#EUDATA26
The European Data Protection and Privacy Conference takes place annually and is a key fixture in the Brussels calendar, fostering lively and interactive discussions on the future of data protection regulation. Attracting more than 200 participants each year, it has become a must-attend event for privacy professionals and other stakeholders in the data protection sector, bringing together top-level speakers and delegates from across industries alongside senior EU and international policymakers and regulators.
Following the European Commission’s release of the Digital Omnibus Package, this year’s conference will explore the future of Europe’s digital and data protection framework. It will examine the extent to which the GDPR can be refined to support an innovative, competitive, and rights-preserving digital future, while placing individuals at the heart of Europe’s evolving digital rulebook through greater coherence, fairness, and trust. The conference will further explore the complex interplay between competition policy and data privacy, highlighting the need to break down regulatory silos and will also take a global view on data protection, examining how regions can cooperate in an increasingly fragmented regulatory landscape. In addition, discussions will address the role of data privacy in the digital transformation of public services, as well as how data, privacy, AI, and privacy-enhancing technologies can underpin trustworthy innovation in the AI era.
Should you wish to find out more about speaking and sponsorship opportunities at this year’s event, please contact [email protected]

Commissioner for Democracy, Justice, the Rule of Law and Consumer Protection European Commission






Michael McGrath, Commissioner for Democracy, Justice, the Rule of Law and Consumer Protection, European Commission Michael McGrath’s task is to uphold and strengthen our core values and principles that underpin our Union, our societies and our economies. He works to ensure that citizens can have confidence in state power being exercised fairly and objectively.
He is responsible for:
Michael McGrath is also in charge of justice and consumer protection. His task is to ensure that rights are defended, corruption is punished, and contracts are enforced.
He is responsible for:
Commissioner for Democracy, Justice, the Rule of Law and Consumer Protection
European Commission
Martynas Dobrovolskis, Vice-Minister of Justice, Lithuania Bio to follow.
Vice-Minister of Justice
Lithuania
Christel Schaldemose, Vice-President, European Parliament Christel Schaldemose has been a Member of the European Parliament since 2006. She currently serves as one of the Parliament’s Vice-Presidents in its 10th legislative term. Her parliamentary work has consistently focused on consumer protection, particularly in the context of digital transformation and the internal market.
As the EP’s lead rapporteur for the Digital Services Act (DSA), she played a pivotal role in shaping the EU’s first-ever regulation targeting online platforms. Her efforts have focused on ensuring greater transparency and accountability, tackling disinformation, and protecting consumers from unsafe products—especially those sold by third-country sellers.
In the 2024-2029 term, her priorities include ensuring the effective implementation of the DSA and other digital regulatory frameworks. She will also continue to advocate for stronger protections for minors and young users online.
Vice-President
European Parliament
Marina Kaljurand, Member, European Parliament Kaljurand serves as the 1st Vice-Chair of the LIBE (Civil Liberties, Justice and Home Affairs) committee in the European Parliament. In LIBE committee she has focused on digital policy, and there she has been appointed Rapporteur of the Digital Omnibus Regulation. This is Kaljurand’s second mandate in the Parliament. She is the Chair of the Steering Committee of the European Internet Forum (EIF), from October 2024.
Kaljurand was a member of the UN Advisory Board on Disarmament Matters (2020 – 2023).
Kaljurand was a member of the UN Secretary General’s High Level Panel on Digital Cooperation (2018-2019). She chaired the Global Commission of the Stability of Cyberspace (2017-2019).
Kaljurand started in the Estonian Foreign Service in 1991 and held several prominent positions, including Estonian Ambassador to the State of Israel, the Russian Federation, United States of America, Canada, Mexico and Kazakhstan.
Kaljurand has served twice as the Estonian National Expert at the United Nations Group of Governmental Experts on Developments in the Field of Information and Telecommunications in the Context of International Security (GGE), in 2014-2015 and in 2016-2017.
Marina Kaljurand graduated cum laude from the Tartu University (1986, LLM). She has a professional diploma from the Estonian School of Diplomacy (1992) and MA from the Fletcher School of Law and Diplomacy, Tufts University (F95).
Member
European Parliament
Leontina Sandu, Head of Unit, Interoperability & Digital Government, DG DIGIT, European Commission Bio to follow.
Head of Unit, Interoperability & Digital Government, DG DIGIT
European Commission
Michael König, Head of Unit, Digital Platforms II, Markets and Cases VI: Digital Platforms, DG COMP, European Commission Mr. Michael KÖNIG is Head of Unit in the European Commission’s Directorate-General for Competition leading one of the units responsible for the implementation of the Digital Markets Act (DMA).
Before taking up this position in DG COMP, Mr König was advisor for platform regulation in DG CNECT and front line negotiator for the Digital Markets Act in the legislative process. He also served several years as Deputy Head of Unit in the European Commission’s Directorate-General for Internal Market, Industry, Entrepreneurship and SMEs (GROW) where he was primarily responsible for B2B relations regarding online platforms and negotiated the Regulation on fairness in platform-to-business relations (P2B Regulation).
Mr König joined the European Commission in 2001 in the Directorate-General for Competition. His assignments included a position as advisor to Directorate-General’s top management and a secondment to the OECD, before he joined the Internal Market Directorate-General in 2008. There he held positions in various policy areas including intellectual property and financial services.
Before joining the Commission, Mr. König worked for several years in the German Competition Authority and an international law firm.
Mr. König graduated in Law and Economics, and holds a PhD degree in Competition Law.
Head of Unit, Digital Platforms II, Markets and Cases VI: Digital Platforms, DG COMP
European Commission
Louisa Klingvall, Acting Head of Unit, International Affairs and Data Flows, DG JUST, European Commission Bio to follow.
Acting Head of Unit, International Affairs and Data Flows, DG JUST
European Commission
Karolina Mojzesowicz, Deputy Head of Unit, Data Protection, DG JUSTICE, European Commission Karolina Mojzesowicz is the Deputy Head of Unit of the unit responsible for data protection at the European Commission (DG Justice and Consumers). She was one of the Commission’s representatives in the interinstitutional negotiations with Parliament and Council on the General data Protection Regulation (GDPR). She is now responsible for its implementation in the EU.
Mrs Mojzesowicz previously served as a member of the European Commission’s Legal Service, focusing on EU Competition law and International Trade law. In that capacity, she represented the Commission in numerous cases before the European Courts and before the WTO panels and Appellate Body. Mrs Mojzesowicz studied law in Poland, the Netherlands and Germany where she obtained her PhD in 2001.
Deputy Head of Unit, Data Protection, DG JUSTICE
European Commission
Joanna Jużak, Legal Officer, AI Office, DG CNECT, European Commission Bio to follow.
Legal Officer, AI Office, DG CNECT
European Commission
Kari Laumann, Head of Section, Research, Analysis and Policy, Norwegian Data Protection Authority (NDPA); Program Manager, Regulatory Sandbox for Privacy and AI Kari Laumann is Head of Section for Research, Analysis, and Policy at the Norwegian Data Protection Authority (Datatilsynet). She has been a leading figure in developing the Regulatory Sandbox for Privacy, Innovation and Digitalisation, a key initiative under Norway’s National Strategy for AI aimed at fostering innovative and responsible AI development. With a background in sociology, Kari has extensive experience in privacy and technology policy, including her tenure as VP for privacy in Telenor’s Asian operations and as an advisor to the Norwegian Parliament through the Board of Technology. Her work bridges the intersection of data protection, AI, and public policy, making her a leading voice in ethical tech governance.
Head of Section, Research, Analysis and Policy
Norwegian Data Protection Authority (NDPA)
Program Manager
Regulatory Sandbox for Privacy and AI
Fernando de Pablo Martín, Director General, Digital Office, City of Madrid Telecommunication Engineer with an extensive professional background in both the public and private sectors. He has over a decade of experience in the private sector, specializing in telecommunications and urban and environmental control systems. Since 1993, he has been employed at the Spanish Tax Agency, where he has held a range of positions and led key initiatives, including the implementation of the Law on electronic access to public services.
In addition, he has occupied senior roles within public administration, serving as Director General for the Promotion of Electronic Administration and Secretary General of Digital Administration. From 2017 to 2018, he served as the President of the Public Society for the Management of Innovation and Tourism Technologies (SEGITTUR). He currently holds the position of Director General of the Digital Office of Madrid, where he leads the city’s digital transformation and data & AI strategy.
