Skip to main content

Quick navigation

What are you looking for?

Suggestions

Enter at least two characters.

GDPR SCOPING

GDPR:
make data processing understandable.

Inventory data and third-party services, clarify decisions requiring approval, then document the technical implementation. With legal support where the context requires it.

Illustration of data protection on a website.
Make choices and data processing understandable. Editorial illustration.

Website GDPR scoping starts with an inventory of data, trackers, forms and third-party services. It then connects each processing activity to a purpose, a documented decision, understandable information and an implementation owner. It is not an automatic legal certification.

PURPOSE
Why collect
An explicit, documented objective
BASIS
Why process
A legal basis suited to the context
MINIMUM
What to collect
Necessary data only
EVIDENCE
How to demonstrate
Decisions, contracts and checks
INTERACTIVE TOOL

Is your documentation
ready for review?

Five questions to identify available information and areas to investigate. The resulting indicator is educational: it does not measure legal compliance.

Answer honestly:

Has the website’s data and tracker inventory been completed?
Forms, measurement, advertising, embeds, logs and third-party services.
Are every purpose and legal basis documented?
Consent is not the only legal basis and does not automatically apply to everything.
Does the information provided reflect actual processing?
Purposes, recipients, retention periods, transfers, rights and contact details.
Are processors and transfers properly governed?
Roles, contracts, processing locations and safeguards to verify.
Do rights requests and incidents have an owner and a procedure?
Access, rectification, erasure, objection and personal data breaches.

Readiness indicator

-
/100

Answer the five questions to assess your readiness.

This indicator helps organise scoping. It is neither a legal audit nor an estimate of the risk of penalties.

Indicative checklist based on five information categories. The actual scope depends on the organisation, processing activities and risks.

Review areas

Six topics to examine in your context.

GDPR goes beyond a cookie banner. Applicable obligations depend on processing activities, roles and risks.

The visual guide

Look beyond the cookie banner

Website data

  • Collection

    Forms, trackers, purposes and information for individuals.

  • Data flows

    Tools, recipients, contracts and transfers to examine.

  • Protection

    Access, backups and measures suited to the risk.

  • Responsibilities

    Rights, incidents, reviews and responsible people.

This map organises review topics. It does not establish website compliance.
01

Processing inventory

Identify data, purposes, data subjects, tools, recipients and responsibilities. The record depends on the conditions of Article 30.

02

Information for individuals

Provide accessible information reflecting actual processing, including rights and the contact point.

03

Cookies and other trackers

Inventory trackers, identify which require consent and offer a compliant choice where required.

04

Processors and transfers

Define roles and verify contracts, processing locations and safeguards applicable to transfers.

05

Security appropriate to the risk

Restricted access, updates, backups, encryption where relevant and an incident management procedure.

06

Rights and governance

Assign requests, document deadlines, determine whether a DPO or impact assessment is required and organise reviews.

Official text

Four reference points to frame the analysis.

These GDPR articles structure the review. Their practical application depends on the facts and, where necessary, legal analysis.

Topic
Reference
Key point
Principles
Art. 5
Lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation and security.
Processing by third parties
Art. 28
Processing entrusted to a processor must be governed by the requirements set out in GDPR.
DPO
Art. 37
Appointment depends on the organisation’s role, regular large-scale monitoring or special categories of data.
Penalties
Art. 83
The maximum fine depends on the category of infringement. The actual amount is assessed according to the circumstances of the case.

Links to the European regulation and the criteria published by the Data Protection Authority appear in this page’s official sources.

Method

A four-phase method.

The schedule is confirmed after the inventory, according to the number of tools, participants and decisions requiring approval.

  1. 01

    Inventory

    Website, third-party tools, data flows, responsibilities and existing documents.

    Phase 1

  2. 02

    Decisions for approval

    Technical gaps, legal questions, responsible people and order of work.

