GDPR Chapter V and Act Article 222, 4, Cross-Border Transfer Restrictions
Regulation (EU) 2016/679, Arts. 44-49, 83(5); Loi du 30 juillet 2018, Art. 222, 4
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 25 May 2018, effective 5 September 2018.
A cross border transfer rule binding public and private bodies.
As of 24 August 2026.
What it requires
- Rely on an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Belgium outside the EEA; a grossly negligent or malicious breach is a criminal offense under Act Article 222, 4.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A transfer of personal data outside the EEA requires an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier.
Belgium adds a criminal offense for the same conduct: Article 222, 4, read verbatim, fines a controller, processor, employee, agent, or competent authority 250 to 15,000 EUR for a Chapter V breach carried out by gross negligence or malicious intent, and the Act of 3 December 2017 Article 100, 14 lets the Litigation Chamber order the suspension of cross-border data flows. No localization mandate was found.
When LexLint raises it
crawls_webtrains_models
Read the law
Moniteur belge, 5 September 2018, Art. 222, 4 (verbatim)
Act of 3 December 2017, Art. 100, 14
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.