IAPP (International)
Isabelle Roccia (moderator, IAPP, International), Clément Perarnaud (Brussels School of Governance, VUB, Belgium), Paul McDonagh-Forde (The Data Protection Commission, Ireland), Thomas Boué (Business Software Alliance (BSA), International)
The political concept of ‘digital sovereignty’ comes in many shades globally. It is often anchored in securing control over data, technology, infrastructure, guided by ambitions of resilience, prosperity, security and privacy, overall reducing dependencies. In Europe, sovereignty already transpires across rules governing the use of personal and non-personal data, addressing supply-chain security, requiring domestic solutions and storage limitations among others. Legislative proposals in data, cybersecurity and artificial intelligence are set to further the EU level approach to tech sovereignty at a time of severe geopolitical disruption. These policies have consequential governance implications for providers, customers and consumers alike.
Academic
Business
Policy
Utrecht University - Data School (Netherlands)
Sanne Janssen (moderator, Utrecht University - Data School, Netherlands), Katalin Feher (KU Leuven, EU/UN Expert, Hungary), Nadia Benaissa (Bits of Freedom, Netherlands), Oliver Marsh (AlgorithmWatch, Germany), Mirko Tobias Schäfer (Utrecht University - Data School, Netherlands)
The alliance of far-right politics and tech bro’s in the Trump administration has politicized artificial intelligence and fueled the so-called global AI race. It shaped a narrative of AI as inevitable for economic progress, and acceptance for sacrificing civil rights, social cohesion, and shared values for a vague promise of innovation. The EU Commission backpaddled on their own AI and data protection regulations. This combination of technical incompetence, political cowardness and intellectual laziness might undermine civil rights and actual opportunities for socially desirable AI futures in Europe. This panel takes measures of the damage done and proposes ways forward for contesting AI and defending democracy. Perspectives shared in this panel come from experts in advocacy, research and politics, to build capacities and practices for aligning algorithmic systems with social norms and values of our open and democratic societies in Europe.
Academic
Business
Policy
Brussels Privacy Hub (Belgium)
Sophie Stalla-Bourdillon (moderator, VUB, Belgium), Karen De Raeymaecker (VUB, Belgium), Camille Biot (Forum des Jeunes, Europe), Carly Kind (OAIC, Australia), Ben Brake (DOT Europe, Europe)
Strict age-gating measures are increasingly promoted in digital policy debates as tools for child protection. When applied rigidly, however, they can create barriers to participation that extend beyond their intended purpose. By segmenting users along fixed age thresholds, such measures may restrict access to information, constrain the circulation of experience and informal learning, and disrupt intergenerational exchange that underpin open digital environments. At the same time, strict age-gating can weaken privacy, discouraging engagement with sensitive yet lawful content, particularly among younger and vulnerable users. Yet, exposure to diverse perspectives and supportive online socialisation play an important role in wellbeing. This panel examines the proportionality and systemic effects of age-gating, drawing on recent Australian policy developments, including social media bans, alongside industry-led age assurance practices. It engages young people and psychologists to assess the value of peer-based and cross-generational socialisation online.
Academic
Business
Policy
Action Line 4, QDNL (Netherlands)
Joris van Hoboken (moderator, Institute for Information Law (IViR), Netherlands), Plixavra Vogiatzoglou (Institute for Information Law (IViR), Netherlands), Thomas Streinz (European University Institute, Italy), Zuzanna Warso (Open Future, Netherlands), Alexandra Paul (Pasqal, Belgium)
As Big Tech controls most of the digital infrastructure on which everyday practices depend, digital sovereignty has emerged as a countervailing strategy to (re)gain control over data, technologies, and infrastructures, thereby safeguarding autonomy and self-determination in the digital era. The EU’s digital sovereignty agenda emphasises investment in sectors it considers critical, like artificial intelligence and quantum technologies. Industry and civil society also advocate for domestic alternatives to hyperscalers. The various digital sovereignty visions share commonalities; they highlight the need for European-based infrastructures that comply with EU digital rules, but raise similar concerns about underlying dependencies and geopolitical tensions. At the same time, they differ in the futures they imagine, from becoming a global leader to developing open-source solutions. This panel will investigate what digital sovereignty entails nowadays and the different pathways, from private to public digital infrastructures, towards achieving it.
Academic
Policy
Vrije Universiteit Amsterdam (Netherlands)
Johan van Banning (moderator, Vrije Universiteit Amsterdam, Netherlands), Teresa Quintel (European Parliament, International), Katalin Ligeti (Université du Luxembourg, Luxembourg), Mojca Plesničar (Institute of Criminology at the faculty of law Ljubljana, Slovenia), Lonneke Stevens (Change Programme Data Driven Policing, Dutch Police, Netherlands)
Due to the increasing datafication of the lives of European citizens, the collection and especially the analysis of large datasets through AI systems becomes an ever more important tool for criminal investigations. Examples of such datasets are those resulting from the EncroChat and Sky ECC cryptophone operations, but even modern smartphones may yield enormous amounts of data, revealing personal information about many individuals that are of no interest to law enforcement whatsoever. When the outcome of the analysis of such datasets is used during criminal proceedings, the fundamental rights of both the defendant and other individuals may be compromised. In this session, we will critically examine how AI systems can be adopted for the analysis of large datasets in criminal investigations, and which possibilities exist for ensuring that fundamental rights of suspects, defendants and others are still respected.
dpo pro (Belgium)
Jacques Folon (dpo pro, Belgium)
dpo pro is a Belgian professional association for and by DPOs. We aim to bring DPO's together and to let them learn from one another. We want to be a platform for discussion and enhance academic research. We will work with different topics and questions so the participants can learn from another and the pro's and con's of certification of DPOs can be well-structured. We will also include exemples and existing projects (p. ex. CNPD). Some questions to explore: Would DPO certification really enhance the credibility of professionals in the eyes of senior management and business teams? Do self-certifications of DPO training courses really guarantee a consistent level of competence, or do they create an illusion of standardisation? Is organisational certification possible for the GDPR? How can we ensure that certifications remain relevant in the face of technological (AI, blockchain, IoT) and regulatory developments?
Academic
Business
Policy
EU Agency for Fundamental Rights (FRA) (Europe)
Elise Lassus (moderator, EU Agency for Fundamental Rights (FRA), Europe), Liam Behan (An Garda Síochána, Ireland), Anna Moscibroda (European Commission (DG JUST), Belgium), Chloé Berthélémy (EDRi European Digital Rights, Belgium), Stéphanie Mihail (European Data Protection Board (EDPB), International)
While the GDPR has been the focus of many debates, the legal framework governing the use of personal data by law enforcement has often gone unnoticed: the law enforcement directive. The way police can use personal data for investigations is also limited by data protection, yet its implementation remains challenging. By bringing together practitioners and experts, this panel aims to bridge the gap between legal principles and operational realities on the ground. We’ll look at the day‑to‑day challenges law enforcement authorities face in applying the LED’s safeguards and highlight the organisational and technical measures that genuinely help operational staff get data protection right. As law enforcement increasingly relies on digital tools and data analytics, the discussion will also consider how new technologies can be developed and used in full respect of fundamental rights.
Academic
Business
Policy
CPDP (Belgium)
Isabelle Vereecken (moderator, EDPB, Europe), Paul Jordan (CEDPO, Europe), Thomas Ajoodha (AFCDP, France), Bénédicte Raevens (European Data Protection Supervisor, Belgium), Daniel Okma (Uber, International)
Panel Description (140 words): Data Protection Officers increasingly operate in complex, interconnected environments where cooperation is not optional but essential. This panel explores how collaboration between DPOs can enhance governance, trust, and transparency across sectors and borders. We examine how the GDPR encourages mutual support, how the European Data Protection Board enables consistent interpretation, and how professional associations build shared knowledge and capacity. Through practical insights from experienced DPOs, the session highlights what successful collaboration looks like in practice, the institutional tensions that can arise, and how cooperative structures can strengthen digital sovereignty. The panel aims to identify concrete mechanisms, networks, and habits that empower DPOs to work together more effectively.
Academic
Business
Policy
European Digital Rights (EDRi) (Belgium)
Yassine Chagh (moderator, The International Lesbian, Gay, Bisexual, Transgender, Queer & Intersex Youth and Student Organisation (IGLYO), International), Luisa Franco Machado (Equilabs, Brazil), Siméon de Brouwer (European Digital Rights (EDRi), Belgium), Stefi Richani (Equinox Initiative for Racial Justice, Belgium), Felix Reda (Github, International)
While the risks and harms of online spaces are being discussed at length in contemporary debates of youth protection, their benefits are often not part of the equation. Whether the focus is on social networks, messaging apps or chatbots, the debates lean towards highly paternalistic/protectionist approaches, often without questioning who defines harm and whose voices are centred. This panel will delve into the benefits and positive impact of the ‘online world’ on youth – and in particular on marginalised youth – and will make a case for strategies which support healthy development without being at the expense of their empowerment, agency, or fundamental rights. At a time where half of the world population is under 30 years old, we make a case for centring diverse youth voices as legitimate and autonomous decision-makers, not as an afterthought.
Academic
Business
Policy
Law Department, University of Turin (Italy)
Ludovica Paseri (moderator, Law Department, University of Turin, Italy), Sofia Ranchordás (Tilburg Law School, Netherlands), Teodora Groza (Faculty of Law, University of Tübingen, Germany), Veronique Ciminà (Directorate-General for Communication Networks, Content and Technology, European Commission, Belgium), Laura Caroli (Women in AI Belgium, International)
The complex interplay of the GDPR, DSA, Data Act, and AI Act draws a tension to the crucial notion of public interest. Although widely invoked in data governance, public interest lacks nonetheless a unified definition, shifting across legal-philosophical traditions policy and competing visions. Building on a theoretical framework rooted in nearly a decade of GDPR practice, the discussion examines how newer regulations reinterpret public interest when addressing platform governance, data sharing, and AI oversight. Particular attention is given to how these instruments respond to individual and structural vulnerabilities, and to the tension between regulatory flexibility and eGective protection. The panel assesses mechanisms for coherence and accountability across Europe’s digital rulebook, asking how robust enforcement and oversight can be ensured without drifting toward deregulation or weakening fundamental rights.
CPDP (Belgium)
Alicja Joanna Kucharska (moderator, Tilburg University - Tilburg Institute for Law, Technology and Society (TILT), Netherlands), Luisa Maciel Perez (European Master in Law, Data and AI (EMILDAI), Europe), Stephanie von Maltzan (FIZ Karlsruhe – Leibniz Institute for Information Infrastructure, Germany), Julia Krämer (Erasmus University Rotterdam, Netherlands), Stella Anne Ming Hui Teoh (Kyushu University, Japan)
The three academic sessions are an integral part of CPDP's mission to connect scholarship with practice and policymaking. In 2026, Academic Session I brings a legal sciences perspective to questions of data protection, privacy, and digital governance. Papers were selected through an open call and presented to foster exchange beyond academia. From the global reach of EU regulation to the granular mechanics of individual rights, the session traces how legal frameworks are tested and reshaped in a digital world. The session features the papers De Jure Brussels Effect: Lessons to the European Union about Digital Regulatory Frameworks according to the experiences of Brazil and Mexico (Luisa Maciel Perez & Mariana De Hoyos), Distributed Memory, Unlearning and the Governance of Forgetting in Large Language Models under the GDPR (Stephanie von Maltzan), The Disparity of Privacy Preference and Cookie "Choice": Is Design more Important than What You Want? (Julia Krämer), and ARCO Rights as the GDPR Legacy (Stella Anne Ming Hui Teoh).
Le Cnam (France)
Stefania Di Stefano (Le Cnam, France), Clara Tabuteau (Le Cnam, France), Suzanne Vergnolle (Le Cnam, France)
Impact and risks assessments are at the core of multiple digital regulations: General Data Protection Regulation (GDPR), AI Act (AIA), Digital Services Act (DSA)… But what can be learned from these experiences? This workshop seeks to enhance the DSA’s risk assessment framework for very large online services. Indeed, early reports lack depth and transparency, often prioritizing formality over substance. Meanwhile, the Privacy Impact Assessments (PIA), with their emphasis on proactive risk identification, stakeholder engagement, and accountability, appear to be an interesting model to learn from. The workshop will convene different stakeholders to: - Analyze the GDPR’s PIA methodologies (stakeholder consultations, risk documentation, iterative assessments); - Compare the DSA and GDPR approaches; - Identify best practices from PIAs to improve the DSA’s rigor, transparency, and accountability. Through collaborative brainstorming and group work, participants will develop and present key recommendations outlining actionable steps for regulators, platforms, and practitioners.
University of Münster (Germany)
Paulina Jo Pesch (FAU Erlangen-Nürnberg, Germany), Martin Bernklau (-, Germany), Kristina Magnussen (University of Münster, Germany)
Due to “hallucinations” and uncurated training data, Large Language Models (LLMs) frequently output false information concerning natural persons. As technical privacy research on LLMs is still at an early stage, there is currently little work concerning these personal data inaccuracies. They are also underexplored in legal discussion. In this workshop, participants gain a deeper understanding of this important issue, both from a legal and technical side. Martin Bernklau, who is a prominent victim of personal data inaccuracies generated by Bing Copilot, will discuss his experience with the participants. We then provide a taxonomy of personal data inaccuracies. The participants are asked to challenge this taxonomy for completeness and precision in interactive discussion and to come up with their own examples. We will incorporate this feedback into future versions of the taxonomy.
University of Florence (Italy)
Fabio Seferi (IMT Lucca, Italy), Filippo Bagni (IMT Lucca, Italy), Andrea Simoncini (University of Florence, Italy), Erik Longo (University of Florence, Italy)
This roundtable gathers academics, regulators, and practitioners to rethink how AI regulatory sandboxes can advance trustworthy innovation while reconfiguring accountability in data governance. Organised by the CybeRights Centre of the University of Florence, it aims to feature voices from the AI Office, EDPS, and national authorities to explore the promise and pitfalls of experimentation in EU regulatory practice. The discussion will deal with forward‑looking questions: Can sandboxes be more than compliance tools - acting instead as laboratories for rewriting AI and data governance? How might sandboxes redistribute trust and responsibility across public and private actors? What forms of evidence should (or should not) shape the next generation of digital regulation? Through dialogic exchange, participants will co‑develop insights for adaptive, ethically grounded models of regulatory experimentation. This will lay the groundwork for a joint publication documenting sandbox governance prototypes and their implications for trustworthy AI across Europe.
Ghent University - imec (Belgium)
Beatriz Esteves (Ghent University - imec, Belgium), Marlin Udo Kisia (Ghent University - imec, Belgium), Ruben Verborgh (Ghent University, Belgium)
Public debates on privacy often assume that personal data flows too freely. We argue the opposite: data frequently does not flow well enough, leading organizations to rely on inefficient, opaque, or even unlawful shortcuts to enable exchange. This workshop explores how personalized, tech-assisted trust can create lawful, sustainable, and economically valuable data-sharing ecosystems beyond the overreliance on consent. We will discuss emerging approaches in data protection engineering technologies, machine-readable agreements, and automated compliance tools that enable dynamic negotiation of legal grounds for data use. The workshop will combine (1) short expert presentations on topics such as techno-legal tools and the economic value of responsible data sharing, (2) facilitated small-group discussions to identify barriers and opportunities across sectors, and (3) a collaborative manifesto-writing session. The outcome will be an action-oriented manifesto outlining technical, legal, and governance steps to foster trusted data flows, to be shared across other conference sessions and communities.