Director General, Digital Office
City of Madrid
Zdravko Vukić, Deputy Chair, EDPB Zdravko Vukić graduated from the Faculty of Law at the University of Osijek and holds a master’s degree in public administration. He further pursued studies in business economy and globalization in Zagreb, earning a master’s degree in economics from Libertas International University. Zdravko also possesses an internationally accredited ISO/IEC 27001:2022 Lead Auditor certificate in information security management systems, specializing in information security, cyber security, and privacy protection. Currently, he is finalizing his postgraduate studies with a thesis on Technical and Organizational Measures and Data Security.
From 2005 to 2016, he served as the Chief Human Resources Officer overseeing the organization’s employees and legal affairs. Additionally, between 2008 and 2016, he held the position of Data Protection Officer. Between 2016 and 2020, Zdravko held the role of Assistant Minister at the Ministry of Construction and Physical Planning, where he supervised the operations of the Directorates for Inspection Affairs, Supervision, and Information System Development.
In 2020, he was appointed as the Director of the Croatian Personal Data Protection Agency, and in February 2024 he was re-elected for another four-year term as director. Zdravko is a guest lecturer on personal data protection at various faculties in Croatia and is a member of the National Cybersecurity Council. He has been actively involved in the European Union initiative for institutional cooperation between Public Administrations of EU Member States and non-EU countries, focusing on aligning national legislation with EU regulations in personal data protection.
Under his guidance, the Croatian Personal Data Protection Agency organized the Spring Conference of the European Supervisory Authorities in 2022, a significant platform for cooperation among European data protection regulatory bodies. He played a key role in the implementation of the EU-funded projects ARC I and ARCII aimed to support SMEs in aligning with the GDPR.
Deputy Chair
EDPB
Ilias Chantzos, Global Privacy Officer and Head of EMEA Government Affairs, Broadcom Ilias Chantzos is Broadcom’s Global Privacy Officer and the Head of Government Affairs programmes for Europe, Middle East & Africa (EMEA). Chantzos leads the global privacy programme of Broadcom across the company’s multiple business units and regions. He also represents Broadcom before government bodies, national authorities and international organisations in EMEA advising on public policy issues.
Before joining Broadcom, Chantzos spent almost 16 years in various government affairs and legal roles in Symantec. During his last post with Symantec, he was in charge of the Government Affairs for the EMEA and the Asia Pacific Japan regions and the Global Advisor for Critical Infrastructure Protection and Privacy.
Before joining Symantec in 2004, Chantzos worked as legal and policy officer in the Directorate General Information Society of the European Commission focusing on information security policy. He covered the Council of Europe Cybercrime Convention and the Framework Decision on Attacks against Information Systems. In addition, he worked on a number of EU legislative initiatives relevant to information society and security, including directives on Privacy of Electronic Communications, the Data Retention Directive and the European Network and Information Security Agency (ENISA). He also represented the European Commission in various international debates and conferences.
Chantzos holds a law degree from Aristotle University, a Master degree in Computers and Communication Law from Queen Mary College, University of London and a Master in Business Administration from Solvay Business School. He has also completed executive education at Lee Kuan Yew School of Public Policy in Singapore and at the JFK School of Government in Harvard. Chantzos is a member of the Athens Bar Association. He served as Chairman of the Executive Board of TechAmerica Europe. He also served for four terms as Chairman of the European Policy Council of the Business Software Alliance (BSA). He has represented Symantec at the NATO Industry Cooperation Platform and he has been a member of the Advisory Board of the European Network and Information Security Agency (ENISA) from 2006 until 2020. He is also a member of Europol’s European Cybercrime Center (EC3) Advisory Board. Chantzos is a member of the Young Global Leaders 2014 class of the World Economic Forum. He speaks English, Greek, Dutch and German.
Global Privacy Officer and Head of EMEA Government Affairs
Broadcom
Yoon Jeong Choi, Head of the International Cooperation Division, South Korea’s Personal Information Protection Commission (PIPC) Ms. Yoon Jeong CHOI is the Director of International Cooperation Division at PIPC Korea. Her division is responsible for formulating policy and driving operations for cross-border transfer of personal information as well as digital trade, and fostering communication & cooperation with international organizations. Her roles prior to joining PIPC includes the Director of Privacy Protection & Ethics Division and Director of Internet User Policy Division, and Director of Broadcasting Advertisement Policy Division at Korea Communications Commission.
Before her career in the public sector, Ms. Choi was an attorney at Aram International Law Offices working in the fields of international trade, IT, and IP.
Ms. Choi earned an LL.M degree at the University of Southern California (Gould School of Law). She has a BA in Law as well as a BA in the Korean Language and Literature from Ewha Woman’s University.
Head of the International Cooperation Division
South Korea’s Personal Information Protection Commission (PIPC)
Maiko Meguro, Lead Coordinator on DFFT / Senior Policy Analyst, Directorate for Science, Technology, and Innovation, Data Flows, Governance and Privacy Division, OECD Maiko Meguro is a Senior Policy Analyst at the OECD, where she leads cross-border data flows and Data Free Flow with Trust (DFFT) initiatives, including the operationalization of the institutional arrangement for expert-policy cooperation. An international lawyer by training, she brings extensive experience spanning international organizations, government, and academia. Prior to joining the OECD, she served at Japan’s Digital Agency as Head of Division for International Data Strategy, acting as lead negotiator in G7/G20, OECD, and other regional/bilateral negotiations on the digital economy and co-chairing the G7 Digital Technology Working Group during Japan’s 2023 G7 Presidency. She has also held positions at Japan’s Ministry of Economy, Trade and Industry (METI), where she served as Head of Division for International Digital Policy and worked on climate change, energy policy, and trade negotiations, as well as at the European Commission’s DG CONNECT.
Lead Coordinator on DFFT / Senior Policy Analyst, Directorate for Science, Technology, and Innovation, Data Flows, Governance and Privacy Division
OECD
Cláudio Teixeira, Head of Digital Policy, BEUC Cláudio Teixeira is the Head of Digital Policy at BEUC, the European Consumer Organisation. Since 2021, Cláudio has led BEUC’s work on Telecommunications, Artificial Intelligence, and Cybersecurity. Prior to joining BEUC, he served as Junior Legal Attaché at the Permanent Representation of Portugal to the EU during the 2021 Portuguese Council Presidency, contributing to legislative negotiations such as the Digital Markets Act and the Public Country-by-Country Reporting Directive. He began his career in competition law at the Portuguese law firm VdA, following a traineeship at the European Parliament and extensive involvement in European youth NGOs. Cláudio holds a Bachelor and Master of Laws in EU Law from the University of Coimbra, and an LL.M. in European Law from the College of Europe in Bruges.
Head of Digital Policy
BEUC
Itxaso Domínguez de Olazábal, Policy Advisor, EDRi Itxaso Domínguez de Olazábal, PhD, is a Policy Advisor at European Digital Rights (EDRi), specialising in data protection, commercial surveillance, and online tracking, with a focus on the protection of fundamental rights under the GDPR and ePrivacy frameworks.
Policy Advisor
EDRi
Natascha Gerlach, Director of Privacy & Data Policy, Centre of Information Policy Leadership (CIPL) Natascha Gerlach holds the position of Director of Privacy and Data Policy at the Center for Information Policy Leadership (CIPL). Her work is focused on a range of privacy and data related topics including AI, Privacy Enhancing Technologies, children’s privacy and safety, data governance, and cross-border data flows. Before joining CIPL, Natascha was a Senior Attorney with Cleary Gottlieb in their Brussels office, where she headed Cleary’s European eDiscovery group, an early adopter of AI technology. As member of Cleary’s Data Privacy group she advised clients on a wide array of data privacy issues, with a special focus on the cross section of international discovery and data protection. Natascha is Chair Emerita of The Sedona Conference Working Group 6 on International Electronic Information Management, Discovery and Disclosure (WG6) Steering Committee. She is a member of the advisory board for the Georgetown Law AEDI, and a founding member of the IDLF. Natascha is a member of the OpenAge Advisory Board.