    Phase 2

  3. 03

    Implementation

    Trackers, forms, information, contracts and settings selected within the scope.

    Phase 3

  4. 04

    Testing and evidence

    Checks, documentation, training for responsible people and a review schedule.

    Phase 4

Transparency

What is included,
and what is not.

Included in the technical scope

  • Technical inventory of the website, trackers and third-party services
  • Consent journey configuration according to approved decisions
  • Technical update of information supplied by the responsible party
  • Review of forms and measurement events
  • List of identifiable processors and transfers
  • Documentation of implemented settings
  • Tests before and after intervention
  • Operational team training according to the quotation

Optional or available separately

  • Legal advice or certification of compliance
  • DPO appointment and assignment
  • Complete impact assessment unless separately scoped
  • In-depth cybersecurity audit
  • Ongoing maintenance and legal monitoring unless separately contracted
Investment

Three scoping packages.

Scoping

One-off review

650 €
Excluding VAT · Technical assessment
  • Website and tracker inventory
  • Documented questions and gaps
  • Prioritised action plan
  • 1-hour presentation
  • No implementation
Most requested

Scoping + implementation

Existing website requiring corrections

€2,200 to €4,500
Excluding VAT · According to scope
  • Full scoping
  • Consent journey
  • Selected tool settings
  • Technical documentation
  • Testing and training

Extended support

E-commerce, multiple websites or many tools

From €6,500
Excluding VAT · Complex scope
  • Everything in Scoping + implementation
  • Extended mapping
  • Processor coordination
  • Documentation support
  • External legal advice if required

Prices excluding VAT. Belgian VAT of 21% applies.

Frequently asked questions

Understand the GDPR scope.

Is my website really subject to the GDPR?
GDPR applies, among other cases, to processing carried out in the context of an establishment in the Union, and to certain offers of goods or services and monitoring of the behaviour of people located there. The fact that a website is technically accessible from the Union does not fully describe the scope of application. The organisation, target individuals and actual processing must be examined.
How much does GDPR scoping cost in Brussels?
The three published scopes range from a technical assessment to extended support. The quotation confirms the tools, flows, documents, responsibilities and interventions included. These services do not replace legal advice or a DPO assignment.
Why examine fonts loaded from a third-party service?
The browser may send technical data, such as the IP address, to the domain serving the resource. Self-hosting reduces some third-party requests but does not make a website compliant on its own. Data flows, their purpose, legal basis and applicable safeguards must be inventoried.
Which cookie banner complies with the Belgian framework?
Start by inventorying trackers and identifying which require consent. The Belgian Data Protection Authority requires clear information, freely given and specific consent where required, and a genuinely accessible refusal option. Consent Mode is a Google mechanism, not a law or a compliance certification.
What penalties does GDPR provide for?
Article 83 sets two levels of maximum fines according to the category of infringement: up to €10 million or €20 million, or 2% or 4% of an undertaking’s total worldwide annual turnover for the preceding financial year, whichever is higher. The actual amount depends on the circumstances and cannot be inferred from a technical questionnaire.
Does my hosting provider have to be in Europe?
GDPR does not impose a general rule that all hosting must be located in the Union. Processing locations must be identified and, where data is transferred to a third country, the applicable mechanism and safeguards verified. A provider name or commercial region alone is insufficient.
Does my company have to appoint a DPO?
Article 37 covers, among other cases, public authorities and bodies, regular and systematic monitoring of individuals on a large scale, and large-scale processing of special categories of data or data relating to criminal convictions. There is no general threshold of 5,000 people per day. The Belgian Data Protection Authority recommends assessing the criteria in context.

This scoping covers website implementation. To address responsibilities, contracts and decisions more broadly, explore our GDPR and digital contracts service. Website maintenance and performance optimisation support ongoing technical checks.

Initial GDPR scoping.

30 minutes by video call to clarify tools, flows, available documents and the intervention scope. No automated legal diagnosis.