This panel brings together artist Geeske Janßen and philosopher-artist Judith Zoe Blijden to explore the intimate, often invisible bonds that can form between humans and artificial intelligence. Drawing on their distinct artistic practices, both artists trace the delicate negotiations that unfold where the familiar meets the radically unknown — attending to quiet dependencies, subtle textures, and the unexpected tenderness that emerges when self and other blur.
Moderated by Professor Joel Baumann of the Kunsthochschule Kassel and artist-researcher Laura Därr, the panel opens into a shared discourse with the audience: an invitation to reflect on what it means to enter into relationship with the unknown.
Academic
Business
Policy
Council of Europe (International)
Peter Kimpian (moderator, Council of Europe, Europe), Ana Brian Nougrères (, International), Mark Lizar (Transparency Lab, Canada), Jan Schallaböck (ISO / DIN / iRights.Law, Europe), Peter Kits (KPMG, )
Cross‑border transfers are where governance models collide and standards are needed: Individuals and even regulators struggle to determine who is accountable, what purpose is pursued, what authority or justification is relied on, until long after processing is underway. (after runtime) In parallel, digital identification demands are frequently introduced early in the interaction before accountability and transfer conditions are inspectable creating an avoidable “trust us” digital privacy risk posture. This panel explores a practical “Operational Transparency” code‑of‑practice approach grounded in Convention 108+ and operationalized through ISO/IEC WG 5 standardisation work—to define what must be inspectable before identification is demanded and before transfer occurs, and what evidence artefacts make oversight scalable.
Academic
Business
Policy
EU Cloud Code of Conduct (Belgium)
Gabriela Mercuri (moderator, SCOPE Europe, Belgium), Tobias Judin (Norwegian Data Protection Authority, Norway), Kai Zenner (European Parliament, Europe), Anu Talus (European Data Protection Board, Europe), Lorelien Hoet (Microsoft, Belgium)
As we reach GDPR’s 10th anniversary, international data transfers continue to impose significant challenges to both organizations and regulators. From crucial court rulings to evolving adequacy discussions, ensuring lawful, resilient, and trustworthy cross-border data flows remains a major concern for privacy professionals. To effectively navigate this fragmented and fast-changing landscape, the performance of appropriate risk assessments and implementation of effective technical and organizational measures are indispensable. This panel will examine key developments shaping international transfer compliance, also reflecting on the potential role of underutilized compliance tools such as codes of conduct and certifications. Finally, the discussion will situate these challenges within the context of the proposed GDPR simplification under the Digital Omnibus Regulation, assessing its potential implications for the future of international data transfers.
Academic
Business
Policy
Knight-Georgetown Institute (KGI) (United States)
Mark Scott (moderator, Atlantic Council’s Democracy & Tech Initiative, International), Peter Chapman (Knight-Georgetown Institute, United States), Catalina Goanta (Utrecht University, Netherlands), Claire Pershan (Mozilla Foundation, Belgium), Victor Alamercery (European Commission, France)
As public concern and regulatory interest in digital platforms intensifies, a central challenge remains: how to enable access to platform data by researchers, civil society, and journalists. Building on KGI’s recent report “Better Access,” this panel examines opportunities and obstacles associated with independent researcher access to platform data. Drawing on emerging regulatory frameworks in the EU, UK, US, and beyond, the panel will unpack barriers to independent research, including corporate resistance, regulatory fragmentation, resource constraints, and geopolitical dynamics. Panelists will describe effective strategies to increase access to data while maintaining strong protections for privacy and security. Ultimately, the panel will help chart a path towards meaningful and sustainable independent study of platform design and impacts. The panel is jointly organized by the Knight-Georgetown Institute and the Institute for Information Law.
Academic
Business
Policy
Catalan Data Protection Authority (APDCAT) (Spain)
Olga Rierola (moderator, Catalan Data Protection Authority (APDCAT), Spain), Marit Hansen (State Data Protection Commissioner of Land Schleswig-Holstein, Germany), Emese Savoia Keleti (European External Action Service, Europe), Esther García Encinas (CaixaBank, Spain), Daniele Nardi (EDPS, Europe)
Ten years after the adoption of the GDPR, the role of DPOs is increasingly shaped by a growing and complex EU digital regulatory landscape. While the GDPR defines the role and tasks of the DPO, recently adopted EU digital laws introduce provisions that directly impact in data protection and, in practice, expand the range of functions that DPOs are expected to perform. This panel aims to analyse how EU regulation -in particular the AI Act, the Data Act, the DSA, and the DMA – affects DPOs’ role and how these changes are experienced in practice. Focusing on organisational practice rather than legal theory, the panel explores the resulting tensions around role expansion, independence, and accountability, and discusses the conditions required for DPOs to effectively fulfil their evolving role while safeguarding their core mandate and ensure users’ rights.
Academic
Policy
University Duisburg-Essen, Ruhr University Bochum, University Kassel, Kunsthochschule Kassel (Germany)
Lisa Mühl (moderator, University Duisburg-Essen, Germany), Geertrui Mieke De Ketelaere (Vlerick Business School, Belgium), Jessica Szczuka (University Duisburg-Essen, Germany), Christian Geminn (University Kassel, Germany), Megan Leal Causton (LSTS, VUB, Belgium)
This panel examines the rise of large language models as AI companions that increasingly operate in intimate, romantic, and emotional contexts. Empirical research shows that users form emotionally meaningful relationships with these systems and engage in sustained self-disclosure, often accompanied by heightened vulnerability and limited privacy awareness. Drawing on interdisciplinary research across psychology, computer science, law, and artistic research, the panel builds on the concepts of Intimacy-by-Design and Privacy-by-Design to analyze how AI companion systems are deliberately engineered to foster emotional validation and relational continuity. It addresses resulting risks, including power asymmetries, insufficient youth protection, and escalating data protection concerns related to highly sensitive personal and relational data.
The Privacy Collective (Netherlands)
Femke Hendriks (The Privacy Collective, Netherlands), Vonne Laan (The Privacy Collective, Netherlands), Amel Fenghour (Innsworth, United Kingdom)
This workshop brings together experts on class actions from different countries and backgrounds. This to explore the rise of GDPR class actions in Europe, though different perspectives. The facilitators include a class action foundation, a lawyer and a funder. The public will also include other practitioners, such as policymakers and academics. We will examine emerging cross-border litigation trends and hurdles, with specific attention for the ECJ Amazon case and the Omnibus package. At the core of the discussion, we will consider how all these developments affect access to justice for individuals that suffered privacy harms. The workshop will include live audience polling and various questions for the public, to share strategic insights. Objectives: • Understand current GDPR class action landscape across EU Member States • Identify current obstacles to effective collective privacy redress • Foster practical cooperation between different actors and experts from various jurisdictions
The Privacy Collective (Netherlands)
Femke Hendriks (The Privacy Collective, Netherlands), Vonne Laan (The Privacy Collective, Netherlands), Amel Fenghour (Innsworth, United Kingdom)
This workshop brings together experts on class actions from different countries and backgrounds. This to explore the rise of GDPR class actions in Europe, though different perspectives. The facilitators include a class action foundation, a lawyer and a funder. The public will also include other practitioners, such as policymakers and academics. We will examine emerging cross-border litigation trends and hurdles, with specific attention for the ECJ Amazon case and the Omnibus package. At the core of the discussion, we will consider how all these developments affect access to justice for individuals that suffered privacy harms. The workshop will include live audience polling and various questions for the public, to share strategic insights. Objectives: • Understand current GDPR class action landscape across EU Member States • Identify current obstacles to effective collective privacy redress • Foster practical cooperation between different actors and experts from various jurisdictions
Digibeetle (Netherlands)
Joost Gerritsen (Digibeetle, Netherlands), Tricia Lee (Utrecht University, Netherlands), Dora Drogeanu (Utrecht University, Netherlands)
Over 300 supervisory authorities now enforce a rapidly expanding EU Digital Rulebook. GDPR, AI Act, DSA, DMA, Data Act, NIS2, DORA, and more, with CJEU case law layered on top. The challenge is no longer access to legal texts. It is finding your way through what already exists. In this interactive workshop, Digibeetle and data science researchers from Utrecht University present a prototype tool that maps the Digital Rulebook in a way traditional legal research cannot. Explicit citations are just the surface. The real value is in the hidden links: a CJEU judgment echoing the Digital Markets Act without naming it, or a term like "high-risk" quietly migrating from one legal domain into another. You will get hands-on time with the tool, test it against your own questions, and help shape the next phase of the research. Designed for professionals at supervisory authorities and government bodies who live inside the Digital Rulebook every day.
Important: This workshop requires registration
Please register here
Centre for Democracy and Technology Europe (Europe)
The harms encountered by minors online are numerous, multi-faceted and well documented. In the EU and beyond, legislators are increasingly turning to age-gating as a potential solution to these harms. However, this is far from a simple fix: besides various fundamental rights implications, recently published research by the Center for Democracy and Technology also shows that this is not a solution favoured by minors and their parents. This workshop will begin with a brief introductory conversation with experts. The conversation will then open to all workshop participants in a fishbowl format, allowing a dynamic exchange of diverse views. The participants will be invited to reflect on the issues previously introduced, such as the blind spots of current policy discussions and their understanding of the technical and fundamental-rights implication of solutions to protect minors online, while thinking creatively about what is really needed, and what different actors can contribute towards it.
In Chilling Effects, Jonathon W. Penney explores the increasing weaponization of surveillance, censorship, and new technology to repress and control us. With corporations, governments, and extremist actors using big data, cyber-mobs, AI, and other threats to limit our rights and freedoms, concerns about chilling effects – or how these activities deter us from exercising our rights – have become urgent. Penney draws on law, privacy, and social science to present a new conformity theory that highlights the dangers of chilling effects and their potential to erode democracy and enable a more illiberal future. He critiques conventional theories and provides a framework for predicting, explaining, and evaluating chilling effects in a range of contexts. Urgent and timely, Chilling Effects sheds light on the repressive and conforming effects of technology, state, and corporate power, and offers a roadmap of how to respond to their weaponization today and in the future.
Are current criminal procedure rules sufficient to address the unique challenges posed by AI evidence? This is the central question explored in the edited volume ‘AI Evidence in Criminal Proceedings’. The book presents the results of the CRIM_AI Project, a four-year research project led by Professor Katalin Ligeti and funded by the Luxembourg National Research Fund. Bringing together experts in criminal law, data protection, and computer science, alongside practitioners and policymakers, the project examined the challenges related to the evidentiary use of AI through a comparative analysis of six jurisdictions: Germany, France, Luxembourg, the Netherlands, the U.K., and the U.S. Can evidence generated or processed by AI be trusted? What safeguards exist for the defendant? Addressing these questions, the volume contributes to the scholarly debate, offers practical guidance for law enforcement and legal practitioners, and proposes solutions to inform policy choices at both national and supranational level.
Are current criminal procedure rules sufficient to address the unique challenges posed by AI evidence? This is the central question explored in the edited volume ‘AI Evidence in Criminal Proceedings’. The book presents the results of the CRIM_AI Project, a four-year research project led by Professor Katalin Ligeti and funded by the Luxembourg National Research Fund. Bringing together experts in criminal law, data protection, and computer science, alongside practitioners and policymakers, the project examined the challenges related to the evidentiary use of AI through a comparative analysis of six jurisdictions: Germany, France, Luxembourg, the Netherlands, the U.K., and the U.S. Can evidence generated or processed by AI be trusted? What safeguards exist for the defendant? Addressing these questions, the volume contributes to the scholarly debate, offers practical guidance for law enforcement and legal practitioners, and proposes solutions to inform policy choices at both national and supranational level.
Academic
Business
Policy
European Data Protection Board (Belgium)
Isabelle Vereecken (moderator, European Data Protection Board, International), Augustin Reyna (BEUC, International), Victoria de Posson (European Tech Alliance, International), Jan Kostijn Dieben (Permanente Vertegenwoordiging, Europe), Charly Helleputte (King & Spalding, Belgium)
Europe’s digital landscape is in a new phase of transformation and policymakers face a pivotal moment. This panel brings together regulators, legislators, industry representatives, academics and civil-society representatives to explore how the reform to data protection legal framework can support European competitiveness and innovation. This session aims to foster an open, balanced and forward-looking discussion on how Europe can shape a digital ecosystem that is innovative, resilient and firmly grounded in fundamental rights.
Academic
Business
Policy
Article 19 (Europe)
Bárbara Simão (moderator, Article 19, Europe), Agustin Ferrari Braun (University of Amsterdam, Netherlands), Corinne Cath (Article 19, Netherlands), Willem Vermost (European Broadcasting Union (EBU)., Switzerland), Sandrine Elmi Hersi (ARCEP, France)
Freedom of expression is increasingly shaped at the infrastructure layer. Cloud providers control the digital foundation that enables communication platforms and democratic systems, yet their influence on human rights remains under-examined. Recent years have highlighted how infrastructure power can constrain expression. Major cloud outages have cascaded across dependent services, temporarily silencing entire sectors. In parallel, providers have deliberately terminated access to services, illustrating how infrastructure control enables censorship without meaningful oversight. Generative AI intensifies this scenario through dependency on hyperscale compute and extractive data practices. Government responses vary between promoting “sovereign” technologies and attracting foreign investment, but both often fall short of addressing governance gaps. This panel examines how cloud and AI infrastructure shapes freedom of expression, and explores regulatory approaches - from competition to HumanRights frameworks - needed to govern this critical layer of digital power.
Academic
Business
Policy
KISA(Korea Internet & Security Agency) (South Korea)
Bianca Ioana Marcu (moderator, Future of Privacy Forum (FPF), Brazil), Sunghyun LEE (KISA(Korea Internet & Security Agency), South Korea), Marie-Ève Nadeau (5rightsfoundation, International), Isabella Henriques (Alana Institute, Brazil), Elise Lassus (EU Agency for Fundamental Rights (FRA), Europe)
In an era where children’s personal data is routinely processed on digital platforms, who truly controls this information? South Korea’s 'Digital eraser' service highlights the risks of AI exploitation and unauthorized data use, showing that the issue extends beyond simple access control. The rise of 'sharenting' further complicates children’s digital autonomy and agency. This panel shifts the focus from shielding children to empowering them with digital self-determination. Should children hold the authority to govern their own digital footprints? We will explore how to grant young people meaningful control—including the rights to deletion, informed consent, and protection from profiling. Drawing on Korea’s 'Delete the Children' initiative, along with policy developments in Brazil, the UK, and educational insights, our panellists will challenge the assumption that shielding is the only path forward. Instead, we advocate for frameworks that balance children’s rights with parental responsibility, ultimately placing children’s voices at the heart of their digital future.
Academic
Policy
Data Rights (France)
Lori Roussey (moderator, Data Rights - Founding member of the PEGA Coalition, Europe), Luigi Malferari (European Commission, Europe), Sophie in t' Veld (Former MEP, Europe), Celia Carbonell (Iridia - Center of Defense of Human Rights (founding member of the PEGA coalition), Spain), Ádám Ramport (Hungarian Civil Liberties Union (HCLU), )
This panel brings litigators, researchers and legislators at the table to discuss the future of spyware regulation. Since the Pegasus scandal, the policy position has been to call for a general ban on spyware. With little progress. Meanwhile, in Europe the situation has worsened. The work of the PEGA Coalition being rooted in litigation, it has to enter into detailed conversations about the technology and its long term stakes on society. Coalition members, as well as researchers and legislators, have now had time to mature where they see absolute red lines, and where nuance is possible. This panel aims to tackle the uncomfortable reality of spyware regulation, where regulatory blockade is a status quo only beneficial to a dubious industry. An industry that consistently fails the test of adequacy to fundamental rights and democratic values.
