth, civil status, family members, national register number, passport number, photos, e-mail addresses, mobile number, bank details, registration plate, IP addresses, location data, fingerprints, ...

Examples of personal data (not exhaustive):

  • Identification data, Financial details, Personal characteristics, Physical data, Lifestyles, Psychological data, Household composition, Hobbies and interests, Affiliations, Judicial data, Consumption habits, Housing characteristics, Health data, Studies and training, Profession and employment, Ethnic data, Data relating to sexual behaviour, Political opinions, Affiliation to a professional association, Philosophical or religious beliefs, Image recordings, Sound recordings, ...
  • Data that could be considered anonymous may constitute personal data if it makes it possible to identify a specific person indirectly or by cross-referencing information. It may well be information that is not attached to a person’s name but that easily makes it possible to identify them and learn their habits or tastes.

How to comply?

  • Minimise the personal data collected
  • Ensure the legal basis of the processing carried out or the legitimate interest of the processing
  • Avoid processing sensitive data, unless necessary
  • Display the legal notices relating to the processing carried out
  • Respect the right to data portability, the right to rectification and the right to be forgotten
  • Set up a register of processing operations carried out on personal data
  • Ensure the security of personal data and that access is limited to those responsible for the processing, within the scope of the intended use
  • Maintain a record of personal data breaches
  • Appoint a data protection officer (DPO) - required if the company has more than 250 employees
  • Carry out a data protection impact assessment, where there is a high risk to the rights and freedoms of individuals

In practice, where to start?

  • Inform company staff about the requirements of the new regulations
  • Make an inventory of all the data managed by the company and identify personal data.
  • Purge personal data of anything that is not necessary to the company’s business and not linked to a legal requirement, or that may no longer be kept under the new regulations.
  • Obtain the consent of individuals for the personal data stored and for the clearly identified use the company will make of it.
  • Document your company’s IT (infrastructure, management tools, security procedures, list of internal and external stakeholders, ...)

The complete regulations (source: official journal of the European Union) can be downloaded directly by clicking here (PDF, 88 pages).

The complete regulations (source: official journal of the European Union) can be downloaded directly by clicking here (PDF, 88 pages).

The Belgian Data Protection Authority has published a document about direct marketing. Download it directly by clicking here (PDF, 78 pages)

Sources: European regulation, data protection authority in Belgium, CNIL in France

Last update on 9 September 2026.

SIGN UP TO RECEIVE OUR NEWSLETTER