{"id":100423,"date":"2025-10-09T19:06:07","date_gmt":"2025-10-09T18:06:07","guid":{"rendered":"https:\/\/www.ictrechtswijzer.be\/?p=100423"},"modified":"2025-10-09T22:32:18","modified_gmt":"2025-10-09T21:32:18","slug":"new-edpb-guidelines-dma-gdpr-on-the-way-why-every-belgian-company-should-pay-attention","status":"publish","type":"post","link":"https:\/\/www.ictrechtswijzer.be\/en\/nieuwe-edpb-richtlijnen-dma-avg-op-komst-waarom-elke-belgische-onderneming-moet-opletten\/","title":{"rendered":"New EDPB guidelines DMA &amp; GDPR on the way: why every Belgian company should pay attention"},"content":{"rendered":"<p class=\"wp-block-paragraph\">On 9 October 2025, the European Commission and the European Data Protection Board (EDPB) published joint <a href=\"https:\/\/www.edpb.europa.eu\/news\/news\/2025\/dma-and-gdpr-edpb-and-european-commission-endorse-joint-guidelines-clarify-common_en\" target=\"_blank\" rel=\"noreferrer noopener\">draft guidelines<\/a> on the interaction between the Digital Markets Act (<a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/NL\/TXT\/?uri=CELEX%3A02022R1925-20221012\" target=\"_blank\" rel=\"noreferrer noopener\">DMA<\/a>) and the General Data Protection Regulation (<a href=\"https:\/\/www.ictrechtswijzer.be\/en\/data-protection\/\" target=\"_blank\" rel=\"noreferrer noopener\">GDPR<\/a>). At first glance, this seems like a technical discussion for \"gatekeepers\" like Google and Meta. However, a thorough analysis shows a different picture: these draft guidelines contain interpretations that threaten to change the application of the GDPR for ALL businesses in the EU. The impact extends far beyond the walls of Big Tech and could touch the foundations of your data processing and online services.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-van-gatekeepers-tot-kmo-s-een-gedeeld-juridisch-speelveld\">From gatekeepers to SMEs: a shared legal playing field<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The DMA aims to limit the power of the largest digital platforms and ensure fairer and more open digital markets. The GDPR, on the other hand, protects the personal data of all European citizens and applies to virtually every business. The new guidelines should clarify how these two important regulations co-exist.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The danger, however, lies in the details. Under the guise of regulating gatekeepers, the EDPB is introducing interpretations of the GDPR that could set a precedent. If adopted in their current form, these guidelines could lead to a stricter and more restrictive reading of the GDPR for everyone.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-artikel-5-2-dma-de-herdefiniering-van-toestemming\">Article 5(2) DMA - The redefinition of consent<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This article is perhaps the most sweeping, prohibiting gatekeepers from combining personal data, crossing between different services, or using it for targeted advertising without valid end-user consent. To still be allowed to perform these processing operations, gatekeepers must meet two cumulative conditions: they must offer a specific choice (including an \"equivalent alternative\") and the user must give explicit, valid GDPR consent to do so.  Several dangers lurk here.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-de-gelijkwaardige-maar-niet-identieke-dienst-een-onmogelijke-spagaat\">The 'equivalent but not identical' service: an impossible split<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">The draft guidelines state that the alternative for users who do not give consent must be \"less personalized but equivalent.\" They then tighten this concept: the alternative service must not be of \"degraded quality\" and must not differ in \"performance, experience and conditions of access.\" <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is a fundamentally contradictory requirement. By definition, a service without personalization (e.g., a news feed that is not tailored to reading behavior) offers a different <em>experience<\/em>. The proposition that experience should not differ is illogical and creates an unworkable, subjective standard. It opens the door to endless discussions about what exactly constitutes an \"equivalent experience,\" leading to immense legal uncertainty for anyone wishing to offer alternative (e.g., paid, ad-free) versions of a service.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Practical impact:<\/strong> This logic can trickle down to the discussion of 'cookie walls' and 'pay or okay' models for all websites. If a non-personalized or paid version is considered \"non-equivalent\" because the \"experience\" is different, it undermines legitimate business models that rely on advertising revenue.