Academic
Business
Policy
Centre for Democracy and Technology Europe (Europe)
Laura Lazaro Cabrera (moderator, Centre for Democracy and Technology Europe, Europe), Miranda Bogen (Center for Democracy and Technology, International), Nele Roekens (Equinet, Belgium), Isabel Barberá (Dutch Coordinating Supervisor on AI and Algorithms (DCA), Dutch DPA, Netherlands), Anahita Valakche (Microsoft, International)
The proposed Digital Omnibus has prompted an intense debate on the necessary interventions to ensure entities developing and using AI are able to identify and rectify bias and discrimination. Far from a one-size-fits-all solution, different use cases and deployment contexts warrant distinct approaches to both identification and correction of discrimination. This session will discuss how to practically navigate trade-offs between privacy and non-discrimination, the regulatory tools and opportunities offered by the EU legal framework, and the necessary changes to empower AI and fundamental rights regulators to robustly enforce existing fundamental rights.
Faculty of Law, Economics and Finance (FDEF), University of Luxembourg (Luxembourg)
Gianmarco Gori (Vrije Universiteit Brussel, Belgium)
he development, procurement and deployment of AI in the context of law enforcement trigger the application of multiple legal frameworks, requiring actors to interface criminal procedure with data protection law, the AI Act, and human rights law more broadly. Each framework autonomously establishes obligations, rights, and oversight mechanisms that may cumulate and interact across different segments of the AI value chain. Effective compliance with applicable obligations depends on the roles and responsibilities of different actors involved, in particular law enforcement authorities, under the LED, the GDPR, and the AI Act, as well as potential overlaps and shifts in their roles. This workshop invites actors from law enforcement, academia, supervisory authorities, civil society and industry to explore this complex normative bundle through a bottom-up approach: engaging with fictional cases, participants will examine the interplay of qualifications as data controllers and processors, providers and deployers, and their obligations arising from those roles.
Faculty of Law, Economics and Finance (FDEF), University of Luxembourg (Luxembourg)
Gianmarco Gori (Vrije Universiteit Brussel, Belgium)
he development, procurement and deployment of AI in the context of law enforcement trigger the application of multiple legal frameworks, requiring actors to interface criminal procedure with data protection law, the AI Act, and human rights law more broadly. Each framework autonomously establishes obligations, rights, and oversight mechanisms that may cumulate and interact across different segments of the AI value chain. Effective compliance with applicable obligations depends on the roles and responsibilities of different actors involved, in particular law enforcement authorities, under the LED, the GDPR, and the AI Act, as well as potential overlaps and shifts in their roles. This workshop invites actors from law enforcement, academia, supervisory authorities, civil society and industry to explore this complex normative bundle through a bottom-up approach: engaging with fictional cases, participants will examine the interplay of qualifications as data controllers and processors, providers and deployers, and their obligations arising from those roles.
Responsum (Belgium)
Bavo Van den Heuvel (Responsum, Belgium)
Ten years after the final text of the GDPR, we have gained significant insights from handling data subject requests. The "obvious" request—“I applied for a job at your company in April last year; can I get a copy of the data you have on me?”—has evolved. Now, we see third parties jumping in, requesting data for their clients and clearly stating that their requests are for reasons other than verifying the lawful processing of that personal data. In this workshop, we will conduct role-plays where you can step into different positions to better understand each perspective: data subject, mandated representative, controller, DPO, Supervisory Authority, and the like. We will also focus on the importance of correct identification and the security elements involved in transferring personal data.
EDRi (Belgium)
As the EU debates the Digital Fairness Act in a broader climate of ‘simplification’, a fundamental question emerges: should digital markets rely primarily on informed choice, or should law address the architecture of influence itself? Digital services increasingly operate as optimisation systems that shape behaviour in real time. Traditional regulatory approaches have focused on disclosure, consent and case-by-case enforcement. This interactive workshop invites participants to test an alternative perspective: what changes when responsibility shifts from individual vigilance to design accountability? Through small-group exercises, participants will redesign concrete digital scenarios under two regulatory logics and compare their implications for autonomy, equality and data protection. The objective is to collectively examine how different understandings of fairness redistribute responsibility between individuals, traders and regulators, and what this means for the future of the Digital Fairness Act.
Microsoft (Belgium), Microsoft ()
As the AI Act begins to apply, organisations must navigate an increasingly complex regulatory overlap with the GDPR. The EDPB and the European Commission are currently preparing guidance to clarify the interplay between both instruments, while the Digital Omnibus proposes targeted changes to Article 9 GDPR and the AI Omnibus finetunes sensitive data usage for bias mitigation. This workshop will examine how the two frameworks can best operate together and how organisations can operationalise them across the AI lifecycle. Key topics include GDPR lawful bases for AI training and deployment, data minimization duties, the approach to human oversight under Article 22 GDPR, as well as opportunities to streamline compliance tools such as DPIAs and AI Act risk assessments, records of processing or broader transparency obligations. Participants will also discuss how regulatory enforcement can be best organized in an increasingly crowded regulatory environment.
Multidisciplinary Institute on Artificial Intelligence (MIAI Cluster) (France)
The European Health Data Space (EHDS) promises to unlock large-scale secondary use of health data for AI-driven medical innovation. But can its authorisation pathway function in practice? This interactive workshop tests that question through a concrete use case: an AI provider developing a cardiovascular disease detection tool and requesting access to health data for model training. Participants are divided into three stakeholder groups, 1) AI System Provider, 2) Health Data Access Body, and 3) Health Data Holder, and simulate the secondary-use chain from request drafting to data preparation. Through structured group work and moderated procedural exchange, the session exposes practical frictions in necessity assessments, proportionality, documentation standards, and dataset preparation, as well as regulatory overlap with the GDPR and the AI Act. Rather than debating the EHDS in the abstract, the workshop stress-tests whether Europe’s regulatory ambition can translate into workable infrastructure for AI training.
LSTS, VUB (Belgium)
with notes by Paulien Broens
In a world seemingly run by the whims and power plays of Musks and Zucks, Insufferable Tools cuts to the core of modern technology’s gendered politics. Sarah Sharma challenges the idea that the Big Tech broligarchs are neutral utilitarians who view technology as mere tools. She shows instead how these tech giants have turned the internet, and, increasingly, “real life” into a set of environments which they cultivate and manipulate to wield the real tools: us, the users. Sharma critiques a popular system of inclusion she calls “Big Tech Feminism” that attempts to incorporate and make useful people of color, queer people, and others who are seen as broken machines in the current gendered power structures. Deconstructing Big Tech’s patriarchal deployment of media theory to gain and maintain power, Sharma proposes a feminist techno-politics that can forge new futures free from the grip of the truly insufferable tools.
Academic
Business
Policy
Law, Science, Technology & Society (LSTS) (Belgium)
Gloria González Fuster (moderator, Law, Science, Technology & Society (LSTS), Belgium), Salomé Lannier (University of Luxembourg, Luxembourg), Mireia Llobera Vila (Universitat de València, Spain), Aída Ponce del Castillo (ETUI, Europe), Madeleine Thomas (Image Angel, International)
Will the Platform Work Directive work, and for whom? As we have entered the last year of its transposition deadline, it is time to focus on gendered forms of digital labour, and which are the most urgent remaining challenges. This panel will look into novel rules on algorithmic data management and surveillance through the lens of gender, zooming into multiple types of digital labour and their regulation. Bringing together a variety of stakeholders, it notably discusses webcamming, and its moving relation with tech affordances and legal struggles; the advent (or not) of domestic work as platform work; and new manifestations of exploitation. In doing so, it will invite a reflection on the Platform Work Directive but also on the state of digital labour more broadly, while this gendered lens sheds a new light on specific or shared privacy issues.
Academic
Business
Policy
EDPS (Europe)
Leonardo Cervera Navas (moderator, EDPS, Europe), Aleida Alcaide (Ministry for Digital Transformation and Public Service, Spain), Antonino Rotolo (University of Bologna, Italy), Yvonne Finger (German Federal Network Agency, Germany), David Dab (Microsoft, United Kingdom)
The EU AI Act establishes AI regulatory sandboxes as a promising mechanism to support flexibility and innovation, while simultaneously fostering compliance and regulatory learning. Over recent years, a number of sandboxes have emerged across the EU, differing in scope, design and coordination mechanisms. As the establishment of regulatory sandboxes by August 2026 is a legal obligation for all EU Member States, and as more actors begin to experiment with sandbox concepts, this is a timely opportunity to take stock of existing experiences. By drawing on insights from stakeholders who have pioneered AI innovation testbeds, the CPDP panel members will explore the opportunities and practical challenges of AI regulatory sandboxes. This will help stakeholders learn from each other's experiences and enable more actors to successfully design sandboxes under the AI Act that generate actionable learnings for compliance and deliver societal value.
Academic
Business
Policy
5Rights Foundation (International)
Leanda Barrington-Leach (moderator, 5Rights Foundation, Europe), Sonia Livingstone (London School of Economics, International), Mark West (UNESCO, International), Hans Martens (European Schoolnet, Europe), Simone Van der Hof (Leiden University, Netherlands)
The COVID-19 pandemic saw a rapid integration of EdTech, that children see now used throughout their school day. The spread of AI has also reached the classroom, with apps embedding AI tools within their services. This has created a new norm for education, but are children’s rights protected? Children tell us that privacy and agency are important, and express concern about recognising when using AI. However, they often have no choice in using this tech, which has been found to carry out extensive data collection, and often has little evidence of pedagogical merit. This panel will explore how we can ensure that the use of EdTech (including AI) in education meets GDPR standards and children’s rights, examine what accountability, transparency, and governance frameworks are needed to make digital learning environments safe, rights-respecting, and genuinely supportive of children’s development.
Academic
Business
Policy
CPDP (Belgium)
Marco Bassini (moderator, Tilburg Law School, Netherlands), Sebastião Barros Vale (EDPS, Europe), Gary Davis (Apple, International), Rob Van Eijk (Team Blaeu, Netherlands), Alba Ribera Martínez (Universidad Villanueva, ), Karina Nimara (Developers Alliance, )
Operating systems are the critical foundation for secure AI deployment and play a central role in shaping the privacy and security of AI systems. This panel will explore how OS-level architecture can enforce privacy protections, including enabling data minimization and preserving user control over personal information used by AI.
Academic
Business
Policy
Panoptykon Foundation (Poland)
Katarzyna Szymielewicz (moderator, Panoptykon Foundation, Poland), Linn Høgåsen (Norwegian Consumer Council, Norway), Vid Logar (independent researcher, Slovenia), Isabelle Pérignon (European Commission (DG JUST), Europe), Felix Hlatky (Mastodon, International)
The internet we used to know is dying. Global technological companies have entrenched their dominance across a vast range of digital services – from social media and search engines to cloud infrastructure and generative AI. They have normalized business models which in many cases are incompatible with fundamental rights, such as the collection and use of vast amounts of personal data for advertising and unfair personalisation. We want to take a look at the platforms, once advertised as “social media”, that chose to prioritise short term user engagement rather than long term consumer value. As a result of this choice, these services are exploited in the cognitive war and pose public security risks. Confronted with these risks, European consumers seek safer and healthier alternatives. Decentralized and interoperable platforms – such as Mastodon – are growing too and start experimenting with fair personalisation. In this panel we will look at emerging policy opportunities, including the DFA, and market incentives to bring more fairness, consumer choice, competition and resilience.
Autoriteit Persoonsgegevens (Netherlands)
Kris Korving (Autoriteit Persoonsgegevens (The Dutch Data Protection Authority), Netherlands), Ricardo Catalan (Autoriteit Persoonsgegevens (The Dutch Data Protection Authority), Netherlands)
The Dutch DPA has developed a unique approach towards DPOs. This approach is based on the philosophy that a well-positioned DPO, as intended by the GDPR, can prevent many privacy infringements before escalating to the level of a DPA. This philosophy has been translated to several actions, such as a DPO conference, DPO hotline, DPO newsletter and an intensified relation with DPO organisations on a national level. During this workshop, you will become familiar with the Dutch DPA approach on a detailed level and you will also be invited to provide feedback. The Dutch DPA is interested in testing current ideas and receiving new ones. Furthermore, it would be appreciated if other DPAs and DPOs attended this workshop to establish a lively and productive session. The Dutch DPA hopes that new cooperations will arise from this workshop.
Wikimedia Europe (Europe)
Michele Failla (Wikimedia Europe, Europe), Saskia Ostendorff (Wikimedia Germany, Germany)
With the example of the César do Paço’s lawsuit against the Wikimedia Foundation we want to highlight a problem within the EU's legal framework, that GDPR is harmonised across EU but freedom of speech is not. This can lead to interesting contradictions, for example, the “right to be forgotten” was enforced, but the protection of personal user data - needed by the claimant to enforce further individual trials - was not. The case is a clear example of the tension between two fundamental rights: on the one hand, freedom of expression and on the other the right to privacy. This lawsuit can be described as a perfect SLAPP case. As SLAPP cases include power imbalances, we will describe very relatable, why freedom of speech and individual rights need to be protected. Starting with a short presentation, we will include interactive elements and discuss extensively with the audience. We would like all to contribute with their knowledge to other legal issues of concern, suggest solutions and maybe even plan future actions (e.g. publications, hearings) on this matter.
DuckDuckGo (United States)
Andreas Dewes (DuckDuckGo, Germany), Paul Francis (Max Planck Institute for Software Systems, Germany)
The Digital Markets Act requires designated search engine gatekeepers to provide competing search engines with access to anonymous ranking, query, click, and view data. Google's approach to anonymization, however, has addressed these privacy concerns by severely diminishing the utility of shared data, effectively undermining Article 6(11) of the DMA. This workshop presents a counter-anonymization methodology, designed by Paul Francis (Director Emeritus, MPI-SWS) in collaboration with Andreas Dewes (Privacy Engineer, DuckDuckGo) that maintains strong anonymity guarantees while preserving significantly greater data utility. Projections were validated using DuckDuckGo search data samples. This workshop will demonstrate that strong anonymization guarantees and meaningful data utility are not mutually exclusive — and will situate this analysis within the draft EC/EDPB guidelines on the interplay between data protection and digital market contestability under the DMA and GDPR.
Important: This workshop requires registration
Please register here
Welcome to an interactive moot court workshop where law, technology, and a bit of drama collide. No wigs or court experience required. At the heart of the case is a modern clash: controllers who operate AI eager to innovate versus individuals demanding strong protection of their fundamental rights. With consent under pressure as a legal basis for AI, the spotlight shifts to legitimate interests under Article 6(1)(f) GDPR. When is AI processing truly necessary? And where is the tipping point when balancing innovation and intrusion? You’ll step into a live legal battle shaped by current EU debates, including the Commission’s draft Article 88(c) GDPR. Together, we’ll test arguments and challenge assumptions. Think sharp arguments, real-world relevance, and lively discussion. If you like tech, rights, or just a good intellectual showdown, please join us!
Join filmmaker Marc Silver and People vs Big Tech for a screening of Molly vs The Machines, a documentary examining the tragic story of a British teenager whose death prompted global scrutiny of the role social media platforms and their recommendation systems play in shaping young people’s online lives.
