What’s GBA-APD and how does it differ from other EU data-protection regulators?
GBA-APD is Belgium’s Data Protection Authority, Gegevensbeschermingsautoriteit (Dutch) / Autorité de Protection des Données (French). It enforces GDPR in Belgium plus the Belgian Data Protection Law (Loi du 30 juillet 2018 / Wet van 30 juli 2018).
Concrete Magento-checkout impacts:
- Cookie consent, GBA-APD aligns broadly with EDPB / CNIL guidance: granular opt-in, equally-prominent “Reject all” button, no pre-ticked checkboxes, no cookie walls for essential content. We ship Cookiebot / Didomi / Axeptio wired into Magento’s cookie API, trilingual NL+FR+DE banner copy reviewed against GBA-APD guidance.
- DSAR (Data Subject Access Requests), must be handled within 1 month, in the customer’s language (NL / FR / DE / EN). We add a self-service DSAR endpoint that exports the customer’s order + account data.
- Breach notification, 72-hour reporting to GBA-APD if a breach risks customer rights. Magento logs + monitoring must support evidence-gathering.
- Data-residency, GBA-APD doesn’t mandate EU-only hosting but strongly prefers it. Combell / Hostbasket / Nucleus / OVHcloud BE / AWS Frankfurt (eu-central-1) are all fine. US-region hosting is a red flag.
- Cross-border GDPR coordination, if you serve NL + FR + DE too, GBA-APD coordinates with AP (NL), CNIL (FR), BfDI / Landesdatenschutzbehörden (DE) via the EDPB.