Act of 30 July 2018 Title 6 Chapter II, Criminal Sanctions
Loi du 30 juillet 2018, Arts. 222-230
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 5 September 2018.
An enforcement supervision rule binding public and private bodies.
As of 24 August 2026.
What it requires
- Expect a criminal fine of up to 20,000 EUR to attach personally to a controller, processor, employee, or agent for the fourteen grounds Act Article 222 enumerates, including processing personal data of a person in Belgium without a legal basis.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Title 6, Chapter II, read verbatim article by article, is Belgium's criminal chapter for data-protection violations, distinct from the Act of 3 December 2017's supervisory structure: Article 222 fines a controller, processor, employee, agent, or competent authority 250 to 15,000 EUR on fourteen enumerated grounds including processing without a legal basis and obstructing the supervisory authority; Article 224 fines a member or staffer of the supervisory authority 200 to 10,000 EUR for breaching confidentiality; Article 227 fines 100 to 20,000 EUR on five grounds including using assault, violence, or threats to compel a person's processing authorization; and Article 229 governs the overlap between administrative and criminal routes.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometricsprocesses_voice
Read the law
Moniteur belge, 5 September 2018, Title 6, Chapter II, Arts. 222-230 (verbatim)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.