Through the voices of Molly’s family, investigators and experts, the film explores how engagement-driven algorithms can push users—particularly children—towards spirals of harmful content.
Academic
Business
Policy
Open Universiteit (Netherlands)
Anna Berlee (moderator, Open Universiteit, Netherlands), Andreas Häuselmann (Open Universiteit, Netherlands), Francesca Palmiotto (IE University, Spain), Charlotte Barot (CNIL (Commission nationale de l'informatique et des libertés), France), Luca Tosoni (Schjødt (law firm), Norway)
AI increasingly influences decisions about people. This raises the question of how individuals are protected from the associated risks. Two provisions in EU law address this challenge. Article 22 GDPR envisages protecting individuals from automated decision-making (ADM). Article 15 (1) lit h GDPR provides a 'genuine right to explanation', allowing individuals to request 'meaningful information about the logic' involved in ADM. The AI Act's Article 86 empowers individuals to obtain explanations for decisions based on an output from a high-risk AI system. Individuals can obtain 'clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision taken'. The similarity of these two rights begs for an explanation, which this panel aims to provide. The panel offers a comprehensive perspective, covering views from legal practice, academia and regulators.
Academic
Business
Policy
Inria (France)
Juliette Sénéchal (moderator, Inria, France), Fabien Lechevalier (Paris-Saclay University (CERDI), United Kingdom), Audrey Pety (CNIL (Commission nationale de l'informatique et des libertés), France), Johanna Gunawan (University of Maastricht, Netherlands), Luis Velasco (EDPS, Europe)
The act of influencing, even manipulating consumers is a practice as widespread as it is age-old. Nevertheless, the digital age has brought about a genuine revolution. The risk of influence and manipulation now stems from algorithms, AI systems articulated HCIs and BCIs, Agentic AI... They either involuntarily induce behaviours below the threshold of awareness, or they are intentionally designed to do so. These digital techniques are truly unique in that they are automated, personalised and scalable. Many european instruments adresses certain digital practices of consumer influence and manipulation : GDPR, AI Act, DSA, UCPD and, in a near future, the Digital Fairness Act. What is at stake in this panel, is to conduct a prospective analysis to assess the relevance of establishing a new and effective neuro-ethical legal framework for consumers, at the intersection of these different instruments.
Academic
Business
Policy
Health & Ageing Law Lab (HALL), Vrije Universiteit Brussel (VUB), Belgium (Belgium)
Paul Quinn (moderator, Health & Ageing Law Lab (HALL), Vrije Universiteit Brussel (VUB), Belgium, Belgium), Federica Casarosa (Sant’Anna School of Advanced Studies, Italy), Jarosław Greser (Uniwersytet Wrocławski, Poland), Oguzhan Yesiltuna (Health & Ageing Law Lab (HALL), Vrije Universiteit Brussel (VUB), Belgium), Elisabetta Biasin (KU Leuven Centre for IT & IP Law (CiTiP), International)
The increasing integration of AI and software into healthcare outpaces traditional regulatory boundaries, creating an intricate landscape of legal requirements. This panel explores the purpose of medical device cybersecurity and the complex interplay between sector-specific rules (e.g. MDR, IVDR, EHDS) and horizontal frameworks (e.g. GDPR, Cybersecurity Act, Cyber Resilience Act, NIS2, AI Act). From the latest legislative omnibus packages to the “grey areas” of wellness apps and Large Language Models, this panel aims to examine whether current efforts at regulatory coherence actually simplify compliance or create new vulnerabilities. By mapping friction points between legal requirements, the panellists seek to discuss how the current regulatory landscape could be further optimised. Can the EU achieve true coherence for medical device cybersecurity, or will the alignment gap continue to burden innovation and compromise patient safety?
University of Luxembourg (Institute for Digital Ethics) (Luxembourg)
Ioana DUTA-VISESCU (University of Luxembourg (Institute for Digital Ethics), Luxembourg), Claudia NEGRI RIBALTA (University of Luxembourg (Institute for Digital Ethics), Luxembourg), Carsten ULLRICH (University of Luxembourg (Institute for Digital Ethics), Luxembourg)
The organisers will openly debate with participants the pros and cons of policy interventions proposed to address the negative effects of social media on children. The debate will focus on how to address: Manipulative design (e.g. infinite scrolling), and Harmful content (e.g., suicidal or extremist posts) Discussions will explore whether and how harms can be effectively and proportionately addressed through policy, such as outcome-based rules, prescriptive design standards, industry-wide norms or outright bans. Is age verification adeauet and necessary? Context will be provided through a brief outline of existing and upcoming legislation (e.g., GDPR, DSA, Audio-Visual Services Media Directive, Digital Fairness Act). The aim is to surface the technical, societal and regulatory challenges and opportunities of intervening in social media design and business models, while generating ideas to advance the current debate. The three organisers - a privacy engineer, an human computer interaction scientist, and a regulatory expert— will guide the debate on both technical and policy levels.
SAI (Belgium)
For the workshop a voting-format will be used to ask input on the following questions and to start discussions and share best practices and experiences: - Which aspects can DPOs’ and CISOs’ influence related to data localisation, cloud procurement and technological dependency in the vendor selection process? - How do DPOs interpret their mandate in relation to broader political goals such as digital sovereignty? - Who are the allies for the DPO on digital sovereignty (p. ex. CISOs’, …)? - Do you know some of these https://european-alternatives.eu technology alternatives? Do you use some of them? What are your experiences?
The screening of Molly vs The Machines is followed by a panel moderated by People vs Big Tech. This discussion brings together the filmmaker and representatives from People vs Big Tech, 5Rights Foundation, Article 19 and DG CONNECT on platform power, algorithmic accountability, and what meaningful regulation should look like in response.
Academic
Business
Policy
IAPP (International)
Trevor Hughes (moderator, IAPP, United States), Aura Salla (European Parliament, Europe), Thomas Le Goff (Telecom Paris, Institut Polytechnique de Paris, France), Sylvie de Oliveira (L'Oréal, France), Gaia Marcus (Ada Lovelace Institute, International), Eduardo Ustaran (Hogan Lovells, Belgium)
Regulation of the online world is increasing across the globe. It leads to a multilayer legal and regulatory landscape, against the backdrop of rapid technology deployment. Organizations – across policymakers, regulators, enterprises and civil society – are faced with an unprecedented challenge of having to rethink digital governance. This panel will analyse the regulatory intersectionality and its implications for organizational governance and digital risk management for stakeholders across the board.
Business
Policy
BEUC (Belgium)
Cláudio Teixeira (moderator, BEUC, Belgium), Finn Myrstad (Norwegian Consumer Council, Norway), Diana Vlad-Calcic (European Commission, DG Connect, International), Andreea Șerban (Future of Privacy Forum (FPF), International), Romain Robert (EDPS, Europe)
In November 2025 the Commission proposed the Digital Omnibus, aimed at simplifying both the General Data Protection Regulation (GDPR) and the AI Act to support the competitiveness agenda. However far from merely simplifying the legal framework, the proposed changes may deregulate critical areas, risk creating legal uncertainties for consumers and businesses alike, and raise serious questions about the safety and security of European consumers’ data in the age of AI. This panel will explore the motivations behind these proposals and question whether they are truly necessary or proportionate. It will assess their potential impact on consumer rights, legal certainty, and the effective enforcement of EU data protection rules, with a particular focus on the risks they may pose to the privacy, security, and trust of European consumers in an AI-driven digital economy.
Academic
Business
Policy
Utrecht University (Netherlands)
Mirko Tobias Schäfer (moderator, University of Helsinki, Finland), Angela Müller (AlgorithmWatch CH, Switzerland), Arnika Zinke (European Parliament, Europe), Katja Mayer (University Vienna, Austria), Rob Heyman (Vrije Universiteit Brussel, Belgium)
As the EU’s Artificial Intelligence Act (AI Act) approaches implementation, we discuss how this landmark legislation will be effectively upheld in practice and through enforcement. This panel will explore the practices for compliance and critical steps needed to ensure that the AI Act goes from a legislative framework into a practical tool for governing AI use across Europe. We will focus on practical solutions and key mechanisms for ensuring compliance: practices for compliances, the role of oversight bodies and supervisory authorities in monitoring AI systems, to the contributions of NGOs and civil society in holding organizations accountable, and the challenges policymakers face in translating regulation into actionable enforcement on the ground. Arguing against the notion of trickle-down policy, the panel will highlight the collective efforts necessary to transform the AI Act into an impactful and enforceable reality.
Academic
Business
Policy
University of the Basque Country (Spain)
Pablo TRIGO KRAMCSÁK (moderator, Vrije Universiteit Brussels (VUB), Belgium), Francesca Tassinari (University of the Basque Country, Spain), Federica Casarosa (Sant’Anna School of Advanced Studies, Italy), Anastasiya Kiseleva (Vrije Universiteit Brussel, Belgium), Owe Langfeldt (European Commission, Belgium)
The main objective of this panel is to analyse some of the main legal issues raised by the implementation of the EHDS in the EU context. These include: the issue of standardisation and quality labels; the role of the European Commission in the overall system; how issues relating to the allocation of fees and the protection of industrial property will be resolved; the distribution of roles between ethics committees, data protection agencies and access bodies, etc. Funded by project GODAS (PID2022-137140OB-I00, financed by MCIN/AEI/10.13039/501100011033/FEDER, UE)
Academic
Business
Policy
KU Leuven Centre for IT & IP Law (CiTiP) (Belgium)
Andrea Palumbo (moderator, KU Leuven Centre for IT & IP Law (CiTiP), Belgium), Elora Fernandes (KU Leuven Centre for IT & IP Law (CiTiP), Belgium), Simone van der Hof (Leiden University, Netherlands), Greta Faieta (European Commission, Europe), Nicoleta Prutean (Centre for Future Generations, International)
The European Union’s Digital Rulebook has undergone significant transformation with the introduction of several new chapters in the past decade (such as the DSA, DMA, or AI Act), while proposals to review its very foundation have been recently introduced, such as the Omnibus package. These fast-paced changes create the need to understand how these frameworks interact and whether they complement or contradict each other. The stakes are even higher when the rights of vulnerable groups, particularly children, are affected. A holistic approach is therefore required to ensure a coherent reading, addressing possible tensions in line with the best interests of the child. This panel explores key areas of interplay across regulatory regimes through the lens of children’s rights, highlighting opportunities and identifying gaps. Discussions will span from age-assurance mechanisms to profiling, social-media bans and children’s mental health.
Academic
Business
Policy
European Ethereum Institute (EEI) (Europe)
Veronika Hurina (moderator, FleishmanHillard EU (Omnicom), Europe), Ondrej Kovarik (European Ethereum Institute (EEI), Europe), Vyara Savova (European Ethereum Institute (EEI), Europe), Amandine Jambert (European Data Protection Board (EDPB), Europe)
Public, permissionless blockchains increasingly function as foundational digital infrastructure, yet they sit in tension with key assumptions in EU data protection law. Recent developments—the EDPB's draft Guidelines 02/2025, now being finalised, and the Commission's November 2025 Digital Omnibus proposal—have exposed frictions around pseudonymity, identifiability, and the allocation of responsibility in decentralised systems. These mirror the Court of Justice's reasoning in EDPS v SRB, which confirmed that personal data must be assessed contextually, by reference to the means reasonably likely to be used by the actor in question. Using Ethereum as an example, this panel brings together legal, policy, and infrastructure perspectives to examine whether current GDPR interpretations can extend to protocol-level activity, whether the cryptographic tools policymakers rely on are sufficiently mature in Europe, and whether the regulatory direction remains coherent with the EU's broader digital ambitions.
KPMG ()
Manon van Rietschoten (KPMG, Netherlands), Alette Horjus (KPMG, Netherlands)
In this session, we explore the legal and regulatory lifecycle through the lens of intelligent compliance, starting with regulatory horizon scanning. We show how emerging regulatory developments can be identified and interpreted in a structured way, illustrated in part through our work on the Tech Reg Radar solution. We then follow the legal and regulatory lifecyle through the legal impact assessment and translation into policies, controls, and automated control activities, highlighting how data, technology, and control automation support ongoing monitoring and more proactive, resilient compliance.
KPMG ()
Manon van Rietschoten (KPMG, Netherlands), Alette Horjus (KPMG, Netherlands)
In this session, we explore the legal and regulatory lifecycle through the lens of intelligent compliance, starting with regulatory horizon scanning. We show how emerging regulatory developments can be identified and interpreted in a structured way, illustrated in part through our work on the Tech Reg Radar solution. We then follow the legal and regulatory lifecyle through the legal impact assessment and translation into policies, controls, and automated control activities, highlighting how data, technology, and control automation support ongoing monitoring and more proactive, resilient compliance.
ADAPT Centre (Ireland) and Joint Research Centre (Italy) (Europe)
Dave Lewis (ADAPT Centre, Trinity College Dublin, Europe), Paula Rodriguez Müller (Joint Research Centre of the European Commission, Europe)
This interactive workshop brings together research exchange and career development reflection. Early-career researchers will present their work through concise three-minute pitches, followed by a world café-style session where participants engage in small-group discussions and provide structured, constructive feedback. The second part features a semi-structured fishbowl discussion exploring key challenges shaping career pathways, including the impact of AI, non-linear trajectories, precarious employment, and the skills needed for adaptable, future-ready profiles. The workshop concludes with a collective reflection, allowing participants to share insights and identify key takeaways on both research communication and evolving career landscapes.
LSTS, VUB (Belgium)
This book is introduced not as a final answer, but as a reflection on issues that are often left unspoken. It is not based on any single case, but on a broader awareness that such experiences are widely recognised across academic environments. It grows out of repeated moments in academic settings where conversations about gender-based violence are followed more quietly by people sharing that these situations are common in their own institutions, even if they are rarely discussed openly.
At the same time, increasing pressures around funding, geopolitical tensions, and concerns about academic freedom raise an important question: how freely can people really speak about these issues? There often seems to be a kind of “cloak” of privacy, where individuals manage difficult experiences without feeling able to voice them publicly. This does not affect everyone in the same way. For those in marginalised groups, such as LGBTQIA+ people or researchers whose perspectives may not align with dominant political views, the risks of speaking out can be even greater. In this way, the session looks at how power works within academia, and also draws a parallel with similar imbalances in big tech companies, where the rights and conditions of data workers are shaped by who gets to speak and be heard. Rather than offering clear solutions, it invites participants to reflect on what is shared, what is held back, and why.
Academic
Business
Policy
Council of Europe (Europe)
Peter Kimpian (moderator, Council of Europe, Europe), Anamarija Mladinić (AZOP, Croatian DPA, member of the Bureau of Convention 108, Croatia), Marcello Ienca (TUM School of Medicine and Health, Germany), Murielle Popa-Fabre (Responsible AI Policies and Governance, France), Cathal McDermott (Microsoft, International), Emma Redmond (Open AI, Ireland)
In a period of rapid technological evolution, many ask how to uphold and secure human rights and fundamental freedoms as defined by international instruments — notably the right to privacy. New data processing techniques and technologies, such as big data and profiling, are almost a thing of the past, and today we face other technologies such as neurotechnology and Large Language Models that elevate the processing of personal data to a complexity never seen before. But not only does the level of complexity become higher, the risk of a potential impact on individuals' private lives through the processing of personal data by these technologies and applications also increases. The panel will look into current challenges international organisations face when elaborating standards in these fields and into solutions to overcome them. It will also delve into whom these international standards are useful for, and how.