Director of Privacy & Data Policy
Centre of Information Policy Leadership (CIPL)
Anne Debet, Vice-President, CNIL Vice-President of the CNIL, Anne Debet is responsible for European affairs (since 2024) and new compliance tools (since 2019). She represents the CNIL on the European Data Protection Board. A professor of law at Paris Cité University and a specialist in digital law, she has contributed to discussions on the integration of the GDPR into French law. In connection with her mandate at the Commission for Access to Documents (2019-2023), Anne Debet took part to the drafting of a guide on the reuse of publicly accessible data at the CNIL. She has also participated in several collective works (symposiums, seminars, and publications) on the regulation of artificial intelligence.
Vice-President
CNIL
Lara Natale, Senior Director Public Affairs, Centre For Future Generations (CFG) Lara leads public affairs across CFG. She capacity-builds and strategises to connect the dots within CFG’s considerable knowledge base, and have CFG’s future-spotting outputs matter in decision making here and now.
Lara brings a broad range of professional perspectives to CFG. Over the course of twenty years she has held roles in public affairs, policy and diplomacy in decision-making hubs Brussels and London, following some early-career years teaching in far-flung locations including Japan and India.
CFG’s purpose, to ensure emerging technology is used in the best interests of humanity, brings together assignments Lara has previously embraced. These include: negotiating EU digital and culture legislation and post-Brexit alignment as attachée for the UK government; coordinating the Brussels secretariat of grassroots networks in civil society; leading talented teams providing strategic EU public policy and regulatory counsel to global businesses with large budgets for a leading global advisory firm; in-house industry senior advisory in telecommunications and directing a regulatory think tank practice. Her policy focus has evolved from migrant integration and human rights, to education and culture, and a decade in tech, media and telecoms.
Lara holds a Masters’ Degree from the University of Oxford and a Postgraduate Certificate from the Brussels School of International Studies.
Senior Director Public Affairs
Centre For Future Generations (CFG)
Lorelien Hoet, Director of EU Government Affairs, Microsoft Lorelien Hoet is Director of EU Government Affairs at Microsoft. In this role, she deals notably with European data protection, law enforcement and content moderation policies and regulations. Before joining Microsoft in 2018, she worked as a legal executive at Proximus, holding different positions including Head of Legal Consumer business, and at Orange where she was active as Director of Regulatory Affairs. She holds an LL.M from KU Leuven and was also active as attorney at the bars of Brussels and Stockholm.
Director of EU Government Affairs
Microsoft
Cláudio Teixeira, Head of Digital Policy, BEUC Cláudio Teixeira is the Head of Digital Policy at BEUC, the European Consumer Organisation. Since 2021, Cláudio has led BEUC’s work on Telecommunications, Artificial Intelligence, and Cybersecurity. Prior to joining BEUC, he served as Junior Legal Attaché at the Permanent Representation of Portugal to the EU during the 2021 Portuguese Council Presidency, contributing to legislative negotiations such as the Digital Markets Act and the Public Country-by-Country Reporting Directive. He began his career in competition law at the Portuguese law firm VdA, following a traineeship at the European Parliament and extensive involvement in European youth NGOs. Cláudio holds a Bachelor and Master of Laws in EU Law from the University of Coimbra, and an LL.M. in European Law from the College of Europe in Bruges.
Head of Digital Policy
BEUC
Itxaso Domínguez de Olazábal, Policy Advisor, EDRi Itxaso Domínguez de Olazábal, PhD, is a Policy Advisor at European Digital Rights (EDRi), specialising in data protection, commercial surveillance, and online tracking, with a focus on the protection of fundamental rights under the GDPR and ePrivacy frameworks.
Policy Advisor
EDRi
Natascha Gerlach, Director of Privacy & Data Policy, Centre of Information Policy Leadership (CIPL) Natascha Gerlach holds the position of Director of Privacy and Data Policy at the Center for Information Policy Leadership (CIPL). Her work is focused on a range of privacy and data related topics including AI, Privacy Enhancing Technologies, children’s privacy and safety, data governance, and cross-border data flows. Before joining CIPL, Natascha was a Senior Attorney with Cleary Gottlieb in their Brussels office, where she headed Cleary’s European eDiscovery group, an early adopter of AI technology. As member of Cleary’s Data Privacy group she advised clients on a wide array of data privacy issues, with a special focus on the cross section of international discovery and data protection. Natascha is Chair Emerita of The Sedona Conference Working Group 6 on International Electronic Information Management, Discovery and Disclosure (WG6) Steering Committee. She is a member of the advisory board for the Georgetown Law AEDI, and a founding member of the IDLF. Natascha is a member of the OpenAge Advisory Board.
Director of Privacy & Data Policy
Centre of Information Policy Leadership (CIPL)
*** TIMES ARE IN CET ***
Michael McGrath’s task is to uphold and strengthen our core values and principles that underpin our Union, our societies and our economies. He works to ensure that citizens can have confidence in state power being exercised fairly and objectively.
He is responsible for:
Michael McGrath is also in charge of justice and consumer protection. His task is to ensure that rights are defended, corruption is punished, and contracts are enforced.
He is responsible for:
Seven years after the GDPR reshaped global data governance, Europe has entered a new phase of regulatory refinement in privacy. The publication of the Digital Omnibus Package and the agreement on the GDPR Procedural Regulation mark pivotal moments as the EU seeks to reduce red tape, strengthen cross-border enforcement, and bolster the continent’s competitiveness in the data-driven economy by addressing a complex constellation of overlapping laws, all while safeguarding individuals’ fundamental rights. With the proposed targeted amendments to the GDPR, which aim to clarify the definition of personal data, streamline certain transparency obligations, improve conditions for scientific research, and recognise legitimate interests in AI system development, the European Commission aims to bring much-needed legal certainty. Yet these efforts have sparked intense debate, with some stakeholders welcoming simplification to unlock innovation and level the playing field with global competitors, while others warn of a potential erosion of safeguards at the heart of the GDPR, particularly around accountability, transparency and data subject rights.
Meanwhile, the GDPR Procedural Regulation seeks to resolve long-standing bottlenecks within the One-Stop-Shop mechanism by harmonising admissibility criteria, strengthening cooperation between national supervisory authorities, and introducing binding deadlines for investigations. But questions remain about whether these new procedures will truly accelerate cross-border cases or introduce new layers of administrative complexity.
Against this backdrop, this session will unpack what these reforms mean for the future of European data privacy. Panellists will assess whether they meaningfully reduce compliance burdens, foster responsible digital tech development and support a harmonised Digital Single Market or whether further work is needed to reconcile innovation, legal certainty and fundamental rights protection.
Possible questions:
Zdravko Vukić graduated from the Faculty of Law at the University of Osijek and holds a master’s degree in public administration. He further pursued studies in business economy and globalization in Zagreb, earning a master’s degree in economics from Libertas International University. Zdravko also possesses an internationally accredited ISO/IEC 27001:2022 Lead Auditor certificate in information security management systems, specializing in information security, cyber security, and privacy protection. Currently, he is finalizing his postgraduate studies with a thesis on Technical and Organizational Measures and Data Security.
From 2005 to 2016, he served as the Chief Human Resources Officer overseeing the organization’s employees and legal affairs. Additionally, between 2008 and 2016, he held the position of Data Protection Officer. Between 2016 and 2020, Zdravko held the role of Assistant Minister at the Ministry of Construction and Physical Planning, where he supervised the operations of the Directorates for Inspection Affairs, Supervision, and Information System Development.
In 2020, he was appointed as the Director of the Croatian Personal Data Protection Agency, and in February 2024 he was re-elected for another four-year term as director. Zdravko is a guest lecturer on personal data protection at various faculties in Croatia and is a member of the National Cybersecurity Council. He has been actively involved in the European Union initiative for institutional cooperation between Public Administrations of EU Member States and non-EU countries, focusing on aligning national legislation with EU regulations in personal data protection.
Under his guidance, the Croatian Personal Data Protection Agency organized the Spring Conference of the European Supervisory Authorities in 2022, a significant platform for cooperation among European data protection regulatory bodies. He played a key role in the implementation of the EU-funded projects ARC I and ARCII aimed to support SMEs in aligning with the GDPR.
Karolina Mojzesowicz is the Deputy Head of Unit of the unit responsible for data protection at the European Commission (DG Justice and Consumers). She was one of the Commission’s representatives in the interinstitutional negotiations with Parliament and Council on the General data Protection Regulation (GDPR). She is now responsible for its implementation in the EU.
