Version 1.0 of 20 September 2026. This version replaces all previous versions.
This notice describes how DECKER LAW handles personal data when you use this website, when you first contact us and when we handle matters that we accept in our own name. When we accept an engagement, we will, where necessary, provide additional information in the engagement confirmation about the specific processing involved in your matter.
1. Who is responsible
DECKER LAW BV, with its registered office at Itegembaan 101, 2590 Berlaar, Belgium, registered with the Crossroads Bank for Enterprises under number 0802.317.385, is the controller for the processing described in this notice. Please address questions and requests concerning personal data in writing to
We have not appointed a data protection officer. Processing client data by an individual legal practice is not considered large-scale processing, as recital 91 GDPR expressly states, so the appointment requirement under Article 37 GDPR does not apply to us. We handle your questions ourselves.
We work for our own clients and also for professional clients, including law firms. When we work on a matter on behalf of, or in cooperation with, such a professional client, that client determines the purposes and means of the processing. It is then the controller and its own privacy notice applies. In that case, we act on its instructions. Requests concerning such data should be addressed to that professional client. As a rule, we cannot disclose the existence or contents of such matters, given the confidentiality obligations that apply.
2. What data we process and why
When you contact us, we process your name, email address, the subject and contents of your message, and any further information you provide in correspondence. If a matter follows, we also process the data necessary to handle it, including identification and contact details, information about the relevant facts and documents, and data concerning opposing parties and other people involved.
Keep your initial message brief. Do not yet send identity documents, medical information, information about criminal offences or complete case files. Sending such documents does not, in itself, constitute consent to unrestricted use, and we may delete unsolicited documents.
We process these data for the following purposes and on the following legal bases.
Assessing and answering your enquiry. When you wish to enter into a contract with us, we process what is necessary for that purpose under Article 6(1)(b) GDPR. For general questions and contact on behalf of a business, we rely, where more appropriate, on our legitimate interest in conducting professional communications and handling enquiries, under Article 6(1)(f) GDPR.
Handling an accepted matter. Performance of the engagement is based on Article 6(1)(b) GDPR where you are the client, and on Article 6(1)(f) GDPR where the data concern other people and the processing is necessary to pursue our client's interests.
Special categories of data and data concerning criminal offences. Where a matter contains health data or other special categories of data, we process them only insofar as necessary for the establishment, exercise or defence of legal claims, under Article 9(2)(f) GDPR. We process data relating to criminal convictions and offences within the limits of Article 10 GDPR and Article 10 of the Act of 30 July 2018, which permits, among other things, processing necessary to manage one's own disputes and, for lawyers, to defend their clients.
Avoiding conflicts of interest and defending our rights. We use limited identification and correspondence data to assess conflicts of interest, investigate abuse and establish, exercise or defend claims. This is based on our legitimate interests, balanced against your rights and freedoms, under Article 6(1)(f) GDPR.
Operating and securing the website. We process technical data, such as session data, IP address, time and error information, insofar as necessary to operate, secure and diagnose the website, on the basis of our legitimate interest in providing a reliable and secure service.
Legal obligations. Processing required by accounting, tax and other legal obligations is based on Article 6(1)(c) GDPR. We explain the specific obligation where it is relevant to your situation.
The mandatory fields in the contact form are needed to understand and answer your message. You are not required to use the form. Without sufficient information, we may be unable to handle your enquiry. The form does not subscribe you to marketing messages. We do not carry out commercial profiling and we do not sell data.
We may assume that the information you provide is accurate and complete. Please inform us of changes in good time so that we can keep our files accurate.
3. Data we do not receive from you directly
In a matter, we also process data received from others, for example from our client, a professional client instructing us, an opposing party or their counsel, an expert, or public sources and registers. These are data relevant to handling the matter.
We do not always inform those people individually. Article 14(5) GDPR provides for exceptions, including where providing the information is impossible or would involve a disproportionate effort, and where the data must remain confidential under a statutory duty of secrecy. We rely on those exceptions insofar as they apply.
4. Contacting us does not create an engagement
A message, an acknowledgement of receipt or an initial exchange does not mean that DECKER LAW has accepted your engagement, is representing your interests or is monitoring a deadline. This requires express confirmation of our involvement.
Until that confirmation has been given, we cannot guarantee that we are not already acting for another party in the same matter. We treat what you send us with appropriate discretion, but sending information does not, in itself, prevent us from assisting another party where no engagement has been established. We do not accept unsolicited case documents for safekeeping. We are not required to review, retain or return them, and we may delete them without keeping a copy. This provision does not limit your statutory data protection rights.
5. Who may receive data
Access within our office is limited to those who need the data for the stated purposes. Outside our office, data may be received by the following categories of recipients.
- Service providers working for us in hosting, email, storage, backup, security and office software. They act as processors and are bound by a processing agreement under Article 28 GDPR.
- Our external accountant and, where necessary, our auditor or tax adviser.
- External specialists, lawyers, notaries, experts or translators whom we involve in a matter in consultation with you or with our client.
- The professional client on whose instructions we are working on a matter.
- Our professional liability insurer and our own counsel, where a claim is made or can reasonably be anticipated.
