
Timelex
INPLP member firm · Brussels, Belgium
Time.lex is currently supporting various cloud related projects of the European Commission, including the drafting of a Cloud Code of Conduct, studies on cross border data flows in the digital single market and the role of self- and co-regulation in the cloud market, and a support study on emerging issues of data ownership, interoperability, (re)usability and access to data, and liability. Hans Graux is an IT lawyer at the Brussels based law firm time.lex (www.timelex.eu), which specialises in information and technology law in the broadest sense. The team is internationally recognized, being both a Legal 500 Top Tier firm in Information Technology, and a Chambers Europe Recommended Firm for TMT - Information Technology. Hans graduated in Law in 2002, and obtained a complementary degree in IT in 2003. He worked as a research assistant at the Catholic University of Louvain, before becoming a lawyer at the bar of Brussels in 2005. In July 2007, he co-founded the IT law firm time.lex. He has participated in a large number of international ICT policy studies, primarily for the European Commission and various European Agencies. Recent work for the Commission has included projects focused on data protection, eSignatures, electronic identity management, cloud computing and information security. Furthermore, he is a member of the ICT Committee of the Council of Bars and Law Societies of Europe (CCBE), and Member of the ICT Committee of the Order of Flemish Bars.
Representatives

Hans Graux
partner
Contact
Publications
- Money Control in Belgium – your bank account speaks louder than words, and the tax authorities are listeningWhen looking for potential fiscal fraud cases, tax authorities have only a limited amount of data sources available to them. But what if they could proactively start looking into your bank accounts, even if you’ve done nothing wrong? A Belgian law, dubbed “Money Control” by its critics, aims to pioneer in controversial terrain.5 March 2026
- Does the GDPR trump the Bible? Probably not, but it might trump religious administrationDepending on where you live, religious ceremonies can trigger a certain degree of administrative follow-up. In Belgium – like in many other Member States - parishes of the Catholic Church keep baptismal records indicating who underwent this particular sacrament. But what if a baptised person no longer wants their records to be kept? A recent decision from the Belgian data protection authority on the right to be forgotten may have far reaching consequences.23 April 2024
- Careful where you point that thing: the right to be forgotten is picky when it comes to targetingThe right to be forgotten is one of the most frequently referenced and misunderstood parts of the GDPR. Like most data subject rights, its actual value is very relative and varies from case to case. A recent decision from the Belgian data protection authority reminds us that, among many other factors, the role of the data controller matters a lot.7 October 2022
- Will co-regulation finally work? The first EU level codes of conduct are approved under the GDPR in Belgium and FranceLike the old Data Protection Directive, the GDPR allows the private sector to draft codes of conduct to help demonstrate compliance with the GDPR. They’ve never been too succesful, with only one such code being approved at the EU level in 25 years of European data protection law. Last week, two new ones joined the playing field, both focused on cloud computing.28 May 2021
- No GDPR fines for public sector bodies at all? No discrimination, and no problem!The GDPR explicitly allows Member States to determine whether and to what extent administrative fines can be imposed on public authorities and public sector bodies. In Belgium, the public sector has been exempted from fines entirely. The Constitutional Court has now explicitly affirmed that this is not an unlawful discrimination.22 February 2021
- 600.000 EUR fine to Google Belgium for misapplying the right to be forgottenThe right to be forgotten is one of the more complex rights in the GDPR, requiring a careful balancing of principles and interests. In a recent case before the Belgian data protection authority, Google Belgium was accused of interpreting the right too narrowly. The authority agreed, and imposed a significant fine.19 November 2020
- The Belgian data protection authority fines a data controller 50,000 EUR for appointing a DPO with a potentially conflicting positionIt is not too uncommon for a single person to be in charge of general compliance in an organisation, and to also act as its DPO. Is that in line with the GDPR's requirements for independence of the DPO? The Belgian DPA says no, and issued a fine to the data controller.6 May 2020
- The Belgian data protection authority bans the use of private sector logins as an access condition to public sector websitesThe Belgian tax authorities maintain an online repository called FisconetPlus, on which tax payers can find key information and guidance on taxation questions. However, the information was only available after loggin on to the portal with a Microsoft user account. Unacceptable and in violation of the GDPR, says the Belgian data protection authority.9 May 2019
Join the network
Applications from qualified privacy practices are reviewed individually by the INPLP board.