Independent comparison · no paid rankings
Home / Blog / Compliance / Belgium: control a host's sub-processors in a GDPR chain

Belgium: control a host's sub-processors in a GDPR chain

In Belgium, the APD expects a readable sub-processing chain: beyond the host's DPA, list its sub-processors and those it engages for your project.

Hébergeurs.eu Editorial Team 3 min read Updated Nov 6, 2026

A Brussels non-profit signs Belgian shared hosting. The GDPR questionnaire asks for the full sub-processor list — including the host's. The provider answers "we are GDPR compliant" with no annexes. The APD, in an inspection, will ask the same question with less patience.

In Belgium, the Data Protection Authority (APD) expects a documented chain, not a badge. The issue goes beyond picking a host: it covers your register, your DPA, and your ability to reject a new sub-processor.

Responsibilities in the Belgian chain

Three roles to separate:

RoleKey sub-processor duty
Controller (you)Choose a host with sufficient guarantees; authorise or reject further sub-processors
Processor (host)Engage another processor only with authorisation; same GDPR obligations by contract
Sub-processor (CDN, backup…)Process on instructions; often invisible without explicit request

Belgian GDPR (Law of 30 July 2018) mirrors EU rules. The local nuance: active APD enforcement culture and high expectations on transparency toward data subjects.

Contract checklist before signing

Require in the DPA or terms:

  1. Initial list of sub-processors with country and role.
  2. Notification mechanism (30 days) before additions.
  3. Right to object or data withdrawal procedure.
  4. Copy of DPAs between host and its sub-processors (or audit summary).
  5. Location clause aligned with your register.
  6. Assistance for data subject rights and APD requests.

Compare profiles via the directory filtering Belgian presence or documented EU jurisdiction.

Map beyond the host

Even with a serious Belgian or European host, your chain often includes:

  • Payment (Mollie, Stripe)
  • Email (Mailchimp, Brevo)
  • Analytics
  • Support (Zendesk)
  • External backup you operate

Each link = register entry + DPA + transfer analysis if outside EEA. See data processing agreement for framing.

Mistakes seen among Belgian controllers

Register missing the host's sub-processors.

No contractual objection right — abusive clause to negotiate.

Confusing hosting with health data hosting — different framework.

Forgetting NL/FR legal mentions — local requirement separate from GDPR but sign of incomplete due diligence.

The crux: "GDPR compliant" without named list

That is the gap in generic terms: compliance is a living list, not a static page.

Decide and move forward without blind spots

  1. Update APD-compatible register with host and its tiers.
  2. Sign DPA with annexed list.
  3. Test new sub-processor alert procedure.
  4. Merge your own sub-processors in the same map.
  5. Compare via compare tool and sub-processor clause guide.

Frequently asked questions

Who is accountable for the host's sub-processors?

The Belgian controller remains accountable; the host may only engage third parties with contractual authorisation.

Must the host be registered with the APD?

The processing register replaced old declarations; some high-risk activities need DPIA or consultation.

How do you audit the chain?

Up-to-date lists, downstream DPAs, countries, measures, change notification — reject vague answers.

Does a Belgian host guarantee a 100% Belgian chain?

No: support, CDN, or backup may be elsewhere. Verify contractually.


Ask for the list before signing — after an incident, the APD does not accept "we did not know."

HDS & compliance hosts

Filter European hosts by HDS, ISO and data residency.

Browse HDS hosts
Blog

Related reading

All articles →