Our Expert in Belgium
No results available
Private investigation act belgium reforms are reshaping how companies in Belgium conduct surveillance, screen candidates, run internal investigations and collect evidence for transactions. The new Private Investigation Act (Wet tot regeling van de private opsporing / Loi réglementant la recherche privée) introduces a tighter framework around private investigation activities, corporate monitoring, background checks and evidence collection, and it arrives with an enforcement timeline that leaves limited room for delay. In-house counsel, HR leaders, compliance officers and M&A teams all have operational obligations to consider, from refreshed Data Protection Impact Assessments (DPIAs) to revised due diligence protocols. This guide sets out what changed, what you must do, and which compliance path your organisation should consider.
Who this guide is for: in-house counsel, HR leaders, compliance officers and M&A teams.
What you will get: a plain-language legal summary, operational checklists for HR and IT, M&A due diligence adjustments, a side-by-side decision table, and a 90-day action plan, with a clear recommendation on which route to take.
The Private Investigation Act regulates who may carry out private investigation activities in Belgium, what techniques are permitted, and under what conditions evidence may be gathered and used. In practical terms, it brings corporate surveillance, pre-employment screening, fraud investigations and transactional diligence more firmly within a licensing and proportionality framework, layered on top of existing data protection obligations under the GDPR. The Act replaces and modernises Belgium’s earlier regime governing private detectives.
The statute addresses a broad range of investigative conduct, including:
Enforcement and administration responsibilities sit with the relevant Belgian authorities, with the Federal Public Service (FPS) Justice providing the administering and procedural context and the Belgian Data Protection Authority leading on the data protection dimension. Companies should confirm the exact effective date and any transitional provisions against the official publication in the Belgian Official Journal (Belgisch Staatsblad / Moniteur belge) via e-Justice. Where final statutory text or a specific transitional window is not yet confirmed in the official entry, treat those details as provisional and verify directly before relying on them. The practical message is unchanged: begin remediation early rather than waiting for the last enforcement date.
Enforcement is widely expected to focus first on the most intrusive and least-documented monitoring practices, which means organisations running covert surveillance or undocumented screening should treat those as immediate priorities.
Employee monitoring Belgium practices are where most companies will feel the Private Investigation Act most acutely. The Act does not displace the GDPR; it operates alongside it. That means any monitoring of staff must rest on a valid lawful basis, be proportionate, be transparent, and, where high risk is involved, be assessed through a DPIA before deployment. The Belgian Data Protection Authority and European Data Protection Board have both made clear that workplace monitoring is a high-scrutiny area, and that employee consent is rarely a reliable lawful basis given the imbalance of power in the employment relationship.
In most cases, employers will rely on legitimate interest rather than consent, which obliges the organisation to document a balancing test, apply data minimisation, and provide clear notice. In Belgium, certain forms of monitoring are also governed by sectoral collective bargaining agreements negotiated within the National Labour Council (for example, those addressing camera surveillance in the workplace and the monitoring of electronic online communications data). Specific categories of monitoring carry additional requirements:
Collective consultation matters as much as the legal basis. Where a works council or trade union representation exists, monitoring technologies and policies typically require information and consultation before implementation. Skipping this step undermines both the lawfulness of the processing and the defensibility of any evidence later derived from it.
Clear, plain-language policy wording reduces disputes and strengthens defensibility. A monitoring clause should state the purpose, scope, lawful basis, retention period and employee rights, for example, setting out that email and network use may be monitored to protect information security and detect fraud, that monitoring is proportionate and logged, that data is retained only for a defined period, and that employees may exercise their data subject rights through a named contact. Policy text should be reviewed by Belgium-qualified counsel before adoption.
Monitoring rarely happens in-house alone. Surveillance software, HR screening platforms and forensic tools usually involve processors, which brings vendor contracts into scope. Each DPIA should assess not only the internal processing but the supplier’s role, security measures and sub-processors. Contracts must contain GDPR-compliant processing clauses (consistent with Article 28 of the GDPR), security commitments, breach notification duties, audit rights and clear instructions limiting the vendor to the agreed purpose. A standardised DPIA template should be used to ensure consistency across the organisation.
