
Split-purchase: position reversal of the General Administration of Taxes
On July 7, 2020, the federal Administration of Taxes was obliged (once again) to reconsider its position regarding the so-called “split purchases” in the Walloon and Brussels Regions, following the opinion issued by the Council of State on June 18, 2018.
It should be recalled that “split-purchase” is an estate planning technique that consists in purchasing (im)movable property in a dismembered form: the parent purchases the usufruct of the property and the child buys the bare ownership. Therefore, on the death of the parent, the usufruct is extinguished and the property becomes fully owned by the child, in principle without taxation.
Nevertheless, from a tax point of view, a legal fiction has been created (i.e. art. 9 of the Inheritance Tax Code and art. 2.7.1.0.7 of the Flemish Tax Code) according to which the property in its entirety will be presumed to form part of the usufructuary’s estate, except where it can be proved that it is a hidden gift. Thus, in order to reverse this presumption and avoid the application of the tax provisions, it is common practice for the parent to make available, prior to the purchase and via a (registrable) donation, the funds necessary to acquire the property.
Previously, the federal tax authorities allowed the presumption to be reversed, provided that (i) either the previous donation of the funds had been registered (necessarily implying the levying of the 3% gift tax in the Flemish and Brussels Regions and 3.3% in the Walloon Region for direct line donations) prior to the acquisition of the property, or (ii) the taxpayer could demonstrate the absence of a link between the donation and the (im)movable purchase. This position has been taken over by the tax administration of the Flemish Region (VLABEL) and extended, in 2016, to split transfers of (portfolio-) securities and cash investments.
However, on 12 June 2018, the Council of State called VLABEL to order, pointing out that it is irrelevant as to how the purchaser of bare ownership had obtained the funds intended for its acquisition. The question of whether or not the gift had been registered in advance was therefore irrelevant. VLABEL therefore had to revise its position.
In this respect, the federal tax authorities asserted on July 7 that in order to provide proof to the contrary, it was sufficient for the bare owner to demonstrate that the donation took place prior to the signature of the purchase deed, no more and no less. Minor precision in the Brussels and Walloon Regions: if the sale agreement provides for the payment of a sum (deposit, guarantee, etc.), it is necessary to provide evidence that the donation was made before the date of the sale agreement, even if the acquisition was made under a suspensive condition. This proof can be brought by any legal means, to the exclusion of any proof originating from the parties themselves, such as the oath or the claims of the parties (thus an “attached pact” does not seem sufficient).
However, in the Flemish Region, this latter condition does not seem to be required, so that it would be sufficient for the donation to take place before the notarial act of sale is signed.
The new position of the federal tax administration applies to all split purchases made after 1 August 2020.
Read More
Google’s failure to respect the « right to be forgotten » results in €600,000 fine
In its Decision 37/2020 of 14 July 2020 X c/Google (Decision) the Belgian Data Protection Authority (APD/GBA) fined Google Belgium 600,000 euros for failing to respect a citizen’s right to have certain harmful information delisted. (The right is sometimes referred to as the ‘right to be forgotten’). This is the highest fine imposed by the APD/GBA to date. The APD/GBA also ordered delisting of the content in the European Economic Area (EU + Iceland, Liechtenstein and Norway) – but it stopped short of ordering the worldwide ban that the Plaintiff (“X”) had called for.
Facts
X brought a complaint against Google Belgium SA (GB) complaining that GB had refused to deregister certain out of date articles appearing on web-pages available from Google Search (Search) which X alleged were damaging to X’s reputation. X has a prominent position in public life. The case therefore meant that the APD/GBA Litigation Chamber had to assess the correct balance between X’s fundamental rights to protection for personal data (Article 7 and 8 EU Charter of Fundamental Rights {EUCFR}) against the public interest right to freedom of information, (Article 11 EUCFR).
The decision has five operative parts each of which is summarised in the headings below.
- Jurisdiction of the APD/GBA; and
- Is Google Belgium a data controller for the purpose of the complaint?
The Litigation Chamber had asked to be informed about the roles of the different entities in the Google Group (GB, Google Ireland Ltd. and Google LLC, established in California (hereafter together ‘Google’). GB argued that the complaint was unfounded because the data controller was Google LLC in California.
That argument should be viewed in the light of the well-known May 2014 judgment of the CJEU in Costeja (Case C-131/12) which found that Google’s national subsidiaries in the EU are establishments of the company and that processing for Search is carried out in the context of the activities of those establishments – which makes them subject to EU data protection rules.
- Although the APD/GBA accepted that Google LLC was the data controller it held that, because the activities of Google Belgium and Google LLC are inextricably linked, the Belgian subsidiary should be considered to be an establishment of the data controller within the EU, subject to compliance with EU data-protection rules and against whom X’s complaint could properly be brought. The territorial application of a request for delisting
X requested a worldwide delisting. The Litigation Chamber had some doubts that a worldwide delisting might be unenforceable. On the other hand it consulted informally with its counterpart supervisory authorities on an EEA-wide delisting to ensure that they considered such an order would not disproportionately infringe the freedom of information of Internet users in other Member States. With one exception the other authorities supported such a course of action.
