EPIC --- Privacy and Human Rights Report 2006

Kingdom of Belgium

Constitutional Privacy Framework

The Belgian Constitution recognizes the right of privacy and private communications.[1273] Article 22 states, "Everyone has the right to the respect of his private and family life, except in the cases and conditions determined by law. . . . The laws, decrees, and rulings alluded to in Article 134 guarantee the protection of this right." Article 29 states, "The confidentiality of letters is inviolable. ... The law determines which nominated representatives can violate the confidentiality of letters entrusted to the postal service." Article 22 was added to the Belgian Constitution in 1994. Prior to the constitutional amendment, the Supreme Court (Cour de cassation) ruled that Article 8 of the European Convention applied directly to the law and prohibited government infringement on the private life of individuals.[1274]

Data Protection Framework

The Law on Protection of Personal Data of 1992 governs the processing and use of personal information in Belgium. Amending legislation to update the 1992 Act and make it consistent with the European Union (EU) Data Protection Directive was approved by the Parliament in December 1998.[1275] A Royal Decree (Arrêté royal) to implement the Act was approved in July 2000. The decree, as a whole, broadens the scope of application of the law by extending the definition of "processing," determines how special categories of data may be processed, and reinforces data subjects' rights. The decree was finally adopted in February 2001, and the law came into effect in September 2001.

Two months after the entry into force of the new data protection regime, the government announced that it had put in place an Internet Rights Observatory (Observatoire des droits de l'Internet)[1276] in order to better assess and analyze the impact of the Internet on the economy and consumer protection. The Observatory aims, through its composition, at being an open forum for all Internet stakeholders, and will issue advisory opinions and annual reports, organize a dialogue between economic actors, and inform the public.[1277] The Observatory has released reports on the protection of minors on the Internet,[1278] e-commerce,[1279] e-government[1280] and Voice over IP.[1281]

Data Protection Authority

The Commission for the Protection of Private Life (Commission de la protection de la vie privée, or Commission) oversees the law and reports directly to the Parliament.[1282] The Commission investigates complaints, issues opinions and maintains the registry of personal files.[1283] In 2004, the Commission answered 678 complaints and requests for information.[1284] The number of public requests also increased from about 6,200 in 1999 to about 7,400 in 2001. As of November 2004, there are 34 permanent staff members,[1285] compared to 19 in 2001 and 28 in 2000.[1286]

The Commission has issued a number of recommendations relating to workplace privacy,[1287] video surveillance,[1288] the compatibility of the census survey (conducted every 10 years) with Belgian privacy regulations,[1289] the protection of privacy in the context of electronic commerce,[1290] the regulation of direct marketing under the data protection legal framework,[1291] the recording by banks of their customers' telephone communications,[1292] the use of electronic communications for electoral advertising purposes,[1293] the project of Royal Decree regarding the model-contract on matrimonial brokerage,[1294] etc.

Since 1998, the Commission has had to determine the legality of specific "black lists," from casinos' lists of cheaters to insurance companies' lists of bad debtors and risks. In 2002, the Commission was asked to assess whether the upload on the Internet of a "black list" of renters[1295] by the National Association of Property Owners (Syndicat National des Propriétaires) was legal. In its opinion, the data protection authority found the database illegal under the Law on Protection of Personal Data of 1992, and that it required prior legislative action to authorize it – if it were to be authorized – and determine the conditions of access.[1296] In 2005, the Commission was asked to deliver an opinion concerning the legality of "black lists" in the private sector. The Commission recommended that they be regulated by a law, especially where they are likely to violate a fundamental right or restrain access to an "essential service." In this latter case, the Commission should authorize the establishment of black lists only upon prior approval. Where the lists process sensitive data (e.g., medical data), they should be regulated by a specific law and strictly follow the provisions of the Law on Protection of Personal Data.[1297]

