Belgium’s New Private Investigation Act: What Organisations Need to Know Before Starting an Internal Investigation

Partnerblog

Internal investigations have become increasingly formalised and strategically important within corporate governance and compliance frameworks. Organisations investigate allegations of fraud, conflicts of interest, data misuse, breaches of internal policy, unfair competition, expense irregularities and many other workplace issues. These investigations often require the collection and analysis of data, including emails, chat messages, HR records, access logs, financial data, laptops and/or mobile phone data, document repositories and other digital evidence.

In Belgium, the legal framework for these investigations has changed significantly. The new Belgian Private Investigation Act (Wet van 18 mei 2024 tot regeling van de private opsporing (WPO) or loi du 18 mai 2024 réglementant la recherche privée (LRP)) of 2024 replaces the older 1991 law on private detectives. This is not just a technical legal update. It changes the way organisations should think about internal investigations. The main message is clear: internal investigations can no longer be treated as informal fact-finding exercises. They need to be properly scoped, documented, proportionate and compliant with both the Private Investigation Act and data protection principles. In this article, we take a closer look at the key changes introduced by the Private Investigation Act and the practical implications for organisations conducting internal investigations.

1. From Private Detectives to Private Investigation Activities

The most important change is the shift from regulating private detectives as a profession to regulating private investigations activities. The 1991 law focused mainly on private detectives: individuals who, regularly and for payment, gathered information about people, their behaviour, assets, status or other personal matters, or collected evidence for disputes. In practice, the law was mainly associated with the classic model of an external private detective being hired to investigate a person or situation.

The 2024 Act adopts a different approach. Rather than focusing on who performs the investigations, it focuses on what activities are carried out. As a result, internal investigations conducted by HR, legal, compliance, audit or another internal function may fall within the scope of the new act where information is gathered about individuals or facts for use in a dispute, disciplinary matter or other internal conflict. This may be particularly relevant for investigations into fraud, misconduct, theft, conflicts of interest, misuse of company systems, unfair competition, sick leave abuse or dismissal for serious cause. Organisations should therefore take the new Act seriously as it imposes specific requirements on how investigations are conducted.

2. Licensing and Authorisation: An Important but Nuanced Requirement

The new Act introduces licensing and authorisation requirements for private investigation companies and internal investigation departments (or individual investigators). In general, the actors involved in investigations will need a licence from the Ministry of Interior to lawfully conduct their investigation. The licence is granted for a renewable five-year period and involves suitability and integrity-type conditions.

It is therefore crucial for legal teams within organisations to determine whether a particular employee or department needs to be licensed, as their activities could fall under the scope of the Act.

3. The Need for an Internal Investigation Policy

The Act requires organisations to regulate investigations through internal rules or policies. Investigations must be clearly permitted and regulated through an internal policy or similar instrument (such as work rules, a collective bargaining agreement or a works council decision). 

Employers have until 16 December 2026 to comply with this policy requirement. After that deadline, if an organisation does not have a compliant policy in place, it may risk being unable to conduct certain internal investigations lawfully, and investigation findings may become unusable or vulnerable to challenge.

This is one of the most important practical points for organisations. Investigation readiness should not start when an incident occurs. By then, it may be too late to build the correct framework. Organisations should prepare in advance by adopting policies that clearly explain when investigations may be opened, who may authorise them, who may conduct them, what methods may be used, how data may be collected, how evidence is handled, how employees or other data subjects may be informed, and how reports are prepared and retained.

A clear investigation policy also helps ensure consistency. It reduces the risk that investigations are handled differently depending on the department, manager or urgency of the situation. In addition, it demonstrates that the organisation has considered proportionality, privacy and procedural safeguards before taking investigative steps.

4. Stronger Procedural and Documentation Requirements

The new Act makes investigations more formal. The new Act imposes procedural obligations such as maintaining investigation documentation, keeping records of investigative steps, preparing written minutes of interviews, maintaining an investigation file, complying with information or consent requirements where applicable, and preparing a final report within defined timeframes.

Before an investigation begins, organisations should define the purpose of the investigation, the legal basis, the relevant custodians, the systems in scope, the time period, the data sources, the review approach and the reporting objective. During the investigation, steps should be recorded and evidence should be handled consistently. At the reporting stage, conclusions should be tied to relevant and lawfully obtained evidence.

