{
  "schema_version": 1,
  "lang": "en",
  "page_type": "guide",
  "source_file": "conformite-site-ia-belgique-en.html",
  "context_url": "https://hebora.be/contexts/conformite-site-ia-belgique-en.en.json",
  "url": "https://hebora.be/conformite-site-ia-belgique-en.html",
  "title": "AI-built website compliance in Belgium | Hebora",
  "meta_description": "AI-built website in Belgium: GDPR, cookies, legal notices, security, accessibility, risks and a technical audit backed by evidence Check the practical steps.",
  "h1": "AI-built website: what still needs checking in Belgium",
  "lead_paragraph": "An AI tool can build the website. It does not automatically know your data, trackers, contracts or sector-specific duties. Your responsibility does not disappear with the prompt.",
  "structured_data_types": [
    "Article",
    "Organization",
    "ImageObject",
    "GovernmentOrganization",
    "WebPage",
    "CreativeWork",
    "BreadcrumbList",
    "ListItem"
  ],
  "entities_mentioned": [
    {
      "name": "Hebora",
      "type": "Organization"
    },
    {
      "name": "Belgian Data Protection Authority",
      "type": "GovernmentOrganization"
    },
    {
      "name": "FPS Economy Belgium",
      "type": "GovernmentOrganization"
    },
    {
      "name": "European Union",
      "type": "Organization"
    }
  ],
  "headings": [
    {
      "level": 2,
      "text": "No, an AI-generated website is not compliant by default"
    },
    {
      "level": 2,
      "text": "What the website owner must decide"
    },
    {
      "level": 2,
      "text": "Risks differ and sanctions are not automatic"
    },
    {
      "level": 2,
      "text": "What Hebora checks and delivers"
    },
    {
      "level": 2,
      "text": "Verified official sources"
    },
    {
      "level": 2,
      "text": "Get a risk map of your website"
    },
    {
      "level": 2,
      "text": "Continue the review"
    },
    {
      "level": 3,
      "text": "Lovable Cloud and GDPR: who is responsible for what in Belgium?"
    },
    {
      "level": 3,
      "text": "Cookie banner in Belgium: what must be blocked before consent"
    },
    {
      "level": 3,
      "text": "AI chatbot on a Belgian website: what must you disclose and check since 2 August 2026?"
    }
  ],
  "sections": [
    {
      "heading": "No, an AI-generated website is not compliant by default",
      "intro": "The website owner must still check business disclosures, legal grounds, notices to individuals, cookies, security, supplier contracts and — when applicable — e-commerce and accessibility rules. The platform helps build; it does not make those decisions for you."
    },
    {
      "heading": "What the website owner must decide",
      "intro": "The website must clearly identify who operates the business. The Belgian FPS Economy lists information including identity, address, contact details, company number and, where relevant, VAT number and details for regulated professions."
    },
    {
      "heading": "Risks differ and sanctions are not automatic",
      "intro": "For certain infringements, the GDPR sets a ceiling of €20 million or 4% of total worldwide annual turnover, whichever is higher. Article 83 still requires a case-by-case assessment: nature, severity, duration, cooperation and corrective action matter."
    },
    {
      "heading": "What Hebora checks and delivers",
      "intro": "Hebora can correct product behaviour and prepare the facts. Final legal choices about a legal ground, retention period or sensitive clause belong with the appropriate professional."
    },
    {
      "heading": "Verified official sources",
      "intro": "Sources checked on 15 August 2026."
    },
    {
      "heading": "Get a risk map of your website",
      "intro": "Hebora maps disclosures, data, trackers, access, suppliers and visible gaps, then delivers a prioritised correction plan with evidence."
    },
    {
      "heading": "Continue the review",
      "intro": "Lovable’s DPA generally describes the customer as controller and Lovable as processor for data handled on the customer’s behalf. The customer still configures the app, informs users, chooses data and integrations, and handles requests to exercise data rights."
    }
  ],
  "proof_points": [
    {
      "label": "Identity, data, cookies, security, commerce and accessibility.",
      "value": "6 surfaces"
    },
    {
      "label": "GDPR ceiling for certain infringements; never an automatic tariff.",
      "value": "€20m / 4%"
    },
    {
      "label": "Belgian maximum stated for the most serious accessibility breaches, subject to conditions.",
      "value": "€200,000 / 6%"
    },
    {
      "label": "Inventory, network captures, configuration and tested corrections.",
      "value": "Evidence"
    }
  ],
  "internal_links": [
    {
      "label": "Home",
      "url": "https://hebora.be/en.html"
    },
    {
      "label": "SEO & GEO in Belgium",
      "url": "https://hebora.be/seo-bruxelles-en.html"
    },
    {
      "label": "Map my website",
      "url": "https://hebora.be/diagnostic-en.html"
    },
    {
      "label": "Lovable Cloud and GDPR: who is responsible for what in Belgium? Lovable’s DPA generally describes the customer as controller and Lovable as processor for data handled on the customer’s behalf. The customer still configures the app, informs users, chooses data and integrations, and handles requests to exercise data rights.",
      "url": "https://hebora.be/lovable-cloud-rgpd-belgique-en.html"
    },
    {
      "label": "Cookie banner in Belgium: what must be blocked before consent The Belgian Data Protection Authority requires prior consent for cookies that are not strictly necessary, a genuine choice, refusal as accessible as acceptance and easy withdrawal. Necessary cookies may operate without consent, but they must genuinely be necessary.",
      "url": "https://hebora.be/banniere-cookies-rgpd-belgique-en.html"
    },
    {
      "label": "AI chatbot on a Belgian website: what must you disclose and check since 2 August 2026? Article 50 of the AI Act requires providers to design direct-interaction systems so people are informed that they are interacting with AI, unless that is obvious. The website owner must also check its own duties as deployer and data controller.",
      "url": "https://hebora.be/transparence-chatbot-ia-belgique-en.html"
    }
  ],
  "open_graph_image": "https://hebora.be/images/legal/conformite-site-ia-belgique-og.png",
  "images": [
    {
      "src": "https://hebora.be/images/legal/conformite-site-ia-belgique-1536.webp",
      "alt": "Small-business owner and adviser reviewing an AI-built website together in Brussels"
    }
  ],
  "answer_summary": "The website owner must still check business disclosures, legal grounds, notices to individuals, cookies, security, supplier contracts and — when applicable — e-commerce and accessibility rules. The platform helps build; it does not make those decisions for you.",
  "services_provided": "Hebora maps disclosures, data, trackers, access, suppliers and visible gaps, then delivers a prioritised correction plan with evidence.",
  "source_urls": [
    "https://eur-lex.europa.eu/eli/reg/2016/679/oj",
    "https://news.economie.fgov.be/203681-informations-obligatoires-sur-le-site-web-de-votre-entreprise/",
    "https://economie.fgov.be/sites/default/files/Files/Entreprises/guidelines-obligations-information-dans-le-cadre-du-e-commerce.pdf",
    "https://news.economie.fgov.be/251714-directive-sur-l-accessibilite-un-pas-en-avant-pour-une-societe-plus-inclusive/",
    "https://www.autoriteprotectiondonnees.be/professionnel/themes/internet/cookies"
  ],
  "last_verified": "2026-08-15",
  "legal_boundary": "Hebora performs technical audits and corrections. This content is not legal advice, does not certify compliance and does not replace a lawyer or DPO when your situation needs legal interpretation."
}
