Law / Belgium

Belgium

European Union law applies in Belgium Belgium is a member state of the European Union, whose 37 researched instruments are listed on the European Union page, not here. The law of Belgium, described on this page below, applies here too.

15 of 16 named instruments researched to a stage, across four of the six areas of law we track: 15 in force. As of 14 September 2026.

When they take effect15 of 15 carry a date.
2018: 9 instruments (9 in force) ’18 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 3 instruments (3 in force) 2023: 0 instruments 2024: 2 instruments (2 in force) 2025: 0 instruments 2026: 1 instrument (1 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 10
  3. Scraping law 2
  4. Cybersecurity law 2
  5. Age gating law none researched
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law10 instruments, 10 in force

Research summary (118 words)

Belgium's private-sector personal-data regime is the General Data Protection Regulation (GDPR) as given domestic effect by the Act of 30 July 2018, with the supervisory structure sitting in a separate Act of 3 December 2017.

Reading the Act of 30 July 2018 end to end in the official bilingual gazette confirms three Belgium-specific additions: a criminal-offense chapter at Title 6, Chapter II, an Article 9 access-designation and confidentiality duty for genetic, biometric, and health data, and a switch turning off GDPR Article 83 fines for most public authorities.

On biometrics the GBA/APD has a dedicated recommendation and one Litigation Chamber decision on the merits, which fined an employer 45,000 EUR for fingerprint-based workplace time registration; it has nothing at all on voiceprints.

Biometric privacy

Act of 30 July 2018 Article 9 and GBA/APD Biometric Recommendation and Enforcement

Loi du 30 juillet 2018, Art. 9; GBA/APD Aanbeveling nr. 01/2021; GBA/APD Beslissing ten gronde nr. 114/2024GBA/APD Aanbeveling nr. 01/2021 (full text)

In force since 5 September 2018. Binds public and private bodies.

What this law does

Belgium has no dedicated biometric-identifier statute; a biometric identifier is General Data Protection Regulation (GDPR) Article 9(1) special-category data, plus Act Article 9's access-designation and confidentiality duties. GBA/APD Recommendation 01/2021, read in full, concludes there is at present a lacuna in Belgian law such that any biometric authentication processing lacking explicit consent, other than eID and passport processing, has no legal basis.

Litigation Chamber Decision 114/2024, read in full, fined an employer 45,000 EUR for fingerprint-based workplace time registration, holding that employee consent failed the power-imbalance analysis and that record-keeping and DPIA duties were also breached.

The GBA/APD's own publication search returns zero results for voice recognition and 16 results for facial recognition, none of them a decision, so Belgium has no facial-recognition Litigation Chamber decision and no voiceprint guidance at all, established from the regulator's own index rather than an inference.

What it requires

Breach notification

GDPR Articles 33-34, Breach Notification

Regulation (EU) 2016/679, Arts. 33-34GDPR Arts. 33-34

In force since 25 May 2018. Binds public and private bodies.

What this law does

A controller must notify the GBA/APD within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. No Belgium-specific derogation from this timeline or threshold was found in the Act of 30 July 2018.

A related but distinct power, Act of 3 December 2017 Article 100, 7, lets the Litigation Chamber order that a data subject be informed of a security problem, a corrective power over an Article 34 failure rather than a separate notification duty.

What it requires

Comprehensive regime

Act of 30 July 2018 on the Protection of Natural Persons with regard to Personal Data

Loi du 30 juillet 2018 relative a la protection des personnes physiques a l'egard des traitements de donnees a caractere personnel (numac 2018040581)Moniteur belge, 5 September 2018, and the consolidated Justel text

In force since 5 September 2018. Binds public and private bodies.

What this law does

Belgium gives the General Data Protection Regulation (GDPR) domestic effect through the Act of 30 July 2018, published in the Moniteur belge 5 September 2018, read end to end in the official bilingual gazette text. Article 6 states Title 1 executes the Regulation; the Act sets the digital-consent age at 13 (Art. 7), designates public-interest processing categories under GDPR Article 9(2)(g) (Art. 8), and adds criminal-conviction-data grounds (Art. 10).