- X’s specific requests for delisting
X made two categories of specific de-listing requests, first concerning political affiliation and second regarding an allegation of harassment that had been declared unfounded more than ten years ago. Google decided not to de-list any of the pages in question. The APD/GBA found that maintenance of the pages concerning X’s political affiliation was in the public interest in view of X’s role in public life. However, concerning the harassment allegations, APD/GBA found the request for delisting was well-founded and that Google’s refusal was negligent and constituted a serious breach because it had clear evidence that the facts alleged had been dismissed.
- Infractions of the GDPR and the penalties applied
The €600,000 fine imposed took account of the lack of transparency in the delisting form that Google provided, the lack of information provided to X to justify the refusal to delist as well as the negligent refusal to delist the historical allegations of harassment. Google was also ordered to change its de-listing request forms so as to clarify which entity or entities are the data controller(s) responsible for the data processing.
Conclusions
In the APD/GBA Press Release Hielke Hijmans, Chairman of the APD/GBA Litigation Chamber, is reported to have commented: (our informal translation): ‘This decision is historic for the protection of personal data in Belgium, not only because of the amount of the penalty, but also because it ensures that full and effective protection of the citizen is supported in cases related to large international groups’ (…) whose structure is very complex. The Decision can be appealed within thirty days.
Practical takeaways from the case include that:
- Data controllers should ensure their privacy policies and their answers to data subject requests are precise and transparent.
- Data subjects have an interest in bringing their complaints before the competent data protection authorities (DPA) as the costs are likely to be less, the DPA has its own investigative powers and the procedure is likely to be quicker.
- The range of sanctions available to a DPA is important and they are being used more actively as experience of implementing GDPR builds up.
- The case confirms the Costeja jurisprudence that, as regards GDPR enforcement, where the activities of an EU subsidiary are inextricably linked with those of a data controller outside the EU a GDPR complaint may be legitimately brought against the EU subsidiary and the competent DPA will have jurisdiction to decide the complaint.
Read More

Schrems II Judgment of 16 July 20: Personal Data Transfers to the USA
“The case raises issues of very major, indeed fundamental, concern to millions of people within the European Union and beyond. Firstly, it is relevant to the data protection rights of millions of residents of the [EU]. Secondly, it has implications for billions of euros worth of trade between the EU and the US and, potentially, the EU and other non-EU countries”. Judgment of Ms. Justice Costello, 3 October 2017, Irish High Court.
“At its core, this case is about a conflict of law between US surveillance laws which demand surveillance and EU data protection laws that require privacy”. //noyb.eu/en/project/eu-us-transfers; consulted on 16 July 2020.
“The Court clarified for a second time now that there is a clash between EU privacy law and US surveillance law. As the EU will not change its fundamental rights to please the NSA” [the US National Security Agency], “the only way to overcome this clash is for the US to introduce solid privacy rights for all people – including foreigners. Surveillance reform thereby becomes crucial for the business interests of Silicon Valley.” Max Schrems (Chair of noyb.eu and party in the case) First Statement 16 July 2020.
(…) “we are still studying the decision to fully understand its practical impacts.” “We have been and will remain in close contact with the European Commission and European Data Protection Board on this matter and hope to be able to limit the negative consequences to the $7.1 trillion transatlantic economic relationship that is so vital to our respective citizens, companies, and governments”. U.S. Secretary of Commerce Wilbur Ross 16 July 2020 Statement on the Schrems II case.
“Today’s judgment provides” [a decisive statement of position from the CJEU], “firmly endorsing the substance of the concerns expressed by the DPC (and by the Irish High Court) to the effect that EU citizens do not enjoy the level of protection demanded by EU law when their data is transferred to the United States. In that regard, while the judgment most obviously captures Facebook’s transfers of data relating to Mr Schrems, it is of course the case that its scope extends far beyond that, addressing the position of EU citizens generally”. Data Protection Commission (Ireland) Statement on CJEU decision 16/07/2020.
[At the time of writing no written statements from Facebook Inc. or Facebook Ireland Limited were available : // about.fb.com/news/]Background
Mr Schrems, an Austrian national resident in Austria and a Facebook social network user since 2008, filed a complaint with the Irish Data Protection Commissioner (the DPC) in June 2013 requesting the DPC to prohibit Facebook Ireland, as data controller, from transferring his personal data to the United States. Mr Schrems complaint was that law and practice in the United States did not ensure ‘adequate’ protection of the personal data held in its territory against the surveillance activities of the US public authorities contrary to the requirements of the Data Protection Directive (the DPD). In result of that complaint, and following a reference to the EU Court of Justice {CJEU}, the original EU Commission Decision which had found that the US Safe Harbor arrangements for transfers of personal data to the USA were ‘adequate’ (providing for essentially equivalent protection for such personal data as that required in the EU) was ruled invalid. (‘Schrems I’, Judgment of the CJEU of 6 October 2015).
In practice, thereafter, many companies turned to Standard Contractual Clauses (the SCCs) as a contractual means of ensuring compliant transfers of personal data to the USA. (There are currently three sets of SCCs, adopted by separate Commission Decisions, including the 2010 SCCs).
