A Brussels non-profit signs Belgian shared hosting. The GDPR questionnaire asks for the full sub-processor list — including the host's. The provider answers "we are GDPR compliant" with no annexes. The APD, in an inspection, will ask the same question with less patience.
In Belgium, the Data Protection Authority (APD) expects a documented chain, not a badge. The issue goes beyond picking a host: it covers your register, your DPA, and your ability to reject a new sub-processor.
Responsibilities in the Belgian chain
Three roles to separate:
| Role | Key sub-processor duty |
|---|---|
| Controller (you) | Choose a host with sufficient guarantees; authorise or reject further sub-processors |
| Processor (host) | Engage another processor only with authorisation; same GDPR obligations by contract |
| Sub-processor (CDN, backup…) | Process on instructions; often invisible without explicit request |
Belgian GDPR (Law of 30 July 2018) mirrors EU rules. The local nuance: active APD enforcement culture and high expectations on transparency toward data subjects.
Contract checklist before signing
Require in the DPA or terms:
- Initial list of sub-processors with country and role.
- Notification mechanism (30 days) before additions.
- Right to object or data withdrawal procedure.
- Copy of DPAs between host and its sub-processors (or audit summary).
- Location clause aligned with your register.
- Assistance for data subject rights and APD requests.
Compare profiles via the directory filtering Belgian presence or documented EU jurisdiction.
Map beyond the host
Even with a serious Belgian or European host, your chain often includes:
- Payment (Mollie, Stripe)
- Email (Mailchimp, Brevo)
- Analytics
- Support (Zendesk)
- External backup you operate
Each link = register entry + DPA + transfer analysis if outside EEA. See data processing agreement for framing.
Mistakes seen among Belgian controllers
Register missing the host's sub-processors.
No contractual objection right — abusive clause to negotiate.
Confusing hosting with health data hosting — different framework.
Forgetting NL/FR legal mentions — local requirement separate from GDPR but sign of incomplete due diligence.
The crux: "GDPR compliant" without named list
That is the gap in generic terms: compliance is a living list, not a static page.
Decide and move forward without blind spots
- Update APD-compatible register with host and its tiers.
- Sign DPA with annexed list.
- Test new sub-processor alert procedure.
- Merge your own sub-processors in the same map.
- Compare via compare tool and sub-processor clause guide.
Frequently asked questions
Who is accountable for the host's sub-processors?
The Belgian controller remains accountable; the host may only engage third parties with contractual authorisation.
Must the host be registered with the APD?
The processing register replaced old declarations; some high-risk activities need DPIA or consultation.
How do you audit the chain?
Up-to-date lists, downstream DPAs, countries, measures, change notification — reject vague answers.
Does a Belgian host guarantee a 100% Belgian chain?
No: support, CDN, or backup may be elsewhere. Verify contractually.
Ask for the list before signing — after an incident, the APD does not accept "we did not know."