The supervisory structure sits in a separate statute, the Act of 3 December 2017. The Act has been amended four times on the Justel record, most recently in 2024.

What it requires

Cross border transfer

GDPR Chapter V and Act Article 222, 4, Cross-Border Transfer Restrictions

Regulation (EU) 2016/679, Arts. 44-49, 83(5); Loi du 30 juillet 2018, Art. 222, 4Moniteur belge, 5 September 2018, Art. 222, 4 (verbatim)

In force since 25 May 2018, effective 5 September 2018. Binds public and private bodies.

What this law does

A transfer of personal data outside the EEA requires an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier.

Belgium adds a criminal offense for the same conduct: Article 222, 4, read verbatim, fines a controller, processor, employee, agent, or competent authority 250 to 15,000 EUR for a Chapter V breach carried out by gross negligence or malicious intent, and the Act of 3 December 2017 Article 100, 14 lets the Litigation Chamber order the suspension of cross-border data flows. No localization mandate was found.

What it requires

Data subject rights

Act of 30 July 2018 Title 5, Action en Cessation, and GDPR Article 22

Loi du 30 juillet 2018, Arts. 11-17, 209-211, 220; Regulation (EU) 2016/679, Art. 22Moniteur belge, 5 September 2018, Arts. 11-17, 209-211, 220 (verbatim)

In force since 25 May 2018, effective 5 September 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Articles 12-23 govern access, rectification, erasure, restriction, portability, objection, and the Article 22 right against solely automated decision-making; Belgium adds no sector-specific automated-decision rule beyond that baseline.

What the Act adds, read verbatim, is a domestic enforcement route: Title 5's action en cessation lets the president of the court of first instance, sitting as in summary proceedings, order the cessation of processing that violates the data-protection rules, with standing confined to the data subject and the supervisory authority (Art. 211).

Article 220 implements GDPR Article 80, letting a data subject mandate a qualifying body active in data protection for at least three years to lodge a complaint on their behalf.

What it requires

Enforcement supervision

Act of 3 December 2017, GBA/APD and Litigation Chamber

Loi du 3 decembre 2017 portant creation de l'Autorite de protection des donnees (numac 2017031916)Act of 3 December 2017, Arts. 32, 33, 100 (verbatim)

In force since 25 May 2018. Binds public and private bodies.

What this law does

The Act of 3 December 2017, enacted 3 December 2017 and in force 25 May 2018, creates the Gegevensbeschermingsautoriteit / Autorite de Protection des Donnees (GBA/APD) and its Chambre Contentieuse / Geschillenkamer (Litigation Chamber, Art. 32). Article 100, read verbatim, lists sixteen measures the Chamber may take, from dismissing a complaint to imposing administrative fines, suspending cross-border data flows, and transferring a file to the public prosecutor. Appeal lies to the Marktenhof.

What it requires

Act of 30 July 2018 Title 6 Chapter II, Criminal Sanctions

Loi du 30 juillet 2018, Arts. 222-230Moniteur belge, 5 September 2018, Title 6, Chapter II, Arts. 222-230 (verbatim)

In force since 5 September 2018. Binds public and private bodies.

What this law does

Title 6, Chapter II, read verbatim article by article, is Belgium's criminal chapter for data-protection violations, distinct from the Act of 3 December 2017's supervisory structure: Article 222 fines a controller, processor, employee, agent, or competent authority 250 to 15,000 EUR on fourteen enumerated grounds including processing without a legal basis and obstructing the supervisory authority; Article 224 fines a member or staffer of the supervisory authority 200 to 10,000 EUR for breaching confidentiality; Article 227 fines 100 to 20,000 EUR on five grounds including using assault, violence, or threats to compel a person's processing authorization; and Article 229 governs the overlap between administrative and criminal routes.