‘Safe Harbor’ was replaced by the ‘EU-US Privacy Shield’ approved by a Commission Decision of July 2016. An innovation in Privacy Shield was the creation of an Ombudsperson, independent of the intelligence community, to mediate surveillance concerns. In its approval Decision the Commission found that the United States ensured an adequate level of protection for personal data transferred from the EU to organisations in the USA who had self-certified that they comply with the Privacy Shield. The 2010 SCCs were amended in 2016 to take account of Schrems I and Privacy Shield.
The General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) was adopted in April 2016 and replaced the Data Protection Directive as from 25 May 2018.
The story does not end there. Back in Dublin, the Irish Data Protection Commissioner (DPC) invited Mr Schrems to amend his original 2013 complaint requesting the DPC to prohibit the transfer of his personal data to Facebook in the USA to take account of the Schrems I judgment. Mr Schrems wrote to Facebook and asked them to clarify the lawful grounds they relied on for making such transfers of users’ personal data. Facebook replied that they substantially relied on the 2010 SCCs for their EU data controller to non-EU data processor transfers.
The Reference to the CJEU
In his reformulated complaint, Mr Schrems asserted that the contractual clauses relied on by Facebook do not correspond to the 2010 SCCs and moreover that the SCCs do not themselves offer adequate protection for personal data of Facebook’s users because Facebook is required to make the data available to the US authorities. The DPC investigated to determine: first, whether the USA ensures adequate protection of the personal data of EU Citizens and, second, whether the SCCs offer sufficient safeguards of fundamental rights and freedoms. In a draft Decision of May 2016 the DPC considered, provisionally, that, taking account of EU citizens’ rights to respect for their private life, home and communications; protection of personal data; and to have an effective remedy before a tribunal; as provided respectively by Articles 7, 8 and 47 of the Charter of Fundamental Rights of the European Union (CFREU): (…) “the SCC Decisions are likely to offend against article 47 of the Charter insofar as they purport to legitimise the transfer of the personal data of EU citizens to the US notwithstanding the absence of a complete framework for any such citizen to pursue effective legal remedies in the US”.
On that basis the DPC brought proceedings before the High Court in Dublin, including Mr Schrems and Facebook as defendants, and requesting the court to determine whether issues regarding validity of the SCCs required a reference to the CJEU, which alone is competent to rule on the validity of EU legislative acts (Schrems I and cf. Achmea, Case C-284/16 [2018] ECLI:EU:C:2018:158). Pursuant to a judgment of Ms. Justice Costello of 3 October 2017, the High Court in Dublin referred eleven detailed questions to the CJEU, under the preliminary ruling procedure, including on the interpretation and validity of the 2010 SCCs.
Case C-311/18 – Advocate General Saugmandsgaard Øe’s Opinion of 19 December 2019
The reference was made on 8 May 2018. In his Opinion the Advocate General stated at the outset that his examination had not disclosed anything to affect the validity of the 2010 SCCs in principle (in abstracto) – but drew a distinction between that determination and whether the transfers in dispute should be suspended in concreto (Opinion at §166). He suggested, however, that the CJEU did not need to respond to the other questions from the referring Court or analyse the validity of the Privacy Shield Decision – because the referring Court had not directly questioned the validity of the finding of adequacy in that Decision. Nevertheless, and in case the CJEU considered that it should respond in detail on the questions asked, he did go on to find that the ‘essential equivalence’ between the judicial protection afforded in the United States legal order to persons whose data are transferred to the United States from the EU was “open to question” (Opinion at §341).
CJEU Judgment in Case C-311/18 of 16 July 2020
The CJEU has been more forthright than the Advocate General felt able to be. Regarding territorial scope, the Court confirmed that Article 2(1) and (2) of the GDPR applied to the transfer of personal data for commercial purposes by an economic operator established in the EU to an economic operator in a third country outside the EU irrespective of whether the data is liable to be processed by authorities in the third country for purposes of public security, defence and State security.
The Court found that the Commission’s Privacy Shield Decision was invalid. On the other hand, it did not invalidate the 2010 SCCs. However, on that subject it clarifiedé that:
- Transfers supported by using SCCs, must provide data subjects with a level of protection equivalent to that guaranteed within the European Union by the GDPR read in the light of the CFREU: [The validity of the Commission’s SCC decisions] “depends, … , on whether, … such a [SCC] decision incorporates effective mechanisms that make it possible, in practice, to ensure compliance with the level of protection required by EU law and that transfers of personal data pursuant to the clauses of such a decision are suspended or prohibited in the event of the breach of such clauses or it being impossible to honour them”. (Judgment at 137.)
- Unless there is a valid European Commission adequacy decision, the National Supervisory Authority which is competent to consider a case, is required to suspend or prohibit the transfer of data to a third country pursuant to SCCs if it takes the view that in practice the contractual clauses cannot be complied with in a third country and cannot be assured by other mechanisms if the controller or processor has not itself suspended or put an end to the transfer. (see Judgment at 113.)
