#EUDATA26
The European Data Protection and Privacy Conference takes place annually and is a key fixture in the Brussels calendar, fostering lively and interactive discussions on the future of data protection regulation. Attracting more than 200 participants each year, it has become a must-attend event for privacy professionals and other stakeholders in the data protection sector, bringing together top-level speakers and delegates from across industries alongside senior EU and international policymakers and regulators.
Following the European Commission’s release of the Digital Omnibus Package, this year’s conference will explore the future of Europe’s digital and data protection framework. It will examine the extent to which the GDPR can be refined to support an innovative, competitive, and rights-preserving digital future, while placing individuals at the heart of Europe’s evolving digital rulebook through greater coherence, fairness, and trust. The conference will further explore the complex interplay between competition policy and data privacy, highlighting the need to break down regulatory silos and will also take a global view on data protection, examining how regions can cooperate in an increasingly fragmented regulatory landscape. In addition, discussions will address the role of data privacy in the digital transformation of public services, as well as how data, privacy, AI, and privacy-enhancing technologies can underpin trustworthy innovation in the AI era.
Should you wish to find out more about speaking and sponsorship opportunities at this year’s event, please contact [email protected]

Commissioner for Democracy, Justice, the Rule of Law and Consumer Protection European Commission






Michael McGrath, Commissioner for Democracy, Justice, the Rule of Law and Consumer Protection, European Commission Michael McGrath’s task is to uphold and strengthen our core values and principles that underpin our Union, our societies and our economies. He works to ensure that citizens can have confidence in state power being exercised fairly and objectively.
He is responsible for:
Michael McGrath is also in charge of justice and consumer protection. His task is to ensure that rights are defended, corruption is punished, and contracts are enforced.
He is responsible for:
Commissioner for Democracy, Justice, the Rule of Law and Consumer Protection
European Commission
Marina Kaljurand, Member, European Parliament Kaljurand serves as the 1st Vice-Chair of the LIBE (Civil Liberties, Justice and Home Affairs) committee in the European Parliament. In LIBE committee she has focused on digital policy, and there she has been appointed Rapporteur of the Digital Omnibus Regulation. This is Kaljurand’s second mandate in the Parliament. She is the Chair of the Steering Committee of the European Internet Forum (EIF), from October 2024.
Kaljurand was a member of the UN Advisory Board on Disarmament Matters (2020 – 2023).
Kaljurand was a member of the UN Secretary General’s High Level Panel on Digital Cooperation (2018-2019). She chaired the Global Commission of the Stability of Cyberspace (2017-2019).
Kaljurand started in the Estonian Foreign Service in 1991 and held several prominent positions, including Estonian Ambassador to the State of Israel, the Russian Federation, United States of America, Canada, Mexico and Kazakhstan.
Kaljurand has served twice as the Estonian National Expert at the United Nations Group of Governmental Experts on Developments in the Field of Information and Telecommunications in the Context of International Security (GGE), in 2014-2015 and in 2016-2017.
Marina Kaljurand graduated cum laude from the Tartu University (1986, LLM). She has a professional diploma from the Estonian School of Diplomacy (1992) and MA from the Fletcher School of Law and Diplomacy, Tufts University (F95).
Member
European Parliament
Leontina Sandu, Head of Unit, Interoperability & Digital Government, DG DIGIT, European Commission Bio to follow.
Head of Unit, Interoperability & Digital Government, DG DIGIT
European Commission
Michael König, Head of Unit, Digital Platforms II, Markets and Cases VI: Digital Platforms, DG COMP, European Commission Mr. Michael KÖNIG is Head of Unit in the European Commission’s Directorate-General for Competition leading one of the units responsible for the implementation of the Digital Markets Act (DMA).
Before taking up this position in DG COMP, Mr König was advisor for platform regulation in DG CNECT and front line negotiator for the Digital Markets Act in the legislative process. He also served several years as Deputy Head of Unit in the European Commission’s Directorate-General for Internal Market, Industry, Entrepreneurship and SMEs (GROW) where he was primarily responsible for B2B relations regarding online platforms and negotiated the Regulation on fairness in platform-to-business relations (P2B Regulation).
Mr König joined the European Commission in 2001 in the Directorate-General for Competition. His assignments included a position as advisor to Directorate-General’s top management and a secondment to the OECD, before he joined the Internal Market Directorate-General in 2008. There he held positions in various policy areas including intellectual property and financial services.
Before joining the Commission, Mr. König worked for several years in the German Competition Authority and an international law firm.
Mr. König graduated in Law and Economics, and holds a PhD degree in Competition Law.
