You buy a ticket online, and right after that, promotional emails start pouring in. Is a company allowed to do that just like that? In a ruling dated July 16, 2026 (No. 163/2026) The Dispute Chamber of the Data Protection Authority (GBA) ruled that a company in the entertainment sector may send emails to its customers about similar products and services, provided that the opt-out process is truly simple and that the website does not mislead the customer about their purchase channel. The company will pay a fine of 5,000 euros and adjust its practices, without the GBA finding a formal violation.
The facts
The complainant purchased a ticket through the company’s website and subsequently received repeated direct-marketing emails that he did not want. What bothered him most was that he normally buys his tickets anonymously at the box office, precisely to avoid ending up in a customer database. However, during the summer of 2020, when the sector reopened after a lockdown, the website stated that tickets could only be purchased online. As a result, the complainant assumed that purchasing a ticket in person was not possible.
The Inspection Service’s investigation revealed that this statement was factually incorrect: tickets could still be purchased on-site, and between July and October 2020, the company did in fact continue to sell a portion of its tickets at its own facilities. The complaint was filed on September 1, 2020. After an investigation and a long period of inactivity, the GBA opted for a settlement process in 2026, which led to an agreement on July 15, 2026.
The decision
The Dispute Resolution Chamber finds no violation. It validates a settlement pursuant to Article 95, § 1, 2° of the Act of December 3, 2017, Establishing the Data Protection Authority (WOG). In a settlement, the GBA does not rule on whether the rules were violated; the company commits to a series of measures and, in this case, to paying a sum of money. The defendant unconditionally agreed to three conditions.
A misleading statement on a website (Article 5(1)(a) of the GDPR)
The Inspection Service found that the incorrect statement that tickets were available for purchase only online violated the duty of due diligence under the General Data Protection Regulation (GDPR). Customers who preferred to shop anonymously at the checkout were thus pushed toward the online channel, resulting in additional processing of personal data. The defendant acknowledged that the statement was factually incorrect. The Dispute Resolution Chamber took into account the exceptional public health circumstances, the company’s good-faith cooperation, and the fact that the statement did not yield any commercial benefit for the company. Regarding this point, the defendant agrees to pay the sum of 5,000 euros to the Belgian Treasury.
Marketing Emails and a Simple Right to Object (Soft Opt-In)
The Inspectorate found that customers received direct marketing immediately after their purchase and that it was not made sufficiently clear how they could opt out. This involves the so-called "soft opt-in" from the e-Privacy Directive (Directive 2002/58/EC): Anyone who obtains electronic contact information in connection with the sale of a product or service may use that information to send advertisements for similar products or services of their own. This exception is set forth in Belgium in Article 1, 1° of the Royal Decree of April 4, 2003, an implementing resolution regarding the general authorization requirement of Article XII.13 of the Code of Economic Law (WER). The condition in each case is that the customer must be able to opt out easily.
The defendant agrees to make the opt-out process simple. Within thirty days, it will provide a dated screenshot of the updated website, and it will include a direct opt-out link in every promotional email that works without requiring a login and without the customer having to re-enter previously provided information.
Retention Periods and Profile Creation (Articles 5(1)(e), 6(1)(b), and 6(1)(f) of the GDPR)
The Inspectorate also raised questions about the creation of customer profiles based on purchase history and the lengthy retention periods. The defendant clarified that its “profiling” amounts to nothing more than segmenting the database based on previous purchases. It had already reduced its retention period for inactive customers from five to three years and has committed to deleting or irreversibly anonymizing historical visitor and purchase data that exceeds the retention period no later than four months after the decision.
Legal analysis and interpretation
Soft opt-in as a standalone basis, and where the GDPR still comes into play
This decision cannot be viewed in isolation from a recent ruling by the Court of Justice. In the Inteligo Media Ruling (ECJ, November 13, 2025, C-654/23) The Court ruled that the soft opt-in under Article 13(2) of the e-Privacy Directive constitutes a standalone legal basis. If the conditions are met, a company is no longer required to demonstrate a separate legal basis under the GDPR for those marketing emails. The e-Privacy Directive applies here as a special regulation that takes precedence over the general legal bases of the GDPR.