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-de-subjectieve-lat-voor-gebruikersinterfaces\">The subjective bar for user interfaces<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">The draft guidelines rightly state that interfaces should not be misleading. However, the draft guidelines go much further. They state that design choices that \"may mislead or <em>nudge<\/em> end users into providing unintended and thus invalid \nconsent accordingt\" are prohibited. The text adds that an interface should not cause users not to \"think about all or some of the \nimplications of providing their consent.\" <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This formulation is problematic. The terms \"nudge,\" \"unintented,\" and \"not to think\" are extremely subjective. What one user sees as a helpful suggestion (nudging), another may perceive as manipulation. It also places an unrealistic burden of proof on the designer. How can a company prove that a user has \"nudged\"? What if a user consciously chooses a fast, standardized interface? Requiring a design to force users to consider <em>all<\/em> implications is unrealistic and could make any standardised, user-friendly interface vulnerable to legal proceedings.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Practical impact:<\/strong> This creates a climate of enormous legal uncertainty for Web designers and developers. Any attempt to make a permission flow smooth and efficient can be attacked as \"nudging. The bar is set so high that it becomes almost impossible to design an interface that is both user-friendly and legally unassailable.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-de-hierarchie-van-rechtsgronden-een-sluipend-gevaar\">The hierarchy of legal grounds: a creeping danger<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Perhaps the most fundamental risk is the implicit message that consent (Article 6(1)(a) GDPR) is a \"better\" legal ground than contractual necessity (6(1)(b)) or legitimate interest (6(1)(f)). The draft guidelines explicitly state that for processing operations under Article 5(2) DMA, gatekeepers cannot rely on the performance of a contract or their legitimate interest. The justification for this is \"ensuring a high level of protection of personal data.\" <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This sets a dangerous precedent. The GDPR provides in article 6 six possible legal grounds for processing personal data, including consent, contractual necessity and legitimate interest. The GDPR itself provides no hierarchy; each legal ground is valid if the conditions are met. By suggesting that excluding certain legal grounds leads to \"better\" protection, it systematically erodes the value of legitimate interest - a crucial and flexible legal ground for innovation, security and service improvement.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Practical impact:<\/strong> If this reasoning is adopted by regulators, it may be for <em>any<\/em> company become more difficult to invoke legitimate interest for essential activities such as fraud prevention, network security, or even improving its own services. This would lead to an inflation of consent requests, resulting in \"consent fatigue\" among users.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-artikel-6-4-dma-app-stores-en-de-verantwoordelijkheid-van-de-verwerkingsverantwoordelijke\">Section 6(4) DMA - App Stores and controller responsibility<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This article requires gatekeepers offering an operating system to allow the installation and use of third-party software and app stores (known as sideloading). However, the gatekeeper may take \"strictly necessary and proportionate\" measures to ensure the integrity and security of the hardware and operating system. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The draft guidelines make a crucial legal clarification here that is relevant to all platform ecosystems: the gatekeeper (as the operating system provider) and the third-party app developer are basically considered separate and independent data controllers. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This means that the gatekeeper may not dictate <em>how<\/em> the app developer meets its own GDPR obligations. The gatekeeper can provide technical tools (e.g., for asking for consent), but the developer remains responsible and should be free to choose its compliance strategy. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Practical impact:<\/strong> For any Belgian company operating on a third-party platform (be it an app store, an e-commerce marketplace or a social network), this affirms a fundamental principle. Be critical of platform terms and conditions that try to dictate to you how to handle your customer data. Basically, you are an independent data controller and bear your own responsibility.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-artikel-6-9-dma-dataportabiliteit-2-0-en-de-gevolgen\">Section 6(9) DMA - Data portability 2.0 and its implications<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Article 6(9) creates an enhanced right to data portability. It goes beyond the well-known Article 20 of the GDPR. Users (and third parties authorized by them) must be given \"continuous real-time access\" to all the data they have provided or that has been generated by their activity <em>.<\/em>This right is free and applies regardless of the original legal basis for the processing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The draft guidelines work out some complex scenarios:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Third-party data:<\/strong> What if the data set that a user wishes to take with them also contains personal data belonging to other individuals (e.g., contacts, photos with others)? The draft guidelines confirm that this falls within the scope. The gatekeeper must facilitate the transfer, but the recipient (the user or authorized third party) becomes a data controller for that data itself and must comply with the GDPR.<\/li>\n\n\n\n<li><strong>International pass-throughs:<\/strong> If a user wishes to transfer their data to a service in a country outside the EEA without an adequate level of protection, the gatekeeper must obtain the user's explicit and informed consent for that specific high-risk transfer, in accordance with Article 49 GDPR. <\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Practical impact:<\/strong> For enterprises that want to build innovative services by combining data from different platforms (with user consent), this article presents enormous opportunities. At the same time, it brings significant responsibilities. If you receive data through this mechanism, you become fully responsible for its proper processing, including informing all data subjects whose data you indirectly obtain.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-artikel-6-11-dma-de-hoge-lat-voor-anonimisering-van-data\">Article 6(11) DMA - The high bar for data anonymization<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">To promote competition in the search engine market, this article requires gatekeepers to give competing search engines access to anonymized ranking, query, click and view data. <sup><\/sup><sup><\/sup><sup><\/sup><sup><\/sup>The crucial condition is that all personal data must be \"anonymized.\" <sup><\/sup><sup><\/sup><sup><\/sup><sup><\/sup><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The draft guidelines dive deep into the definition of anonymity, citing recital 26 of the GDPR. Data is anonymous only when a person is no longer identifiable, taking into account \"all means reasonably available\" by anyone to identify that person. The challenge here is the inherent tension that the draft guidelines themselves recognize: anonymization must be effective, but at the same time must not \"\u201csubstantially degrading the \nquality or usefulness of the data\".<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Practical impact:<\/strong> This illustrates the extremely high threshold for effective anonymization under the GDPR. For any company working with anonymized or pseudonymized datasets, this is a warning sign. The techniques must be robust and the risk of re-identification (e.g., by combining the data with other datasets) must be negligible. True anonymization is complex and requires thorough technical and legal analysis.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-wat-kunt-u-doen-de-publieke-consultatie-is-cruciaal\">What can you do? Public consultation is crucial<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">These draft guidelines are not law, but they give a clear indication of the direction European regulators want to go. The implications for non-gatekeepers could be significant. Fortunately, a public consultation has been opened where all interested parties can provide their feedback. This runs until <strong>December 4, 2025<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is vital that business, from SMEs to larger players, make their voices heard. The voice of practitioners is essential to prevent theoretical and unworkable principles from becoming the norm. Speak to your industry federation or consider submitting a contribution yourself.