Head of Unit, Digital Platforms II, Markets and Cases VI: Digital Platforms, DG COMP
European Commission
Karolina Mojzesowicz, Deputy Head of Unit, Data Protection, DG JUSTICE, European Commission Karolina Mojzesowicz is the Deputy Head of Unit of the unit responsible for data protection at the European Commission (DG Justice and Consumers). She was one of the Commission’s representatives in the interinstitutional negotiations with Parliament and Council on the General data Protection Regulation (GDPR). She is now responsible for its implementation in the EU.
Mrs Mojzesowicz previously served as a member of the European Commission’s Legal Service, focusing on EU Competition law and International Trade law. In that capacity, she represented the Commission in numerous cases before the European Courts and before the WTO panels and Appellate Body. Mrs Mojzesowicz studied law in Poland, the Netherlands and Germany where she obtained her PhD in 2001.
Deputy Head of Unit, Data Protection, DG JUSTICE
European Commission
Joanna Jużak, Legal Officer, AI Office, DG CNECT, European Commission Bio to follow.
Legal Officer, AI Office, DG CNECT
European Commission
Kari Laumann, Head of Section, Research, Analysis and Policy, Norwegian Data Protection Authority (NDPA); Program Manager, Regulatory Sandbox for Privacy and AI Kari Laumann is Head of Section for Research, Analysis, and Policy at the Norwegian Data Protection Authority (Datatilsynet). She has been a leading figure in developing the Regulatory Sandbox for Privacy, Innovation and Digitalisation, a key initiative under Norway’s National Strategy for AI aimed at fostering innovative and responsible AI development. With a background in sociology, Kari has extensive experience in privacy and technology policy, including her tenure as VP for privacy in Telenor’s Asian operations and as an advisor to the Norwegian Parliament through the Board of Technology. Her work bridges the intersection of data protection, AI, and public policy, making her a leading voice in ethical tech governance.
Head of Section, Research, Analysis and Policy
Norwegian Data Protection Authority (NDPA)
Program Manager
Regulatory Sandbox for Privacy and AI
Fernando de Pablo Martín, Director General, Digital Office, City of Madrid Telecommunication Engineer with an extensive professional background in both the public and private sectors. He has over a decade of experience in the private sector, specializing in telecommunications and urban and environmental control systems. Since 1993, he has been employed at the Spanish Tax Agency, where he has held a range of positions and led key initiatives, including the implementation of the Law on electronic access to public services.
In addition, he has occupied senior roles within public administration, serving as Director General for the Promotion of Electronic Administration and Secretary General of Digital Administration. From 2017 to 2018, he served as the President of the Public Society for the Management of Innovation and Tourism Technologies (SEGITTUR). He currently holds the position of Director General of the Digital Office of Madrid, where he leads the city’s digital transformation and data & AI strategy.
Director General, Digital Office
City of Madrid
Cláudio Teixeira, Head of Digital Policy, BEUC Cláudio Teixeira is the Head of Digital Policy at BEUC, the European Consumer Organisation. Since 2021, Cláudio has led BEUC’s work on Telecommunications, Artificial Intelligence, and Cybersecurity. Prior to joining BEUC, he served as Junior Legal Attaché at the Permanent Representation of Portugal to the EU during the 2021 Portuguese Council Presidency, contributing to legislative negotiations such as the Digital Markets Act and the Public Country-by-Country Reporting Directive. He began his career in competition law at the Portuguese law firm VdA, following a traineeship at the European Parliament and extensive involvement in European youth NGOs. Cláudio holds a Bachelor and Master of Laws in EU Law from the University of Coimbra, and an LL.M. in European Law from the College of Europe in Bruges.
Head of Digital Policy
BEUC
Zdravko Vukić, Deputy Chair, EDPB Zdravko Vukić graduated from the Faculty of Law at the University of Osijek and holds a master’s degree in public administration. He further pursued studies in business economy and globalization in Zagreb, earning a master’s degree in economics from Libertas International University. Zdravko also possesses an internationally accredited ISO/IEC 27001:2022 Lead Auditor certificate in information security management systems, specializing in information security, cyber security, and privacy protection. Currently, he is finalizing his postgraduate studies with a thesis on Technical and Organizational Measures and Data Security.
From 2005 to 2016, he served as the Chief Human Resources Officer overseeing the organization’s employees and legal affairs. Additionally, between 2008 and 2016, he held the position of Data Protection Officer. Between 2016 and 2020, Zdravko held the role of Assistant Minister at the Ministry of Construction and Physical Planning, where he supervised the operations of the Directorates for Inspection Affairs, Supervision, and Information System Development.
