Website & Development
A GDPR-compliant website in Belgium: the B2B checklist
Copy for AI
A GDPR-compliant website in Belgium means you only collect the personal data you genuinely need, that you ask for valid consent before you track, that you contractually formalise the arrangements with your suppliers and that you are transparent about what happens to the data. It is not a legal formality you tack on afterwards, but a set of choices you build into your forms, your tracking and your hosting. In this article you get a concrete checklist tailored to B2B sites: what the Belgian Data Protection Authority expects, where most companies go wrong, and how to keep the risk of a fine and of lost trust small.
What does GDPR-compliant mean for a B2B website exactly?
GDPR-compliant means that every place where your site touches personal data meets the General Data Protection Regulation (GDPR). For a B2B website that comes down to four zones: your forms, your tracking and cookies, your external services such as hosting and email tools, and your duty to inform via a privacy statement.
Many B2B entrepreneurs think the GDPR mainly applies to webshops and consumer brands. That is not true. As soon as you process a name, a business email address or an IP address, you fall under the rules. A contact form, a newsletter sign-up or a Google Analytics script is already enough. The good news: for a typical B2B site the bar is well within reach, as long as you set up the basics deliberately instead of scrolling past them.
What are the rules around cookies and tracking in Belgium?
In Belgium the rule is clear: no prior consent, no non-essential cookies. Only strictly necessary cookies, such as those for a shopping basket or a logged-in session, may be placed without consent. For all others, think of third-party analytics, marketing and tracking cookies, you need the visitor’s active, prior consent.
The Data Protection Authority has clear expectations about this and published a cookie checklist. A few hard points that in practice often go wrong:
- Consent must be free, specific, informed and active. A pre-ticked box or a banner that says “by continuing to browse you agree” does not count as valid consent.
- Refusing must be as easy as accepting. A banner with only a prominent “Accept all” button and a hidden refuse option does not comply.
- No cookie wall. You may not block access to your site for anyone who refuses the non-essential cookies.
- A cookie policy is mandatory as soon as you place trackers, so visitors can transparently see what is happening.
That this is not theory became clear when the authority fined a Belgian press site because the cookies on the website did not meet the rules. For B2B it means concretely: only switch on your analytics and advertising scripts after there is consent, not when the page loads. A correctly configured consent tool that blocks scripts until the visitor chooses is the workhorse for this. Whether a cookie banner is mandatory in your case, you can read in cookie banner rules in Belgium.
How do you make your forms GDPR-compliant?
A form is GDPR-compliant if you only ask for what you genuinely need, make clear what you use the data for, and do not confuse consent with functionality. Data minimisation is the core principle here: every extra field you do not use is data you unnecessarily store and have to secure.
Practical for your B2B forms:
- Ask for less. A name and a business email address usually suffice for a first contact. Phone number, company size and budget you can gather later in the conversation. This is, moreover, simply good form conversion optimisation: shorter forms generally produce more leads.
- Separate consents. Processing a contact request is allowed on the basis of the conversation the visitor starts themselves. If you then also want to send someone newsletters, you ask for a separate, non-pre-ticked opt-in for that.
- Be explicit about the purpose. A short sentence next to the form (“We only use your data to answer your request”) plus a link to your privacy statement is enough.
- Secure the transmission. Your site should run over HTTPS so that submitted data is sent encrypted, and the submissions must not linger endlessly in an unsecured mailbox.
That same discipline applies to your contact page, often the busiest form on a B2B site.
What is a data processing agreement and do you need one?
A data processing agreement is a contract between you and every external party that processes personal data on your behalf, and yes, for virtually every B2B site you need several. The GDPR requires this as soon as a supplier processes data for you.
Think of the parties behind your site that are easy to overlook: your hosting provider, your CRM, your email marketing tool, your form or chat service, and analytics suppliers. One by one, they process your visitors’ data on your instructions. The large platforms offer a standard data processing agreement (often called a DPA) for this that you accept or sign online.
Two points of attention for B2B in Belgium. First: keep a simple overview of which services see which data. That is immediately the basis of your record of processing activities. Second: pay attention to where the data ends up. If data is processed outside the European Economic Area, for example at American suppliers, there must be a valid transfer basis, such as the European Commission’s standard contractual clauses. It pays to check, when choosing your tools, whether an EU hosting option exists. More about that trade-off you can read in choosing web hosting in Belgium.
What do you risk if your site does not comply?
The most serious infringements of the GDPR can reach up to 20 million euros or 4 percent of global annual turnover, whichever is higher. A second category, for matters such as a missing record of processing activities or weak security, goes up to 10 million euros or 2 percent. In practice, the authority rarely hits smaller B2B companies with the maximum amounts; it looks at the nature and severity of the infringement, the number of people affected and your cooperation.
But do not fixate on the fine. The more realistic risk for most B2B companies is reputational damage and lost trust. An intrusive cookie banner, a form that asks for too much or a data breach you could have prevented undermines precisely the signal your site should radiate: that you are a reliable partner. Handling privacy properly is therefore also simply a way to build trust on your B2B website. Visitors who feel respected fill in a form more easily.
The short summary
A GDPR-compliant website in Belgium stands or falls with four things: only collect data you genuinely use, ask for valid prior consent for non-essential cookies and tracking, formalise a data processing agreement with every supplier and be transparent via a clear privacy statement. The authority’s rules around cookies are strict, but well within reach for a thoughtful B2B site. If you build it in from the start in your forms, your tracking and your hosting, compliance is not a brake but a trust signal that helps conversion.
Want this properly anchored in a site that produces leads? Then read our complete guide to building a B2B website or see how we handle website development, where privacy and conversion go hand in hand.
Plan your free intake call
Free website scan
Enter your website and get an automatic scan within minutes, with concrete technical and SEO improvements. No sales pitch.
We only use your details for your scan. No spam, unsubscribe anytime.