Academic
Business
Policy
Ada Lovelace Institute (International)
Valentina Pavel (moderator, Ada Lovelace Institute, International), Karolina Mojzesowicz (European Commission, Europe), Max von Thun (Open Markets Institute, Europe), Orla Lynskey (UCL Faculty of Laws, International), Laura Brodahl (Wilson Sonsini Goodrich & Rosati, Belgium)
The European Commission's Digital and AI Omnibus is presented as a measure to cut red tape and boost competitiveness. Wrapped in the language of ‘simplification’, the package contains substantial changes with far-reaching implications for people's fundamental rights, the European market and the EU's sovereignty. The proposals raise critical questions: Will people enjoy meaningful safeguards around privacy and wider AI risks? Will they maintain choice and agency over data? How would the shape and character of the EU market change if Europe’s competitive advantage in responsible innovation was undermined? This panel will discuss the real-world impact of the proposals and unpack the interplay between the changes across the different regulations, with a focus on the GDPR and AI proposals.
Academic
Business
Policy
Autoriteit Persoonsgegevens (Dutch DPA) (Netherlands)
Berna Keskindemir (moderator, Autoriteit Persoonsgegevens (Dutch DPA), Netherlands), David Reichel (European Union Agency for Fundamental Rights (FRA), Europe), Karolina Iwańska (European Center for Not-for-profit Law (ECNL), Netherlands), Harshvardhan Pandit (Trinity College Dublin, Ireland)
Fundamental Rights Impact Assessments (FRIAs) are emerging as a key tool for embedding fundamental rights protection for its people in EU’s digital governance. At the same time, the implementation efforts of new legal obligations in this regard raise pressing questions related to operationality across sectors and regulatory frameworks in the EU and in relation to EU’s ambition for AI innovation and competitiveness in a global context. This panel aims to share lessons learned from multi-stakeholder cooperation and explore how FRIAs are being operationalized, safeguarding people’s rights effectively, while also being an indispensable tool for EU’s AI innovation and competitiveness efforts.
Academic
Policy
Europol Data Protection Experts Network (EDEN) (Europe)
Jan Ellermann (moderator, Europol, Germany), Jeroen Wauman (EDPS, Belgium), Anke Theresia Paulusz (Europol, Netherlands), Jessica Galissaire (Interface, France), Jaap-Henk Hoepman (Radboud Universiteit, Netherlands)
Beneath the surface of the digital world, new and deeply concerning phenomena are emerging—among them the loosely structured and highly disturbing online network often referred to as “764 COM.” Operating across platforms and borders, such communities exploit vulnerabilities, evade detection, and challenge traditional approaches to child protection. This panel brings together a unique cross-section of expertise: a Europol analyst with operational insight into evolving online threats, a representative from the European Data Protection Supervisor (EDPS) addressing the fundamental rights dimension, an academic perspective from Radboud University, Nijmegen, and a voice from civil society providing frontline experience and advocacy perspectives. Together, they will explore how law enforcement, regulators, and NGOs can respond effectively to emerging risks, while ensuring that efforts to combat harm remain grounded in the protection of fundamental rights.
Academic
Policy
FIZ Karlsruhe (Germany)
Franziska Boehm (moderator, FIZ Karlsruhe, Germany), Eleni Kosta (University of Tilburg, Netherlands), Juraj Seifert (VuB and DG Justice and Consumers of the European Commission, Europe), Evangelos Zarkadoulas (PhD Justice and Home Affairs Counsellor at the Permanent Representation of Greece to the EU, Greece), Evanthia (Evi) Chatziliasi (EDPS, Europe)
The LED is the core framework through which European law enforcement agencies must demonstrate the legality, proportionality and accountability of their actions in an increasingly data-intensive environment. As set out in the 2025 Roadmap and in the ‘ProtectEU’ strategy, discussions within the EU on lawful access to data have increasingly focused on data retention, cooperation with service providers, digital forensics, decryption, standardisation and AI-enabled analysis. Against this, the panel considers the LED not as a static legal instrument, but as part of a broader landscape of governance and system design that is being tested by technological, institutional and policy developments. The discussion will explore recent case law on the LED and the reform in EU digital governance (e.g. Digital Omnibus), including in the context of AI-enabled law enforcement practices, as well as points of friction arising from current developments.
Business
Policy
AI.REGULATION.COM Chair, MIAI, University Grenoble Alpes (France)
Theodore CHRISTAKIS (moderator, AI.REGULATION.COM Chair, MIAI, University Grenoble Alpes, France), Declan McDowell-Naylor (Information Commissioner's Office (ICO), Europe), Natascha Gerlach (CIPL, International), Peter Swire (Georgia Tech, United States), Yann Padova (Wilson Sonsini Goodrich & Rosati, Belgium)
Generative AI chatbots are rapidly becoming digital confidants for health worries, relationship crises, workplace dilemmas and even legal questions. Yet, unlike doctors or lawyers, these “AI listeners” offer no recognised privilege, and the intimate prompts they receive can be logged, mined for training, optimization and tomorrow advertising, accessed by employees, requested by law enforcement or pulled into discovery. This panel asks whether current data protection and procedural rules are enough when our inner lives are mediated by large language models. Bringing together a regulator, two academics, a leading Think Tank representative and a practicing lawyer, we will explore the reality behind privacy policies, the limits of GDPR, the government access risks, and the emerging calls for an “AI privilege” or privacy-by-design alternatives. How to build trust in Generative AI systems? How do we ensure talking to your chatbot never becomes a liability?
Google ()
Sarah de Haas (Google, )
The internet is shifting from a human-first web to an agentic ecosystem, creating new privacy gaps where agents need deep access to personal context. Static, binary security rules ("YOLO risk") are insufficient for this level of autonomy as dynamic systems can change behavior constantly. This workshop introduces Contextual Integrity (CI) as a dynamic normative framework that ensures the appropriate flow of personal data based on social norms. CI acts as both a curriculum for teaching agents to recognize norms and a benchmark for measuring their effectiveness in handling data appropriately across diverse contexts.
Join us for a highly interactive session where we’ll dive right into real-life scenarios! You will have the opportunity to actively brainstorm and work through practical use cases, identifying the pitfalls of existing rules and directly applying CI principles. Most importantly, we will outline concrete ways for you to get involved in the ongoing work around Contextual Integrity, giving you the chance to help shape these emerging standards and enhance the ecosystem's security and privacy for all.
Proposed Discussion Questions:
Q1: How can we define "correct" behavior in dynamic agentic systems where behavior cannot be pre-defined for every scenario?
Q2: What are the risks of relying on static, identity-only access controls as agents scale, and how does "YOLO risk" manifest?
Q3: How can agents establish provable trust through attestation and behavioral constraints rather than blind faith?
Q4: How do we ensure agentic ecosystems align with human expectations, diverse cultural contexts, and societal norms?
Google ()
Sarah de Haas (Google, )
The internet is shifting from a human-first web to an agentic ecosystem, creating new privacy gaps where agents need deep access to personal context. Static, binary security rules ("YOLO risk") are insufficient for this level of autonomy as dynamic systems can change behavior constantly. This workshop introduces Contextual Integrity (CI) as a dynamic normative framework that ensures the appropriate flow of personal data based on social norms. CI acts as both a curriculum for teaching agents to recognize norms and a benchmark for measuring their effectiveness in handling data appropriately across diverse contexts.
Join us for a highly interactive session where we’ll dive right into real-life scenarios! You will have the opportunity to actively brainstorm and work through practical use cases, identifying the pitfalls of existing rules and directly applying CI principles. Most importantly, we will outline concrete ways for you to get involved in the ongoing work around Contextual Integrity, giving you the chance to help shape these emerging standards and enhance the ecosystem's security and privacy for all.
Proposed Discussion Questions:
Q1: How can we define "correct" behavior in dynamic agentic systems where behavior cannot be pre-defined for every scenario?
Q2: What are the risks of relying on static, identity-only access controls as agents scale, and how does "YOLO risk" manifest?
Q3: How can agents establish provable trust through attestation and behavioral constraints rather than blind faith?
Q4: How do we ensure agentic ecosystems align with human expectations, diverse cultural contexts, and societal norms?
Appeals Centre Europe (Ireland)
Jenny Campbell (Appeals Centre Europe, Ireland), Sophie-Charlotte Walter (Appeals Centre Europe, Ireland)
The Appeal Centre's workshop will be relevant equally to CSOs, policymakers, legal practitioners, activists and academics. This workshop will take place in two parts: In part one, we'll take stock of how the new user right to out-of-court dispute settlement has been implemented two years after the EU's Digital Services Act came into force. By May, we hope to draw insights from nearly 20k disputes submitted to us. With plenty of room for Q&A, we'll discuss fundamental rights impacts, opportunities and challenges. Part 2 will be interactive: We'll use case studies of online harms and discuss whether and how these can be addressed through DSA out-of-court dispute settlement. This will be a mutual learning opportunity. We will share our perspective and hope to hear about the challenges our audience faces in dealing with social media platforms, as well as discussing strategies on how to navigate these.
TikTok (Europe)
Over the past decade, digital-first societies have enabled citizen engagement, offered consumers greater choice, and facilitated a major leap in how we efficiently go about our daily lives. But with greater online connectivity comes a wider threat landscape for traditionally offline risks to move online, and vice versa.
Data protection law has been around for all of that change, but in recent years the rulebook on how the online world is governed has expanded greatly. Data protection has been joined by new laws on online safety, minor protections, AI, and a modernisation of cybersecurity laws to address new concerns and threats. In particular, we have seen sustained focus by policymakers in Europe on risks to youth wellbeing, and on the proliferation of online-enabled fraud.
Efforts at regulatory coordination across the digital rulebook are underway, but the legal frameworks remain distinct and create their own specific obligations on organisations under their scope. This creates the potential for gaps in how threats and risks in one domain are understood in another. This can mean that governance and design choices made for online safety purposes may need to be demonstrated and evidenced as necessary and effective to a data protection regulator, if personal data is engaged. And it can mean that these issues rise up the political agenda where alignment is not universal, such as the current situation regarding CSAM detection in the EU.
Organisations under scope of multiple digital laws in Europe face a challenge of having to make distinct necessity cases under distinct regulatory regimes. This session seeks to explore where some of those intersectional issues between safety and data protection arise, and how multistakeholder dialogue can contribute to a sustainable way forward.
Aim of session:
Build Up (Spain)
Alexander Ramsbotham (Conciliation Resources, International), Guy Banim (Build Up, Europe), Lena Slachmuijlder (Council on Tech and Social Cohesion, Belgium)
Focus and rationale – Tech and AI are changing how war is fought and peace is made: AI-driven narrative threats shape armed conflict; the race for AI dominance is redrawing the geopolitical order; conventional ways peacemaking are being disrupted. Can tech help? Strategies for interactive collaboration – Expert insights from contributors to a major project on Digital Peacemaking will stimulate interdisciplinary exchange among workshop participants, in order to better understand: how tech and AI are affecting conflict; and how they can help peacemaking to adapt. Discussion will explore real-world case studies on tech in conflict, implications for peacemaking and priority areas to adapt and innovate. Workshop objectives Expand understanding of how technology is changing conflict and geopolitics Explore implications for peacemaking Stimulate interdisciplinary exchange among diverse tech experiences and perspectives Inform development of a major research project on Digital Peacemaking by the workshop organisers, to be published in January 2027.
Privacy Salon ()
In this discussion titled "A bit, a prompt," we will focus on the eponymous exhibition by artist aaajiao, held in 2024 at SETAREH Gallery in Berlin. The exhibition, spanning video, painting, and installation, explores the internet as a direct manifestation of computational power—how algorithmic mechanisms rooted in the attention economy and ideological tensions gradually alienate our behavior, turning everyday life into flickering, fragmented bits of information. Within this system, aaajiao seeks the void (gaps in the internet)—fluid spaces not yet fully occupied by systemic power, capable of soothing our wounds and dismantling the structures shaped by distraction and hatred.
EU Data Privacy Law and Serious Crime: Data Retention and Policymaking offers a comprehensive and comparative study of the right to private life and data retention within the EU and ECHR legal orders. Exploring EU data retention law and the role of Article 8 ECHR in a variety of contexts, from communications data to passenger name record data, the book casts a spotlight on the mainstreaming of the right to private life across EU policymaking, critically analysing the role of the European Commission and the CJEU as guardians of fundamental rights in their rights review of EU data retention measures.
Academic
Business
Policy
FRA ()
Alyson Kilpatrick (moderator, European Network of National Human Rights Institutions (ENNHRI); Northern Ireland Human Rights Commission, Europe), Kilian Gross (AI Office, Europe), Hanne Juncher (Council of Europe, Europe), Sirpa Rautio (European Union Agency for Fundamental Rights, Europe), Wojciech Wiewiórowski (European Data Protection Supervisor, Europe)
The use of AI presents both opportunities and challenges to fundamental rights, and its regulation will impact the future of Europe. Two important legal instruments adopted in 2024 – the EU AI Act and the Council of Europe Framework Convention on AI – include a variety of safeguards to address challenges ahead. Among other things, the AI Act foresees that providers and certain deployers have to identify, analyse and manage risks that high-risk AI systems pose to fundamental rights through risk management obligations and a fundamental rights impact assessment, respectively. The Council of Europe has developed a methodology to assess AI systems’ impact on human rights, democracy and the rule of law. There is much discussion about what these assessments should encompass. This panel will consider ways ahead and the relevance of fundamental rights assessments to protect European values when using AI.
Academic
Business
Policy
SURF (Netherlands)
Debby Kappetijn (moderator, SURF, Netherlands), Sjoera Nas (SURF (Privacy company, external researcher), Netherlands), Julian Kunkel (University of Göttingen, Germany), Cynthia Liem (University Delft, Netherlands)
(How) can generative AI be ethical and privacy-friendly in education and research? This panel brings together a vibrant mix of experts with experience and knowledge on how to make generative AI privacy-friendly while remaining critical of the double-edged situation the educational sector is in. Two GenAI tools, developed, governed and used by the educational sectors of the Netherlands and Germany, demonstrate how GenAI can align with public values and EU data protection principles. Sjoera Nas (Sr. Privacy Advisor) zooms in on the Dutch EduGenAI initiative, while Prof. Julian Kunkel (High-Performance Computing) shares insights into the German Chat AI project. As the necessary critical voice, Cynthia Liem (Associate Professor) challenges the responsible adoption of AI within the educational context.
Academic
Business
Policy
Ping (Privacy in Germany) & German Bar Association (Deutscher Anwaltverein) (Germany)
Niko Härting (moderator, Ping (Privacy in Germany) & German Bar Association, Germany), Christiane Wendehorst (University of Vienna, Austria), Christopher Millard (Queen Mary University of London, International), Markus Wünschelbaum (Data Protection Authority Hamburg, Germany), Merel Van Aar (Fieldfisher, Netherlands)
After nearly 8 years of the GDPR, we will discuss the concept of consent. In practice, consent is increasingly relied upon – more so than in 2018. This is mainly due to the CJEU case law on Article 6 of the GDPR, on “contract” and “legitimate interests”. It is a well-known fact that consent has its flaws. Data subjects tend to be overburdened with information and are rarely able to comprehend the exact consequences of consent. In our panel, we will discuss the shortcomings of consent and possible alternatives.