Alerted by a complained filed by Privacy International alleging the secret disclosure of million of records of European citizens undertaken without regard to legal process under Data Protection law, the Commission started its investigation into the SWIFT case.[1298] SWIFT is a multinational service provider in the financial sector and its headquarters are established in La Hulpe, Belgium.[1299] At the request of the US Treasury Department, SWIFT systematically transmitted information of financial transactions of millions of European bank clients. It appeared that the US Department of Treasury periodically addressed warrants to SWIFT in the US. In its opinion of September 27, 2006, the Commission expressed its astonishment about the exportation of information about Belgian citizens to the US and their revelation to the US authorities each time an individual performs an international payment transaction.[1300] The Commission stated that these practices violate basic provisions of the Belgian and European data protection legislation. This opinion was later confirmed by an opinion of the Article 29 Working Party.[1301]

In November 2006, the Commission received a letter from the Belgian Prime Minister requesting advice on a possible agreement with the US about the transfer of SWIFT data to the US Department of Treasury. In its second opinion, the Commission reminded the Belgian government of the essential principles with regard to transfers of personal data between Europe and the US and suggested a series of possible actions.[1302] In June 2007, the Council of Europe and the US reached an agreement on the transfer of personal financial information from SWIFT to the US.[1303] The agreement stipulates that the US will only obtain information for terrorism investigations; the US will periodically review the information received and delete any unnecessary information from its system; and no information will be kept by the US for longer than 5 years.[1304]

In 2005, the Commission issued an opinion about a project of bill (avant-projet de loi) regarding the Analysis of Threat.[1305] The purpose of the bill is to improve the gathering, use and analysis of information useful to assess terrorist and extremist threats likely to harm national security, Belgian assets and the safety of Belgian citizens abroad. To this end, the bill creates a new institution, the Coordination Agency for the Analysis of Threat (Organe de coordination pour l'analyse de la menace, or OCAM); its task will be to coordinate the collection of that information from various security and intelligence government agencies, and evaluate it. The privacy authority emphasizes that this new type of data collection and analysis by law enforcement is highly sensitive due to the grounds on which it is justified (likelihood and probability) and because it operates unbeknownst to the persons concerned. Although it welcomes the government's project because it provides at least a legal basis to its new processing of data, the Commission has reservations about how the project of bill complies with the provisions of the Law on Protection of Personal Data. In this regard, it recommends that the language of the bill be modified in order to specify the purposes (more than only for "threat analysis" purposes) for which personal data will be transferred between partner security and police agencies and the OCAM, and determine the criteria to be used to appreciate whether to proceed with this transfer; better implement the security safeguards surrounding the processing of data; and establish the guarantees to protect international data transfers among foreign authorities.[1306] The Commission is currently in the process of adopting guidelines to help organizations comply with their security obligations under the Law on Protection of Personal Data of 1992.[1307]

Statutory Rules Related to Privacy

In November 2000, the Belgian Parliament enacted a Computer Crime Law.[1308] The law creates four new crimes: computer forgery ("faux en informatique"), computer fraud ("fraude informatique"), hacking, and sabotage of computer data ("sabotage de données informatiques"). Recent case law tends to temper the harshness of some provisions of the new law.[1309]

In December 1999, the Commission issued an opinion on the Computer Crime Bill, in which it raised serious concerns about its potential negative impact on the protection of privacy. It recommended certain amendments to the Bill including the establishment of a "police monitoring system," which would report back to the Commission, and a three-year review provision.[1310] These suggestions were not included in the law, and the data retention provision even goes against the Commission's official opinion. However, the law provides that the Privacy Commission's opinion is mandatory before any royal decree is enacted on the issue of data retention.