What it requires

Code de Droit Économique Article XVII.37, 10 degrees/1, Collective Redress for GDPR Claims

Code de droit economique Art. XVII.37, 10 degrees/1, as inserted by the Loi du 30 juillet 2018 portant dispositions diverses en matiere d'Economie (numac 2018031589), Art. 43Act of 30 July 2018 on various economic provisions, Arts. 43, 104 (verbatim)

In force since 25 May 2018. Binds private bodies.

What this law does

General Data Protection Regulation (GDPR) Article 82 arms an individual data subject to claim damages directly.

Belgium separately added the GDPR to the Code of Economic Law's collective redress action, Book XVII, Title 2: Article 43(a) of the Act of 30 July 2018 on various economic provisions, read verbatim, inserted point 10 degrees/1 naming Regulation (EU) 2016/679 into Article XVII.37's list of instruments whose breach can found a collective redress action, and Article 104 of the same act gives that insertion retroactive effect from 25 May 2018.

Article XVII.37's complete current list is not independently confirmed, because the Code's own consolidated text truncates before Book XVII, so confidence is high on the GDPR's inclusion and low on the article's present overall shape.

What it requires

Sensitive categories

Act of 30 July 2018 Article 10/1, Recorded Commercial Communications

Loi du 30 juillet 2018, Art. 10/1, as inserted by the Act of 21 December 2021, article 255Moniteur belge, 5 September 2018, Art. 10/1 (verbatim)

In force since 10 January 2022. Binds public and private bodies.

What this law does

Article 10/1, read verbatim, permits recording an electronic communication and its traffic data in lawful commercial transactions as proof, on condition the parties are informed of the recording, its precise purposes, and the storage period before the recording, with data erased at the latest when the transaction can no longer be challenged in court.

Paragraph 2 separately permits listening to and recording calls solely to monitor service quality in call centres, on prior information to staff, with a maximum retention of one month. This is the Belgian provision most likely to bind a voice-recording product, distinct from the biometric rules above.

What it requires

Act of 30 July 2018 Articles 8-10, Special-Category Processing Grounds

Loi du 30 juillet 2018, Arts. 8-10Moniteur belge, 5 September 2018, Arts. 8-10 (verbatim)

In force since 5 September 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Article 9(1) lists biometric data processed for unique identification as a special category. Article 9 of the Act, read verbatim, requires every controller processing genetic, biometric, or health data to designate the categories of staff with access, keep that list available to the supervisory authority, and bind those staff to confidentiality.

Article 8, paragraph 1's final subparagraph outright prohibits genetic and biometric processing for unique identification by the specific associations and foundations it authorizes under Article 9(2)(g), absent particular legal provisions. Article 10, paragraph 1, point 6 makes processing of criminal-conviction data manifestly made public by the data subject a lawful-basis ground, not a scope exclusion.

What it requires

Scraping law2 instruments, 2 in force

Research summary (137 words)

Belgium recodified its unauthorised-access computer offence into the new Penal Code's Book II, in force since 1 September 2026, replacing Article 550bis of the 1867 Penal Code with Articles 524 to 530; the offence turns on the actor knowingly lacking authorisation, and its text does not add a separate requirement that a technical security measure be defeated.

The Code of Economic Law's text-and-data-mining exception, inserted into Article XI.190, 20° by the Act of 19 June 2022 transposing Directive (EU) 2019/790, permits reproducing a lawfully accessible work for text and data mining unless the rightsholder has reserved that use, and for content available online only a machine-readable reservation counts as an appropriate one.

Belgium's position on terms-of-service enforceability, a sui generis database right, robots.txt's legal weight, and an unfair-competition or misappropriation doctrine for scraping is not described here.

Computer misuse

Code pénal, Livre II, articles 524 à 527, accès non autorisé dans un système informatique

Code pénal Livre II, arts. 524-527 (accès non autorisé dans un système informatique), inséré par la loi du 29 février 2024 introduisant le livre II du Code pénal; peines fixées au Livre Ier, art. 36 et 38Belgian Official Gazette, consolidated text of the Law of 29 February 2024 introducing Book II of the Penal Code

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://www.ejustice.just.fgov.be/eli/loi/2024/02/29/2024002088/justel

In force 22 days, effective 1 September 2026. Binds public and private bodies.