5. Sensitive Data: A Clear Compliance Risk

The new Act also draws clear boundaries around certain categories of information. For instance, investigations into a person’s health, political beliefs or trade union affiliation are expressly prohibited.

This point is particularly important in employment investigations. An organisation may have a legitimate reason to investigate suspected misconduct, but the investigation can become legally risky if it drifts into protected areas. For example, investigations involving employee representatives, workplace activism, trade union activities or employee health-related issues require particular care.

The practical lesson is that organisations must define the scope of the investigation carefully before collecting data. Investigators should ask what question they are trying to answer and what information is genuinely necessary to answer it. If sensitive or prohibited information may appear in the dataset, safeguards may be needed, such as targeted collection, exclusion terms, restricted review access, ring-fencing, escalation protocols and careful reporting rules.

6. GDPR and Data Protection Are Central

When an investigation is lawfully in scope, organisations must still comply with modern expectations around privacy and data protection. Internal investigations often involve personal data, including data contained in emails, chat messages, HR files, access logs, expense data, device images, document metadata and other business records that relate to identifiable individuals. Organisations therefore need to consider both the Private Investigation Act and data protection obligations when planning an investigation.

This means that the principles of proportionality and data minimisation should shape the entire investigation strategy. Organisations should ask which custodians are relevant, which systems need to be collected, what date range is necessary, which search terms or filters reduce unnecessary exposure, whether certain categories of data should be excluded, who may access the data, how long the data will be retained and how the final report will be limited to what is necessary

7. Exclusions from Scope: Useful but Not Always Simple

The Act does not apply to every activity that looks like an investigation. The Private Investigation Act notes that certain professional activities are excluded, including activities of HR, lawyers, notaries, bailiffs, journalists, auditors and statutory auditors. Some cybersecurity incident identification and analysis activities are also excluded.

Activities carried out to fulfil legal obligations may also be excluded, such as investigations in the framework of whistleblower reports or psychosocial-risk complaints handled by the competent prevention adviser. However, the position may become more complex if the results are later used outside that legal-obligation context, for example in disciplinary or dismissal proceedings.

This is a key practical nuance. Organisations should not assume that a matter is outside the scope simply because it began as a whistleblower review, audit, cybersecurity issue or legally required process. If the output is later used to protect the company’s interests in a dispute or internal conflict, the Private Investigation Act will have to be taken into consideration.

As there is currently limited practical experience, enforcement guidance and case law under the new regime, the precise boundaries of some exclusions remain uncertain. Greater clarity will likely emerge over time. Until then, organisations should adopt a cautious approach and ensure that relevant stakeholders are aware of the legal assessments and balancing exercises that may need to be carried out before, during and after an investigation. In many cases, the most prudent approach will be to actively consider the applicability of the Act rather than assume that an exclusion automatically applies.

8. Evidentiary Risk: The Process Matters

The new Act has significant consequences. Non-compliance can lead to regulatory consequences, nullity of investigative acts and exclusion or disregard of evidence in litigation.

This does not necessarily mean that every breach will automatically invalidate an entire investigation. The result may depend on the nature of the breach, the evidence affected, the role of the report and the assessment of the court. But the direction is clear: procedural failures can seriously damage the evidentiary value of the investigation.

For organisations, this means the investigation process itself becomes part of the evidentiary record. It is not enough to find relevant facts. The company must also be able to show that those facts were obtained lawfully, proportionately and in line with the applicable framework

9. What Organisations Should Consider Before Starting an Investigation

  • Is the matter potentially within the scope of the Private Investigation Act?
  • Who is conducting the investigation?
  • Is a licence or authorisation required?
  • Is there a compliant investigation policy?
  • Is the scope proportionate?
  • Could sensitive information be involved?
  • How will the investigation be documented?
  • How will evidence be collected, handled and retained?

FORCYD helps organisations prepare for investigations and conduct them in a compliant way. This includes support with investigation scoping, data strategy, collection planning, review workflows, documentation, evidence handling, reporting structures and the establishment of internal investigation policies. With the right framework in place, organisations can reduce legal risk, protect employee privacy and improve the reliability of their investigation findings. FORCYD conducts their activities in accordance with the transitional provision provided in Article 177 of the Act.

Authors:

Damien van Outryve d’Ydewalle and Max Schuster

Delen