After almost a year of negotiations, a national collective labor organization of employers and employees' representatives (the Conseil national du travail) eventually agreed on common rules regulating the electronic surveillance of workers' computers in the workplace. The common agreement (called convention collective de travail or CCT) entered into force on June 29, 2002 through a royal decree[1311] and applies to all employers and employees in the country. It provides for rules implementing to the specific setting of the workplace the already existing and enforceable European and Belgian general data protection regulations, by ensuring the workers of fairness, information, and compliance with the basic data processing principles of proportionality, purpose specification, and transparency.[1312] The data protection authority had released earlier an opinion[1313] on the same topic in which it refers to the general principles applicable: a general prohibition of the interception of telecommunications, proportionality and transparency, balance of the interests and limited storage of personal data. Also in the field of workplace privacy, another CCT was released in 1998 to regulate the surveillance of workers by video surveillance cameras.[1314] The Commission also issued an Opinion on the use of badges and on employee tracking by means of GPS tracking systems. The Commissioner concluded that the continual surveillance of employees is disproportionate and unnecessary, particularly the use of badges that collect both geographic identifiers and biometric identifiers.[1315]

In August 2002, a new law was enacted that better protects patients' privacy rights by giving them, e.g., the right to be clearly informed about their health state, to consent to any medical interventions, and to have access to their medical files.[1316] There are also laws relating to consumer credit,[1317] social security,[1318] electoral rolls,[1319] the national ID number,[1320] professional secrets,[1321] and employee rights.[1322]

Wiretapping and Other Government Surveillance

Surveillance of communications is regulated under a 1994 law.[1323] Prior to its enactment, there was no specific law. The law requires permission of a juge d'instruction before wiretapping can take place. Orders are limited to a period of one month. There were 114 orders issued in 1996,[1324] and, reportedly, around 1,000 in 2002.[1325] The law was amended in 1997 to remove restrictions on encryption.[1326] The Parliament also amended the law in 1998[1327] to require greater assistance from telecommunications carriers and to give the juge d'instruction and the Attorney General (Procureur du Roi) more powers. The juge d'instruction now has the authority to request the cooperation of experts or network managers to help decrypt telecommunications messages that have been intercepted. The experts, network managers, etc., cannot refuse to cooperate; criminal sanctions are possible in cases of refusal. The law also provides that telecommunications network operators and telecommunications service providers have to record and store calling data (données d'appel) and telecommunications services subscribers' identification data for future law enforcement authorities' needs during a minimum period of 12 months. The law is very vague as to the duration of data retention ("a certain time") and would not prevent an implementing decree from increasing this period for much longer. The Belgian police are officially in favor of a three-year general retention policy.[1328] In 2003, a new royal decree was enacted to implement the June 10, 1998 Law to provide more details about the practical and technical measures that telecommunications network and service providers have to comply with to cooperate with law enforcement authorities.[1329]

Almost unnoticed, a law enacted in December 2001 bans anonymity for subscribers and users of telecommunications network operators and services providers, while the application of the law is, however, subject to a proportionality requirement. A royal decree may prohibit the exploitation of telecommunications services if they render the identification of the caller impossible, or otherwise make it difficult to track, monitor, wiretap, or record communications. With this new rule, the government can now prohibit any telecommunications service that hinders the application of the wiretapping laws.[1330]

In March 2005, the Council of Ministers (Conseil des Ministres) adopted a new Pre-Project of Law (avant-projet de loi) creating a new entity, OCAM, to coordinate the evaluation of the threats of terrorism and extremism. The project of law assigns this task to the OCAM and provides it with the authority to coordinate the collection of such information from security and intelligence entities, as well as other government agencies, such as the Customs Bureau and the Ministry of Foreign Affairs, and assess and analyze it.[1331]

National ID, Travel Documents and Smart Cards

Belgium is the first country in Europe to embed a digital signature in an ID card and to massively roll out ID smart cards at a national level.[1332] The "e-ID" (which stands for "electronic ID") embeds a digital certificate that will, according to the government, allow Belgians to communicate online and conduct secure transactions with government agencies, access e-government applications, and perform e-banking, or other future private applications.[1333] Under the plan, every Belgian citizen (as young as 6 years old)[1334] gets an identification card with his or her name and other identifiers,[1335] photograph and two digital certificates. One is to be used for authentication, the other as a digital signature to sign documents such as declarations or application forms, which will have the same legal value as documents signed by hand.[1336]

