Consent first, under the Code of Economic Law
Belgium prohibits the use of email for advertising without the recipient's prior, free, specific and informed consent. The rule sits in Article XII.13 of the Code of Economic Law (Code de droit économique / Wetboek van economisch recht), which transposes the European ePrivacy Directive.
If you have read older guidance, note that the frequently cited Law of 11 March 2003 on information society services was repealed and absorbed into the Code in 2013. Note too that Book VI of the Code, which many summaries cite, governs automated calling systems, fax and telephone — not email. For email, Book XII is the operative text.
Two narrow exceptions, and they are narrower than they look
A Royal Decree of 4 April 2003, still in force, sets out the limited cases where prior consent is not required.
The first is the existing-customer exception. You may email your own customers without fresh consent where you obtained the address directly from them in the course of selling a product or service, you use it only to advertise analogous products or services that you yourself supply, and you offered a free and simple way to object at the moment the address was collected. "Analogous" is judged from what the recipient would reasonably expect, not from how you categorise your catalogue.
One consequence catches groups of companies repeatedly: a parent, a subsidiary and a sister company are separate legal persons, and therefore third parties. A list built on the customer exception cannot be shared across the group without new consent.
The second exception covers legal persons contacted at impersonal addresses — the classic info@ or orders@ mailbox. It is not a general B2B exemption. Where a functional address is used and managed by one identifiable person, it can still be personal data, and the GDPR applies to it regardless. Belgium's data protection authority explicitly warns senders to be cautious here.
What every message must do
Advertising sent by email must be clearly identifiable as advertising as soon as it arrives, and the person on whose behalf it is sent must be clearly identifiable. Every message must give clear information about the right to refuse future advertising, and provide an appropriate electronic means of exercising that right.
Belgium then adds a requirement that is unusual in Europe and easy to miss: when someone asks to stop receiving your messages, you must send them an acknowledgement of receipt within a reasonable time, act on the request within a reasonable time, and maintain a suppression list of people who have opted out. Concealing the origin of a message, or using someone else's address or identity, is separately prohibited — and if consent is disputed, the burden of proving it falls on the sender.
Two regulators, two layers
Enforcement is split. The Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit) supervises the data protection and ePrivacy layer, and can impose GDPR administrative fines. The economic inspection of the federal public service for the economy enforces Book XII itself, where breaches of the email rules carry criminal penalties.
If you are working from older material, be aware that the former Commission for the Protection of Privacy was replaced by the Data Protection Authority in 2018. Guidance and links pointing to the old body are out of date.
See also:
- Definition of spam, emailing abuse
- Comply to French law with your email marketing campaigns
- Professional emailing tightly controlled by Swiss law
- Conduct professional email campaigns in accordance with Canadian law