In 2020, he was appointed as the Director of the Croatian Personal Data Protection Agency, and in February 2024 he was re-elected for another four-year term as director. Zdravko is a guest lecturer on personal data protection at various faculties in Croatia and is a member of the National Cybersecurity Council. He has been actively involved in the European Union initiative for institutional cooperation between Public Administrations of EU Member States and non-EU countries, focusing on aligning national legislation with EU regulations in personal data protection.
Under his guidance, the Croatian Personal Data Protection Agency organized the Spring Conference of the European Supervisory Authorities in 2022, a significant platform for cooperation among European data protection regulatory bodies. He played a key role in the implementation of the EU-funded projects ARC I and ARCII aimed to support SMEs in aligning with the GDPR.
Deputy Chair
EDPB
Ilias Chantzos, Global Privacy Officer and Head of EMEA Government Affairs, Broadcom Ilias Chantzos is Broadcom’s Global Privacy Officer and the Head of Government Affairs programmes for Europe, Middle East & Africa (EMEA). Chantzos leads the global privacy programme of Broadcom across the company’s multiple business units and regions. He also represents Broadcom before government bodies, national authorities and international organisations in EMEA advising on public policy issues.
Before joining Broadcom, Chantzos spent almost 16 years in various government affairs and legal roles in Symantec. During his last post with Symantec, he was in charge of the Government Affairs for the EMEA and the Asia Pacific Japan regions and the Global Advisor for Critical Infrastructure Protection and Privacy.
Before joining Symantec in 2004, Chantzos worked as legal and policy officer in the Directorate General Information Society of the European Commission focusing on information security policy. He covered the Council of Europe Cybercrime Convention and the Framework Decision on Attacks against Information Systems. In addition, he worked on a number of EU legislative initiatives relevant to information society and security, including directives on Privacy of Electronic Communications, the Data Retention Directive and the European Network and Information Security Agency (ENISA). He also represented the European Commission in various international debates and conferences.
Chantzos holds a law degree from Aristotle University, a Master degree in Computers and Communication Law from Queen Mary College, University of London and a Master in Business Administration from Solvay Business School. He has also completed executive education at Lee Kuan Yew School of Public Policy in Singapore and at the JFK School of Government in Harvard. Chantzos is a member of the Athens Bar Association. He served as Chairman of the Executive Board of TechAmerica Europe. He also served for four terms as Chairman of the European Policy Council of the Business Software Alliance (BSA). He has represented Symantec at the NATO Industry Cooperation Platform and he has been a member of the Advisory Board of the European Network and Information Security Agency (ENISA) from 2006 until 2020. He is also a member of Europol’s European Cybercrime Center (EC3) Advisory Board. Chantzos is a member of the Young Global Leaders 2014 class of the World Economic Forum. He speaks English, Greek, Dutch and German.
Global Privacy Officer and Head of EMEA Government Affairs
Broadcom
Yoon Jeong Choi, Head of the International Cooperation Division, South Korea’s Personal Information Protection Commission (PIPC) Ms. Yoon Jeong CHOI is the Director of International Cooperation Division at PIPC Korea. Her division is responsible for formulating policy and driving operations for cross-border transfer of personal information as well as digital trade, and fostering communication & cooperation with international organizations. Her roles prior to joining PIPC includes the Director of Privacy Protection & Ethics Division and Director of Internet User Policy Division, and Director of Broadcasting Advertisement Policy Division at Korea Communications Commission.
Before her career in the public sector, Ms. Choi was an attorney at Aram International Law Offices working in the fields of international trade, IT, and IP.
Ms. Choi earned an LL.M degree at the University of Southern California (Gould School of Law). She has a BA in Law as well as a BA in the Korean Language and Literature from Ewha Woman’s University.
Head of the International Cooperation Division
South Korea’s Personal Information Protection Commission (PIPC)
Maiko Meguro, Lead Coordinator on DFFT / Senior Policy Analyst, Directorate for Science, Technology, and Innovation, Data Flows, Governance and Privacy Division, OECD Maiko Meguro is a Senior Policy Analyst at the OECD, where she leads cross-border data flows and Data Free Flow with Trust (DFFT) initiatives, including the operationalization of the institutional arrangement for expert-policy cooperation. An international lawyer by training, she brings extensive experience spanning international organizations, government, and academia. Prior to joining the OECD, she served at Japan’s Digital Agency as Head of Division for International Data Strategy, acting as lead negotiator in G7/G20, OECD, and other regional/bilateral negotiations on the digital economy and co-chairing the G7 Digital Technology Working Group during Japan’s 2023 G7 Presidency. She has also held positions at Japan’s Ministry of Economy, Trade and Industry (METI), where she served as Head of Division for International Digital Policy and worked on climate change, energy policy, and trade negotiations, as well as at the European Commission’s DG CONNECT.