Conclusions
- The judgment makes very clear how important a finding of adequacy is to permit frictionless personal data transfers to third countries.
- It emphasises that SCCs are not ‘sign-and-forget’ documents but need to be reviewed and supported where necessary. “In that regard, recital 109 of the [GDPR] states that ‘the possibility for the controller … to use [SCCs] … should [not] prevent [it] … from adding other clauses or additional safeguards’ and states, in particular, that the controller ‘should be encouraged to provide additional safeguards… that supplement [SCCs]” (Judgment at 132).
- The Irish DPC will now need to assess whether it is required to suspend or prohibit the transfer of personal data from Facebook Ireland to Facebook Inc. in the United States. (A more general prohibition on personal data transfers to the USA, would need to be referred to the European Data Protection Board for a binding opinion: see Judgment at 147.)
- For the United Kingdom (UK), taking account of the fact that it has chosen to exit from the CFREU, the judgment increases the pressure to secure an adequacy decision before 31 December 2020 and the end of the transition period.

Consequences of the United Kingdom’s withdrawal from the European Union n° 5: Implementing the Protocol on Ireland (I) / Northern Ireland (NI)
2 July 2020
“Clarity on the practical measures that will be necessary to implement the Protocol, and the steps that businesses based in or trading with Northern Ireland need to take to prepare, is now required as a matter of acute urgency if damage to the Northern Ireland economy is to be avoided”. (House of Lords European Union Committee: Report on the Protocol on Ireland/Northern Ireland [HL Report on the P-INI] – 1 June 2020, paragraph 329).
Trade in Goods – Some Brief Facts
Most trade in goods through Northern Ireland’s ports (68%) was with Great Britain (England, Scotland and Wales). A total of 863,511 road goods vehicles passed through NI ports in 2018. Source: NISRA Northern Ireland Ports Traffic 2018 Published on June 2020. Source: NISRA Northern Ireland Ports Traffic 2018 Published in June 2020.

NI – Intersection of EU’s Customs Union & Single Market with the UK’s Internal Market
In less than six months’ time, on 1 January 2021, the P-INI to the UK Withdrawal Agreement (WA) becomes operational – whether or not a Free Trade Agreement is concluded. Northern Ireland is where the UK’s Internal Market intersects with the EU’s Customs Union and Single Market. The significance of that intersection lies in the acutely important link between economic prosperity and political stability.
The P-INI expressly recognises the unique circumstances that exist on the island of Ireland. It affirms that the successful culmination of the peace process, the Belfast/Good Friday Agreement of 10 April 1998, should be protected. Its key assumption is that there shall be no return to a hard border for the movement of goods on the island of Ireland. Practically, that objective is achieved by situating a (virtual) border between GB and NI – in the Irish Sea.
Trade in goods the tension between P-INI Articles 4 and 5
The main proposition of P-INI Article 4 is short and straightforward, it states that “Northern Ireland is part of the customs territory of the United Kingdom”. That apparent simplicity has to be read subject to Article 5 which is about customs and the free movement of goods.
P-INI Articles 5(1), 5(3) and 5(4) are more technical, they say respectively:
- P-INI 5(1) No customs duties shall be payable for a good brought into Northern Ireland from another part of the United Kingdom by direct transport, notwithstanding paragraph 3, unless that good is at risk of subsequently being moved into the Union, whether by itself or forming part of another good following processing. (…)
- P-INI 5(3) “Legislation as defined in point (2) of Article 5 of Regulation (EU) No 952/2013 shall apply to and in the United Kingdom in respect of Northern Ireland (not including the territorial waters of the United Kingdom)” (…).
- P-INI 5(4) “The provisions of Union law listed in Annex 2 to this Protocol shall also apply, under the conditions set out in that Annex, to and in the United Kingdom in respect of Northern Ireland”. (…) (All emphases added.)
Interpretation of the combined effect of P-INI Articles 4 and 5
The reference to Regulation 952/2013 makes the entirety of the EU Customs legislation applicable in Northern Ireland. The provisions listed in P-INI Annex 2 are EU single market rules and regulations. The combined effect is to introduce what we can refer to for simplicity’s sake as red and green channels for direct transport of goods from GB to NI. Goods that are ‘at risk’ of being moved subsequently to Ireland (whether by themselves or having been incorporated in other products) will be subject to EU standards, customs treatment and EU tariffs – (red channel). The Joint Committee which is to administer the P-INI is to define what ‘at risk goods’ are. Green channel goods that are not ‘at risk’ will be subject to fewer formalities.
Reducing the complexity of implementing P-INI Article 5
The HL Report referred to at the start of this article identifies a number of potential means to mitigate the potential impact of Article 5 on Northern Ireland (at para. 98) including:
- Agreement of a comprehensive UK-EU free trade agreement;
- Streamlining customs processes;
- Implementing the Joint Committee’s definitions of goods that are ‘at risk’.
- Technological solutions;
However, neither the FTA nor these practical arrangements are yet in place.