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-conclusie-een-trojaans-paard-voor-de-avg\">Conclusion: a Trojan horse for the GDPR<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The joint Commission and EDPB guidelines are more than a technical document for a handful of tech giants. They threaten to be a Trojan horse that ushers in a much more restrictive interpretation of the GDPR throughout the European Union. The proposed principles around legal grounds, equivalent services and interface design create uncertainty and could hurt the innovation and competitiveness of European companies. Vigilance and active participation in the public debate are now crucial.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\">The interaction between the DMA and the GDPRG is creating a complex legal landscape. Do you have questions about how these evolutions affect your data processing and online services? Our attorneys specializing in privacy and technology law are ready to assess the risks to your case and determine your strategy. Contact us for clear, strategic advice.<\/a><\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>","protected":false},"excerpt":{"rendered":"<p>De Europese Commissie en de European Data Protection Board (EDPB) hebben op 9 oktober 2025 gezamenlijke ontwerprichtlijnen gepubliceerd over de wisselwerking tussen de Digitalemarktenverordening (DMA) en de Algemene Verordening Gegevensbescherming (AVG). Op het eerste gezicht lijkt dit een technische discussie voor &#8216;gatekeepers&#8217; zoals Google en Meta. Een grondige analyse toont echter een ander beeld: deze [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":100424,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-100423","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-geen-categorie"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v28.5) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Nieuwe EDPB richtlijnen DMA &amp; AVG op komst: waarom elke Belgische onderneming moet opletten - ICT Rechtswijzer Advocaat<\/title>\n<meta name=\"description\" content=\"Een diepgaande analyse van de EDPB ontwerprichtlijnen over de wisselwerking tussen de DMA en AVG. Ontdek waarom deze regels voor Big Tech een precedent scheppen en een aanzienlijk risico vormen voor elke Belgische onderneming.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.ictrechtswijzer.be\/en\/new-edpb-guidelines-dma-gdpr-on-the-way-why-every-belgian-company-should-pay-attention\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Nieuwe EDPB richtlijnen DMA &amp; AVG op komst: waarom elke Belgische onderneming moet opletten\" \/>\n<meta property=\"og:description\" content=\"Een diepgaande analyse van de EDPB ontwerprichtlijnen over de wisselwerking tussen de DMA en AVG. Ontdek waarom deze regels voor Big Tech een precedent scheppen en een aanzienlijk risico vormen voor elke Belgische onderneming.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.ictrechtswijzer.be\/en\/new-edpb-guidelines-dma-gdpr-on-the-way-why-every-belgian-company-should-pay-attention\/\" \/>\n<meta property=\"og:site_name\" content=\"ICT Rechtswijzer Advocaat\" \/>\n<meta property=\"article:published_time\" content=\"2025-10-09T18:06:07+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-10-09T21:32:18+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2025\/10\/internet-search-engine-1433323_1280.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"854\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Joris Deene\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Joris Deene\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/nieuwe-edpb-richtlijnen-dma-avg-op-komst-waarom-elke-belgische-onderneming-moet-opletten\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/nieuwe-edpb-richtlijnen-dma-avg-op-komst-waarom-elke-belgische-onderneming-moet-opletten\\\/\"},\"author\":{\"name\":\"Joris Deene\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#\\\/schema\\\/person\\\/29025dc007e8d33a89422580a534d685\"},\"headline\":\"Nieuwe EDPB richtlijnen DMA &amp; AVG op komst: waarom elke Belgische onderneming moet opletten\",\"datePublished\":\"2025-10-09T18:06:07+00:00\",\"dateModified\":\"2025-10-09T21:32:18+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/nieuwe-edpb-richtlijnen-dma-avg-op-komst-waarom-elke-belgische-onderneming-moet-opletten\\\/\"},\"wordCount\":1744,\"publisher\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/nieuwe-edpb-richtlijnen-dma-avg-op-komst-waarom-elke-belgische-onderneming-moet-opletten\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/internet-search-engine-1433323_1280.jpg\",\"articleSection\":[\"Geen