Lead Coordinator on DFFT / Senior Policy Analyst, Directorate for Science, Technology, and Innovation, Data Flows, Governance and Privacy Division
OECD
Itxaso Domínguez de Olazábal, Policy Advisor, EDRi Itxaso Domínguez de Olazábal, PhD, is an expert in data protection and privacy, with a focus on commercial surveillance and the multidimensional virtual harms caused by online tracking. She also specialises in online freedom of expression, examining the role of security forces in content governance. Her work critically explores the intersection of technology, various forms of surveillance, and the imperative to protect both individual and collective rights, particularly for vulnerable communities within, and outside, European borders. Dr. Domínguez de Olazábal has extensive experience in the field of digital rights, having worked with 7amleh, an organisation dedicated to defending Palestinian digital rights. There, she raised critical questions about the extraterritorial impact of EU digital laws, addressing issues such as content governance, the regulation (or lack thereof) of spyware, and corporate responsibility in violating the rights of the Global Majority.
Her diverse professional background includes roles within the European Parliament and the EU Delegation to Egypt, where she contributed to policy-making and diplomatic initiatives at both regional and international levels. In addition to her work at EDRi, Dr. Domínguez de Olazábal is a professor of international relations and geopolitics. She collaborates regularly with think tanks and academic institutions, using a critical and interdisciplinary approach to global politics. Her research examines key issues such as tech colonialism, racial capitalism, and the evolving dynamics of securitisation, with a particular focus on the SWANA region and the Mediterranean.
Policy Advisor
EDRi
Zdravko Vukić, Deputy Chair, EDPB Zdravko Vukić graduated from the Faculty of Law at the University of Osijek and holds a master’s degree in public administration. He further pursued studies in business economy and globalization in Zagreb, earning a master’s degree in economics from Libertas International University. Zdravko also possesses an internationally accredited ISO/IEC 27001:2022 Lead Auditor certificate in information security management systems, specializing in information security, cyber security, and privacy protection. Currently, he is finalizing his postgraduate studies with a thesis on Technical and Organizational Measures and Data Security.
From 2005 to 2016, he served as the Chief Human Resources Officer overseeing the organization’s employees and legal affairs. Additionally, between 2008 and 2016, he held the position of Data Protection Officer. Between 2016 and 2020, Zdravko held the role of Assistant Minister at the Ministry of Construction and Physical Planning, where he supervised the operations of the Directorates for Inspection Affairs, Supervision, and Information System Development.
In 2020, he was appointed as the Director of the Croatian Personal Data Protection Agency, and in February 2024 he was re-elected for another four-year term as director. Zdravko is a guest lecturer on personal data protection at various faculties in Croatia and is a member of the National Cybersecurity Council. He has been actively involved in the European Union initiative for institutional cooperation between Public Administrations of EU Member States and non-EU countries, focusing on aligning national legislation with EU regulations in personal data protection.
Under his guidance, the Croatian Personal Data Protection Agency organized the Spring Conference of the European Supervisory Authorities in 2022, a significant platform for cooperation among European data protection regulatory bodies. He played a key role in the implementation of the EU-funded projects ARC I and ARCII aimed to support SMEs in aligning with the GDPR.
Deputy Chair
EDPB
Ilias Chantzos, Global Privacy Officer and Head of EMEA Government Affairs, Broadcom Ilias Chantzos is Broadcom’s Global Privacy Officer and the Head of Government Affairs programmes for Europe, Middle East & Africa (EMEA). Chantzos leads the global privacy programme of Broadcom across the company’s multiple business units and regions. He also represents Broadcom before government bodies, national authorities and international organisations in EMEA advising on public policy issues.
Before joining Broadcom, Chantzos spent almost 16 years in various government affairs and legal roles in Symantec. During his last post with Symantec, he was in charge of the Government Affairs for the EMEA and the Asia Pacific Japan regions and the Global Advisor for Critical Infrastructure Protection and Privacy.
Before joining Symantec in 2004, Chantzos worked as legal and policy officer in the Directorate General Information Society of the European Commission focusing on information security policy. He covered the Council of Europe Cybercrime Convention and the Framework Decision on Attacks against Information Systems. In addition, he worked on a number of EU legislative initiatives relevant to information society and security, including directives on Privacy of Electronic Communications, the Data Retention Directive and the European Network and Information Security Agency (ENISA). He also represented the European Commission in various international debates and conferences.