Northern Ireland Business – Brexit Working Group (NIB-BWG) working paper
On 29 May the NIB-BWG published a detailed paper on implementing the P-INI subtitled: What Business in Northern Ireland needs and why. It sets out almost sixty practical questions about implementing the arrangements. (The paper is a response to the UK Government’s 20 May Command Paper: The UK’s Approach to the Northern Ireland Protocol. ‘Command Papers’ are official publications that set out details about major government initiatives.)
The delayed ‘Freeports’ consultation – an added complexity?
Up to ten ‘Freeports’ are to be introduced within the UK’s geographical territory but outside its ordinary customs territory including, potentially, in Northern Ireland. Freeports are intended to be innovative hubs and attract inward investment. They will have separate customs rules. The UK Government’s Freeports consultation, due to close in April, will now close on 13 July 2020.
Conclusion: A great deal remains to be done in a short time to help businesses that are either in or trading with NI make practical preparations to implement the P-INI.
Disclaimer: This general memorandum may not deal with every important topic or cover all important aspects of the subject matter. It is not intended, and should not be used, as a substitute for seeking appropriate legal advice on specific questions. FLINN stands ready to provide any further information that you may require.
Read More
Making compliant use of CCTV
In line with its 2020 priorities (see the previous article ‘Two years of the GDPR’), the Belgian Data Protection Authority (APD/GBA) recently published Decision 16/2020 (Decision) clarifying the regulatory requirements for use of surveillance cameras (CCTV) and keeping of compliant records.
Facts
Plaintiff (“P”) complained that his image was captured without his consent while walking on the pavement outside the defendant’s shop in violation of the applicable law. P stated that he could see his image displayed on a screen at the rear of the shop. He assumed the images had been recorded. The APD/GBA Litigation Chamber formally reprimanded the defendant (D) for D’s failure to declare the use of CCTV as well as failure to establish a Register of its personal data processing activities. It also required D to establish a record of all processing activities within 3 months.
Rules on the installation and use of CCTV
Article 6 § 2 of the “Camera Law” (Law of 21 March 2007 on the installation and use of surveillance cameras as amended and up-dated), requires a data controller who intends to install surveillance cameras in an “enclosed place accessible to the public”, such as a shop or supermarket, to notify the APD/GBA and police authorities using the mandatory electronic form before the surveillance cameras are put into operation. They must also display signs showing that CCTV is in use.
Register of CCTV image processing
A Royal Decree of 8 May 2018 (Royal Decree) defines the record of the image processing activities that must be kept. In addition to the data controller’s record of personal data processing (required by article 30(1) General Data Protection Regulation (GDPR) – see below) the image processing register must include information such as:
- The legal basis for the processing;
- What type of premises are concerned;
- A technical description of the surveillance cameras and, in the case of fixed cameras, a plan of the premises showing where they are installed;
- Whether or not viewing in real-time is organized and, if so, how it is organized.
The image processing register must be made available to the APD/GBA or to the police on request.
Record of personal data processing under GDPR
According to article 30(1) GDPR, any controller of personal data must keep a record of data processing activities carried out under his/her responsibility including, amongst other things:
- Name and contact details of the controller and the purpose(s) of the processing;
- Description of the categories of data subjects and the categories of personal data processed.
The article 30 GDPR register of processing activities is a living document which needs to evolve as the data controller’s activities change. It must be kept up to date.
Clarifications and confirmations made by the APD/GBA Decision
The APD/GBA Decision clarifies that it is not necessary to maintain two separate registers. A single Register can be kept, provided that it contains all the mandatory entries – including those specifically required by the Royal Decree for surveillance cameras.
The Decision also confirms that keeping of an article 30(1) GDPR register will be mandatory for most small and medium sized businesses. The four exceptions for enterprises with fewer than 250 employees set out in article 30(5) GDPR will be considered separately and interpreted narrowly.
In particular, the exception for ‘occasional’ processing of personal data is unlikely to apply in the majority of cases, because data processing related to customer management, personnel management (human resources) or supplier management is routine (in practice often monthly) and therefore not occasional.
Disclaimer: This general memorandum may not deal with every important topic or cover all important aspects of the subject matter. It is not intended, and should not be used, as a substitute for seeking appropriate legal advice on specific questions. FLINN stands ready to provide any further information that you may require.
Read More
Two years of the « GDPR »
25 May 2020
Today is the second anniversary of the date in 2018 when the General Data Protection Regulation (GDPR) became enforceable. It is also the date on which the first official evaluation of the GDPR should be made. Even if the formal evaluation is delayed – some trends can already be identified.
Requirement for an evaluation
The formal requirement for the EU Commission to submit a review and evaluation to the European Parliament and to the Council is set out in Article 97 GDPR. The first such evaluation was scheduled for today, 25 May 2020. Subsequent reviews are to be made every four years.
European Data Protection Board (EDPB) pre-evaluation
The EDPB issued its contribution to the EU Commission’s formal evaluation in February this year. It made a generally positive assessment of the GDPR but acknowledged that implementation has been especially challenging for small or medium sized enterprises (SMEs). It pointed out that the ability of the member states’ Data Protection Authorities (DPAs) to support the ‘one-stop-shop’ mechanism (intended, together with co-operation, to improve cross-border legal certainty for data controllers and data processors) depends on them being provided with sufficient resources. As regards international transfers, to third countries outside the EU, EDPB called on the EU Commission to update the existing Standard Contract Clauses (SCC’s) in-line with the GDPR and emphasised the need to adopt a set of processor-to-processor SCC’s. (The Court of Justice of the European Union is due to deliver its judgment, regarding legality of the existing SCCs, on 16 July in the Schrems II case, Case C‑311/18.)