categorie\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/nieuwe-edpb-richtlijnen-dma-avg-op-komst-waarom-elke-belgische-onderneming-moet-opletten\\\/\",\"url\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/nieuwe-edpb-richtlijnen-dma-avg-op-komst-waarom-elke-belgische-onderneming-moet-opletten\\\/\",\"name\":\"Nieuwe EDPB richtlijnen DMA &amp; AVG op komst: waarom elke Belgische onderneming moet opletten - ICT Rechtswijzer Advocaat\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/nieuwe-edpb-richtlijnen-dma-avg-op-komst-waarom-elke-belgische-onderneming-moet-opletten\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/nieuwe-edpb-richtlijnen-dma-avg-op-komst-waarom-elke-belgische-onderneming-moet-opletten\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/internet-search-engine-1433323_1280.jpg\",\"datePublished\":\"2025-10-09T18:06:07+00:00\",\"dateModified\":\"2025-10-09T21:32:18+00:00\",\"description\":\"Een diepgaande analyse van de EDPB ontwerprichtlijnen over de wisselwerking tussen de DMA en AVG. Ontdek waarom deze regels voor Big Tech een precedent scheppen en een aanzienlijk risico vormen voor elke Belgische onderneming.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/nieuwe-edpb-richtlijnen-dma-avg-op-komst-waarom-elke-belgische-onderneming-moet-opletten\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.ictrechtswijzer.be\\\/nieuwe-edpb-richtlijnen-dma-avg-op-komst-waarom-elke-belgische-onderneming-moet-opletten\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/nieuwe-edpb-richtlijnen-dma-avg-op-komst-waarom-elke-belgische-onderneming-moet-opletten\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/internet-search-engine-1433323_1280.jpg\",\"contentUrl\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/internet-search-engine-1433323_1280.jpg\",\"width\":1280,\"height\":854},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/nieuwe-edpb-richtlijnen-dma-avg-op-komst-waarom-elke-belgische-onderneming-moet-opletten\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Nieuwe EDPB richtlijnen DMA &amp; AVG op komst: waarom elke Belgische onderneming moet opletten\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#website\",\"url\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/\",\"name\":\"ICT Rechtswijzer Advocaat\",\"description\":\"Advocaten in IP, AI, IT, privacy &amp; media\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Organization\",\"LegalService\"],\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#organization\",\"name\":\"ICT Rechtswijzer\",\"alternateName\":\"ICT Rechtswijzer, kennisplatform van Everest Advocaten\",\"url\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wp-content\\\/uploads\\\/2018\\\/08\\\/joris-deene-auteursrecht-in-een-digitale-omgeving-1-638.jpg\",\"contentUrl\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wp-content\\\/uploads\\\/2018\\\/08\\\/joris-deene-auteursrecht-in-een-digitale-omgeving-1-638.jpg\",\"width\":638,\"height\":479,\"caption\":\"ICT Rechtswijzer\"},\"image\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/be.linkedin.com\\\/company\\\/everest-law\",\"https:\\\/\\\/www.everest-law.eu\\\/\"],\"description\":\"Kennisplatform van het departement intellectuele eigendom, IT-recht, AI-recht, gegevensbescherming en mediarecht van Everest Advocaten, onder leiding van mr. Joris Deene.\",\"parentOrganization\":{\"@type\":\"LegalService\",\"name\":\"Everest Advocaten\",\"url\":\"https:\\\/\\\/www.everest-law.eu\",\"address\":{\"@type\":\"PostalAddress\",\"streetAddress\":\"Bollebergen 2A bus 20\",\"postalCode\":\"9052\",\"addressLocality\":\"Gent\",\"addressCountry\":\"BE\"}}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#\\\/schema\\\/person\\\/29025dc007e8d33a89422580a534d685\",\"name\":\"Joris Deene\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7073c8d7ef4db19fbc2d462ac2571a2b0a3e5c89329cba99b4d3caf0bcd7cfc1?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7073c8d7ef4db19fbc2d462ac2571a2b0a3e5c89329cba99b4d3caf0bcd7cfc1?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7073c8d7ef4db19fbc2d462ac2571a2b0a3e5c89329cba99b4d3caf0bcd7cfc1?s=96&d=mm&r=g\",\"caption\":\"Joris Deene\"},\"description\":\"Mr. Joris Deene is advocaat-partner bij Everest Advocaten en leidt het departement intellectuele eigendom, IT-recht, AI-recht, gegevensbescherming en mediarecht. ICT Rechtswijzer is het kennisplatform van dat departement. Joris publiceert en doceert over auteursrecht, merkenrecht, softwarerecht, de AVG, de AI-Act, de DSA en het mediarecht.