Academic
Business
Policy
University of Lausanne (Switzerland)
Aurelia Tamo-Larrieux (moderator, University of Lausanne, Switzerland), Sandra Cortesi (TUM, Germany), Luka Bekavac (University of St. Gallen, Switzerland), Ulrik Lyngs (Oxford University, International), Michael Veale (UCL Faculty of Laws, International)
The continuous and deepening integration of generative AI and pervasive social media platforms is fundamentally reshaping children’s digital experiences. While these technologies offer opportunities for connection and learning, they simultaneously heighten the persistent challenge of exposure to harmful content, ranging from misleading information to unsolicited sexual contacts to hate speech. While the EU's Digital Services Act (DSA) introduces stricter regulatory measures, including trusted flagger mechanisms for content removal, a significant gap remains: how to provide immediate, contextual support that is connected to a child's real-world social network. In this panel, we investigate child-centered strategies that move beyond mere restriction, through stricter age verification and prevention, and through increased content moderation provided by platforms, to actively promote children’s agency and well-being in the digital sphere.
Academic
Business
Policy
Institute for Information Law (IViR) (Netherlands)
Vilma Margarit Nikolaeva (moderator, Institute for Information Law (IViR), Netherlands), Danny Mekić (University of Leiden, Netherlands), Ljubiša Metikoš (Institute for Information Law (IViR), Netherlands), Lisa Steinfeld (NOYB – European Center for Digital Rights, Austria), Michaela Gehring (European Ombudsman, Belgium)
The EU digital rulebook strikes a balance between transparency for affected users and actors’ claims of confidentiality. The most prominent ex post transparency mechanism is the data subject access right to personal data under the General Data Protection Regulation. Yet, such access rights can be restricted in order to protect the rights and freedoms of others, including trade secrets. While jurisprudence about the balancing between conflicting positions of rights is consistent about the right to access corporate documentation such as log files in practice this often leads to a protracted legal battle. This panel will revisit experiences with trade secret claims by providers of digital technologies, the responsibilities of regulators and the impact of the digital omnibus on transparency rights.
Academic
Business
Policy
Stiftung Datenschutz (Germany)
Anja Wyrobek (moderator, European Parliament, Europe), Magdalena Steringer (European Commission, Europe), Nathalie Laneret (Criteo, France), Felix Mikolasch (noyb, Austria), Maximilian von Grafenstein (Alexander von Humboldt Institute for Internet and Society, Germany)
Informed consent is largely fictional in practice. Consumers are asked for consent at inconvenient moments and with exhausting frequency. To address ineffective consent, the EU legislator proposes the introduction of consent agents in Article 88b of the Digital Omnibus draft, requiring service providers to accept their signals. These agents would give consumers centralised, upfront information about consent purposes and allow them to set preferences once, which are then transmitted automatically to services. This would eliminate the need to repeatedly respond to individual consent requests. However, consent agents raise significant questions, particularly regarding the technical and visual design of agent-based consent processes. Such processes must enable truly informed and legally secure decisions and be governed by standards that are technology-neutral, future-proof, and constantly improvable. The panel will discuss current legislative and standardisation efforts and provide an overview of existing solutions.
Academic
Business
Policy
TILT (Tilburg Institute for Law, Technology and Society) (Netherlands)
Suzanne Nusselder (moderator, TILT (Tilburg Institute for Law, Technology and Society), Netherlands), Lokke Moerel (Morrison & Foerster, Netherlands), Renate Verheijen (ENISA, Europe), Pier Giorgio Chiara (University of Bologna, School of Law and ALMA-AI Research Center, Italy), Niovi Vavoula (University of Luxembourg, Luxembourg)
Cybersecurity, a rapidly evolving regulatory domain, has seen an explosion of legislative developments in recent years (NIS2, DORA, CRA). Effective cooperation and information sharing is crucial for strengthening the overall level of cybersecurity and is increasingly mandated by law. Cybersecurity is a multistakeholder endeavour characterised by a complex institutional landscape whereby information sharing occurs between various (decentralised) EU bodies, Member States, and an array of actors, such as CSIRTs, SOCs, public authorities, private actors, and occasionally law enforcement authorities. Importantly, such information-sharing ought to be done in accordance with EU data protection law. Inappropriate sharing and disclosure of cybersecurity information not only poses risks to cybersecurity itself but also to users. The panel will discuss the data protection challenges arising from cybersecurity information sharing and how these shall be addressed to ensure compliance with the EU data protection framework.
Mozilla (United States)
Udbhav Tiwari (Signal, United States), Elizabeth Renieris (Institute for Ethics in AI - University of Oxford, International), Julia Smakman (Ada Lovelace Institute, International)
Agentic AI systems are evolving from passive assistants into autonomous actors that operate across applications, services, and devices on users’ behalf. To function, they often require persistent access to personal data, communications, credentials, and system environments. This challenges privacy and security models built around user-initiated actions and limited data flows, raising questions about encryption, data minimisation, delegated authority and accountability. This workshop will examine how privacy, security, and agency can remain central in the agentic AI era. Rather than adopting an alarmist framing, it will focus on responsible innovation: clarifying how agentic systems alter traditional assumptions and identifying mechanisms to strengthen user control, including scoped permissions, revocable delegation, strong authentication, and oversight. Drawing on lessons from encrypted communications and browser security models, the session will explore how core privacy and security principles can be operationalised in agent architectures, placing user control at the centre of AI agent design and deployment.
Academic
Business
Policy
TILT (Tilburg Institute for Law, Technology and Society) (Netherlands)
Suzanne Nusselder (moderator, TILT (Tilburg Institute for Law, Technology and Society), Netherlands), Lokke Moerel (Morrison & Foerster, Netherlands), Renate Verheijen (ENISA, Europe), Pier Giorgio Chiara (University of Bologna, School of Law and ALMA-AI Research Center, Italy), Niovi Vavoula (University of Luxembourg, Luxembourg)
Cybersecurity, a rapidly evolving regulatory domain, has seen an explosion of legislative developments in recent years (NIS2, DORA, CRA). Effective cooperation and information sharing is crucial for strengthening the overall level of cybersecurity and is increasingly mandated by law. Cybersecurity is a multistakeholder endeavour characterised by a complex institutional landscape whereby information sharing occurs between various (decentralised) EU bodies, Member States, and an array of actors, such as CSIRTs, SOCs, public authorities, private actors, and occasionally law enforcement authorities. Importantly, such information-sharing ought to be done in accordance with EU data protection law. Inappropriate sharing and disclosure of cybersecurity information not only poses risks to cybersecurity itself but also to users. The panel will discuss the data protection challenges arising from cybersecurity information sharing and how these shall be addressed to ensure compliance with the EU data protection framework.
Mozilla (United States)
Udbhav Tiwari (Signal, United States), Elizabeth Renieris (Institute for Ethics in AI - University of Oxford, International), Julia Smakman (Ada Lovelace Institute, International)
Agentic AI systems are evolving from passive assistants into autonomous actors that operate across applications, services, and devices on users’ behalf. To function, they often require persistent access to personal data, communications, credentials, and system environments. This challenges privacy and security models built around user-initiated actions and limited data flows, raising questions about encryption, data minimisation, delegated authority and accountability. This workshop will examine how privacy, security, and agency can remain central in the agentic AI era. Rather than adopting an alarmist framing, it will focus on responsible innovation: clarifying how agentic systems alter traditional assumptions and identifying mechanisms to strengthen user control, including scoped permissions, revocable delegation, strong authentication, and oversight. Drawing on lessons from encrypted communications and browser security models, the session will explore how core privacy and security principles can be operationalised in agent architectures, placing user control at the centre of AI agent design and deployment.
Data Protection Moot Court (Europe)
Martin Baumann (noyb, Europe), Mariana Alicia Rissetto (Data Protection Moot Court, Europe), Marie-Catherine Hochreiter-Wagner (University of Vienna, Austria)
The Data Protection Moot Court (DPMC), supported by noyb and the University of Vienna, is an international competition for law students, willing to apply legal reasoning to a fictional data protection related case. They immerse themselves in the role of a legal representative of either a data subject or data controller. Bringing this format to the CPDP 2026, this interactive workshop simulates a complaint procedure before a Data Protection Authority, allowing participants to find and present arguments in small groups. The case will address key issues such as the processing of health data in a scientific research context and the use of AI for scientific research purposes. To give the case a special twist, it will take into account some amendments proposed by the Digital Omnibus framework. The workshop offers a hands-on opportunity to explore the DPMC and to explore future data protection challenges in health-related scientific research.
Check My Ads (International)
Iesha White (Check My Ads, International), Lex Zard (Check My Ads, International)
Google’s Performance Max (PMax) is an artificial intelligence (AI) media buying product that Google relies on for optimisation for advertising campaigns in its Google Ads advertising platform. As Google pushes advertisers to use this AI product, instead of traditional manual curation for ad placement, it is becoming increasingly important in online advertising. Check My Ads has conducted test campaigns using PMax to better understand the effects on advertisers, end-users, and within the digital advertising ecosystem. This workshop is designed to show the main findings of these campaigns, highlighting some of the tensions of Google PMax with personal data protection, consumer protection, online safety, and competition law, and seeks feedback from the CPDP community to the best policy solutions for addressing potential harms.
imec - KU Leuven CiTiP (Belgium)
Abdullah Elbi (imec - KU Leuven CiTiP, Belgium), Mandy Melissa Jane Wittens (imec-SMIT, Vrije Universiteit Brussel, Belgium)
Human oversight of AI is one of the key requirements in the EU AI Act to avoid unwanted consequences of high-risk AI systems. But the rise of agentic AI systems, capable of autonomous planning, tool use, and goal execution with minimal human involvement, calls into question how human oversight can still be exercised in practice. This interactive workshop discusses oversight models (human-in-the-loop, on-the-loop, in-command) to examine how agentic AI challenges current EU-level regulatory assumptions and emerging implementation practices under the EU AI Act, and to identify the pressure points. The session will start with two short expert provocations from legal, societal, and technical perspectives, followed by small-group work to discuss failure points and vulnerabilities of human oversight in high-risk agentic AI scenarios. Join us to discuss the following questions: (1) How does the EU AI Act regulate the role of humans in the agentic AI lifecycle? (2) What does meaningful human oversight look like in agentic AI systems, and where are the limits of human control reached?
LSTS, VUB (Belgium)
This book introduces the revolutionary use of AI in the field of cervical cancer detection. The book explores how advanced computer algorithms can analyse medical images and patient data to enhance early detection and accurate diagnosis of cervical cancer. The book starts by providing a comprehensive overview of cervical cancer, its risk factors, and the importance of early detection. It then delves into the fundamental concepts of artificial intelligence and its application in healthcare. Readers will gain a deeper understanding of how AI algorithms can "see" patterns in cervical cells and tissue, enabling the detection of abnormal cells and precancerous changes that may indicate the presence of cervical cancer. Drawing on the latest research and real-world case studies, the book showcases the various AI techniques used for cervical cancer screening, including the analysis of Pap smear and liquid-based cytology images.
In Like Moths to Light, a woman talks to us from inside a machine that records her brain activity. She describes a mental labyrinth composed of an old amusement park called Dreamland, 19th-century dream photography, contemporary experiments in mental decoding using AI, and Prophetic, a start-up whose goal is to control dreams. But what do our dreams see when they look at us?
Departing from Gala Hernandez Lopez short film, Virginia Mahieu will elaborate on her research into the societal impact of neurotechnology combining neuroscience and foresight to ensure that governance frameworks are up to scratch to serve a brain-healthy future.
Academic
Business
Policy
LSTS (Belgium)
Gloria GONZÁLEZ FUSTER (moderator, LSTS/VUB, Belgium), Asha Allen (Centre for Democracy and Technology Europe, International), Elisabetta Stringhi (Università degli Studi di Milano, Italy), Aleksandra Kuczerawy (KU Leuven, Belgium), Farieha Aziz (Bolo Bhi, Pakistan)
Gender-based violence keeps being a major problem online, with serious implications for our rights and freedoms. The Digital Services Act (DSA) was supposed to contribute to progress in this area, notably by obliging providers of very large online platforms and of very large online search engines to consider and act upon the possible systemic risk of negative effects in relation to gender-based violence. How is this working in practice, if it is? This panel, exploring developments in Europe but also other experiences and perspectives, will notably discuss:
EDPS (Europe)
Brendan Van Alsenoy (moderator, EDPS, Europe), Gianclaudio Malgieri (the Leiden University, Netherlands), Ruth Boardman (Bird & Bird's International Privacy and Data Protection Group, International), Anne Debet (CNIL (Commission nationale de l'informatique et des libertés), France), Stephane Kolanowski (International Committee of the Red Cross (ICRC), Switzerland)
The broad interpretation of the notion of special categories of data under the GDPR is informed by the aim of ensuring a high level of protection of fundamental rights and freedoms. Despite the general prohibition set forth in Article 9 GDPR, there is a clear increase in the processing of sensitive data in practice. In addition, an increasing number of policy and legislative initiatives would further legitimate the processing of special categories of data. These developments invite us to reflect upon the specific nature of sensitive data: what makes it so special? Is it "intrinsically" sensitive, or does its nature depend on the purpose and the context of the processing? The panel will take stock of both legal developments and operational challenges to provide a better understanding of the scope, logic and limits of special categories of data.
Academic
Business
Policy
ULD (Germany)
Felix Bieker (moderator, ULD and FIZ Karlsruhe, Germany), Maria Magierska (University of Maastricht, Netherlands), Itxaso Domínguez de Olazábal (EDRi, Europe), Midas Nouwens (Autoriteit Persoonsgegevens, Netherlands)
The Draghi report set the European Commission in regulatory overdrive. After spending the last decade on the creation of a (more or less) ambitious legal framework, it now follows an agenda to ‘simplify’ the digital domain in the name of competitiveness. While the Commission still emphasizes European values, these have become secondary both in rhetoric and substance, as it empowers enterprises to become arbiters of fundamental rights protections. This is particularly visible with so-called Artifical Intelligence, where the Commission displays massive anxiety and invokes colonial roots when it sees the EU as losing ground in a race to the ‘frontier’ with the USA and China. This panel will consider the consequences of the digital omnibus for the protection of individuals and the current AI rush. We will consider the following questions:
Academic
Business
Policy
Erasmus Center of Law and Digitalization, as part of Erasmus University Rotterdam (Netherlands)
Larisa Munteanu (moderator, Erasmus Center of Law and Digitalization, as part of Erasmus University Rotterdam, Netherlands), Adrianus van Heusden (European Commission, Europe), Paloma Krõõt Tupay (University of Tartu, Estonia), David Korteweg (Authority for Consumers and Markets in the Netherlands, Netherlands), Felix Mikolasch (noyb, Austria)
In the age of ticking boxes, we are gradually losing track of what we agree to: be it on social media, marketplaces, or even healthcare apps. The GDPR is the cornerstone of consent in the EU, but, recent phenomena such as platformisation and datafication established the premises of two new tools aimed at ensuring that the EU digital market is fostering both (a) a safe online environment for consumers (DSA) and (b) fair competition (DMA). This panel aims to dive into how this trichotomy works when it comes to consent mechanisms, looking at current challenges, trends and harmonisation ideas. The diverse expertise of the panellists allows us to illustrate a cross-sectoral perspective, which combines academia, policy-making, private practice and enforcement.