What else do we know Europe-wide?
Before the impact of Covid-19 in April/May 2020, the number of fines per month was increasing significantly. An insufficient legal basis for data processing was the reason for the greatest number of fines. The heaviest fines were issued for a lack of technical and organisational measures to ensure data security. (Supporting statistics are available here.)
What else do we know that specifically concerns Belgium?
Although legislation creating the Belgian DPA (APD/GBA) was adopted in December 2017, the transition period towards full GDPR implementation has been relatively long. The new Executive Committee, of five directors, did not take office until 24 April 2019, just over one year ago. Priority areas for the APD/GBA’s Strategic Plan 2020-2025 include: Telecommunications and Media, Direct Marketing, Education, support for SMEs and certain societal issues, notably: use of surveillance cameras and photography, online data protection and protection of sensitive data (see the summary here).
The APD/GBA now has significant inspection and sanctioning powers. Accordingly, it has two new departments: a litigation chamber, which is supported by an inspection service. Complaints to the APD/GBA are the source of the majority of most ongoing case referrals, but current own initiative investigations of the cookies policies of online media websites are likely to be followed by reviews of several of the other ‘most consulted’ websites in Belgium.
Conclusions
The level and intensity of GDPR enforcement in Belgium and across the EU is set to increase.
Disclaimer: This general memorandum may not deal with every important topic or cover all important aspects of the subject matter. It is not intended, and should not be used, as a substitute for seeking appropriate legal advice on specific questions.
Read More
How can contact tracing help limit the spread of the Covid-19 coronavirus?
19 May 2020
Belgium has taken the decision that a coronavirus ‘App’ is not necessary for contact tracing. In the UK, NHSX has launched a trial on the Isle of Wight of a proprietary smartphone App. Other European countries, including Germany, have opted to deploy systems facilitated by co-operation between Apple (iOS) and Google (Android) on Blue-tooth technology. Are there clear benefits of using data applications for contact tracing? What are the potential detriments?
Contact tracing – a proven technique
Contact tracing is used to help break chains of transmission and control virus outbreaks. Using interviews and questionnaires to carry out the contact tracing manually is a well-known and proven technique. Nevertheless, it is labour intensive and time consuming. (You can consult the WHO’s report on using manual tracing to help control outbreaks of Ebola here.)
Digital proximity tracing using smartphones
The idea behind digital proximity tracing is to make use of ‘Bluetooth’ Low Energy (LE) signals, from the smartphone in your pocket, to record and estimate the distance between you and other smartphone users with whom you have come into reasonably close contact. Such tracing can establish, from among those who subscribe to and turn on the App, a list of persons to whom you have been physically close. If you test positive, contacts identified through the App can be alerted to take action, by self-isolating or accessing a Covid-19 test for example.
Centralised or decentralised digital proximity tracing?
In digital proximity tracing, users download an App to their smartphone which, when enabled, transmits random ‘identifiers’ (a string of digits) using Bluetooth LE. Other similarly enabled smartphones, that come close enough, detect and record the unique identifiers.
In a centralised system, if a person tests positive for Covid-19, the anonymised identifiers transmitted by their phone can be uploaded to the central server together with the time and duration of near contacts with other smartphones. Third-party contacts calculated to be at risk are centrally contacted and notified that they have been in proximity to an infected person.
In a decentralised system, a person who tests positive for Covid-19 self-reports their identifiers to a database. The database of positive identifiers is available to be consulted daily by all other users of the App, but any matching takes place on the user’s own device – not centrally.
The legal issues?
A balance needs to be struck between a government’s duty to protect public health and restrictions of individual rights to privacy. Even if App usage is voluntary, the health advantages must be weighed against privacy disadvantages (see the open letters here and here). Public confidence that the right balance has been struck will underpin widespread adoption.
Data Protection Authorities and Contact Tracing Apps
The ICO document about how data protection principles should be implemented in such Apps is here. Data protection aspects of the UK’s current NHSX proposal were criticised by politicians here and by an academic here. France’s CNIL emphasised that voluntariness, a correct legal basis, transparency and technical efficiency are all necessary to generate public confidence. Its cautious initial approval for a (centralised) French contact tracing system is here.
Disclaimer: This general memorandum may not deal with every important topic or cover all important aspects of the subject matter. It is not intended, and should not be used, as a substitute for seeking appropriate legal advice on specific questions.
Read More
Prolongation of the general moratorium provided for by Royal Decree No. 15
On Wednesday 13th of May, the Belgian Government decided to extend the series of measures contained in Royal Decree No. 15 regarding the temporary suspension of enforcement measures and other measures in favour of companies during the COVID-19 crisis. The initial date of the end of the moratorium scheduled for 17 May 2020 has been postponed until 17 June 2020, which date could itself be subject to further prolongation by further legislative decree.