Chantzos holds a law degree from Aristotle University, a Master degree in Computers and Communication Law from Queen Mary College, University of London and a Master in Business Administration from Solvay Business School. He has also completed executive education at Lee Kuan Yew School of Public Policy in Singapore and at the JFK School of Government in Harvard. Chantzos is a member of the Athens Bar Association. He served as Chairman of the Executive Board of TechAmerica Europe. He also served for four terms as Chairman of the European Policy Council of the Business Software Alliance (BSA). He has represented Symantec at the NATO Industry Cooperation Platform and he has been a member of the Advisory Board of the European Network and Information Security Agency (ENISA) from 2006 until 2020. He is also a member of Europol’s European Cybercrime Center (EC3) Advisory Board. Chantzos is a member of the Young Global Leaders 2014 class of the World Economic Forum. He speaks English, Greek, Dutch and German.
Global Privacy Officer and Head of EMEA Government Affairs
Broadcom
Maiko Meguro, Lead Coordinator on DFFT / Senior Policy Analyst, Directorate for Science, Technology, and Innovation, Data Flows, Governance and Privacy Division, OECD Maiko Meguro is a Senior Policy Analyst at the OECD, where she leads cross-border data flows and Data Free Flow with Trust (DFFT) initiatives, including the operationalization of the institutional arrangement for expert-policy cooperation. An international lawyer by training, she brings extensive experience spanning international organizations, government, and academia. Prior to joining the OECD, she served at Japan’s Digital Agency as Head of Division for International Data Strategy, acting as lead negotiator in G7/G20, OECD, and other regional/bilateral negotiations on the digital economy and co-chairing the G7 Digital Technology Working Group during Japan’s 2023 G7 Presidency. She has also held positions at Japan’s Ministry of Economy, Trade and Industry (METI), where she served as Head of Division for International Digital Policy and worked on climate change, energy policy, and trade negotiations, as well as at the European Commission’s DG CONNECT.
Lead Coordinator on DFFT / Senior Policy Analyst, Directorate for Science, Technology, and Innovation, Data Flows, Governance and Privacy Division
OECD
Maiko Meguro, Lead Coordinator on DFFT / Senior Policy Analyst, Directorate for Science, Technology, and Innovation, Data Flows, Governance and Privacy Division, OECD Maiko Meguro is a Senior Policy Analyst at the OECD, where she leads cross-border data flows and Data Free Flow with Trust (DFFT) initiatives, including the operationalization of the institutional arrangement for expert-policy cooperation. An international lawyer by training, she brings extensive experience spanning international organizations, government, and academia. Prior to joining the OECD, she served at Japan’s Digital Agency as Head of Division for International Data Strategy, acting as lead negotiator in G7/G20, OECD, and other regional/bilateral negotiations on the digital economy and co-chairing the G7 Digital Technology Working Group during Japan’s 2023 G7 Presidency. She has also held positions at Japan’s Ministry of Economy, Trade and Industry (METI), where she served as Head of Division for International Digital Policy and worked on climate change, energy policy, and trade negotiations, as well as at the European Commission’s DG CONNECT.
Lead Coordinator on DFFT / Senior Policy Analyst, Directorate for Science, Technology, and Innovation, Data Flows, Governance and Privacy Division
OECD
*** TIMES ARE IN CET ***
Seven years after the GDPR reshaped global data governance, Europe has entered a new phase of regulatory refinement in privacy. The publication of the Digital Omnibus Package and the agreement on the GDPR Procedural Regulation mark pivotal moments as the EU seeks to reduce red tape, strengthen cross-border enforcement, and bolster the continent’s competitiveness in the data-driven economy by addressing a complex constellation of overlapping laws, all while safeguarding individuals’ fundamental rights. With the proposed targeted amendments to the GDPR, which aim to clarify the definition of personal data, streamline certain transparency obligations, improve conditions for scientific research, and recognise legitimate interests in AI system development, the European Commission aims to bring much-needed legal certainty. Yet these efforts have sparked intense debate, with some stakeholders welcoming simplification to unlock innovation and level the playing field with global competitors, while others warn of a potential erosion of safeguards at the heart of the GDPR, particularly around accountability, transparency and data subject rights.
Meanwhile, the GDPR Procedural Regulation seeks to resolve long-standing bottlenecks within the One-Stop-Shop mechanism by harmonising admissibility criteria, strengthening cooperation between national supervisory authorities, and introducing binding deadlines for investigations. But questions remain about whether these new procedures will truly accelerate cross-border cases or introduce new layers of administrative complexity.
Against this backdrop, this session will unpack what these reforms mean for the future of European data privacy. Panellists will assess whether they meaningfully reduce compliance burdens, foster responsible digital tech development and support a harmonised Digital Single Market or whether further work is needed to reconcile innovation, legal certainty and fundamental rights protection.