Mrs Mojzesowicz previously served as a member of the European Commission’s Legal Service, focusing on EU Competition law and International Trade law. In that capacity, she represented the Commission in numerous cases before the European Courts and before the WTO panels and Appellate Body. Mrs Mojzesowicz studied law in Poland, the Netherlands and Germany where she obtained her PhD in 2001.
Kaljurand serves as the 1st Vice-Chair of the LIBE (Civil Liberties, Justice and Home Affairs) committee in the European Parliament. In LIBE committee she has focused on digital policy, and there she has been appointed Rapporteur of the Digital Omnibus Regulation. This is Kaljurand’s second mandate in the Parliament. She is the Chair of the Steering Committee of the European Internet Forum (EIF), from October 2024.
Kaljurand was a member of the UN Advisory Board on Disarmament Matters (2020 – 2023).
Kaljurand was a member of the UN Secretary General’s High Level Panel on Digital Cooperation (2018-2019). She chaired the Global Commission of the Stability of Cyberspace (2017-2019).
Kaljurand started in the Estonian Foreign Service in 1991 and held several prominent positions, including Estonian Ambassador to the State of Israel, the Russian Federation, United States of America, Canada, Mexico and Kazakhstan.
Kaljurand has served twice as the Estonian National Expert at the United Nations Group of Governmental Experts on Developments in the Field of Information and Telecommunications in the Context of International Security (GGE), in 2014-2015 and in 2016-2017.
Marina Kaljurand graduated cum laude from the Tartu University (1986, LLM). She has a professional diploma from the Estonian School of Diplomacy (1992) and MA from the Fletcher School of Law and Diplomacy, Tufts University (F95).
Itxaso Domínguez de Olazábal, PhD, is a Policy Advisor at European Digital Rights (EDRi), specialising in data protection, commercial surveillance, and online tracking, with a focus on the protection of fundamental rights under the GDPR and ePrivacy frameworks.
Lorelien Hoet is Director of EU Government Affairs at Microsoft. In this role, she deals notably with European data protection, law enforcement and content moderation policies and regulations. Before joining Microsoft in 2018, she worked as a legal executive at Proximus, holding different positions including Head of Legal Consumer business, and at Orange where she was active as Director of Regulatory Affairs. She holds an LL.M from KU Leuven and was also active as attorney at the bars of Brussels and Stockholm.
In an era defined by hyper-personalisation and AI-driven services, where nearly every digital interaction can be tracked, analysed and monetised, the tension between seamless user experiences and meaningful individual control has intensified. In Europe, the regulatory response spans multiple frameworks, such as the GDPR, ePrivacy reforms, the Digital Services Act, and the anticipated Digital Fairness Act, each addressing distinct yet interconnected dimensions of the digital economy. Recent EDPB guidelines on the DSA-GDPR interplay, along with proposed measures in the Digital Simplification Package around automated consent mechanisms, new tracking technology rules, and the Digital Fairness Act’s anticipated provisions on manipulative design, collectively signal Europe’s determination to shield users from dark patterns, unfair personalisation and opaque data practices.
This session will examine whether Europe’s evolving digital rulebook can successfully anchor innovation in a framework of fairness, trust and user empowerment. Panellists will explore the EDPB’s latest guidance on GDPR–DSA interplay, the implications of automated consent mechanisms and browser-based signals, the DFA’s forthcoming impact on advertising models, persuasive vs. manipulative design, and the future of AdTech. Against the backdrop of widespread consent fatigue and declining public trust, the discussion will ask whether simplification will truly deliver user empowerment or risks undermining the very individuals these reforms aim to protect. Speakers will assess what coherent, future-proof enforcement looks like, how organisations can provide meaningful transparency, and how placing individuals at the centre can become a competitive advantage in Europe’s digital economy.
Possible questions:
Christel Schaldemose has been a Member of the European Parliament since 2006. She currently serves as one of the Parliament’s Vice-Presidents in its 10th legislative term. Her parliamentary work has consistently focused on consumer protection, particularly in the context of digital transformation and the internal market.
As the EP’s lead rapporteur for the Digital Services Act (DSA), she played a pivotal role in shaping the EU’s first-ever regulation targeting online platforms. Her efforts have focused on ensuring greater transparency and accountability, tackling disinformation, and protecting consumers from unsafe products—especially those sold by third-country sellers.
In the 2024-2029 term, her priorities include ensuring the effective implementation of the DSA and other digital regulatory frameworks. She will also continue to advocate for stronger protections for minors and young users online.
Karolina Mojzesowicz is the Deputy Head of Unit of the unit responsible for data protection at the European Commission (DG Justice and Consumers). She was one of the Commission’s representatives in the interinstitutional negotiations with Parliament and Council on the General data Protection Regulation (GDPR). She is now responsible for its implementation in the EU.
Mrs Mojzesowicz previously served as a member of the European Commission’s Legal Service, focusing on EU Competition law and International Trade law. In that capacity, she represented the Commission in numerous cases before the European Courts and before the WTO panels and Appellate Body. Mrs Mojzesowicz studied law in Poland, the Netherlands and Germany where she obtained her PhD in 2001.
Vice-President of the CNIL, Anne Debet is responsible for European affairs (since 2024) and new compliance tools (since 2019). She represents the CNIL on the European Data Protection Board. A professor of law at Paris Cité University and a specialist in digital law, she has contributed to discussions on the integration of the GDPR into French law. In connection with her mandate at the Commission for Access to Documents (2019-2023), Anne Debet took part to the drafting of a guide on the reuse of publicly accessible data at the CNIL. She has also participated in several collective works (symposiums, seminars, and publications) on the regulation of artificial intelligence.
Cláudio Teixeira is the Head of Digital Policy at BEUC, the European Consumer Organisation. Since 2021, Cláudio has led BEUC’s work on Telecommunications, Artificial Intelligence, and Cybersecurity. Prior to joining BEUC, he served as Junior Legal Attaché at the Permanent Representation of Portugal to the EU during the 2021 Portuguese Council Presidency, contributing to legislative negotiations such as the Digital Markets Act and the Public Country-by-Country Reporting Directive. He began his career in competition law at the Portuguese law firm VdA, following a traineeship at the European Parliament and extensive involvement in European youth NGOs. Cláudio holds a Bachelor and Master of Laws in EU Law from the University of Coimbra, and an LL.M. in European Law from the College of Europe in Bruges.
Lara leads public affairs across CFG. She capacity-builds and strategises to connect the dots within CFG’s considerable knowledge base, and have CFG’s future-spotting outputs matter in decision making here and now.
Lara brings a broad range of professional perspectives to CFG. Over the course of twenty years she has held roles in public affairs, policy and diplomacy in decision-making hubs Brussels and London, following some early-career years teaching in far-flung locations including Japan and India.
CFG’s purpose, to ensure emerging technology is used in the best interests of humanity, brings together assignments Lara has previously embraced. These include: negotiating EU digital and culture legislation and post-Brexit alignment as attachée for the UK government; coordinating the Brussels secretariat of grassroots networks in civil society; leading talented teams providing strategic EU public policy and regulatory counsel to global businesses with large budgets for a leading global advisory firm; in-house industry senior advisory in telecommunications and directing a regulatory think tank practice. Her policy focus has evolved from migrant integration and human rights, to education and culture, and a decade in tech, media and telecoms.
Lara holds a Masters’ Degree from the University of Oxford and a Postgraduate Certificate from the Brussels School of International Studies.
The digital economy has fundamentally altered the regulatory landscape, forcing a convergence of two regimes that once operated in silos: Competition Law and Data Protection. The implementation of the DMA, together with the ongoing application of the GDPR, has transformed Europe’s regulatory ecosystem, forcing regulators, gatekeepers, and business users alike to confront how these frameworks intersect, complement, and challenge one another. As the European Commission and European Data Protection Board have issued joint guidance on the interplay between the DMA and GDPR clarifying how gatekeepers should navigate DMA obligations (such as real-time data portability, data access for business users, and interoperability) while remaining fully compliant with GDPR principles on consent, minimisation, anonymisation, and purpose limitation, critical questions have emerged: Can privacy enforcement unlock competition by reducing data-driven market power? Or will the compliance burden disproportionately advantage large incumbents? Do interoperability and data-sharing obligations risk conflicting with GDPR provisions? What does this regulatory convergence mean for innovation, AI development, and the competitiveness of the EU’s digital sector?