What this law does

Belgium's new Penal Code Book II criminalises accessing or remaining in a computer system without authorisation (Article 524, external access) and, separately, exceeding one's own access rights with fraudulent intent or intent to harm (Article 525, internal access), each punished at sentencing level 2. The offence is aggravated to level 3 under Article 526 where the offender also retrieves the system's data, uses a third party's system, or causes any damage.

Attempt is punished the same as the completed offence (Article 527), and possessing or supplying a device designed to enable the offence (Article 528) or inciting its commission (Article 529) are separate offences; knowingly holding or disclosing data obtained through the offence is a further offence under Article 530. The provision replaces Article 550bis of the 1867 Penal Code, which had criminalised the same conduct in materially the same terms since 13 February 2001.

Article 524 turns on the actor knowingly lacking authorisation to access the system; its text does not add a separate requirement that a technical security measure be defeated.

What it requires

Copyright and text and data mining (TDM)

Code de droit économique, article XI.190, 20°, exception de fouille de textes et de données

Code de droit économique art. XI.190, 20°, inséré par la loi du 19 juin 2022 transposant partiellement la directive (UE) 2019/790 (Moniteur belge, 1 août 2022)Belgian Official Gazette, text of the Act of 19 June 2022 amending the Code of Economic Law

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://www.ejustice.just.fgov.be/eli/loi/2022/06/19/2022015053/justel

In force since 1 August 2022. Binds public and private bodies.

What this law does

The Act of 19 June 2022, transposing Directive (EU) 2019/790, added a text-and-data-mining exception to Article XI.190 of the Code of Economic Law. Point 20° permits reproducing a work that has been made accessible in a lawful manner for the purposes of text and data mining, provided the rightsholder has not expressly reserved that use in an appropriate manner. For content made available online, a reservation counts as appropriate only if it is carried out by machine-readable means.

A reproduction made under the exception may be kept for as long as the text-and-data-mining purpose requires. The same article carries a neighbouring exception at point 19° for a non-profit purpose, which the same 2022 Act lightly amended alongside the new point 20°.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (643 words)

Belgium completed its NIS2 transposition on time to take effect.

The Loi du 26 avril 2024 établissant un cadre pour la cybersécurité des réseaux et des systèmes d'information d'intérêt général pour la sécurité publique (the NIS2 law), published in the Moniteur belge on 17 May 2024 (Numéro 2024202344), entered into force on 18 October 2024 under its own Article 98, and its own Article 97 repeals the predecessor Loi du 7 avril 2019, the original NIS Directive transposition, so no earlier Belgian cybersecurity-framework act remains in force alongside it.

A Royal Decree of 9 June 2024 designates the Centre for Cybersecurity Belgium (CCB), created by the Royal Decree of 10 October 2014, as the national cybersecurity authority under Article 15 of the NIS2 law, and Article 16 gives it the combined roles of competent authority, national CSIRT and single point of contact.

The NIS2 law binds an essential entity and an important entity drawn from its Annex I and Annex II sector lists, which restate the NIS2 Annex I and Annex II sectors, to appropriate and proportionate risk-management measures over their network and information systems (Article 30, an eleven-point list covering risk analysis policy, incident handling, business continuity, supply-chain security, secure acquisition and development including vulnerability handling and disclosure, effectiveness-assessment policy, cyber hygiene and training, cryptography policy, personnel and access-management security, multi-factor or continuous authentication, and its own separate coordinated vulnerability-disclosure policy point, with the management body responsible for approving the measures and answering for a violation under Article 31) and to a graduated significant-incident notification clock to the national CSIRT: a 24-hour early warning, a 72-hour notification, an interim report on request, and a final report within one month (Articles 34 and 35).