Further information on Royal Decree No. 15 can be found in our article “Royal Decree No. 15 regarding the temporary suspension of enforcement measures and other measures in favour of companies during the COVID-19 crisis” and its practical implications are discussed in our FAQs:
- What precautions should be taken prior to initiating new business relationships?
- What securities may be effectively taken notwithstanding the limitations imposed by Royal Decree No. 15?
- My debtor is known to be bankrupt, what can I do?

Royal Decree No. 15 regarding the temporary suspension of enforcement measures and other measures in favour of companies during the COVID-19 crisis
Many companies are facing a cash shortfall as a result of the COVID-19 crisis. How to protect their business’s continuity?
The judicial reorganisation procedure and the payment obligation suspension that it provides for (Book XX Code of Economic Law – CEL) is currently not regarded by the authorities to be an appropriate rescue measure because, firstly, it would overload the Companies Court during this period of crisis and, secondly, because the suspension applies only to ”old” debts that existed prior to the initiation of the procedure.
Consequently, the government has temporarily organised a moratorium, (or a ’ceasefire’) in order to protect any company in debt as a result of the Covid-19 crisis, which is in need of liquidity, against either precautionary or executory attachment proceedings, and against any bankruptcy or judicial settlement.
Royal Decree No 15 foresees four temporary suspension measures covering the period from 24 April 2020 to 17 May 2020 (subject to possible extension):
- Impossibility of initiating or pursuing enforcement measures as well as precautionary or executory attachment measures
EXCEPTION: precautionary and enforceable attachment of real property (as well as precautionary attachment of seagoing and inland waterway vessels) remain possible.
- No bankruptcy filing on summons or judicial resolution is possible
EXCEPTION: Possibility of filing a bankruptcy petition or an admission of bankruptcy on the claim by the Public Prosecutor’s Office or of a provisional administrator.
- Extension of payment terms within the framework of a previously approved reorganization plan
- Prohibition of unilateral or judicial termination of agreements concluded before 24 April 2020 for failure to pay a due and payable debt
EXCEPTION: employment contracts.
It is worth pointing out that such a system of legal suspension does not in any way affect the obligation as regards the payment of one’s debts, whether regarding principal, interest or indemnities. It is therefore in the interest of each company to respect the payments as far as possible, because following the moratorium, interest and damages can be claimed by the creditor.
To prevent certain companies from benefiting unduly from such protection, the creditor is given the possibility of summoning the debtor before the president of the Companies Court to request the withdrawal of this suspension. The President of the Companies Court, ruling as in summary proceedings, will assess whether the debtor has truly been affected by the Covid-19 crisis and subsequent measures, also taking into account the impact of the suspension with respect to the creditor’s interests so as to avoid a cascading (or ‘domino’) effect.
Furthermore, there is also a temporary suspension of the obligation to file a bankruptcy petition, if the conditions are met because of the COVID-19 pandemic and its consequences.
Lastly, the legislator intends to stimulate granting of credit, whether by a bank or by a supplier by, on the one hand, protecting new credits and, on the other hand, by lightening the potential liability of those who provide such credits. A renegotiated credit is not regarded as a new credit.
Read More

Suspension of the social elections: What are the consequences for your company?
On April 23, 2020, the law “to regulate suspension of the procedure for the 2020 social elections, because of the coronavirus COVID-19 pandemic” was adopted by the Belgian Parliament.
The law follows the opinion of the National Labour Council delivered on 24 March and suspends the electoral procedure with retroactive effect to 17 March 2020.
Here are certain points of attention for the organization of your social elections.
1. The social consultation bodies in place remain operational
Existing Works Councils and committees for prevention and protection at work (CPPT) shall continue to meet until the new consultation bodies are installed, scheduled for 45 days after election day (“Y+45”) in the absence of any appeal.
The worker representatives sitting on these bodies will continue to exercise their mandates and as such enjoy prerogatives and legal protection against dismissal, at least until 1 January 2021.
2. New date for social elections (Y-day) between 16 and 29 November 2020
You had initially chosen an election date between May 11 and May 24, 2020. This is postponed to the second half of November 2020.
Your election day will now be as follows:
| Initial Y Day | 11 May | 12 May | 13 May | 14 May | 15 May | 16 May | 17 May | 18 May | 19 May | 20 May | 21 May | 22 May | 23 May | 24 May |
| Post-poned
Y Day |
16 Nov | 17 Nov | 18 Nov | 19 Nov | 20 Nov | 21 Nov | 22 Nov | 23 Nov | 24 Nov | 25 Nov | 26 Nov | 27 Nov | 28 Nov | 29 Nov |
3. Suspension of the procedure and its reactivation at the end of September 2020.
Your electoral procedure is interrupted retroactively to the day after the communication of the lists of candidates by the trade unions (X+36).
