Back to insights
Tag

GDPR: protect your customers' data and stay compliant

The GDPR has governed the collection and use of personal data since May 2018. In Belgium, the Data Protection Authority (DPA) oversees its application. For an SME, compliance concerns the website and contact forms as much as IT security and your relationships with subcontractors.

GDPR obligations for a Belgian company

Four obligations come up in almost every project. First, consent: you must obtain clear and explicit agreement before collecting data, with no pre-ticked boxes. Second, individual rights: your customers can ask which data you hold about them and request its deletion, and you must reply within one month. Third, the record of processing activities documents which data you process, why, how and for how long. Finally, if a data breach occurs, you must notify the DPA within 72 hours.

Sanctions show what is at stake: the GDPR provides for fines of up to 20 million euros or 4% of worldwide annual turnover. However, compliance means more than a constraint. It reassures your customers, clarifies your internal processes and limits the impact of an incident. It also strengthens your position when a large client or a public buyer checks how you handle data.

GDPR checklist for your website

Your website often acts as the first point of data collection. Therefore, check these items: a cookie banner with explicit consent, a clear and accessible privacy policy, contact forms with an appropriate notice, an SSL certificate (HTTPS), a data deletion process and compliant subcontractors, from your host to your analytics tool. Each missing element exposes your company, even if you sell nothing online. Review this list at least once a year, and again whenever you add a new tool.

Security also belongs to the GDPR. Indeed, protecting data requires concrete measures: multi-factor authentication, regular backups following the 3-2-1 rule, systematic updates and staff training on phishing. Finally, prepare an incident response plan, so that everyone knows who does what on the day of a breach. Test your restores regularly, too.

Our GDPR articles and when to call in a professional

Our practical guide to the GDPR in Belgium details the obligations, the website checklist and the role of the DPA. Our cybersecurity guide for Belgian SMEs completes the picture with common threats (phishing, ransomware, web vulnerabilities) and seven essential measures, including GDPR compliance. Together, they cover both the legal and the technical side.

Call in a professional if you collect a lot of data, rely on many third-party tools or run a website that dates back several years. At Espero-Soft, we build compliance into every web project: cookie management, forms with explicit consent, a tailored privacy policy and data hosting in Europe. We also advise you on good practices for your forms and third-party scripts.

Need IT support?

Tell us about your project: we reply within 24 hours with advice that fits your situation.