Commentary: On the HR side, a common failure point is not the technology itself but the absence of a documented balancing test and timely works council consultation. Monitoring maintained without those records is often the easiest target for both regulators and litigation opponents.
Background checks Belgium practices sit within the Private Investigation Act’s reach, because pre-employment vetting can amount to an investigation into an individual. Companies must distinguish between checks that are routinely permissible and those that are restricted. Verification of qualifications, professional references and publicly available professional information is generally defensible where it is relevant to the role and proportionate. Criminal record extracts (uittreksel uit het strafregister / extrait de casier judiciaire), by contrast, are tightly controlled and are only appropriate where the role genuinely justifies them, for example, positions involving significant trust, safety responsibilities or regulated functions.
Core rules for lawful screening include:
Standardised documentation reduces risk. A compliant screening process uses a clear candidate information notice, a defined checklist of permitted checks per role category, and a documented retention schedule. Red flags that should trigger legal review include: blanket criminal checks applied to all roles regardless of relevance, open-ended social media surveillance of candidates, reliance on undisclosed third-party investigators, and retention of screening data with no deletion trigger.
Corporate investigations Belgium teams, whether handling suspected fraud, misconduct or whistleblower reports, must operate with heightened care about method and documentation. The Private Investigation Act reinforces the line between lawful investigative activity and impermissible intrusion, and it connects directly to the investigator licensing and authorisation framework. Internal investigations that stray into covert surveillance, pretexting or unauthorised access to personal data risk not only regulatory exposure but the exclusion of the resulting evidence.
Admissibility of evidence in Belgian courts depends heavily on how it was gathered. Evidence collected unlawfully, without a proper basis, or without a reliable chain of custody is vulnerable to challenge. Legal commentary on privacy and investigations underscores that lawful collection and robust documentation materially strengthen the evidentiary position, while covert methods face a high justification threshold. Companies should assume that any evidence they may later need to rely on in litigation or disciplinary proceedings must survive scrutiny of both the Act and the GDPR.
M&A due diligence Belgium processes are directly affected by the Private Investigation Act, because diligence frequently involves investigating a target’s people, contracts and conduct. Buyers can no longer assume that any investigative method is fair game. Covert investigation of a target’s management or workforce, or acquisition of personal data gathered unlawfully by the seller, creates liability that can follow the buyer post-closing. Sellers, in turn, must be able to warrant that their own monitoring, screening and investigation practices were lawful.
Key adjustments to the deal process include:
For buyers, the practical checklist is to confirm what can and cannot be investigated before signing, to secure seller warranties on lawful investigations and monitoring, to validate data protection compliance in the data room, and to protect against latent liability through reps, indemnities and escrow. For sellers, the priority is to prepare clean documentation in advance, policies, DPIAs, consultation records and screening logs, so that warranties can be given confidently and the transaction is not delayed by avoidable diligence findings.
Commentary: In transactions, the sharpest practical effect of the Act is on warranties and escrow. The likely result is that buyers will insist on explicit representations about lawful investigations and monitoring, and will price unresolved compliance gaps into escrow. Sellers who prepare documentation early typically negotiate from a stronger position and avoid deal friction.
Enforcement of the private investigation act belgium framework involves the competent Belgian authorities, with the FPS Justice providing the administering and procedural context and the Belgian Data Protection Authority handling the data protection dimension. Non-compliance carries several layers of exposure:
Confirm the specific sanctions, thresholds and procedural routes against the official statutory text via e-Justice once the final Act is published; where those details remain provisional, verify before relying on any figure. GDPR fines are, separately, subject to the maximum thresholds set by Regulation (EU) 2016/679.