The e-ID project, which was originally called "BELPIC" (or Belgian Personal Identity Card) started in July 2001, when the Council of Ministers (Conseil des ministres) approved the idea of introducing an electronic identity card for all Belgians.[1337] In February 2003, the Parliament approved the introduction of BELPIC[1338] and the new chipcards were tested in 11 municipalities (communes) until September 2003. After the government considered the test satisfactory, it decided to roll out the cards to the rest of the Belgian population[1339] – about nine million individuals – on a schedule that would end in late 2009.[1340] By Royal Decree, the government began issuing Kids-ID for Belgian children between the ages of 6 and 12.[1341] The Kids-ID card replaces paper identity certificates and shows the child’s name and an emergency contact number. All other information, such as home address, is contained on the chip. Six pilot projects are currently being conducted.[1342]

The Commission and civil liberties organizations criticized the new ID card as presenting a serious threat to individuals' privacy. The data protection authority noted that it was still unclear how the government answers several important privacy concerns due to the uncertainty of many aspects of the project, and the information that the Commission has so far been provided with from the government.[1343] Other critics say that the e-commerce identity of Internet users should not be linked to day-to-day authentication, that integration of data damages the integrity and rights of users, and that the fact that the Belgian government handed the project to a private company (security firm Ubizen) jeopardizes citizens' privacy rights.[1344] While it does not appear such concerns have been thus far addressed, both the public and private sectors have already developed several new applications and services compatible with e-ID, including online tax returns, certified e-mail, online request of official documents, Internet banking services and electronic library services.[1345] The Commissioner expressed serious reservations regarding the inclusion on the e-card of such information as organ donation choices, or medical files. The Commissioner states that the inclusion of information extraneous to identification and authentication sets a dangerous precedent.[1346]

Belgium began a test program in May 2004 that made it the second country in the world (after Malaysia) to issue passports with an imbedded computer chip for personal information.[1347] The government began producing the RFID[1348] passports in November 2004, and issuing them to the public on January 30, 2005, in full compliance with the current European, US and ICAO[1349] standards and deadlines for biometric based e-passports.[1350] Initially, the chip will be used only for basic information, such as name, date and place of birth, passport number, issuing date and place, digital photo and signature. However, it has the ability to store fingerprints, an iris scan and other biometrics.[1351] Although the Belgian passport received "the world's most secure passport" award from Interpol in 2003,[1352] now that it is equipped with a RFID chip, it may present new privacy and security risks, including the unauthorized reading of its data.[1353]

Miscellaneous Developments

Since 2003, the use of e-mails for marketing purposes is prohibited without the prior, free, specific and informed consent of the recipients, in compliance with the EU Directive on Electronic Commerce,[1354] transposed by the Law of March 11, 2003,[1355] and with the EU Electronic Communications and Privacy Directive.[1356] Further spam provisions were implemented by the Royal Decree of April 4, 2003.[1357] The deadline for the implementation of the Directive expired on October 31, 2003 and infringement proceedings had been launched against Belgium by the European Commission for failure to transpose the remaining provisions into national law. In April 2005, Belgium’s failure to transpose the Directive was confirmed in a judgment of the European Court of Justice. In June 2005, Belgium finally adopted its Law on Electronic Communications.[1358] Belgium has now fully implemented the EU Directive on Privacy & Electronic Communications of 2002.[1359]

The Law on Electronic Communications adds two exceptions to the prohibition on electronic eavesdropping guaranteed in the Penal Code. The recording of electronic communications and their traffic data is lawful as proof of a commercial transaction, or for the purpose of service quality control. Retention, however, cannot exceed one month.[1360]