Mr. Michael KÖNIG is Head of Unit in the European Commission’s Directorate-General for Competition leading one of the units responsible for the implementation of the Digital Markets Act (DMA).
Before taking up this position in DG COMP, Mr König was advisor for platform regulation in DG CNECT and front line negotiator for the Digital Markets Act in the legislative process. He also served several years as Deputy Head of Unit in the European Commission’s Directorate-General for Internal Market, Industry, Entrepreneurship and SMEs (GROW) where he was primarily responsible for B2B relations regarding online platforms and negotiated the Regulation on fairness in platform-to-business relations (P2B Regulation).
Mr König joined the European Commission in 2001 in the Directorate-General for Competition. His assignments included a position as advisor to Directorate-General’s top management and a secondment to the OECD, before he joined the Internal Market Directorate-General in 2008. There he held positions in various policy areas including intellectual property and financial services.
Before joining the Commission, Mr. König worked for several years in the German Competition Authority and an international law firm.
Mr. König graduated in Law and Economics, and holds a PhD degree in Competition Law.
In an increasingly connected world, the smooth and secure flow of personal data across borders is the lifeblood of the global digital economy. However, as geopolitical shifts influence policy and countries adopt unique national approaches to data protection and digital sovereignty strategies, international organizations are left to navigate a maze of divergent regulatory frameworks. Policymakers, regulators, and industry actors worldwide are increasingly focusing on interoperability and on practical ways for data protection frameworks to work together without lowering standards.
This session will explore how to strengthen high-level data protection while enabling the secure and seamless transfer of personal information worldwide. Speakers will examine progress to date, including progress toward adequacy decisions, mutual recognition and shared standards, and discuss the further steps needed to reduce complexity for organisations, enhance legal certainty, and deliver stronger protections for individuals, regardless of where their data travels.
Possible questions:
Bio to follow.
Ms. Yoon Jeong CHOI is the Director of International Cooperation Division at PIPC Korea. Her division is responsible for formulating policy and driving operations for cross-border transfer of personal information as well as digital trade, and fostering communication & cooperation with international organizations. Her roles prior to joining PIPC includes the Director of Privacy Protection & Ethics Division and Director of Internet User Policy Division, and Director of Broadcasting Advertisement Policy Division at Korea Communications Commission.
Before her career in the public sector, Ms. Choi was an attorney at Aram International Law Offices working in the fields of international trade, IT, and IP.
Ms. Choi earned an LL.M degree at the University of Southern California (Gould School of Law). She has a BA in Law as well as a BA in the Korean Language and Literature from Ewha Woman’s University.
Maiko Meguro is a Senior Policy Analyst at the OECD, where she leads cross-border data flows and Data Free Flow with Trust (DFFT) initiatives, including the operationalization of the institutional arrangement for expert-policy cooperation. An international lawyer by training, she brings extensive experience spanning international organizations, government, and academia. Prior to joining the OECD, she served at Japan’s Digital Agency as Head of Division for International Data Strategy, acting as lead negotiator in G7/G20, OECD, and other regional/bilateral negotiations on the digital economy and co-chairing the G7 Digital Technology Working Group during Japan’s 2023 G7 Presidency. She has also held positions at Japan’s Ministry of Economy, Trade and Industry (METI), where she served as Head of Division for International Digital Policy and worked on climate change, energy policy, and trade negotiations, as well as at the European Commission’s DG CONNECT.
Natascha Gerlach holds the position of Director of Privacy and Data Policy at the Center for Information Policy Leadership (CIPL). Her work is focused on a range of privacy and data related topics including AI, Privacy Enhancing Technologies, children’s privacy and safety, data governance, and cross-border data flows. Before joining CIPL, Natascha was a Senior Attorney with Cleary Gottlieb in their Brussels office, where she headed Cleary’s European eDiscovery group, an early adopter of AI technology. As member of Cleary’s Data Privacy group she advised clients on a wide array of data privacy issues, with a special focus on the cross section of international discovery and data protection. Natascha is Chair Emerita of The Sedona Conference Working Group 6 on International Electronic Information Management, Discovery and Disclosure (WG6) Steering Committee. She is a member of the advisory board for the Georgetown Law AEDI, and a founding member of the IDLF. Natascha is a member of the OpenAge Advisory Board.
As governments accelerate the digitisation of public services, they face a critical dual imperative: leveraging innovation to enhance service delivery while strictly safeguarding citizen privacy. Public agencies are the custodians of society’s most sensitive assets, from healthcare records to national security data, while navigating an increasingly complex landscape of cyber threats, legacy systems, data silos and growing public expectations for transparency and trust. How can Public Authorities harness the power of digital innovation while maintaining the trust that underpins democratic governance?
This session will examine the complex intersection of data sovereignty, cybersecurity, and privacy rights in the public sector. The discussion will address how modern regulatory frameworks, including the EU Digital Identity Wallet and evolving data protection standards, are shaping the landscape of digital public services. Participants will explore the opportunities and risks associated with cloud computing, AI deployment, and data retention practices in government contexts. The session will also explore how innovation, modern governance, and privacy-by-design principles can enable governments to manage, share, and protect data responsibly and effectively. It will address the persistent structural challenges facing the public sector, from data silos to outdated infrastructure and high-velocity data streams, and discuss what is needed to build secure, future-ready public services that enhance public trust.
Possible questions:
Bio to follow.
Telecommunication Engineer with an extensive professional background in both the public and private sectors. He has over a decade of experience in the private sector, specializing in telecommunications and urban and environmental control systems. Since 1993, he has been employed at the Spanish Tax Agency, where he has held a range of positions and led key initiatives, including the implementation of the Law on electronic access to public services. In addition, he has occupied senior roles within public administration, serving as Director General for the Promotion of Electronic Administration and Secretary General of Digital Administration. From 2017 to 2018, he served as the President of the Public Society for the Management of Innovation and Tourism Technologies (SEGITTUR). He currently holds the position of Director General of the Digital Office of Madrid, where he leads the city’s digital transformation and data & AI strategy.
Ilias Chantzos is Broadcom’s Global Privacy Officer and the Head of Government Affairs programmes for Europe, Middle East & Africa (EMEA). Chantzos leads the global privacy programme of Broadcom across the company’s multiple business units and regions. He also represents Broadcom before government bodies, national authorities and international organisations in EMEA advising on public policy issues.
Before joining Broadcom, Chantzos spent almost 16 years in various government affairs and legal roles in Symantec. During his last post with Symantec, he was in charge of the Government Affairs for the EMEA and the Asia Pacific Japan regions and the Global Advisor for Critical Infrastructure Protection and Privacy.
Before joining Symantec in 2004, Chantzos worked as legal and policy officer in the Directorate General Information Society of the European Commission focusing on information security policy. He covered the Council of Europe Cybercrime Convention and the Framework Decision on Attacks against Information Systems. In addition, he worked on a number of EU legislative initiatives relevant to information society and security, including directives on Privacy of Electronic Communications, the Data Retention Directive and the European Network and Information Security Agency (ENISA). He also represented the European Commission in various international debates and conferences.
Chantzos holds a law degree from Aristotle University, a Master degree in Computers and Communication Law from Queen Mary College, University of London and a Master in Business Administration from Solvay Business School. He has also completed executive education at Lee Kuan Yew School of Public Policy in Singapore and at the JFK School of Government in Harvard. Chantzos is a member of the Athens Bar Association. He served as Chairman of the Executive Board of TechAmerica Europe. He also served for four terms as Chairman of the European Policy Council of the Business Software Alliance (BSA). He has represented Symantec at the NATO Industry Cooperation Platform and he has been a member of the Advisory Board of the European Network and Information Security Agency (ENISA) from 2006 until 2020. He is also a member of Europol’s European Cybercrime Center (EC3) Advisory Board. Chantzos is a member of the Young Global Leaders 2014 class of the World Economic Forum. He speaks English, Greek, Dutch and German.
The rapid ascent of generative and agentic AI has intensified long-standing questions around data collection, training practices, transparency, and the rights of individuals whose personal data fuels these technologies. Indeed, from training data to automated decision-making outputs, personal data can be implicated at every stage of the AI lifecycle, and ensuring coordinated, complementary rules between AI and data protection regimes is therefore essential to providing legal certainty, preserving cross-border data flows, and enabling responsible AI deployment.
