Moniteur Belge · 03 Sep 2026 · 3 vistas
Telecom data retention: German translation published in the Belgian Official Gazette
Por FactBox Admin

The Belgian Official Gazette of September 3, 2026 (p. 48087) publishes the German translation of excerpts from the law of July 20, 2022, regarding the collection and retention of identification data and metadata in the electronic communications sector and the provision of such data to authorities. This text, referenced as C-2026/006228, is published under the aegis of the Federal Public Service Interior and the Federal Public Service Justice.
The translation, established by the Central German Translation Service in Malmedy, covers Articles 2 to 17, 40, 41, and 45 to 48 of the law of July 20, 2022, initially published in the Belgian Official Gazette of August 8, 2022. It makes the provision enforceable in the German-speaking region of the country.
A legal framework resulting from a long constitutional saga
The law of July 20, 2022, amends the law of June 13, 2005, on electronic communications, following several annulments by the Constitutional Court (decisions No. 84/2015 and No. 57/2021) of previous generalized data retention regimes. It establishes a targeted retention regime based on objective criteria, while precisely defining the notions of electronic communication data, content, and metadata.
The text guarantees the freedom to use cryptography, while providing that it cannot prevent the identification of the caller nor the execution of a targeted request from a competent authority. Operators must take proportionate measures to detect fraud and the malicious use of their networks.
Graduated retention periods
Operators are required to retain traffic data for varying durations depending on the purposes:
- 4 months for data necessary for the detection of fraud or malicious use of the network;
- 12 months for data allowing the identification of the author of an incoming communication;
- 12 months after the end of the session for identification data (national register number, alias, contact details, IMSI, SUPI, SUCI, IP addresses, IMEI, PEI, MAC addresses identifiers);
- 6 months for MAC addresses when other identification data are retained.
Targeted retention applies in judicial districts and police zones presenting at least three serious offenses per 1,000 inhabitants per year, with durations of 6, 9, or 12 months depending on the crime rate. Vital risk zones (royal palace, embassies, European Union and NATO buildings, hospitals, National Bank of Belgium) are also concerned.
Regulated and traceable access
Access to retained data is reserved for a limited list of authorities: intelligence services, judicial and administrative authorities responsible for the prevention and prosecution of serious crime, authorities protecting vital interests, as well as the Institute (telecommunications regulator) and data protection authorities. Each operator must establish a coordination office responsible for responding to requests from authorities, whose members are subject to professional secrecy and security clearance.
All consultations of data are recorded in a logbook kept for ten years, the modification of which is prohibited and access to which is reserved for the Institute and inspectors from the Data Protection Authority. Data must be stored within the territory of the European Union and transmitted to Belgium, then deleted or anonymized upon expiration of the deadlines.
Strengthened Sanctions
Failure to comply with these obligations exposes offenders to fines of 50 to 100,000 euros. The fraudulent possession or use of retained data is punishable by a fine of 50 to 50,000 euros and imprisonment from six months to three years. Targeted retention by geographical zones will enter into force no later than January 1, 2027.
This publication confirms the national scope of a system that directly affects all telecom operators and the privacy of every citizen: by strictly framing retention periods and authority access, Belgium seeks to reconcile the requirements of national security and the fight against crime with the guarantees imposed by constitutional and European case law regarding the protection of personal data.
Source: Belgian Official Gazette of September 3, 2026, No. 199, p. 48087 — reference C-2026/006228.