Possible questions:
In an era defined by hyper-personalisation and AI-driven services, where nearly every digital interaction can be tracked, analysed and monetised, the tension between seamless user experiences and meaningful individual control has intensified. In Europe, the regulatory response spans multiple frameworks, such as the GDPR, ePrivacy reforms, the Digital Services Act, and the anticipated Digital Fairness Act, each addressing distinct yet interconnected dimensions of the digital economy. Recent EDPB guidelines on the DSA-GDPR interplay, along with proposed measures in the Digital Simplification Package around automated consent mechanisms, new tracking technology rules, and the Digital Fairness Act’s anticipated provisions on manipulative design, collectively signal Europe’s determination to shield users from dark patterns, unfair personalisation and opaque data practices.
This session will examine whether Europe’s evolving digital rulebook can successfully anchor innovation in a framework of fairness, trust and user empowerment. Panellists will explore the EDPB’s latest guidance on GDPR–DSA interplay, the implications of automated consent mechanisms and browser-based signals, the DFA’s forthcoming impact on advertising models, persuasive vs. manipulative design, and the future of AdTech. Against the backdrop of widespread consent fatigue and declining public trust, the discussion will ask whether simplification will truly deliver user empowerment or risks undermining the very individuals these reforms aim to protect. Speakers will assess what coherent, future-proof enforcement looks like, how organisations can provide meaningful transparency, and how placing individuals at the centre can become a competitive advantage in Europe’s digital economy.
Possible questions:
The digital economy has fundamentally altered the regulatory landscape, forcing a convergence of two regimes that once operated in silos: Competition Law and Data Protection. The implementation of the DMA, together with the ongoing application of the GDPR, has transformed Europe’s regulatory ecosystem, forcing regulators, gatekeepers, and business users alike to confront how these frameworks intersect, complement, and challenge one another. As the European Commission and European Data Protection Board have issued joint guidance on the interplay between the DMA and GDPR clarifying how gatekeepers should navigate DMA obligations (such as real-time data portability, data access for business users, and interoperability) while remaining fully compliant with GDPR principles on consent, minimisation, anonymisation, and purpose limitation, critical questions have emerged: Can privacy enforcement unlock competition by reducing data-driven market power? Or will the compliance burden disproportionately advantage large incumbents? Do interoperability and data-sharing obligations risk conflicting with GDPR provisions? What does this regulatory convergence mean for innovation, AI development, and the competitiveness of the EU’s digital sector?
In an increasingly connected world, the smooth and secure flow of personal data across borders is the lifeblood of the global digital economy. However, as geopolitical shifts influence policy and countries adopt unique national approaches to data protection and digital sovereignty strategies, international organizations are left to navigate a maze of divergent regulatory frameworks. Policymakers, regulators, and industry actors worldwide are increasingly focusing on interoperability and on practical ways for data protection frameworks to work together without lowering standards.
This session will explore how to strengthen high-level data protection while enabling the secure and seamless transfer of personal information worldwide. Speakers will examine progress to date, including progress toward adequacy decisions, mutual recognition and shared standards, and discuss the further steps needed to reduce complexity for organisations, enhance legal certainty, and deliver stronger protections for individuals, regardless of where their data travels.
Possible questions:
As governments accelerate the digitisation of public services, they face a critical dual imperative: leveraging innovation to enhance service delivery while strictly safeguarding citizen privacy. Public agencies are the custodians of society’s most sensitive assets, from healthcare records to national security data, while navigating an increasingly complex landscape of cyber threats, legacy systems, data silos and growing public expectations for transparency and trust. How can Public Authorities harness the power of digital innovation while maintaining the trust that underpins democratic governance?
This session will examine the complex intersection of data sovereignty, cybersecurity, and privacy rights in the public sector. The discussion will address how modern regulatory frameworks, including the EU Digital Identity Wallet and evolving data protection standards, are shaping the landscape of digital public services. Participants will explore the opportunities and risks associated with cloud computing, AI deployment, and data retention practices in government contexts. The session will also explore how innovation, modern governance, and privacy-by-design principles can enable governments to manage, share, and protect data responsibly and effectively. It will address the persistent structural challenges facing the public sector, from data silos to outdated infrastructure and high-velocity data streams, and discuss what is needed to build secure, future-ready public services that enhance public trust.
Possible questions:
The rapid ascent of generative and agentic AI has intensified long-standing questions around data collection, training practices, transparency, and the rights of individuals whose personal data fuels these technologies. Indeed, from training data to automated decision-making outputs, personal data can be implicated at every stage of the AI lifecycle, and ensuring coordinated, complementary rules between AI and data protection regimes is therefore essential to providing legal certainty, preserving cross-border data flows, and enabling responsible AI deployment.