This session will explore how privacy-by-design, data minimisation, PETs, and emerging governance frameworks can enable responsible, trustworthy high-impact AI innovation without compromising data protection. Speakers will also examine how the GDPR, the EU AI Act, and international regulatory initiatives interact, discuss the evolving role of Data Protection Authorities in AI oversight, and examine emerging operational models for assessing risks associated with large language models and agentic AI. This session offers a roadmap for building trust-based, compliant AI ecosystems that protect privacy, support digital sovereignty, unlock data value, and deliver social and economic benefits for the greater good.
Possible questions:
Kari Laumann is Head of Section for Research, Analysis, and Policy at the Norwegian Data Protection Authority (Datatilsynet). She has been a leading figure in developing the Regulatory Sandbox for Privacy, Innovation and Digitalisation, a key initiative under Norway’s National Strategy for AI aimed at fostering innovative and responsible AI development. With a background in sociology, Kari has extensive experience in privacy and technology policy, including her tenure as VP for privacy in Telenor’s Asian operations and as an advisor to the Norwegian Parliament through the Board of Technology. Her work bridges the intersection of data protection, AI, and public policy, making her a leading voice in ethical tech governance.
Michael McGrath’s task is to uphold and strengthen our core values and principles that underpin our Union, our societies and our economies. He works to ensure that citizens can have confidence in state power being exercised fairly and objectively.
He is responsible for:
Michael McGrath is also in charge of justice and consumer protection. His task is to ensure that rights are defended, corruption is punished, and contracts are enforced.
He is responsible for:
Seven years after the GDPR reshaped global data governance, Europe has entered a new phase of regulatory refinement in privacy. The publication of the Digital Omnibus Package and the agreement on the GDPR Procedural Regulation mark pivotal moments as the EU seeks to reduce red tape, strengthen cross-border enforcement, and bolster the continent’s competitiveness in the data-driven economy by addressing a complex constellation of overlapping laws, all while safeguarding individuals’ fundamental rights. With the proposed targeted amendments to the GDPR, which aim to clarify the definition of personal data, streamline certain transparency obligations, improve conditions for scientific research, and recognise legitimate interests in AI system development, the European Commission aims to bring much-needed legal certainty. Yet these efforts have sparked intense debate, with some stakeholders welcoming simplification to unlock innovation and level the playing field with global competitors, while others warn of a potential erosion of safeguards at the heart of the GDPR, particularly around accountability, transparency and data subject rights.
Meanwhile, the GDPR Procedural Regulation seeks to resolve long-standing bottlenecks within the One-Stop-Shop mechanism by harmonising admissibility criteria, strengthening cooperation between national supervisory authorities, and introducing binding deadlines for investigations. But questions remain about whether these new procedures will truly accelerate cross-border cases or introduce new layers of administrative complexity.
Against this backdrop, this session will unpack what these reforms mean for the future of European data privacy. Panellists will assess whether they meaningfully reduce compliance burdens, foster responsible digital tech development and support a harmonised Digital Single Market or whether further work is needed to reconcile innovation, legal certainty and fundamental rights protection.
Possible questions:
Zdravko Vukić graduated from the Faculty of Law at the University of Osijek and holds a master’s degree in public administration. He further pursued studies in business economy and globalization in Zagreb, earning a master’s degree in economics from Libertas International University. Zdravko also possesses an internationally accredited ISO/IEC 27001:2022 Lead Auditor certificate in information security management systems, specializing in information security, cyber security, and privacy protection. Currently, he is finalizing his postgraduate studies with a thesis on Technical and Organizational Measures and Data Security.
From 2005 to 2016, he served as the Chief Human Resources Officer overseeing the organization’s employees and legal affairs. Additionally, between 2008 and 2016, he held the position of Data Protection Officer. Between 2016 and 2020, Zdravko held the role of Assistant Minister at the Ministry of Construction and Physical Planning, where he supervised the operations of the Directorates for Inspection Affairs, Supervision, and Information System Development.
In 2020, he was appointed as the Director of the Croatian Personal Data Protection Agency, and in February 2024 he was re-elected for another four-year term as director. Zdravko is a guest lecturer on personal data protection at various faculties in Croatia and is a member of the National Cybersecurity Council. He has been actively involved in the European Union initiative for institutional cooperation between Public Administrations of EU Member States and non-EU countries, focusing on aligning national legislation with EU regulations in personal data protection.
Under his guidance, the Croatian Personal Data Protection Agency organized the Spring Conference of the European Supervisory Authorities in 2022, a significant platform for cooperation among European data protection regulatory bodies. He played a key role in the implementation of the EU-funded projects ARC I and ARCII aimed to support SMEs in aligning with the GDPR.
Karolina Mojzesowicz is the Deputy Head of Unit of the unit responsible for data protection at the European Commission (DG Justice and Consumers). She was one of the Commission’s representatives in the interinstitutional negotiations with Parliament and Council on the General data Protection Regulation (GDPR). She is now responsible for its implementation in the EU.
Mrs Mojzesowicz previously served as a member of the European Commission’s Legal Service, focusing on EU Competition law and International Trade law. In that capacity, she represented the Commission in numerous cases before the European Courts and before the WTO panels and Appellate Body. Mrs Mojzesowicz studied law in Poland, the Netherlands and Germany where she obtained her PhD in 2001.
Kaljurand serves as the 1st Vice-Chair of the LIBE (Civil Liberties, Justice and Home Affairs) committee in the European Parliament. In LIBE committee she has focused on digital policy, and there she has been appointed Rapporteur of the Digital Omnibus Regulation. This is Kaljurand’s second mandate in the Parliament. She is the Chair of the Steering Committee of the European Internet Forum (EIF), from October 2024.
Kaljurand was a member of the UN Advisory Board on Disarmament Matters (2020 – 2023).
Kaljurand was a member of the UN Secretary General’s High Level Panel on Digital Cooperation (2018-2019). She chaired the Global Commission of the Stability of Cyberspace (2017-2019).
Kaljurand started in the Estonian Foreign Service in 1991 and held several prominent positions, including Estonian Ambassador to the State of Israel, the Russian Federation, United States of America, Canada, Mexico and Kazakhstan.
Kaljurand has served twice as the Estonian National Expert at the United Nations Group of Governmental Experts on Developments in the Field of Information and Telecommunications in the Context of International Security (GGE), in 2014-2015 and in 2016-2017.
Marina Kaljurand graduated cum laude from the Tartu University (1986, LLM). She has a professional diploma from the Estonian School of Diplomacy (1992) and MA from the Fletcher School of Law and Diplomacy, Tufts University (F95).
Itxaso Domínguez de Olazábal, PhD, is a Policy Advisor at European Digital Rights (EDRi), specialising in data protection, commercial surveillance, and online tracking, with a focus on the protection of fundamental rights under the GDPR and ePrivacy frameworks.
Lorelien Hoet is Director of EU Government Affairs at Microsoft. In this role, she deals notably with European data protection, law enforcement and content moderation policies and regulations. Before joining Microsoft in 2018, she worked as a legal executive at Proximus, holding different positions including Head of Legal Consumer business, and at Orange where she was active as Director of Regulatory Affairs. She holds an LL.M from KU Leuven and was also active as attorney at the bars of Brussels and Stockholm.
In an era defined by hyper-personalisation and AI-driven services, where nearly every digital interaction can be tracked, analysed and monetised, the tension between seamless user experiences and meaningful individual control has intensified. In Europe, the regulatory response spans multiple frameworks, such as the GDPR, ePrivacy reforms, the Digital Services Act, and the anticipated Digital Fairness Act, each addressing distinct yet interconnected dimensions of the digital economy. Recent EDPB guidelines on the DSA-GDPR interplay, along with proposed measures in the Digital Simplification Package around automated consent mechanisms, new tracking technology rules, and the Digital Fairness Act’s anticipated provisions on manipulative design, collectively signal Europe’s determination to shield users from dark patterns, unfair personalisation and opaque data practices.
