First status update of Belgian DPA after six months of GDPR
The Belgian Data Protection Authority (DPA) has issued a first status update six months after the GDPR became applicable. The statistics show a remarkable increase in the number of data breach notifications, complaints and requests received.
Since 25 May 2018, 317 data breaches have been notified to the DPA. This is an enormous increase compared to last year, when only 13 data breaches were reported. This increase is obviously due to the fact that there was no obligation to report at that time (except for telecommunication companies or financial service providers).
The top 5 industries reporting data breaches are: (1) health care, (2) insurance, (3) public administrations and defence, (4) telecom and (5) financial services.
In addition, the DPA reports to have received 148 complaints in the past six months, which comes down to almost one complaint per day.
This amount has increased compared to 2017 (when only 76 complaints were received). It is, however, negligible compared to our neighbouring countries, who reported to have received a lot more complaints in the period following 25 May. The CNIL reported that after four months it had already received 3.767 complaints. In the Netherlands, the first six months of the new privacy law yielded more than 7.000 complaints. In both cases, the number of complaints in relation to the number of residents is much higher than in Belgium.
The DPA has released some other noteworthy figures. Since 25 May, the DPA has received:
- 3.599 information requests (compared to 2.145 information requests in 2017);
- 137 requests for advice (compared to 44 requests for advice in 2017);
- 2.551 notifications of the appointment of a DPO (compared to 989 notifications before May 2018).
Furthermore, the DPA announced that the number of cases has increased exponentially under the application of the GDPR. In 2017, the Authority handled just under 5.000 core cases, while for 2018 this number will exceed 7.000.
Lastly, the DPA announced that it has meanwhile started its first investigations. No cases have yet been transferred to the Dispute Chamber in order to be dealt with on the merits (fore more information on the different bodies within the DPA, see our previous newsflash). Unlike Germany, Portugal and Austria, no fines have been issued yet.
On this point, the DPA is running a bit behind our neighbouring countries, who have started their first systematic inspections already at the beginning of the summer and who have already imposed a large number of warnings and sanctions.
It now looks like the DPA is getting up to speed, although it should be remembered that the members of the DPA still have to be formally appointed by the Parliament. As soon as the DPA will be fully operational, it will undoubtedly increase its advisory, inspection and sanctioning activities.
ValérieVerstraetenAttorney at law Associate
Valérie Verstraeten is a member of the Loyens & Loeff Litigation and Risk Management Practice Group in Belgium and of the firmwide Privacy & Data Protection Team. She is an associate in our Brussels office.T: +32 2 743 43 65 E: firstname.lastname@example.org
StéphanieDe SmedtAttorney at law Associate
Stéphanie De Smedt is a member of the Loyens & Loeff Litigation & Risk Management Practice Group in Belgium and a key member of the firm-wide Privacy and Data Protection Team, the Automotive Team and the Healthcare & Life Sciences Team. She is an associate in our Brussels office.T: +32 2 773 23 77 E: email@example.com
YvesVan CouterAttorney at law Partner
Yves Van Couter is a partner at Loyens & Loeff in Brussels. He is the chairman of the Brussels Litigation & Risk Management Practice Group, heads the firm-wide Food & Beverages Team and co-heads the Data Protection & Privacy Team.T: +32 2 773 23 69 E: firstname.lastname@example.org
Don't miss out. Stay up to date about our latest news and events.Subscribe