5 min read By Erwan Goossens
GDPR and cookies: what your website must comply with in Belgium
Cookie banner, consent, privacy policy, forms: the essential GDPR rules for a business website in Belgium, explained simply.
In Belgium, your website must comply with two sets of rules: the GDPR, which governs any collection of personal data (forms, newsletter, analytics), and the cookie rules, which require prior consent for any non-essential cookie or tracker. In practice, that means a cookie banner that lets visitors refuse as easily as they accept, a clear privacy policy, forms that only ask for what is necessary, and well-protected data.
This article gives a practical overview. It is not a substitute for legal advice tailored to your situation.
The GDPR in brief
The General Data Protection Regulation (GDPR) has applied throughout the European Union since 2018. It concerns every business that processes personal data, whatever its size: a freelancer who receives quote requests through their website is concerned.
Its main principles:
- purpose limitation: collect data for a specific, stated purpose;
- data minimisation: only ask for what is necessary;
- transparency: inform people clearly;
- storage limitation: do not keep data indefinitely;
- security: protect data against loss and unauthorised access.
In Belgium, the Data Protection Authority (DPA) monitors compliance with these rules and handles complaints.
Cookies: the prior consent rule
A cookie is a small file stored in the visitor’s browser. The rule is simple:
- strictly necessary cookies for the website to work (session, basket, security, remembering the cookie choice) do not require consent;
- all others (analytics, advertising, social networks, embedded videos and maps) may only be set after the visitor has given consent.
Consent must be freely given, specific, informed and unambiguous. In practice:
- no pre-ticked boxes: the Court of Justice of the European Union confirmed this in 2019 (Planet49 ruling);
- simply continuing to browse does not count as consent;
- refusing must be as easy as accepting;
- visitors must be able to withdraw their consent at any time, as easily as they gave it;
- you must be able to prove consent.
The Belgian DPA takes a demanding view of these rules, including for audience measurement tools. To be on the safe side, ask for consent for any analytics tool, even one that presents itself as privacy-friendly.
A compliant cookie banner: the checklist
- A banner that appears on the very first visit, before any non-essential cookie is set.
- “Accept all” and “Reject all” buttons with the same visual weight.
- A “Customise” button, with a choice per category (analytics, marketing, external content).
- Clear information: who sets which cookies, why and for how long.
- A permanent link, for example in the footer, to change one’s choice.
- New consent requested when the cookie policy changes significantly.
Watch out for embedded content
A Google Maps map, a YouTube video, fonts loaded from an external service or a reCAPTCHA send data to third parties, at the very least the visitor’s IP address, and often set cookies. The solutions:
- only show the map or video after consent, with a button such as “Show the map”;
- host fonts on your own server;
- replace non-essential services with solutions that collect nothing.
The privacy policy
As soon as your website collects personal data (contact form, newsletter, booking, analytics), you must publish an easy-to-find privacy policy. It states in particular:
- who the data controller is and how to contact them;
- what data is collected and why;
- on what legal basis (consent, contract, legitimate interest…);
- who receives the data (hosting provider, emailing tool…) and whether it leaves the European Union;
- how long it is kept;
- people’s rights: access, rectification, erasure, objection, restriction and portability;
- the right to lodge a complaint with the DPA.
Forms and newsletters
- Only ask for what is necessary: for a quote request, a name, a means of contact and a message are often enough.
- Explain what the data is used for, right next to the form.
- Newsletter: a separate checkbox, never pre-ticked. Sending marketing emails in principle requires prior consent. Double opt-in, meaning confirmation of the subscription by email, is good practice and also lets you prove the subscription.
- An unsubscribe link in every email.
Security and processors
- Your website must use HTTPS, with the padlock in the browser.
- Software and plug-ins must be updated regularly, and the website backed up.
- With every provider that processes data on your behalf (hosting provider, emailing tool, payment provider), a data processing agreement must govern that processing.
- In the event of a data breach that presents a risk, you must notify the DPA within 72 hours.
What a non-compliant website risks
The DPA can issue warnings and reprimands, order compliance measures and, in serious cases, impose fines of up to €20 million or 4% of worldwide annual turnover. Beyond penalties, a website that respects its visitors’ privacy inspires more trust.
The example of the Novexa Digital website
The Novexa Digital website applies these principles: no non-essential cookie or tracker before you choose, a banner that lets you refuse in one click, analytics (Plausible) loaded only after consent, a Google Maps map shown only if you accept it, fonts hosted on our own server and a “Manage my cookies” link in every footer. Would you like the same care for your website? Let’s talk.
Frequently asked questions
My website uses no analytics cookies: do I need a banner?
If your website only uses strictly necessary cookies, no consent banner is required. A privacy policy is still needed as soon as you collect data, for example through a contact form.
Are cookieless analytics tools exempt from consent?
Not necessarily: the rules also cover other tracking techniques, and the DPA takes a strict approach. To be on the safe side, ask for consent, as for other audience measurement tools.
Who is responsible for my website’s compliance?
You are, as the website publisher and data controller. Your web provider helps you put the right tools in place, but it is up to you to decide what data you collect and why.
In short
Prior consent for non-essential cookies, refusing as easy as accepting, a clear privacy policy, minimal forms and up-to-date security: these are the basics of a compliant website in Belgium. To go further, the DPA publishes practical information on its website, dataprotectionauthority.be. And for a website that is compliant by design, discover our services.