This session will examine whether Europe’s evolving digital rulebook can successfully anchor innovation in a framework of fairness, trust and user empowerment. Panellists will explore the EDPB’s latest guidance on GDPR–DSA interplay, the implications of automated consent mechanisms and browser-based signals, the DFA’s forthcoming impact on advertising models, persuasive vs. manipulative design, and the future of AdTech. Against the backdrop of widespread consent fatigue and declining public trust, the discussion will ask whether simplification will truly deliver user empowerment or risks undermining the very individuals these reforms aim to protect. Speakers will assess what coherent, future-proof enforcement looks like, how organisations can provide meaningful transparency, and how placing individuals at the centre can become a competitive advantage in Europe’s digital economy.
Possible questions:
Christel Schaldemose has been a Member of the European Parliament since 2006. She currently serves as one of the Parliament’s Vice-Presidents in its 10th legislative term. Her parliamentary work has consistently focused on consumer protection, particularly in the context of digital transformation and the internal market.
As the EP’s lead rapporteur for the Digital Services Act (DSA), she played a pivotal role in shaping the EU’s first-ever regulation targeting online platforms. Her efforts have focused on ensuring greater transparency and accountability, tackling disinformation, and protecting consumers from unsafe products—especially those sold by third-country sellers.
In the 2024-2029 term, her priorities include ensuring the effective implementation of the DSA and other digital regulatory frameworks. She will also continue to advocate for stronger protections for minors and young users online.
Karolina Mojzesowicz is the Deputy Head of Unit of the unit responsible for data protection at the European Commission (DG Justice and Consumers). She was one of the Commission’s representatives in the interinstitutional negotiations with Parliament and Council on the General data Protection Regulation (GDPR). She is now responsible for its implementation in the EU.
Mrs Mojzesowicz previously served as a member of the European Commission’s Legal Service, focusing on EU Competition law and International Trade law. In that capacity, she represented the Commission in numerous cases before the European Courts and before the WTO panels and Appellate Body. Mrs Mojzesowicz studied law in Poland, the Netherlands and Germany where she obtained her PhD in 2001.
Vice-President of the CNIL, Anne Debet is responsible for European affairs (since 2024) and new compliance tools (since 2019). She represents the CNIL on the European Data Protection Board. A professor of law at Paris Cité University and a specialist in digital law, she has contributed to discussions on the integration of the GDPR into French law. In connection with her mandate at the Commission for Access to Documents (2019-2023), Anne Debet took part to the drafting of a guide on the reuse of publicly accessible data at the CNIL. She has also participated in several collective works (symposiums, seminars, and publications) on the regulation of artificial intelligence.
Cláudio Teixeira is the Head of Digital Policy at BEUC, the European Consumer Organisation. Since 2021, Cláudio has led BEUC’s work on Telecommunications, Artificial Intelligence, and Cybersecurity. Prior to joining BEUC, he served as Junior Legal Attaché at the Permanent Representation of Portugal to the EU during the 2021 Portuguese Council Presidency, contributing to legislative negotiations such as the Digital Markets Act and the Public Country-by-Country Reporting Directive. He began his career in competition law at the Portuguese law firm VdA, following a traineeship at the European Parliament and extensive involvement in European youth NGOs. Cláudio holds a Bachelor and Master of Laws in EU Law from the University of Coimbra, and an LL.M. in European Law from the College of Europe in Bruges.
Lara leads public affairs across CFG. She capacity-builds and strategises to connect the dots within CFG’s considerable knowledge base, and have CFG’s future-spotting outputs matter in decision making here and now.
Lara brings a broad range of professional perspectives to CFG. Over the course of twenty years she has held roles in public affairs, policy and diplomacy in decision-making hubs Brussels and London, following some early-career years teaching in far-flung locations including Japan and India.
CFG’s purpose, to ensure emerging technology is used in the best interests of humanity, brings together assignments Lara has previously embraced. These include: negotiating EU digital and culture legislation and post-Brexit alignment as attachée for the UK government; coordinating the Brussels secretariat of grassroots networks in civil society; leading talented teams providing strategic EU public policy and regulatory counsel to global businesses with large budgets for a leading global advisory firm; in-house industry senior advisory in telecommunications and directing a regulatory think tank practice. Her policy focus has evolved from migrant integration and human rights, to education and culture, and a decade in tech, media and telecoms.
Lara holds a Masters’ Degree from the University of Oxford and a Postgraduate Certificate from the Brussels School of International Studies.
The digital economy has fundamentally altered the regulatory landscape, forcing a convergence of two regimes that once operated in silos: Competition Law and Data Protection. The implementation of the DMA, together with the ongoing application of the GDPR, has transformed Europe’s regulatory ecosystem, forcing regulators, gatekeepers, and business users alike to confront how these frameworks intersect, complement, and challenge one another. As the European Commission and European Data Protection Board have issued joint guidance on the interplay between the DMA and GDPR clarifying how gatekeepers should navigate DMA obligations (such as real-time data portability, data access for business users, and interoperability) while remaining fully compliant with GDPR principles on consent, minimisation, anonymisation, and purpose limitation, critical questions have emerged: Can privacy enforcement unlock competition by reducing data-driven market power? Or will the compliance burden disproportionately advantage large incumbents? Do interoperability and data-sharing obligations risk conflicting with GDPR provisions? What does this regulatory convergence mean for innovation, AI development, and the competitiveness of the EU’s digital sector?
Mr. Michael KÖNIG is Head of Unit in the European Commission’s Directorate-General for Competition leading one of the units responsible for the implementation of the Digital Markets Act (DMA).
Before taking up this position in DG COMP, Mr König was advisor for platform regulation in DG CNECT and front line negotiator for the Digital Markets Act in the legislative process. He also served several years as Deputy Head of Unit in the European Commission’s Directorate-General for Internal Market, Industry, Entrepreneurship and SMEs (GROW) where he was primarily responsible for B2B relations regarding online platforms and negotiated the Regulation on fairness in platform-to-business relations (P2B Regulation).
Mr König joined the European Commission in 2001 in the Directorate-General for Competition. His assignments included a position as advisor to Directorate-General’s top management and a secondment to the OECD, before he joined the Internal Market Directorate-General in 2008. There he held positions in various policy areas including intellectual property and financial services.
Before joining the Commission, Mr. König worked for several years in the German Competition Authority and an international law firm.
Mr. König graduated in Law and Economics, and holds a PhD degree in Competition Law.
In an increasingly connected world, the smooth and secure flow of personal data across borders is the lifeblood of the global digital economy. However, as geopolitical shifts influence policy and countries adopt unique national approaches to data protection and digital sovereignty strategies, international organizations are left to navigate a maze of divergent regulatory frameworks. Policymakers, regulators, and industry actors worldwide are increasingly focusing on interoperability and on practical ways for data protection frameworks to work together without lowering standards.
This session will explore how to strengthen high-level data protection while enabling the secure and seamless transfer of personal information worldwide. Speakers will examine progress to date, including progress toward adequacy decisions, mutual recognition and shared standards, and discuss the further steps needed to reduce complexity for organisations, enhance legal certainty, and deliver stronger protections for individuals, regardless of where their data travels.
Possible questions:
Bio to follow.
Ms. Yoon Jeong CHOI is the Director of International Cooperation Division at PIPC Korea. Her division is responsible for formulating policy and driving operations for cross-border transfer of personal information as well as digital trade, and fostering communication & cooperation with international organizations. Her roles prior to joining PIPC includes the Director of Privacy Protection & Ethics Division and Director of Internet User Policy Division, and Director of Broadcasting Advertisement Policy Division at Korea Communications Commission.
Before her career in the public sector, Ms. Choi was an attorney at Aram International Law Offices working in the fields of international trade, IT, and IP.
Ms. Choi earned an LL.M degree at the University of Southern California (Gould School of Law). She has a BA in Law as well as a BA in the Korean Language and Literature from Ewha Woman’s University.
Maiko Meguro is a Senior Policy Analyst at the OECD, where she leads cross-border data flows and Data Free Flow with Trust (DFFT) initiatives, including the operationalization of the institutional arrangement for expert-policy cooperation. An international lawyer by training, she brings extensive experience spanning international organizations, government, and academia. Prior to joining the OECD, she served at Japan’s Digital Agency as Head of Division for International Data Strategy, acting as lead negotiator in G7/G20, OECD, and other regional/bilateral negotiations on the digital economy and co-chairing the G7 Digital Technology Working Group during Japan’s 2023 G7 Presidency. She has also held positions at Japan’s Ministry of Economy, Trade and Industry (METI), where she served as Head of Division for International Digital Policy and worked on climate change, energy policy, and trade negotiations, as well as at the European Commission’s DG CONNECT.