\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/joris-deene-5144096\\\/\"],\"honorificPrefix\":\"Mr.\",\"knowsAbout\":[\"intellectuele eigendom\",\"auteursrecht\",\"merkenrecht\",\"IT-recht\",\"AI-recht\",\"gegevensbescherming\",\"AVG\",\"mediarecht\",\"digitaledienstenverordening\",\"AI-verordening\"],\"knowsLanguage\":[\"Nederlands\",\"Engels\",\"Frans\"],\"jobTitle\":\"Advocaat-partner, hoofd departement intellectuele eigendom, IT-recht, AI-recht, gegevensbescherming en mediarecht\",\"worksFor\":\"Everest Advocaten\",\"url\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/en\\\/author\\\/joris-deene\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"New EDPB guidelines DMA &amp; AVG on the way: why every Belgian company should pay attention - ICT Lawyer's Guide","description":"An in-depth analysis of the EDPB draft guidelines on the interaction between the DMA and AVG. Discover why these Big Tech rules set a precedent and pose a significant risk to any Belgian company.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.ictrechtswijzer.be\/en\/new-edpb-guidelines-dma-gdpr-on-the-way-why-every-belgian-company-should-pay-attention\/","og_locale":"en_US","og_type":"article","og_title":"Nieuwe EDPB richtlijnen DMA &amp; AVG op komst: waarom elke Belgische onderneming moet opletten","og_description":"Een diepgaande analyse van de EDPB ontwerprichtlijnen over de wisselwerking tussen de DMA en AVG. Ontdek waarom deze regels voor Big Tech een precedent scheppen en een aanzienlijk risico vormen voor elke Belgische onderneming.","og_url":"https:\/\/www.ictrechtswijzer.be\/en\/new-edpb-guidelines-dma-gdpr-on-the-way-why-every-belgian-company-should-pay-attention\/","og_site_name":"ICT Rechtswijzer Advocaat","article_published_time":"2025-10-09T18:06:07+00:00","article_modified_time":"2025-10-09T21:32:18+00:00","og_image":[{"width":1280,"height":854,"url":"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2025\/10\/internet-search-engine-1433323_1280.jpg","type":"image\/jpeg"}],"author":"Joris Deene","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Joris Deene","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.ictrechtswijzer.be\/nieuwe-edpb-richtlijnen-dma-avg-op-komst-waarom-elke-belgische-onderneming-moet-opletten\/#article","isPartOf":{"@id":"https:\/\/www.ictrechtswijzer.be\/nieuwe-edpb-richtlijnen-dma-avg-op-komst-waarom-elke-belgische-onderneming-moet-opletten\/"},"author":{"name":"Joris Deene","@id":"https:\/\/www.ictrechtswijzer.be\/#\/schema\/person\/29025dc007e8d33a89422580a534d685"},"headline":"Nieuwe EDPB richtlijnen DMA &amp; AVG op komst: waarom elke Belgische onderneming moet opletten","datePublished":"2025-10-09T18:06:07+00:00","dateModified":"2025-10-09T21:32:18+00:00","mainEntityOfPage":{"@id":"https:\/\/www.ictrechtswijzer.be\/nieuwe-edpb-richtlijnen-dma-avg-op-komst-waarom-elke-belgische-onderneming-moet-opletten\/"},"wordCount":1744,"publisher":{"@id":"https:\/\/www.ictrechtswijzer.be\/#organization"},"image":{"@id":"https:\/\/www.ictrechtswijzer.be\/nieuwe-edpb-richtlijnen-dma-avg-op-komst-waarom-elke-belgische-onderneming-moet-opletten\/#primaryimage"},"thumbnailUrl":"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2025\/10\/internet-search-engine-1433323_1280.jpg","articleSection":["Geen categorie"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.ictrechtswijzer.be\/nieuwe-edpb-richtlijnen-dma-avg-op-komst-waarom-elke-belgische-onderneming-moet-opletten\/","url":"https:\/\/www.ictrechtswijzer.be\/nieuwe-edpb-richtlijnen-dma-avg-op-komst-waarom-elke-belgische-onderneming-moet-opletten\/","name":"New EDPB guidelines DMA &amp; AVG on the way: why every Belgian company should pay attention - ICT Lawyer's Guide","isPartOf":{"@id":"https:\/\/www.ictrechtswijzer.be\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.ictrechtswijzer.be\/nieuwe-edpb-richtlijnen-dma-avg-op-komst-waarom-elke-belgische-onderneming-moet-opletten\/#primaryimage"},"image":{"@id":"https:\/\/www.ictrechtswijzer.be\/nieuwe-edpb-richtlijnen-dma-avg-op-komst-waarom-elke-belgische-onderneming-moet-opletten\/#primaryimage"},"thumbnailUrl":"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2025\/10\/internet-search-engine-1433323_1280.jpg","datePublished":"2025-10-09T18:06:07+00:00","dateModified":"2025-10-09T21:32:18+00:00","description":"An in-depth analysis of the EDPB draft guidelines on the interaction between the DMA and AVG. Discover why these Big Tech rules set a precedent and pose a significant risk to any Belgian