Academic
Business
Policy
University of Luxembourg (Luxembourg)
Stanislaw Tosza (moderator, University of Luxembourg, Luxembourg), Vanessa Franssen (University of Liège, Belgium), Tania Schroeter (European Commission (DG JUST), Europe), George Zlati (European Criminal Bar Association, Romania), Riane Harper (Microsoft, United States)
The e-Evidence Package is set to become operational in August 2026, when the Regulation on European Production and Preservation Orders starts applying. Since its adoption, Member States and EU institutions have been required to undertake significant preparations, notably the adaptation of national legal frameworks, the development of secure systems for data exchange between service providers and law enforcement authorities, and the negotiation of the EU–US agreement under the CLOUD Act to address conflicts of legal obligations concerning content data. At national level, these efforts include the introduction of effective sanctions for non-compliance, the provision of effective remedies for individuals concerned, and decisions on whether national rules on access to data should be aligned with the Regulation. This panel will take stock of these developments and assess the readiness for the entry into application of the e-Evidence Package.
Academic
Business
Policy
Law and Internet Foundation (Bulgaria)
Defne Halil (moderator, Law and Internet Foundation, Bulgaria), George Dimitrov (Law and Internet Foundation, Bulgaria), Guy Banim (Build Up, Europe), Polina Petrova (Law and Internet Foundation, Bulgaria)
Modern conflicts increasingly depend on digital infrastructures ranging from connectivity, data systems, analytics, and surveillance, operated by both public and private actors. In Europe and beyond, such dependencies raise important questions about digital sovereignty in wartime, where technological control shapes security and power. This panel starts by examining why digital sovereignty matters for the European Union in war times, and what is at stake when key digital infrastructures lie beyond public control. It then analyses the current legal and policy landscapes, asking how the Union is addressing these challenges. The panel then turns to prevention, recognising that acting in advance often matters more than reacting after incidents. It explores preparedness measures such as training infrastructures. Finally, the panel considers how the EU could strengthen its position and the consequences if current trajectories continue in the event of digital war.
University of Birmingham (International)
Teresa Rodríguez de las Heras Ballell (Universidad Carlos III de Madrid (and the European Law Institute President), Spain), Régis Chatellier (CNIL (Commission Nationale de l’Informatique et des Libertés - French Data Protection Authority), France), Elwira Macierzyńska (Kozminski University (also practicing lawyer at Lotus Kancelaria), Poland), James Norris (Digital Legacy Association (DLA) and My Wishes, International)
As digital lives become digital estates, who governs the data, assets, and identities we leave behind? This interactive workshop explores post-mortem governance at the crossroads of succession law, GDPR, platform contracts, and generative AI. Using the European Law Institute’s Model Rules on Succession to Digital Remains as a catalyst, the session includes short expert provocations, live audience polling, and a reflective exercise (“From Law to Self”) that invites participants to apply legal principles to their own digital lives. The workshop’s objectives are to: • clarify the distinction between digital assets and personal digital remains; • test the limits of platform terms versus succession and public policy; • explore GDPR-coherent access models that protect third parties; and • assess cross-border solutions that ensure predictable enforcement. By combining expert insight with participant engagement, the session aims to humanise digital legacy governance and generate concrete regulatory insights for policymakers, regulators, practitioners, and scholars.
University of Birmingham (International)
Teresa Rodríguez de las Heras Ballell (Universidad Carlos III de Madrid (and the European Law Institute President), Spain), Régis Chatellier (CNIL (Commission Nationale de l’Informatique et des Libertés - French Data Protection Authority), France), Elwira Macierzyńska (Kozminski University (also practicing lawyer at Lotus Kancelaria), Poland), James Norris (Digital Legacy Association (DLA) and My Wishes, International)
As digital lives become digital estates, who governs the data, assets, and identities we leave behind? This interactive workshop explores post-mortem governance at the crossroads of succession law, GDPR, platform contracts, and generative AI. Using the European Law Institute’s Model Rules on Succession to Digital Remains as a catalyst, the session includes short expert provocations, live audience polling, and a reflective exercise (“From Law to Self”) that invites participants to apply legal principles to their own digital lives. The workshop’s objectives are to: • clarify the distinction between digital assets and personal digital remains; • test the limits of platform terms versus succession and public policy; • explore GDPR-coherent access models that protect third parties; and • assess cross-border solutions that ensure predictable enforcement. By combining expert insight with participant engagement, the session aims to humanise digital legacy governance and generate concrete regulatory insights for policymakers, regulators, practitioners, and scholars.
FIZ Karlsruhe – Leibniz Institute for Information Infrastructure (Germany)
Franziska Boehm (FIZ Karlsruhe – Leibniz Institute for Information Infrastructure, Germany), Stephanie von Maltzan (FIZ Karlsruhe – Leibniz Institute for Information Infrastructure, Germany), Cosimo Monda (European Center on Privacy and Cybersecurity - Maastricht University, Netherlands), Karolina Podstawa (European Center on Privacy and Cybersecurity - Maastricht University, Netherlands)
This workshop involves an interactive, governance-level crisis simulation where participants' decisions determine the outcome of a high-stakes EU scenario. In the run-up to a major holiday period, compromised software updates trigger ransomware, disrupting rail and port logistics across two EU member states. Services fail and safety concerns rise, while attribution remains uncertain - organised crime or a state actor? The scenario unfolds in a series of fast-paced, timed rounds with live QR code polling on participants' phones, displaying results instantly to inform the next move. Under escalating pressure, participants must navigate ransom demands and uncertain attribution, make defensible decisions regarding legal obligations, develop public messaging strategies, decide whether to act nationally or coordinate at EU level and consider recovery options that may trade speed for sovereignty by relying on non-EU tools. After each vote, a moderated expert panel unpacks the implications for security, compliance, fundamental rights and strategic autonomy.
Privacy Studies Journal (Denmark)
Natalie Koerner (Privacy Studies Journal, Denmark), Lucas Rigillo (Privacy Studies Journal, Denmark)
Offline privacy depends on spatial and social cues (looking away, closing a door, etc)—with privacy as the power to exclude others. Online privacy lacks this dimension and is solely structured on personal information, rooted in Warren and Brandeis’s legal articulation of a “right to be let alone”. To ground the discussion, we will engage experimentally with common offline privacy practices. We will contrast embodied, situational experiences with online privacy mechanisms, such as cookie consent. Together, we will map the limits of “experiencing” privacy in digital environments, where there is often no tangible other, no shared space, and no immediate social situation. Warren and Brandeis’s wrote in response to the rise of mass media. These differed significantly from the internet. In this workshop, we examine the gap between the experience of privacy and the regulation of online privacy; participants will achieve a nuanced understanding of how to address this gap.
University of Lausanne (Switzerland)
With the promise of greater efficiency and effectiveness, public authorities have increasingly turned to algorithmic systems to regulate and govern society. In Algorithmic Rule By Law, Nathalie Smuha examines this reliance on algorithmic regulation and shows how it can erode the rule of law. Drawing on extensive research and examples, Smuha argues that outsourcing important administrative decisions to algorithmic systems undermines core principles of democracy. Smuha further demonstrates that this risk is far from hypothetical or one that can be confined to authoritarian regimes, as many of her examples are drawn from public authorities in liberal democracies that are already making use of algorithmic regulation. Focusing on the European Union, Smuha argues that the EU's digital agenda is misaligned with its aim to protect the rule of law. Novel and timely, this book should be read by anyone interested in the intersection of law, technology and government.
Disco & Atomic War directed by Jaak Kilmi
Winner of the Best Documentary prize at the Warsaw International Film Festival, this witty, charming, and provocative film recounts how in the mid 1980's, the nation of Estonia still lay firmly in the grip of the Soviet Union, and the repressive authorities controlled virtually all aspects of Estonian life. Just a few miles across the border in Finland, a huge new television antenna was built that broadcast western signals in all directions-including directly into the heart of the Talinn, the capital of Estonia. Estonians secretly tuned in, turning television and radio into subtle but powerful tools of resistance. Through stories of media “piracy,” cultural curiosity, and the historical and social context of the time, the film highlights how the desire for free information cannot be contained. Much like the internet today, radio and television served as the primary means of accessing external information, and the film suggests that repressive control can hardly prevent shared futures.
Academic
Business
Policy
Microsoft (Belgium)
Lorelien Hoet (moderator, Microsoft, Belgium), Michael Aendenhof (Belgian Permanent Representation to the EU, Belgium), Alexandre Ferreira Gomes (Clingendael Institute, Netherlands), Valerie Höss (Commerzbank, Germany), Chiara Manfredini (Access Now, Italy), Andres Raieste (Nortal, Estonia)
In our global and digital world, marked by geopolitical uncertainty, Europe aims to stimulate digital infrastructure that is trusted, resilient and secure, while fostering competitiveness, innovation and tech sovereignty. Some stakeholders believe that achieving these goals requires a shift towards more localized digital infrastructure and fewer data transfers. Conversely, others argue that the key lies in expanding digital solutions to boost Europe's competitiveness, and that this cannot be done without international cooperation. In this panel, we aim to gather insights from selected experts and thought leaders on these diverse viewpoints. Specifically, we seek to explore how robust cybersecurity protection and resilience can go hand in hand with EU's data protection framework.
Mozilla Foundation (Belgium)
Claire Pershan (moderator, Mozilla Foundation, Belgium), Benoît Courty (CodeCarbon, France), Nadia Nadesan (Civic Tech/Platoniq, Spain), Agnès Crepet (Fairphone, Le Mouton Numerique, Netherlands)
Public value does not always align with immediate market returns. At Mozilla Foundation, we believe that when people design technology for the problems they understand best, those technologies will find their communities and outlive the boom and bust hype cycles of the next big thing. Profit-driven models predominantly push technology toward rapid growth, commercialization and market validation, often forcing compromises that undermine community values. These growth models tend to yield technology with both outsized data collection practices and outsized environmental impacts. But right-sized alternatives do exist.
Academic
Business
Policy
Georgia Institute of Technology (United States)
Kenneth Propp (moderator, Georgetown University Law Center, United States), Ignacio Gomez Navarro (E-Evidence and Cybercrime, European Commission, Europe), Elonnai Hickok (Global Network Initiative, International), DeBrae Kennedy-Mayo (Georgia Institute of Technology, United States), Jan Kralik (Cybercrime Division, Council of Europe, Europe)
The United Nations has completed work on a new multilateral Convention Against Cybercrime; many UN members are expected to sign in 2025. The Convention obliges State Parties to criminalize a range of cyber-dependent offenses and to assist each other in obtaining electronic evidence for criminal investigations and prosecutions. The UN Convention has many similarities to the Council of Europe (COE) Cybercrime Convention (Budapest Convention). Nonetheless, the new instrument has attracted strong opposition from human rights groups and technology companies. They believe the UN Convention lacks safeguards against abuse by authoritarian governments seeking to suppress free speech and dissent, and that it could undermine data protection guarantees. This panel will explore the UN Convention’s potential law enforcement benefits, its value in relation to the Budapest Convention, and the sufficiency of its protections against misuse.
Academic
Business
Policy
AlgoSoc (Netherlands)
Maria Luisa Stasi (moderator, Article 19, Europe), Cecilia Rikap (University College London, International), Natali Helberger (University of Amsterdam, Netherlands), Wladimir Mufty (SURF, Netherlands), Frank Karlitschek (Nextcloud, International)
Digital infrastructures are essential resources enabling research and education. Now, however, universities that have long made themselves dependent on cloud services provided by BigTech are additionally incorporating a variety of AI-tools that it offers. This does not only come with risks to privacy, data protection, and security, but also threatens the very core of universities: academic freedom. Firstly, such freedom – next to scientific advancements and institutional autonomy – may fall victim to changes in transatlantic relations. Secondly, though less manifestly, academia may become shaped by economic rather than public values, such as research integrity. This panel will consider whether the use of alternative research infrastructures by universities – opposing Big Tech’s dominance – is feasible and can preserve universities’ independence by enhancing digital sovereignty, which is a prerequisite for academic freedom in the age of AI and cloud computing.
Academic
Business
Policy
Open Markets Europe (Europe)
Max von Thun (moderator, Open Markets Europe, International), Udbhav Tiwari (Signal, United States), Frederike Kaltheuner (AI Now Institute, Europe), Schwartz Ori (OECD, International), Luca Aguzzoni (DMA, DG Connect, European Commissio, Italy)
While AGI remains hypothetical, the emergence of universal digital intermediaries appears a real possibility. AI assistants are increasingly being enhanced with agentic capabilities that enable them to interact with digital content across the internet, as well as with other agents. This represents a fundamentally new, mass-market digital consumer technology that will challenge today's open web, potentially becoming the dominant gateway through which many interact with the digital world. But while it may make our lives more convenient and productive, the creation of a new layer of intermediation in the online realm will also create new opportunities for exploitation and abuse by those who control it, particularly in a concentrated market. In delegating agency, people and businesses risk putting themselves at the mercy of whoever they entrust it to. This panel will discuss how fair competition can shape the landscape of this potentially transformative technology for the better, preventing it from becoming yet another tool that concentrates power in the hands of tech monopolies.
Academic
Business
Policy
Dutch Association for AI Lawyers (VAI-A) (Netherlands)
Joost Gerritsen (moderator, Utrecht University, Netherlands), Dr Laura Drechsler (KU Leuven, Belgium), Simon Hania (NL Net Foundation, Netherlands), Berend van der Eijk (Bird & Bird, International), Georgia Bakatsia (EDPS, International)
The Data Act, in force since September 2025, is reshaping Europe’s data economy by introducing new rules for fairness, access, and innovation. This panel brings together experts from academia, industry, and legal practice to explore its early real‑world impact, the challenges emerging in implementation, and how it interacts with the broader EU digital rulebook, including the GDPR, DSA, DMA and AI Act. We will discuss practical issues faced by manufacturers, cloud providers and data users; the complexities of overlapping regulatory obligations; and the implications for competitiveness and compliance. Finally, the panel will consider the Data Act’s forward‑looking role as a foundation for future European data‑sharing frameworks, from financial and health data spaces to sector‑specific legislation, and assess whether it is delivering on its promise to enable innovation while safeguarding rights and reducing burdens on businesses.
Lexxion (Germany)
Bart van der Sloot (moderator, Tilburg University, Netherlands), Giorgia Loredan (Queen Mary University of London, United Kingdom), Güliz Arpalı (University of Münster, Germany), Hielke Hijmans (Belgian Data Protection Authority, Belgium), Frederik Zuiderveen Borgesius (Radboud University, Netherlands)
This panel brings together the two finalists of the 2026 EDPL Young Scholar Award to present and discuss their cutting-edge research with the jury. The discussion will explore current judicial uncertainties surrounding compensation for non-material damages under Article 82 GDPR, alongside the challenge of operationalising explainability-by-design in automated decision-making systems under the GDPR. Together, the presentations examine GDPR rights in action, at the intersection of enforcement, accountability, and AI governance. The panel concludes with the announcement of the Young Scholar Award winner and a short award ceremony.
Law & Innovation / Einstein Center Digital Future / Alexander von Humboldt Institute for Internet and Society (Europe)
Jan Schallaböck (ISO / DIN / iRights.Law, Europe), Felix Mikolasch (noyb, Austria), Valentin Rupp (Law & Innovation, Europe), Max von Grafenstein (Einstein Center Digital Future / Alexander von Humboldt Institute for Internet and Society / Law & Innovation, Europe)
According to its current draft, the EU Commission has the task of developing or commissioning the development of a standard for the technical implementation of Article 88b Digital Omnibus. Article 88b solves the current cookie banner problem by forcing service providers to respect the signals of consent agents. Consent agents allow consumers to set their preferences for their consent once and in advance, which the agent then passes on to the provider of the service used. However, the success of Article 88b in practice, and thus already in the trilogue, will depend heavily on how these agents are technically designed. Will consumers simply be enabled to accept or reject everything without still understanding what the data is actually to be used for and what the advantages and disadvantages are? In this workshop, we want to critically discuss a draft standard (ConStand) that we have developed to avoid this risk.