From the end of 2000, IFPI Belgium, the recording industry trade association, started tracking people downloading and uploading music files from MP3 audio file-sharing web sites such as Napster, Gnutella or KaZaa. In a move that left many Belgian music fans outraged, IFPI collaborated by simple "gentlemen's agreements,"[1361] outside any legal framework, with Internet service providers (ISPs) to get the names and addresses of high-speed Internet connection subscribers in order to send them personalized letters threatening them with legal action if they did not stop their file-sharing practices. In November 2001, the Privacy Commission released an initiative opinion[1362] severely condemning the way IFPI had behaved with respect to the protection of people's privacy and stating that IFPI had violated several Belgian and European telecommunications privacy and data protection laws.[1363] In June 2007, the Belgian Society of Authors, Composers, and Publishers (SABAM) won a case against ISP Scarlet Extended SA in which the court ruled that Scarlet would be required to use Audible Magic filtering technology to stop the spread of music on P2P networks. Scarlet was given six months to comply with the order. Scarlet is appealing the decision. SABAM is currently trying to use the ruling to convince other ISPs to follow suit.[1364] While the Brussels Court ruled that such filtering would not violate user privacy nor create a general expectation of network surveillance, it is not unreasonable to ISPs being required to do the same for movies or other infringing media or activities.[1365]

Voting Privacy

Voting is mandatory for those 18 years and older.[1366] The laws regarding voting, enacted in 1919 and amended to include women in 1949, are strictly enforced.[1367] Non-voting requires an acceptable explanation and may result in a fine, imprisonment, infringement of civil rights, disenfranchisement, or prevent employment in the public sector.[1368] Voter registration lists are publicly posted in polling locations on Election Day and may also be obtained for political campaign purposes.[1369] Election administrators take an oath to maintain the secrecy of votes cast. Voters are guaranteed the right of secrecy of their vote.[1370] In 1989, Belgium became one of the first countries to use electronic means of casting ballots in public elections.[1371] In 1991, experiments began with the use of electronic voting machines at polling locations.[1372] The Election Law was amended by the Act of April 11, 1994 to allow a "system of electronic voters" and was amended again on December 18, 1998 to allow "automated" voting.[1373] The Federal Council of Ministers Rulings of June 20 and July 18, 1997 formally endorsed the adoption of electronic voting. By 1999, 40 percent of voters participating in Belgium's public elections used electronic voting machines.[1374] The direct recording electronic (DRE) system identified was used by 44 percent of voters in 2000. By 2003, an estimated three million votes were cast using electronic voting technology.[1375]

Open Government

The Constitution recognizes that "everyone has the right to consult any administrative document and to have a copy made, except in the cases and conditions stipulated by the laws, decrees, or regional council decrees (i.e., the "rulings referred to in Article 134").[1376] There are freedom of information laws, implementing this constitutional right, on the right of access to administrative documents on the federal,[1377] regional,[1378] community,[1379] provincial and municipal levels.[1380] The basic exemptions to the general rule of access are public security, the protection of fundamental rights, international interests, public order, security or defense, confidentiality, and privacy. Each jurisdiction has a Commission of Access to Administrative Documents (Commission d'Accès aux Documents Administratifs, or CADA) that oversees the act. Citizens can appeal denials of information requests to the administrative agency, which in turn asks for advice from the CADA. The CADA issues advisory opinions both on request and on its own initiative. Requestors can then pursue a limited judicial appeal to the Counsel of State (Conseil d'Etat).[1381] At the federal level, each federal public authority is required to provide a description of their functions and organization, and must have an information officer.[1382] The Law on Protection of Personal Data gives individuals the right to access and correct files about themselves that public and private entities hold, and is enforced by the Commission for the Protection of Private Life. As to the administrative documents that contain personal information, access is regulated by the Law of April 11, 1994.

International Obligations

Belgium is a member of the Council of Europe (CoE) and has signed and ratified the Convention for the Protection of Individuals with Regard to Automatic Processing of Personal Data (Convention No. 108).[1383] It has signed and ratified the European Convention for the Protection of Human Rights and Fundamental Freedoms.[1384] It is a member of the Organization for Economic Cooperation and Development (OECD) and has adopted the OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data. The government signed, but has not ratified, the CoE Convention on Cybercrime.[1385]