company.","breadcrumb":{"@id":"https:\/\/www.ictrechtswijzer.be\/nieuwe-edpb-richtlijnen-dma-avg-op-komst-waarom-elke-belgische-onderneming-moet-opletten\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.ictrechtswijzer.be\/nieuwe-edpb-richtlijnen-dma-avg-op-komst-waarom-elke-belgische-onderneming-moet-opletten\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.ictrechtswijzer.be\/nieuwe-edpb-richtlijnen-dma-avg-op-komst-waarom-elke-belgische-onderneming-moet-opletten\/#primaryimage","url":"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2025\/10\/internet-search-engine-1433323_1280.jpg","contentUrl":"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2025\/10\/internet-search-engine-1433323_1280.jpg","width":1280,"height":854},{"@type":"BreadcrumbList","@id":"https:\/\/www.ictrechtswijzer.be\/nieuwe-edpb-richtlijnen-dma-avg-op-komst-waarom-elke-belgische-onderneming-moet-opletten\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.ictrechtswijzer.be\/"},{"@type":"ListItem","position":2,"name":"Nieuwe EDPB richtlijnen DMA &amp; AVG op komst: waarom elke Belgische onderneming moet opletten"}]},{"@type":"WebSite","@id":"https:\/\/www.ictrechtswijzer.be\/#website","url":"https:\/\/www.ictrechtswijzer.be\/","name":"ICT Lawyer","description":"Lawyers in IP, AI, IT, privacy &amp; media","publisher":{"@id":"https:\/\/www.ictrechtswijzer.be\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.ictrechtswijzer.be\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Organization","LegalService"],"@id":"https:\/\/www.ictrechtswijzer.be\/#organization","name":"ICT Legal Guide","alternateName":"ICT Rechtswijzer, kennisplatform van Everest Advocaten","url":"https:\/\/www.ictrechtswijzer.be\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.ictrechtswijzer.be\/#\/schema\/logo\/image\/","url":"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2018\/08\/joris-deene-auteursrecht-in-een-digitale-omgeving-1-638.jpg","contentUrl":"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2018\/08\/joris-deene-auteursrecht-in-een-digitale-omgeving-1-638.jpg","width":638,"height":479,"caption":"ICT Rechtswijzer"},"image":{"@id":"https:\/\/www.ictrechtswijzer.be\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/be.linkedin.com\/company\/everest-law","https:\/\/www.everest-law.eu\/"],"description":"Knowledge platform of the Intellectual Property, IT Law, AI Law, Data Protection, and Media Law department at Everest Advocaten, led by Joris Deene, Esq.","parentOrganization":{"@type":"LegalService","name":"Everest Advocaten","url":"https:\/\/www.everest-law.eu","address":{"@type":"PostalAddress","streetAddress":"Bollebergen 2A bus 20","postalCode":"9052","addressLocality":"Gent","addressCountry":"BE"}}},{"@type":"Person","@id":"https:\/\/www.ictrechtswijzer.be\/#\/schema\/person\/29025dc007e8d33a89422580a534d685","name":"Joris Deene","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/7073c8d7ef4db19fbc2d462ac2571a2b0a3e5c89329cba99b4d3caf0bcd7cfc1?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/7073c8d7ef4db19fbc2d462ac2571a2b0a3e5c89329cba99b4d3caf0bcd7cfc1?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/7073c8d7ef4db19fbc2d462ac2571a2b0a3e5c89329cba99b4d3caf0bcd7cfc1?s=96&d=mm&r=g","caption":"Joris Deene"},"description":"Mr. Joris Deene is a partner at Everest Attorneys and heads the department of intellectual property, IT law, AI law, data protection, and media law. ICT Legal Guide is that department\u2019s knowledge platform. Joris publishes and teaches on copyright law, trademark law, software law, the GDPR, the AI Act, the DSA, and media law.","sameAs":["https:\/\/www.linkedin.com\/in\/joris-deene-5144096\/"],"honorificPrefix":"Mr.","knowsAbout":["intellectuele eigendom","auteursrecht","merkenrecht","IT-recht","AI-recht","gegevensbescherming","AVG","mediarecht","digitaledienstenverordening","AI-verordening"],"knowsLanguage":["Nederlands","Engels","Frans"],"jobTitle":"Advocaat-partner, hoofd departement intellectuele eigendom, IT-recht, AI-recht, gegevensbescherming en mediarecht","worksFor":"Everest Advocaten","url":"https:\/\/www.ictrechtswijzer.be\/en\/author\/joris-deene\/"}]}},"_links":{"self":[{"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/posts\/100423","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/comments?post=100423"}],"version-history":[{"count":0,"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/posts\/100423\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/media\/100424"}],"wp:attachment":[{"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/media?parent=100423"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/categories?post=100423"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/tags?post=100423"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}