That does not mean that the GDPR will disappear entirely. The Court confirmed that related processing activities, such as transparency toward the customer and the limitation of the retention period, remain fully subject to the GDPR. The Dutch Data Protection Authority (GBA) applies this distinction strictly in this case: it assesses the sending of the email itself based on the “soft opt-in” principle, but it evaluates the separate creation of profiles or segments based on purchase history independently under Article 6 of the GDPR. This creates a distinction that companies would do well to keep in mind: one action (the marketing email) may fall under the e-Privacy Regulation, while another action (the profile behind that email) requires its own legal basis under the GDPR. The GBA recently elaborated on its broader view of direct marketing in Recommendation 01/2026.
A settlement does not constitute a finding of infringement
The decision is not a conviction. The Dispute Resolution Chamber expressly does not find any violation and does not impose a fine; it ratifies an agreement in which the company agrees to take certain measures and pay a sum of money. This distinction has legal implications. A settlement does not constitute an acknowledgment of an infringement as an established fact and exhausts the GBA’s remedial authority with respect to the specified points. The payment of 5,000 euros is therefore not an administrative fine within the meaning of the GDPR, but rather a component of the settlement agreement.
The Dispute Chamber takes the company’s conduct into account: the explicit acknowledgment of the factual error and the provision of information in good faith to the Inspectorate are viewed as the conduct of a responsible data controller. For those facing a GBA case, this illustrates the appeal of a settlement: it offers a way out without a formal finding of a violation. At the same time, a settlement decision remains subject to appeal before the Market Court (Article 108 of the WOG), ensuring that a party or third party who considers itself aggrieved is not left without legal protection.
Specifically, what does this mean?
For businesses that sell online. You can send promotional messages to existing customers without prior consent, but only within the limits of the soft opt-in: the messages must concern similar products or services offered by your company, and the customer must be able to easily unsubscribe at any time. Include a direct unsubscribe link in every email that does not require a login or re-entry of previously provided information. Also pay attention to your own messaging: an incorrect statement that a purchase can only be made online can in itself raise an issue of fairness, even if there is no commercial benefit behind it.
For those who build customer profiles. Sending the email and creating a profile are two separate processing operations. Soft opt-in is not sufficient for that profile; you need your own legal basis under Article 6 of the GDPR, and that varies depending on whether the data subjects are account holders (performance of the contract) or other customers (legitimate interest). Keep the retention period short and tailored to specific purposes, and delete or anonymize data that falls outside of those parameters.
For anyone considering a settlement in a GBA case. The settlement is a de-escalation process: no finding of violation, no fine, but enforceable measures and, in some cases, a monetary payment. A fair and cooperative attitude, along with acknowledging factual inaccuracies, can work in your favor. Keep in mind that the decision may be appealed to the Marktenhof within thirty days.
Frequently asked questions (FAQ)
Can an online store send me promotional emails after I've made a purchase?
Yes, this is permitted without separate consent under the soft opt-in rule, as long as the products or services are similar and offered by the same company, and you can easily opt out. For completely new prospects or for non-similar products, the situation is different, and consent is generally required.
How long can a company keep my purchase information?
There is no fixed retention period. The principle of data minimization requires that data not be retained for longer than is necessary for the purpose. In this case, the company reduced the retention period for inactive customers from five to three years and committed to deleting or anonymizing older data.
What is a settlement with the Data Protection Authority?
A settlement is an agreement under which the company agrees to take certain measures and, in some cases, pay a sum of money, without the GBA finding an infringement or imposing a fine. It is an alternative to proceedings on the merits and remains subject to appeal before the Marktenhof.
Conclusion
Marketing emails sent after an online purchase are not prohibited in Belgium, but their legality hinges on a simple right to opt out and on providing accurate information to the customer. This settlement decision confirms, in line with the Inteligo Media ruling, that the promotional email itself falls under the soft opt-in rule, while the profile behind it requires its own GDPR assessment. And it shows that a misleading statement on a website, even without commercial intent, can come at a cost.