- Courts, opposing parties and public authorities, insofar as handling the matter or a legal obligation requires this.
We disclose no more than is necessary for the relevant purpose. We do not sell data or make data available for third-party commercial purposes.
Our service providers generally process your data within the European Economic Area. Where a service provider may nevertheless have access from outside the European Economic Area, for example for technical support, this takes place on the basis of an adequacy decision by the European Commission or the standard contractual clauses adopted by the Commission, together with the accompanying safeguards, in accordance with Articles 44 to 49 GDPR. Information about the applicable mechanism is available on request.
6. How long we retain data
We retain data no longer than necessary for the purpose for which we obtained them, except where a legal obligation or a claim justifies longer retention.
Enquiries that do not lead to an engagement. These are retained until the enquiry has been dealt with and reasonably foreseeable follow-up has been completed, and are then deleted or anonymised. A limited record of your name, the opposing party's name and the nature of the matter is subsequently retained for as long as our office remains active. Without that record, we cannot rule out a conflict of interest when a later enquiry is received; this protects both you and our other clients.
Case data. These are retained while the matter is being handled and afterwards for as long as necessary in view of our liability, applicable limitation periods and statutory retention obligations. Documents subject to accounting and tax retention obligations are subject to the statutory ten-year period under Article 60 of the Belgian VAT Code, as amended by the Act of 20 November 2022 containing various tax and financial provisions.
Technical data. Session data serve only the current session. Security and error data are retained for as long as the relevant technical problem or incident and the necessary follow-up require.
Backups. Data deleted from our active systems may temporarily remain in secure backups. They are overwritten in the next cycle and are no longer used for the stated purposes in the meantime.
There is no general, unlimited retention period.
7. Security and confidentiality
We take appropriate technical and organisational measures under Article 32 GDPR, including access restrictions according to need, secure storage, encrypted connections and regular backups. Our staff and service providers are bound by confidentiality obligations. Matters that we handle for a law firm are also subject to the confidentiality obligations applicable to that firm.
Ordinary email is not encrypted against access by third parties. If you wish to send sensitive documents, we will agree on a more secure channel at your request. We cannot be responsible for the security of your own equipment, mailbox or network.
If a personal data breach occurs, we assess and handle it in accordance with Articles 33 and 34 GDPR.
8. Cookies and external content
This website uses only functional cookies necessary to provide the service you request, such as maintaining your session and language preference. Such strictly necessary cookies do not require prior consent under Article 10/2 of the Act of 30 July 2018, which, since 10 January 2022, has replaced the former rules in Article 129 of the Act of 13 June 2005 on electronic communications.
We do not place advertising trackers or visitor analytics cookies. Images and fonts are loaded from our own server. We do not use embedded external videos or maps.
If we later add non-essential cookies or external services, we will update this information beforehand and, where required, first obtain your consent. This notice does not itself constitute consent.
9. Your rights
Subject to the conditions in Articles 15 to 22 GDPR, you may request access, rectification, erasure and restriction of processing. Portability applies to data you have provided to us yourself, insofar as the processing is automated and based on your consent or on a contract, in accordance with Article 20 GDPR.
Where processing is based on a legitimate interest, you may object on grounds relating to your particular situation. We assess that objection and continue the processing only where there are compelling legitimate grounds overriding your interests, rights and freedoms, or where the processing relates to legal claims, in accordance with Article 21(1) GDPR. Where processing is based on consent, you may withdraw that consent without affecting the lawfulness of earlier processing.
Please send your request to
Your rights are subject to statutory limits. They must not adversely affect the rights and freedoms of others, including those of our clients and other people involved in a matter (Article 15(4) GDPR). Data subject to a statutory or professional duty of secrecy are not disclosed. Data that remain necessary to comply with a legal obligation or for the establishment, exercise or defence of legal claims are not erased (Article 17(3)(b) and (e) GDPR). For manifestly unfounded or excessive requests, we may, subject to the conditions in Article 12(5) GDPR, charge a reasonable fee or refuse the request. Requests are otherwise free of charge.
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you, within the meaning of Article 22 GDPR. We do use technical tools, including artificial intelligence applications, when preparing our work. Every substantive assessment is made by a legal professional who remains responsible for it. Our AI statement explains this.
You may lodge a complaint with the Belgian Data Protection Authority, Drukpersstraat 35, 1000 Brussels, or another competent supervisory authority, and you have the right to an effective judicial remedy under Article 79 GDPR. We kindly ask you to contact us first so that we can address your question. This notice does not restrict your right to complain.
10. Changes and status of this notice
When processing changes, we update this notice and provide additional information where necessary. A change does not grant retroactive consent or affect your statutory rights.
This notice informs you about our processing. It creates no obligations beyond those provided by law and by the contract concluded with you. The engagement confirmation and our general terms and conditions govern the contractual relationship, without prejudice to your statutory rights.
The content of this website is general information and does not constitute legal advice. This website may contain links to third-party websites. We have no control over those third parties' processing of personal data and bear no responsibility for it.
In the event of differences between language versions, the Dutch text prevails. This notice is governed by Belgian law.
Applicable legislation: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, OJ L 119 of 4 May 2016, pp. 1–88. Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data, Belgian Official Gazette, 5 September 2018.