Inventory data and third-party services, clarify decisions requiring approval, then document the technical implementation. With legal support where the context requires it.
Make choices and data processing understandable. Editorial illustration.
Website GDPR scoping starts with an inventory of data, trackers, forms and third-party services. It then connects each processing activity to a purpose, a documented decision, understandable information and an implementation owner. It is not an automatic legal certification.
PURPOSE
Why collect
An explicit, documented objective
BASIS
Why process
A legal basis suited to the context
MINIMUM
What to collect
Necessary data only
EVIDENCE
How to demonstrate
Decisions, contracts and checks
INTERACTIVE TOOL
Is your documentation ready for review?
Five questions to identify available information and areas to investigate. The resulting indicator is educational: it does not measure legal compliance.
Answer honestly:
Has the website’s data and tracker inventory been completed?
Forms, measurement, advertising, embeds, logs and third-party services.
Are every purpose and legal basis documented?
Consent is not the only legal basis and does not automatically apply to everything.
Does the information provided reflect actual processing?
Purposes, recipients, retention periods, transfers, rights and contact details.
Are processors and transfers properly governed?
Roles, contracts, processing locations and safeguards to verify.
Do rights requests and incidents have an owner and a procedure?
Access, rectification, erasure, objection and personal data breaches.
Readiness indicator
-
/100
Answer the five questions to assess your readiness.
This indicator helps organise scoping. It is neither a legal audit nor an estimate of the risk of penalties.
Ongoing maintenance and legal monitoring unless separately contracted
Investment
Three scoping packages.
Scoping
One-off review
650 €
Excluding VAT · Technical assessment
Website and tracker inventory
Documented questions and gaps
Prioritised action plan
1-hour presentation
No implementation
Most requested
Scoping + implementation
Existing website requiring corrections
€2,200 to €4,500
Excluding VAT · According to scope
Full scoping
Consent journey
Selected tool settings
Technical documentation
Testing and training
Extended support
E-commerce, multiple websites or many tools
From €6,500
Excluding VAT · Complex scope
Everything in Scoping + implementation
Extended mapping
Processor coordination
Documentation support
External legal advice if required
Prices excluding VAT. Belgian VAT of 21% applies.
Frequently asked questions
Understand the GDPR scope.
Is my website really subject to the GDPR?
GDPR applies, among other cases, to processing carried out in the context of an establishment in the Union, and to certain offers of goods or services and monitoring of the behaviour of people located there. The fact that a website is technically accessible from the Union does not fully describe the scope of application. The organisation, target individuals and actual processing must be examined.
How much does GDPR scoping cost in Brussels?
The three published scopes range from a technical assessment to extended support. The quotation confirms the tools, flows, documents, responsibilities and interventions included. These services do not replace legal advice or a DPO assignment.
Why examine fonts loaded from a third-party service?
The browser may send technical data, such as the IP address, to the domain serving the resource. Self-hosting reduces some third-party requests but does not make a website compliant on its own. Data flows, their purpose, legal basis and applicable safeguards must be inventoried.
Which cookie banner complies with the Belgian framework?
Start by inventorying trackers and identifying which require consent. The Belgian Data Protection Authority requires clear information, freely given and specific consent where required, and a genuinely accessible refusal option. Consent Mode is a Google mechanism, not a law or a compliance certification.
What penalties does GDPR provide for?
Article 83 sets two levels of maximum fines according to the category of infringement: up to €10 million or €20 million, or 2% or 4% of an undertaking’s total worldwide annual turnover for the preceding financial year, whichever is higher. The actual amount depends on the circumstances and cannot be inferred from a technical questionnaire.
Does my hosting provider have to be in Europe?
GDPR does not impose a general rule that all hosting must be located in the Union. Processing locations must be identified and, where data is transferred to a third country, the applicable mechanism and safeguards verified. A provider name or commercial region alone is insufficient.
Does my company have to appoint a DPO?
Article 37 covers, among other cases, public authorities and bodies, regular and systematic monitoring of individuals on a large scale, and large-scale processing of special categories of data or data relating to criminal convictions. There is no general threshold of 5,000 people per day. The Belgian Data Protection Authority recommends assessing the criteria in context.