This session will explore how privacy-by-design, data minimisation, PETs, and emerging governance frameworks can enable responsible, trustworthy high-impact AI innovation without compromising data protection. Speakers will also examine how the GDPR, the EU AI Act, and international regulatory initiatives interact, discuss the evolving role of Data Protection Authorities in AI oversight, and examine emerging operational models for assessing risks associated with large language models and agentic AI. This session offers a roadmap for building trust-based, compliant AI ecosystems that protect privacy, support digital sovereignty, unlock data value, and deliver social and economic benefits for the greater good.
Possible questions:
Seven years after the GDPR reshaped global data governance, Europe has entered a new phase of regulatory refinement in privacy. The publication of the Digital Omnibus Package and the agreement on the GDPR Procedural Regulation mark pivotal moments as the EU seeks to reduce red tape, strengthen cross-border enforcement, and bolster the continent’s competitiveness in the data-driven economy by addressing a complex constellation of overlapping laws, all while safeguarding individuals’ fundamental rights. With the proposed targeted amendments to the GDPR, which aim to clarify the definition of personal data, streamline certain transparency obligations, improve conditions for scientific research, and recognise legitimate interests in AI system development, the European Commission aims to bring much-needed legal certainty. Yet these efforts have sparked intense debate, with some stakeholders welcoming simplification to unlock innovation and level the playing field with global competitors, while others warn of a potential erosion of safeguards at the heart of the GDPR, particularly around accountability, transparency and data subject rights.
Meanwhile, the GDPR Procedural Regulation seeks to resolve long-standing bottlenecks within the One-Stop-Shop mechanism by harmonising admissibility criteria, strengthening cooperation between national supervisory authorities, and introducing binding deadlines for investigations. But questions remain about whether these new procedures will truly accelerate cross-border cases or introduce new layers of administrative complexity.
Against this backdrop, this session will unpack what these reforms mean for the future of European data privacy. Panellists will assess whether they meaningfully reduce compliance burdens, foster responsible digital tech development and support a harmonised Digital Single Market or whether further work is needed to reconcile innovation, legal certainty and fundamental rights protection.
Possible questions:
In an era defined by hyper-personalisation and AI-driven services, where nearly every digital interaction can be tracked, analysed and monetised, the tension between seamless user experiences and meaningful individual control has intensified. In Europe, the regulatory response spans multiple frameworks, such as the GDPR, ePrivacy reforms, the Digital Services Act, and the anticipated Digital Fairness Act, each addressing distinct yet interconnected dimensions of the digital economy. Recent EDPB guidelines on the DSA-GDPR interplay, along with proposed measures in the Digital Simplification Package around automated consent mechanisms, new tracking technology rules, and the Digital Fairness Act’s anticipated provisions on manipulative design, collectively signal Europe’s determination to shield users from dark patterns, unfair personalisation and opaque data practices.
This session will examine whether Europe’s evolving digital rulebook can successfully anchor innovation in a framework of fairness, trust and user empowerment. Panellists will explore the EDPB’s latest guidance on GDPR–DSA interplay, the implications of automated consent mechanisms and browser-based signals, the DFA’s forthcoming impact on advertising models, persuasive vs. manipulative design, and the future of AdTech. Against the backdrop of widespread consent fatigue and declining public trust, the discussion will ask whether simplification will truly deliver user empowerment or risks undermining the very individuals these reforms aim to protect. Speakers will assess what coherent, future-proof enforcement looks like, how organisations can provide meaningful transparency, and how placing individuals at the centre can become a competitive advantage in Europe’s digital economy.
Possible questions:
The digital economy has fundamentally altered the regulatory landscape, forcing a convergence of two regimes that once operated in silos: Competition Law and Data Protection. The implementation of the DMA, together with the ongoing application of the GDPR, has transformed Europe’s regulatory ecosystem, forcing regulators, gatekeepers, and business users alike to confront how these frameworks intersect, complement, and challenge one another. As the European Commission and European Data Protection Board have issued joint guidance on the interplay between the DMA and GDPR clarifying how gatekeepers should navigate DMA obligations (such as real-time data portability, data access for business users, and interoperability) while remaining fully compliant with GDPR principles on consent, minimisation, anonymisation, and purpose limitation, critical questions have emerged: Can privacy enforcement unlock competition by reducing data-driven market power? Or will the compliance burden disproportionately advantage large incumbents? Do interoperability and data-sharing obligations risk conflicting with GDPR provisions? What does this regulatory convergence mean for innovation, AI development, and the competitiveness of the EU’s digital sector?