If no candidate has been put forward, the electoral procedure can now be definitively stopped (“total” stop procedure to be notified by displaying the following form to the staff and sending the form to the Federal Public Employment Service)
If more than one candidate, or even if only one candidate is standing, the election procedure must be continued even if the number of candidates is equal to or less than the number of eligible places. In such a case, the procedure will be stopped the day before the invitations to the elections are sent out, at “X+79”, i.e. no earlier than 5 November 2020.
If the procedure continues, it will recommence on the new day “X+36”, between 23 September and 4 October 2020 depending on your new election date (determined in accordance with point 2 above).
Thus, it will not be until the end of September 2020, at the earliest, that you will have to take new steps in connection with the organisation of your elections (displaying the electoral lists and appointment of the president of the voting office at X+40, lodging of complaints and proceedings before the labour courts to denounce an abusive candidature, appointment of the electoral office, agreement on postal voting at X+56, …). In the meantime, no particular steps need to be taken, as the law stipulates that operations carried out during the suspension period are null and void (i.e. even if you have, for example, already displayed the list of candidates in March/April, you will have to do so again on the new day X in September/October 2020). Moreover, legal actions already brought by some employers against lists of candidates will be postponed until after the procedure has been recommenced.
4. Consequences for the steps already taken
All operations carried out, information displayed, judicial decisions rendered and agreements reached at company level prior to the suspension of the procedure at X+36 remain in place.
If you had entered into a special agreement with the trade unions in connection with the consequences of the coronavirus pandemic (e.g. a change of schedule for the voting day), it will automatically become inoperative unless you agree otherwise with the trade unions.
The forms displayed (with the date of the elections, the schedule of the election day and the different steps of the procedure (on form X)) will have to be adapted. A Royal Decree of Special Powers will define the modalities for resuming the procedure and the formalities to be carried out in this respect. In the meantime, forms X-60; X – 35 and X should always be displayed.
5. Impact on protection against dismissal
Candidates registered on the electoral lists communicated by the trade unions are protected against dismissal.
Employees who stood as candidates for the first time in the 2016 social elections and who are no longer represented in 2020 are also protected until the day the new consultation bodies are set up (see point 1 above). Please therefore verify the identity of the candidates not elected in 2016 and see if this was their first candidacy, before making any redundancies.
Workers who were not registered on the lists in 2020 and who did not stand for the first time in 2016 are temporarily no longer protected against dismissal until “36 days before day X + 36 of the resumption of the electoral procedure”. In concrete terms, these workers are currently no longer protected against dismissal notified before 18 August (minimum) and 31 August 2020 (if your election day is 29 November 2020). After this date, workers will again be protected by secrecy (“de manière occulte”) having regard to the discretion left to the trade union organisations to replace up to X+76 a candidate registered on the list and whose candidacy is rejected, notably where rejection follows a complaint, a disaffiliation from the trade union or a change of category.
In the event of unlawful dismissal, the protected candidate will be able to claim :
- a lump-sum protection indemnity calculated on the basis of his seniority (2 years’ remuneration when he has less than 10 years’ service; 3 years remuneration for seniority of 10 to 20 years and 4 years for seniority of more than 20 years);
- a variable indemnity (subject to a request for reinstatement formulated in the forms and within the time limits set by law and not respected by the employer), the amount of this indemnity varies according to the following two hypotheses:
- The dismissal was notified before March 17, 2020: the variable indemnity amounts to the remuneration due up to the day “Y + 45” calculated in accordance with the original calendar and the presumed installation (“Y+45”) between June 25, 2020 and July 8, 2020;
- Dismissal was notified as of March 17, 2020: the variable compensation is equal to the compensation due up to the “Y+45” day calculated in accordance with the new electoral calendar (following an election date in November 2020 and a “Y+45” day between December 31, 2020 and January 13, 2020).
For companies that are not due to hold social elections in 2020 but have a Works Council or a CPPT (in particular, following a reduction in staff resulting in an average workforce of less than 50 workers), candidates elected in the 2016 elections continue to benefit from protection against dismissal for a period of six months from the new day Y. The same applies when new elections are not held due to a lack of candidates.
6. Who will (still) be able to stand as a candidate in the November 2020 elections?
The lists of candidates have already been communicated to X+35 and, in principle, the identities of all your candidates are known.
However, in view of the discretion left to the trade unions to replace candidates on their list up to X+76, it remains possible that workers may present themselves as “new candidates” to replace a candidate who is currently registered but whose application will be rejected.
Which workers can be registered to replace them?
Only employees who, on the original date of the elections (i.e., the date initially chosen in May 2020), met the eligibility requirements (being bound by a contract of employment, not being part of the management staff, having been employed for at least three months in the undertaking as defined within the meaning of the Technical Operations Unit (‘UTE’)), may be registered to replace a candidate who has been replaced.
For temporary workers, they have the right to vote (but not to stand as a candidate) in elections provided they have been employed at least 65 days before “day X” and 26 days “between day X and day X+76”, the suspension period between March and September 2020 not being taken into account for the calculation of these 26 required days of employment.
Do not hesitate to send us an e-mail (alexandre.hachez@playground.flinn.law) with any questions you may have, the greatest caution needs to be exercised having regard to the substantial compensatory indemnities payable in respect of any irregularities or unlawful dismissal.
Read More

