EY Law BE

Belgian DPA changes its portal for notifying data breaches!

Belgian DPA creates a new portal to optimize the reporting process, thus replacing the e-forms which were cumbersome to complete.

    Key takeaways
  • Belgian DPA has a developed a new platform to manage your DPO case and for notifications of data breaches
  • Make sure you take actions as soon as possible as this will impact your data breach reporting timeline

You may have heard that the Belgian National Data Protection Authority (‘DPA’) has changed its portal for notifying data breaches and managing your Data Protection Officer case. The Belgian DPA has created a new portal to optimize the process, thus replacing the cumbersome e-forms which many struggled to complete. A welcome and positive change!

How does this new portal impact you?

  • The platform works with a company account. Persons with access to this company account are the ones who can perform actions in the portal on behalf of the company. Only one unique company account can be created.
  • Only one e-mail address can be registered for exchanging contact with the DPA and the DPO or your data protection team.
  • Only one DPO or Data Protection Manager (DPM) can be registered per company. It is therefore no longer possible to register multiple DPOs for the same company at the same time.
  • DPOs will not automatically have access to the account of the company for whom they are registered as DPO.

Access to the platform is very important for the correct functioning of the DPO or the DPM. Access can only be granted through the company registered in the Crossroads Bank for Enterprise and via the Federal Authentication System (FAS). Thus persons who have been assigned the role of Data Protection Officer via MyGov role management can access the portal and thus notify the Belgian DPA in case of a data breach as well as a change in the person exercising the role of the DPO. 

Do you need to take action?

  • Yes, you should verify your existing roles in the eGov-module and create an additional role for the DPO. Allowing your DPO or DPM to efficiently access the platform in case of data breaches and allowing your organization to respect the 72 hours reporting deadline.
  • Update your procedures for Data breaches and DPO notifications
  • Are wondering how you need to do this? We can certainly assist you by setting up the correct profile.