In an increasingly connected world, the smooth and secure flow of personal data across borders is the lifeblood of the global digital economy. However, as geopolitical shifts influence policy and countries adopt unique national approaches to data protection and digital sovereignty strategies, international organizations are left to navigate a maze of divergent regulatory frameworks. Policymakers, regulators, and industry actors worldwide are increasingly focusing on interoperability and on practical ways for data protection frameworks to work together without lowering standards.
This session will explore how to strengthen high-level data protection while enabling the secure and seamless transfer of personal information worldwide. Speakers will examine progress to date, including progress toward adequacy decisions, mutual recognition and shared standards, and discuss the further steps needed to reduce complexity for organisations, enhance legal certainty, and deliver stronger protections for individuals, regardless of where their data travels.
Possible questions:
As governments accelerate the digitisation of public services, they face a critical dual imperative: leveraging innovation to enhance service delivery while strictly safeguarding citizen privacy. Public agencies are the custodians of society’s most sensitive assets, from healthcare records to national security data, while navigating an increasingly complex landscape of cyber threats, legacy systems, data silos and growing public expectations for transparency and trust. How can Public Authorities harness the power of digital innovation while maintaining the trust that underpins democratic governance?
This session will examine the complex intersection of data sovereignty, cybersecurity, and privacy rights in the public sector. The discussion will address how modern regulatory frameworks, including the EU Digital Identity Wallet and evolving data protection standards, are shaping the landscape of digital public services. Participants will explore the opportunities and risks associated with cloud computing, AI deployment, and data retention practices in government contexts. The session will also explore how innovation, modern governance, and privacy-by-design principles can enable governments to manage, share, and protect data responsibly and effectively. It will address the persistent structural challenges facing the public sector, from data silos to outdated infrastructure and high-velocity data streams, and discuss what is needed to build secure, future-ready public services that enhance public trust.
Possible questions:
The rapid ascent of generative and agentic AI has intensified long-standing questions around data collection, training practices, transparency, and the rights of individuals whose personal data fuels these technologies. Indeed, from training data to automated decision-making outputs, personal data can be implicated at every stage of the AI lifecycle, and ensuring coordinated, complementary rules between AI and data protection regimes is therefore essential to providing legal certainty, preserving cross-border data flows, and enabling responsible AI deployment.
This session will explore how privacy-by-design, data minimisation, PETs, and emerging governance frameworks can enable responsible, trustworthy high-impact AI innovation without compromising data protection. Speakers will also examine how the GDPR, the EU AI Act, and international regulatory initiatives interact, discuss the evolving role of Data Protection Authorities in AI oversight, and examine emerging operational models for assessing risks associated with large language models and agentic AI. This session offers a roadmap for building trust-based, compliant AI ecosystems that protect privacy, support digital sovereignty, unlock data value, and deliver social and economic benefits for the greater good.
Possible questions:
For further details on the 2025 edition, you can view the previous event website here.

































Applies to: Corporate Organisations, Trade Associations, Law Firms
Applies to: NGO / Not for Profit, Academic / Student
Applies to: European Commission / Parliament / Council, National Government / Regulator, Diplomatic Missions to the EU, Permanent Representations to the EU, Accredited Journalists
* Please note that fees do not include Belgian VAT @ 21%, and this amount will be added to the total price when you are invoiced.
Please note that all registrations are subject to review by the organisers. The organisational categories listed reflect the most common participant profiles from previous editions and may not cover every individual circumstance. If you are unsure which category applies to you, please contact us via the Contact section before completing your registration. Selecting an incorrect category may delay or prevent confirmation of your place at the event. We are always happy to assist to ensure the correct category is selected.
Number of delegates
3-5
6-8
9+
Group discount
10%
20%
25%
To discuss sponsorship and visibility opportunities at the 15th Annual European Data Protection & Privacy Conference, please contact Anne-Lise Simon on [email protected]
Exclusive speaking positions | Your organisation can contribute to the discussion.
Engaging and Interactive format | Engage in a fully immersive and interactive debate with decision makers, businesses and policymakers.
European and global outreach | Convey your message to a broad and international audience.
Networking opportunities | Connect with your fellow attendees during coffee and lunch breaks throughout the event.
Visibility Opportunities | Ensure maximum visibility through branding in the room, on the event website and marketing activities.
Rue du Parnasse 19, Brussels, Belgium, 1050
For more information on any aspect of this event, please contact Karolina Stankiewicz using any of the details below.
Karolina Stankiewicz
Event Manager
Forum Europe
+44 (0) 7845 645 853
[email protected]
Sign up to receive updates on our upcoming policy events. We will only send you emails about the conferences and topics that interest you, and you can unsubscribe at any time.