Every company must now decide how to realign its practices. There are two credible strategies. Most organisations will land on one of the two paths below. Use the table to compare them on the dimensions that matter, then apply the decision framework.
| Dimension | Option A, Risk-Minimiser (Conservative) | Option B, Pragmatic (Business-Continuity) |
|---|---|---|
| Core approach | Immediately restrict surveillance and adopt strict minimisation models; pause intrusive monitoring until full legal review | Continue essential monitoring with mitigations (DPIAs, limited retention, targeted notices) while updating policies |
| Cost (implementation) | Higher short-term cost: audits, tech changes, legal reviews, possible reduced productivity | Moderate cost: targeted audits, vendor SLA updates, incremental tech adjustments |
| Legal liability (administrative/civil) | Lowest exposure if fully compliant; reduces risk of fines and civil claims | Moderate exposure if controls are robust but some monitoring continues under lawful basis |
| Timing to implement | Longer, full policy overhaul and workforce consultation (3–6 months depending on scale) | Faster, targeted actions can be completed in 30–90 days |
| Evidence admissibility | Stronger chain of custody and lawful collection increases admissibility | Admissibility riskier if surveillance maintained without full compliance |
| M&A impact (buyer view) | Buyers insist on clear warranties and remediation, smoother negotiations but possible delays | Preserves business continuity; buyers need stronger reps and escrows |
| Enforceability under Act | Aligns closely with statutory restrictions, easier to demonstrate compliance | Depends on documentation and DPIAs; stronger record-keeping needed to defend approach |
| Operational impact (employee relations) | Reduces perceived intrusion, positive relations but operational limitations | Pushback mitigated by transparent communication and limited scope |
| Recommended companies | Regulated sectors (finance, healthcare), high-litigation-risk firms, groups in sensitive transactions | Fast-moving tech firms, operations requiring continuous monitoring (security, fraud detection) |
| Key first steps | Comprehensive monitoring audit; stop/modify high-risk surveillance; consult works council; update contracts | Conduct DPIA for active systems; update vendor contracts; targeted notices and training |
Our recommendation and decision framework:
If you are unsure, default to Option A for any system you cannot currently document and defend, and apply Option B only to monitoring that already has a completed DPIA, a tested lawful basis and works council sign-off.
For Option A, plan a 3–6 month programme: audit (weeks 1–4), high-risk suspension and interim measures (weeks 2–6), works council consultation (weeks 4–10), policy and contract overhaul (weeks 8–16), and full redeployment under compliant terms (weeks 16–24). For Option B, compress to 30–90 days: DPIA of active systems (weeks 1–4), vendor contract updates (weeks 2–6), targeted notices and training (weeks 4–8), and a documented review checkpoint (weeks 8–12).
Board minutes should record the decision, its rationale and accountability. Indicative wording: “The Board, having reviewed the obligations arising under the Private Investigation Act and applicable data protection law, resolves to adopt the [Risk-Minimiser / Pragmatic] compliance path, approves the associated budget and timeline, and delegates implementation and reporting to [named officer], with a compliance review to be presented to the Board within [period].” Final wording should be confirmed by Belgium-qualified counsel.
Transaction documents should include a warranty that the target’s investigations, monitoring and screening complied with the Act and data protection law; an indemnity covering losses arising from pre-closing non-compliance; a data protection compliance representation covering DPIAs and consultation records; and, where gaps exist, an escrow mechanism tied to defined remediation milestones.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Sabien Lemiegre at Notius Advocaten, a member of the Global Law Experts network.
The following assets support implementation. Where you do not have a current in-house version, ask Belgium-qualified counsel to prepare one tailored to your organisation:
The private investigation act belgium reforms call for action, not observation. Companies should audit their monitoring, screening and investigation practices now, document a lawful basis for everything they intend to keep, complete DPIAs, consult employee representatives, and align M&A warranties and escrow to the new framework. For most regulated and transaction-exposed organisations, the Risk-Minimiser path is the safer choice; for genuinely monitoring-dependent operations with rigorous documentation, the Pragmatic path is defensible. Either way, the 90-day plan above provides a workable route to compliance. To validate your chosen path and adapt these templates to your business, consult a Belgium-qualified corporate lawyer.
posted 2 minutes ago
posted 22 minutes ago
posted 26 minutes ago
posted 59 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message