Since May 2018, the General Data Protection Regulation has governed every collection of personal information: customer files, contact forms, newsletter tools and HR records. This guide to GDPR compliance brings together the essential obligations for a Belgian business, without jargon. It ends with a checklist you can apply directly to your website.
GDPR compliance: who enforces it and who must comply?
In Belgium, the Data Protection Authority (DPA) oversees how the regulation applies. It handles complaints, carries out inspections and publishes practical recommendations. Any organisation that processes personal data must comply, from sole traders to large companies. The size of your business mainly changes the scale of the measures, not the principle. You will find official guidance and templates on the website of the Belgian Data Protection Authority.
The essential obligations
This GDPR compliance guide focuses on five obligations that apply to almost every company.
A legal basis for every processing activity
Each use of personal data must rest on one of six legal bases: consent, contract, legal obligation, vital interests, public task or legitimate interests. Consent is therefore not necessary everywhere. However, when you rely on it, for example for advertising cookies, it must be freely given, specific, informed and unambiguous. Pre-ticked boxes and implied consent do not qualify.
Individual rights
Your customers, prospects and employees can find out what data you hold about them. They can also have it corrected, object to certain processing or request its deletion. As a rule, you have one month to respond. So set up a dedicated contact address and a simple internal procedure. However, check the requester's identity before you send anything, so that no data reaches the wrong person.
Records of processing activities
Document your processing: which data, for what purpose, on which legal basis, with which processors and for how long. In practice, even an SME must keep these records as soon as it processes data regularly, such as customer or staff information.
Data breaches
If a data breach poses a risk, you must notify the DPA within 72 hours. When the risk to the people concerned turns out to be high, inform them too. Also keep an internal log of every incident, even minor ones. Finally, decide in advance who assesses an incident and who sends the notification, so that you lose no time.
Processors
Your hosting provider, email marketing tool and invoicing software process data on your behalf. Sign a data processing agreement with each of them. Also favour hosting within the European Union, which simplifies the question of transfers.
How long should you keep data?
The regulation sets no single retention period: you have to define one for each purpose and then stick to it. Some documents, such as invoices, fall under accounting and tax rules that require you to keep them for several years. By contrast, a rejected CV or an inactive prospect does not justify indefinite storage. Record these periods in your register and schedule regular deletions.
GDPR compliance checklist for your website
- A cookie banner that blocks non-essential trackers until visitors accept, with refusing as easy as accepting.
- A clear privacy policy, accessible from every page.
- Forms that ask only for useful information and link to the privacy policy.
- An active SSL certificate (HTTPS) across the whole site.
- A procedure for deleting data on request.
- Trustworthy processors: hosting, analytics tools, CRM.
Sanctions in Belgium
The DPA can issue warnings, order corrective measures or impose fines. The regulation provides for amounts of up to €20 million or 4% of annual worldwide turnover. Beyond the fine itself, a complaint or a publicised breach mostly damages your customers' trust. Individuals can also lodge a complaint with the DPA or take the matter to court.
Common mistakes in SMEs
- Copying another website's privacy policy without adapting it.
- Keeping CVs or old prospect lists indefinitely.
- Installing an analytics tool or advertising pixel without checking consent.
- Sending customer files by email without protection.
- Installing a surveillance camera without declaring it to the police or displaying the required pictogram.
How Espero-Soft builds in GDPR compliance
We take data protection into account in every web project: a cookie management system that respects consent, forms with explicit consent where needed, a customised privacy policy, European data hosting and advice on best practices. As a result, your showcase website meets these requirements from launch day.
GDPR compliance is both a legal obligation and a mark of trust for your customers. Ask us to review your website and put it in order.