Annex II's digital-provider entry names an online marketplace, an online search engine and a social-networking-services platform, and Annex I's digital-infrastructure entry separately names a DNS service provider, a top-level-domain name registry, a cloud-computing-service provider, a data-centre-service provider, a content-delivery-network provider, a managed service provider and a managed security service provider; the Belgian Institute for Postal Services and Telecommunications (BIPT, called "l'Institut" in the text) holds a parallel supervisory and instruction power over a digital-infrastructure provider specifically, inserted into the Loi du 13 juin 2005 relative aux communications électroniques by the NIS2 law's own Articles 84 to 94, while CCB remains the general competent authority for the rest.

No instrument reviewed here imposes a product-security or market-placement duty on a manufacturer independent of the directly applicable Cyber Resilience Act, which is documented at the European Union level and is not restated here.

Belgium has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation and the Loi du 30 juillet 2018's implementation of GDPR Articles 33 and 34's breach-notification duties to the Autorité de protection des données, both of which sit in the privacy topic rather than here.

Separately, the NIS2 law also inserted a conditional safe harbour into the Code penal's unauthorised-access offences (articles 550bis and 550ter) and into article 145 of the 2005 electronic-communications law, for a good-faith vulnerability finder who notifies the system's operator and the national CSIRT within 24 hours and follows with a complete notification within 72 hours; because that duty runs to the person who discovered the vulnerability by accessing another's system rather than to the entity operating it, it reads as a defence to an unauthorised-access offence, whose home is the scraping topic's computer-misuse family, so it is not filed as an instrument here.

The NIS2 law's own penalty provision is administrative rather than criminal: Title 4, Chapter 2 empowers the national cybersecurity authority or the competent sectoral authority to impose an administrative fine, doubled on recidivism within three years, and Article 54, paragraph 2 bars a further administrative fine for conduct already fined by the data protection authorities under GDPR Article 58(2)(i).

Sector security regimes

Loi du 26 avril 2024, Cybersecurity Risk-Management Measures and Governance

Loi du 26 avril 2024 établissant un cadre pour la cybersécurité des réseaux et des systèmes d'information d'intérêt général pour la… sécurité publique, Artt. 30-33Consolidated text, ejustice.just.fgov.be Justel database (mirrored via Internet Archive), Loi du 26 avril 2024, updated to 19 January 2026

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://www.ejustice.just.fgov.be/eli/loi/2024/04/26/2024202344/justel

In force since 18 October 2024. Binds public and private bodies.

What this law does

Article 30 requires an essential entity or an important entity to take appropriate and proportionate technical, operational and organisational measures to manage the risks threatening the security of the network and information systems it uses for its activities or to provide its services, on an all-hazards approach covering at minimum eleven points: risk-analysis and information-system-security policy, incident handling, business continuity (backup management, disaster recovery and crisis management), supply-chain security, security in the acquisition, development and maintenance of network and information systems including vulnerability handling and disclosure, policies to assess the effectiveness of the risk-management measures, basic cyber-hygiene practices and training, cryptography and encryption policy, human-resources security and access-control and asset management, multi-factor or continuous authentication and secure voice, video, text and emergency communications, and the entity's own coordinated vulnerability-disclosure policy.

Article 31 requires the management body of an essential or important entity to approve the cybersecurity risk-management measures it takes to comply with Article 30, supervise their implementation, and answer for that entity's violation of Article 30, without prejudice to the liability rules that otherwise apply to a public institution. Article 32 makes the entity itself responsible for the risk analysis it performs and for the choice and implementation of the Article 30 measures.

Article 33 lets the King, after consulting the national cybersecurity authority, any sectoral authority concerned and the federated entities concerned, impose additional appropriate and proportionate sector- or subsector-specific risk-management measures by decree deliberated in the Council of Ministers. This Act's own Article 97 repeals the predecessor Loi du 7 avril 2019, the original NIS Directive transposition, effective the same date.

What it requires

Vulnerability and incident reporting

Loi du 26 avril 2024, Significant-Incident Notification Obligations

Loi du 26 avril 2024 établissant un cadre pour la cybersécurité des réseaux et des systèmes d'information d'intérêt général pour la… sécurité publique, Artt. 34-37Consolidated text, ejustice.just.fgov.be Justel database (mirrored via Internet Archive), Loi du 26 avril 2024, updated to 19 January 2026

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://www.ejustice.just.fgov.be/eli/loi/2024/04/26/2024202344/justel

In force since 18 October 2024. Binds public and private bodies.