Natascha Gerlach holds the position of Director of Privacy and Data Policy at the Center for Information Policy Leadership (CIPL). Her work is focused on a range of privacy and data related topics including AI, Privacy Enhancing Technologies, children’s privacy and safety, data governance, and cross-border data flows. Before joining CIPL, Natascha was a Senior Attorney with Cleary Gottlieb in their Brussels office, where she headed Cleary’s European eDiscovery group, an early adopter of AI technology. As member of Cleary’s Data Privacy group she advised clients on a wide array of data privacy issues, with a special focus on the cross section of international discovery and data protection. Natascha is Chair Emerita of The Sedona Conference Working Group 6 on International Electronic Information Management, Discovery and Disclosure (WG6) Steering Committee. She is a member of the advisory board for the Georgetown Law AEDI, and a founding member of the IDLF. Natascha is a member of the OpenAge Advisory Board.
As governments accelerate the digitisation of public services, they face a critical dual imperative: leveraging innovation to enhance service delivery while strictly safeguarding citizen privacy. Public agencies are the custodians of society’s most sensitive assets, from healthcare records to national security data, while navigating an increasingly complex landscape of cyber threats, legacy systems, data silos and growing public expectations for transparency and trust. How can Public Authorities harness the power of digital innovation while maintaining the trust that underpins democratic governance?
This session will examine the complex intersection of data sovereignty, cybersecurity, and privacy rights in the public sector. The discussion will address how modern regulatory frameworks, including the EU Digital Identity Wallet and evolving data protection standards, are shaping the landscape of digital public services. Participants will explore the opportunities and risks associated with cloud computing, AI deployment, and data retention practices in government contexts. The session will also explore how innovation, modern governance, and privacy-by-design principles can enable governments to manage, share, and protect data responsibly and effectively. It will address the persistent structural challenges facing the public sector, from data silos to outdated infrastructure and high-velocity data streams, and discuss what is needed to build secure, future-ready public services that enhance public trust.
Possible questions:
Bio to follow.
Telecommunication Engineer with an extensive professional background in both the public and private sectors. He has over a decade of experience in the private sector, specializing in telecommunications and urban and environmental control systems. Since 1993, he has been employed at the Spanish Tax Agency, where he has held a range of positions and led key initiatives, including the implementation of the Law on electronic access to public services. In addition, he has occupied senior roles within public administration, serving as Director General for the Promotion of Electronic Administration and Secretary General of Digital Administration. From 2017 to 2018, he served as the President of the Public Society for the Management of Innovation and Tourism Technologies (SEGITTUR). He currently holds the position of Director General of the Digital Office of Madrid, where he leads the city’s digital transformation and data & AI strategy.
Ilias Chantzos is Broadcom’s Global Privacy Officer and the Head of Government Affairs programmes for Europe, Middle East & Africa (EMEA). Chantzos leads the global privacy programme of Broadcom across the company’s multiple business units and regions. He also represents Broadcom before government bodies, national authorities and international organisations in EMEA advising on public policy issues.
Before joining Broadcom, Chantzos spent almost 16 years in various government affairs and legal roles in Symantec. During his last post with Symantec, he was in charge of the Government Affairs for the EMEA and the Asia Pacific Japan regions and the Global Advisor for Critical Infrastructure Protection and Privacy.
Before joining Symantec in 2004, Chantzos worked as legal and policy officer in the Directorate General Information Society of the European Commission focusing on information security policy. He covered the Council of Europe Cybercrime Convention and the Framework Decision on Attacks against Information Systems. In addition, he worked on a number of EU legislative initiatives relevant to information society and security, including directives on Privacy of Electronic Communications, the Data Retention Directive and the European Network and Information Security Agency (ENISA). He also represented the European Commission in various international debates and conferences.
Chantzos holds a law degree from Aristotle University, a Master degree in Computers and Communication Law from Queen Mary College, University of London and a Master in Business Administration from Solvay Business School. He has also completed executive education at Lee Kuan Yew School of Public Policy in Singapore and at the JFK School of Government in Harvard. Chantzos is a member of the Athens Bar Association. He served as Chairman of the Executive Board of TechAmerica Europe. He also served for four terms as Chairman of the European Policy Council of the Business Software Alliance (BSA). He has represented Symantec at the NATO Industry Cooperation Platform and he has been a member of the Advisory Board of the European Network and Information Security Agency (ENISA) from 2006 until 2020. He is also a member of Europol’s European Cybercrime Center (EC3) Advisory Board. Chantzos is a member of the Young Global Leaders 2014 class of the World Economic Forum. He speaks English, Greek, Dutch and German.
The rapid ascent of generative and agentic AI has intensified long-standing questions around data collection, training practices, transparency, and the rights of individuals whose personal data fuels these technologies. Indeed, from training data to automated decision-making outputs, personal data can be implicated at every stage of the AI lifecycle, and ensuring coordinated, complementary rules between AI and data protection regimes is therefore essential to providing legal certainty, preserving cross-border data flows, and enabling responsible AI deployment.
This session will explore how privacy-by-design, data minimisation, PETs, and emerging governance frameworks can enable responsible, trustworthy high-impact AI innovation without compromising data protection. Speakers will also examine how the GDPR, the EU AI Act, and international regulatory initiatives interact, discuss the evolving role of Data Protection Authorities in AI oversight, and examine emerging operational models for assessing risks associated with large language models and agentic AI. This session offers a roadmap for building trust-based, compliant AI ecosystems that protect privacy, support digital sovereignty, unlock data value, and deliver social and economic benefits for the greater good.
Possible questions:
Kari Laumann is Head of Section for Research, Analysis, and Policy at the Norwegian Data Protection Authority (Datatilsynet). She has been a leading figure in developing the Regulatory Sandbox for Privacy, Innovation and Digitalisation, a key initiative under Norway’s National Strategy for AI aimed at fostering innovative and responsible AI development. With a background in sociology, Kari has extensive experience in privacy and technology policy, including her tenure as VP for privacy in Telenor’s Asian operations and as an advisor to the Norwegian Parliament through the Board of Technology. Her work bridges the intersection of data protection, AI, and public policy, making her a leading voice in ethical tech governance.
For further details on the 2025 edition, you can view the previous event website here.

































Applies to: Corporate Organisations, Trade Associations, Law Firms
Applies to: NGO / Not for Profit, Academic / Student
Applies to: European Commission / Parliament / Council, National Government / Regulator, Diplomatic Missions to the EU, Permanent Representations to the EU, Accredited Journalists
* Please note that fees do not include Belgian VAT @ 21%, and this amount will be added to the total price when you are invoiced.
Please note that all registrations are subject to review by the organisers. The organisational categories listed reflect the most common participant profiles from previous editions and may not cover every individual circumstance. If you are unsure which category applies to you, please contact us via the Contact section before completing your registration. Selecting an incorrect category may delay or prevent confirmation of your place at the event. We are always happy to assist to ensure the correct category is selected.
Number of delegates
3-5
6-8
9+
Group discount
10%
20%
25%
To discuss sponsorship and visibility opportunities at the 15th Annual European Data Protection & Privacy Conference, please contact Anne-Lise Simon on [email protected]
Exclusive speaking positions | Your organisation can contribute to the discussion.
Engaging and Interactive format | Engage in a fully immersive and interactive debate with decision makers, businesses and policymakers.
European and global outreach | Convey your message to a broad and international audience.
Networking opportunities | Connect with your fellow attendees during coffee and lunch breaks throughout the event.
Visibility Opportunities | Ensure maximum visibility through branding in the room, on the event website and marketing activities.
Rue du Parnasse 19, Brussels, Belgium, 1050
For more information on any aspect of this event, please contact Karolina Stankiewicz using any of the details below.
Karolina Stankiewicz
Event Manager
Forum Europe
+44 (0) 7845 645 853
[email protected]
Sign up to receive updates on our upcoming policy events. We will only send you emails about the conferences and topics that interest you, and you can unsubscribe at any time.