What this law does

Article 34 requires an essential entity or an important entity to notify any significant incident to the national CSIRT without undue delay, following the arrangements set out in a protocol between the CSIRT and the National Crisis Centre (NCCN).

Article 35 sets the clock: an early warning within 24 hours of becoming aware of the significant incident, stating whether it is suspected to result from unlawful or malicious action and whether it may have a cross-border impact; an incident notification within 72 hours, updating the early warning with an initial assessment of the incident's severity and impact and any available indicators of compromise; an interim report if the national CSIRT or the competent sectoral authority asks for one; and a final report no later than one month after the incident notification, describing the incident, its severity and impact, the likely threat or root cause, the mitigation measures applied, and any cross-border impact.

A qualified trust service provider instead reports any significant incident affecting its trust services within 24 hours in a single stage. Article 36 requires the national CSIRT to respond to an early warning within 24 hours where possible, with initial feedback and, on request, operational guidance.

Article 37 lets the national CSIRT, after consulting the entity, the NCCN, any sectoral authority concerned and the responsible minister, inform the public of a significant incident or require the entity to do so, where public awareness is necessary to prevent or manage the incident or where disclosure is otherwise in the public interest. Article 54, paragraph 2 bars a further administrative fine for conduct already fined by the data protection authorities under General Data Protection Regulation (GDPR) Article 58(2)(i).

What it requires

News aggregation law1 instrument, 1 in force

Research summary (171 words)

Belgium transposed the EU press-publisher neighbouring right, Article 15 of Directive (EU) 2019/790, into Article XI.216/2 of the Code of Economic Law by the Act of 19 June 2022, giving a press publisher established in an EU member state an exclusive online reproduction and making-available right, subject to a good-faith negotiation duty and a dispute-resolution avenue before the Belgian Institute for Postal Services and Telecommunications (BIPT), and exempting hyperlinks, isolated words, and very short extracts.

Belgium has no compelled platform-to-publisher bargaining regime comparable to Australia's News Media Bargaining Code or Canada's Online News Act; the BIPT mechanism can fix remuneration once a dispute is referred to it, but nothing compels a platform to strike a deal in the first place. A text-and-data-mining opt-out exception exists in the same Code, inserted by the same 2022 Act at Article XI.190, 20°, and is catalogued in this jurisdiction's scraping-topic record rather than repeated here.

No hot-news or misappropriation doctrine distinct from ordinary unfair-competition law, and no reported decision construing Article XI.216/2, are described here.

Press publishers' right

Code de droit économique, article XI.216/2, droit voisin des éditeurs de presse

Code de droit économique art. XI.216/2, inséré par la loi du 19 juin 2022 transposant partiellement la directive (UE) 2019/790, art. 15 (Moniteur belge, 1 août 2022)Belgian Official Gazette, text of the Act of 19 June 2022 amending the Code of Economic Law

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://www.ejustice.just.fgov.be/eli/loi/2022/06/19/2022015053/justel

In force since 1 August 2022. Binds private bodies.

What this law does

A press publisher established in an EU member state has the sole right to reproduce its press publication and to make it available online for use by an information-society service provider, per Article XI.216/2, paragraph 1.

The publisher and the service provider must negotiate in good faith over that use and the remuneration due, and either may refer an unresolved dispute to the Belgian Institute for Postal Services and Telecommunications, which can decide the remuneration and take a binding administrative decision.

A service provider must give the publisher updated, relevant, and complete information on the number of consultations and the revenue it draws from the publications, on the publisher's written request, so the publisher can value the right, and authors of works integrated into a press publication are entitled to an appropriate, non-transferable share of what publishers collect for the use, set by a collective agreement.

The right does not reach hyperlinking, the use of isolated words or very short extracts of a press publication, or works whose protection has expired. It expires two years after the press publication was first published.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.