Law & Innovation / Einstein Center Digital Future / Alexander von Humboldt Institute for Internet and Society (Europe)
Jan Schallaböck (ISO / DIN / iRights.Law, Europe), Felix Mikolasch (noyb, Austria), Valentin Rupp (Law & Innovation, Europe), Max von Grafenstein (Einstein Center Digital Future / Alexander von Humboldt Institute for Internet and Society / Law & Innovation, Europe)
According to its current draft, the EU Commission has the task of developing or commissioning the development of a standard for the technical implementation of Article 88b Digital Omnibus. Article 88b solves the current cookie banner problem by forcing service providers to respect the signals of consent agents. Consent agents allow consumers to set their preferences for their consent once and in advance, which the agent then passes on to the provider of the service used. However, the success of Article 88b in practice, and thus already in the trilogue, will depend heavily on how these agents are technically designed. Will consumers simply be enabled to accept or reject everything without still understanding what the data is actually to be used for and what the advantages and disadvantages are? In this workshop, we want to critically discuss a draft standard (ConStand) that we have developed to avoid this risk.
Autoriteit Persoonsgegevens (The Dutch Data Protection Authority) (Netherlands)
Natalja Krijgsman (Autoriteit Persoonsgegevens (The Dutch Data Protection Authority), Netherlands)
Individuals subject to solely automated, significant decision-making have a right to receive “meaningful information about the logic involved”. The Dutch DPA observes automated decision-making is rapidly increasing, along with a growing integration of LLM's into workplace software. The black-box nature of some of these systems poses serious risks to transparency. In light of this, the Dutch DPA is developing guidance on the Right to an Explanation that will be published later this year. In this workshop, we wish to consult the main points of our draft guidance with the CPDP audience. The workshop will consist of a short presentation of our guidance, followed by a workshop where participants will design their own explanation for an algorithmic decision.
TU Delft (Netherlands)
Nina Baranowska (Leiden University, Netherlands), Gianclaudio Malgieri (Leiden University, Netherlands), Ben Wagner (TU Delft, InHolland, IT:U, Europe), Marie-Therese Sekwenz (TU Delft, Netherlands)
We examine the Digital Services Act’s systemic risk assessment obligations through the lens of social media users in vulnerable positions. Participants work with two case studies inspired by X’s “undressing” feature and TikTok’s addictive design to test a toolkit for identifying potential negative effects on fundamental rights while explicitly accounting for vulnerability. Participants are divided into interdisciplinary groups based on expertise. Each group runs the case through a prepared decision tree, surfacing key tensions in DSA systemic risk assessment and translating them into actionable guidance. Groups will identify and prioritise systemic risks and affected rights, specify what evidence regulators should request to substantiate platform claims, and propose mitigation and monitoring steps that regulators can operationalise. The workshop produces concrete outputs: draft regulator-facing guidelines and an annotated decision tree showing where the tool supports consistent assessment and where gaps or ambiguities remain that require further policymaker attention.
The Digital Period (Europe)
Sophie-Louise Feith (Hanah Ecosystem, Netherlands), Marie Kochsiek (Drip, Germany)
What can Europe learn from not-for-profit feminist femtech initiatives that build health technologies from the ground up together with the people whose bodies are directly affected? As Europe advances value-based and trustworthy technology through initiatives such as the European Health Data Space, key decisions on data governance, ownership, and funding are still often made far from lived experience. Femtech initiatives offer a democratic alternative to the dominant tech players in our digital economy: they design and govern technology with users and embed collective decision-making, and shared responsibility in the design and governance of technology itself. Through facilitated small-group collaboration using concrete cases, participants will examine solutions going forward. This workshop is organized by the FemTechCollective consisting out of The Digital Period, Drip period & cycle tracker and Hanah Ecosystem and has been made possible with the support of Mama Cash and Post-X Society.
Privacy Salon ()
In this discussion, we take artist YAO Qingmei’s work The Burrow—Monitor & Control (2022) as a point of departure to explore mechanisms of bodily governance under global surveillance systems.
Inspired by Franz Kafka’s novella The Burrow, the video depicts a female security guard deeply connected to security machines, situated in an underground surveillance room of a gated middle-class community in China. In this hidden digital prison, the controller experiences the outside world—its time, nature, and weather—only through LCD screens and cameras. Yet she herself is also under constant surveillance, reflecting how individuals are disciplined and self-disciplined under invisible regimes of panoptic control.
In Russia, every piece of data can be bought—this means not only your passport or insurance number, but also information about your reservations, trips, food orders, taxes and everything else you can imagine. For years, the government has been attempting to put this market under its full control and turn Russia into a digital concentration camp. So far, however, these attempts have been far from successful. While it’s true that Putin’s Russia is a digital surveillance state, it is also true that anyone with financial means and internet access can gain access to the most sensitive data of both ordinary and high-ranking people. Criminals use this information to create intricate scams, stalkers use it to follow their victims, and investigative journalists use it to uncover the state's darkest secrets.
In The Russian Cyberpunk, Andrei Zakharov, one of Russian top investigative journalists, paints the full picture of this wild reality, and makes sense of it. The main characters of the book are people who created this reality: tech moguls (such as Pavel Durov, Telegram’s founder), KGB agents, sellers of private information and others major players in the market of de-anonymization and surveillance in Russia. The book explains how this careless attitude towards data and tech can bring the worst out in people, and helps to understand how data can be used against those who are in power.
Academic
Business
Policy
Max Planck Institute For Security And Privacy (Germany)
Asia Biega (moderator, Max Planck Institute For Security And Privacy, Germany), Jane Suiter (Dublin City University, Ireland), Kristina Zenner (BFDI, Germany), Nicholas Vincent (Simon Fraser University, Canada), Six Silberman (University of Oxford and International Trade Union Confederation, International)
Current technology and data governance frameworks center on individuals. Yet, these approaches face fundamental limitations: they place a burden on fine-grained individual decision-making, ignore the interconnected nature of data, and struggle to address harms that are inherently collective. Beyond simplistic fixes, these limitations may require the development of new governance approaches that align with the collective nature of contemporary technologies and their impacts. This panel brings together experts in computer science, social sciences, law, and policy, to explore collective approaches to technology governance. We examine the forms collective governance might take, from data trusts to consent assemblies to participatory policy processes, and interrogate the socio-technical infrastructure, legal foundations, and legitimacy conditions that these approaches require. Rather than abandoning individual rights, we ask how collective mechanisms can complement and strengthen them while addressing governance challenges that individualistic frameworks cannot.
Academic
Policy
Católica Global School of Law (Portugal)
Giovanni De Gregorio (moderator, Católica Global School of Law, Portugal), Simona Demkova (Leiden University, Netherlands), Angelica Fernandez (Commission Nationale pour la Protection des Données – CNPD, Luxembourg), Lubos Kuklis (European Commission, Europe), Bianca-Ioana Marcu (Future of Privacy Forum (FPF), International)
As the European Union has positioned itself as a global standard-setter in digital governance, attention has been increasingly shifting from regulation to enforcement and its global implications. When viewed internally, the expansion of the European regulatory approach, as reflected in the GDPR, the DSA and the AI Act, has generated overlapping mandates and institutional friction in enforcing this regulatory framework, raising concerns about legal certainty and the rule of law. These challenges are particularly relevant in the context of current “omnibus” efforts to simplify digital regulation, which risk overlooking the urgency of effective and coordinated enforcement. This panel brings together diverse perspectives from academia, policy-making and civil society to examine how EU enforcement structures can adapt in a time when competing regulatory visions and shared democratic commitments shape the role of digital regulation.
Academic
Business
Policy
Statistics Netherlands (Netherlands)
Matjaž Jug (moderator, Statistics Netherlands, Netherlands), Dave Buckley (OpenMined, International), Robert Pisarczyk (Oblivious, Ireland), Rosanne Turner (Statistics Netherlands, Netherlands), Yurii Sushko (Google, International)
National statistical offices have long operated at the sharp edge of privacy, trust, and public-interest data use. As governments demand more timely, granular, and integrated data - often spanning borders - NSOs are turning to privacy-enhancing technologies (PETs) to reconcile data needs with strict legal and ethical constraints. Drawing on the work of the UN Committee of Experts and real PETs deployments – from international trade reconciliation to privacy-preserving linkage, federated learning, and differential privacy – this panel examines what it takes to use PETs in production. It explores how legal, policy, and technical stakeholders collaborate, and why standard anonymisation and traditional disclosure controls are insufficient for today’s data ecosystems. What emerges are practical lessons for strengthening privacy-by-design, shaping cross-border data frameworks, and building the trusted data infrastructures needed for the next decade..
Academic
Business
Policy
Crime & Society Research Group (CRiS), VUB (Belgium)
Orla Drummond (moderator, Trilateral Research, Ireland), Karen Garland (Marie Collins Foundation, International), Tamara Polajnar (herEthical AI, International), Aagje Ieven (Missing Children Europe, Belgium), Desara Dushi (Vrije Universiteit Brussel, Belgium)
In the context of the EU legislative developments, debates on online child sexual abuse (CSA) investigations often focus on privacy, security and encryption issues. This panel will however refocus on children’s rights and victim support policies based on lived experience and trauma informed knowledge. Drawing on SALVUS (Horizon Europe project) research, we map the full investigatory pathway from detection, reporting to platforms and law enforcement, evidence collection and preservation, to redress and victim support. The latter stages are particularly often associated with practical difficulties. We will discuss how and what European instruments and national laws enable or constrain child- and human-rights compliant investigations in practice, and where accountability gaps may remain. Speakers from academia, children’s rights NGOs, victim support, and platform safety practitioner will discuss practical, rights-based safeguards that protect children and their rights.
Academic
Business
Policy
FGV (Brazil)
Nicolo Zingales (moderator, Nicolo Zingales, Brazil), Cecilia Rikaap (University College of London, International), Divij Joshi (ODI Global, India), Melody Musoni (European Center for Development Policy Management, Netherlands), Sebastiano Toffaletti (Digital SME Alliance, International)
As Artificial Intelligence becomes a strategic infrastructure shaping economic development, public governance, and geopolitical power, debates on AI sovereignty have been predominantly framed from the perspective of the most developed countries. Yet, countries from the Global Majority are increasingly articulating alternative models of AI sovereignty, grounded in distinct institutional capacities, development priorities, and governance traditions. This panel aims to analyze he concept of AI Sovereignty and how Global Majority countries can build meaningful AI sovereignty and what lessons their experiences offer in comparison to dominant approaches. The panel will explore AI sovereignty as the ability to build and govern an integrated AI Stack, including data governance, digital public infrastructure, computational capacity, digital literacy, strong cybersecurity, reliable electrical power, and regulatory frameworks. Particular attention will be given to identifying Key Sovereignty AI Enablers (KASE) that could enable countries to move beyond dependency toward sustainable AI ecosystem
CPDP (Belgium)
Stefania Milan (moderator, University of Amsterdam, Netherlands), Mariam Ibrahim (AI Safety Initiative Groningen, Europe), Saffron Sadiq (University of Cambridge, International), Mustapha JID (Télécom Paris (Institut Polytechnique de Paris), France), Thiago Moraes (Vrije Universiteit Brussels, Belgium)
The three academic sessions are an integral part of CPDP's mission to connect scholarship with practice and policymaking. In 2026, Academic Session II examines questions of data protection, privacy, and digital governance through an AI lens. Papers were selected through an open call and presented to foster exchange beyond academia. The session features Oversight or Overreach? Rethinking Accountability in Automated Societies (Saffron Sadiq), Setting up a Definition for Regulatory Sandboxes (Thiago Moraes), Data Governance in EU Smart Mobility: Competing Visions of Access, Privacy, and Cybersecurity in Connected Vehicles (Mustapha Jid), and EU-Agent-Bench: Measuring Illegal Behavior of LLM Agents Under EU Law (Mariam Ibrahim, Tiwai Mhundwa, Ilija Lichkovski & Alexander Müller).
CPDP (Belgium)
Stefania Milan (moderator, University of Amsterdam, Netherlands), Mariam Ibrahim (AI Safety Initiative Groningen, Europe), Saffron Sadiq (University of Cambridge, International), Mustapha JID (Télécom Paris (Institut Polytechnique de Paris), France), Thiago Moraes (Vrije Universiteit Brussels, Belgium)
The three academic sessions are an integral part of CPDP's mission to connect scholarship with practice and policymaking. In 2026, Academic Session II examines questions of data protection, privacy, and digital governance through an AI lens. Papers were selected through an open call and presented to foster exchange beyond academia. The session features Oversight or Overreach? Rethinking Accountability in Automated Societies (Saffron Sadiq), Setting up a Definition for Regulatory Sandboxes (Thiago Moraes), Data Governance in EU Smart Mobility: Competing Visions of Access, Privacy, and Cybersecurity in Connected Vehicles (Mustapha Jid), and EU-Agent-Bench: Measuring Illegal Behavior of LLM Agents Under EU Law (Mariam Ibrahim, Tiwai Mhundwa, Ilija Lichkovski & Alexander Müller).
Brazilian Internet Steering Committee (CGI.br) (Brazil)
Marcelo Fornazin (Brazilian Internet Steering Committee (CGI.br), Brazil), Bárbara Simão (Article 19, Europe), Laura Lazaro Cabrera (Centre for Democracy and Technology Europe (CDT), Europe)
This workshop aims to bring an expository analysis of public digital services offered globally, focusing on the datafication of public services from diverse perspectives. Through invited facilitators, realities of different regions will be explored, such as the Brazilian (LatAm) and European ones.They will present real-world success cases while addressing systemic concerns regarding digital exclusion, state surveillance, and privacy risks within their respective contexts. The session will promote reciprocal learning via a shared questionnaire at the beginning to gather information on the national digital public service contexts of the participants. These responses will be compiled and discussed in the final segment, fostering a dialogue on the diverse realities represented. The goal is to provide a shared perspective on infrastructure building, balancing efficiency gains with the protection of fundamental rights in datafied societies.
Frederik de Wilde is an artist whose practice spans visual art, media art, and philosophy. He investigates and works at the intersection of art, science, and technology. His oeuvre offers critical insights into technology and society, exploring the inaudible, the elusive, and the invisible in both digital and physical spaces.
With TARPIT, the art project he is developing as a net-artist-in-residence, he aims to investigate how web bots shamelessly scrape the internet—including our own websites—in search of relevant data. This raises important questions: For whom? For what purpose?
At CPDP.ai, he is primarily seeking expertise as a source of input for this open-source project. What ethical questions are at stake? They can emerge from all directions—for instance, from the art world or the field of cybersecurity.
The panel is conceived as a workshop and Q&A—not one where questions come only from the audience, but one where the artist will also pose questions to the CPDP.ai community.
The Science Fiction & Information Law Writing Competition was born out of the idea that science fiction and information law have much in common. Not only is there a fair share of law in science fiction, but information law experts and science fiction authors also share a vivid interest in the way technology is interfacing and transforming our digital society, and the values and rules that matter to us. And rules as well as narratives are powerful tools in shaping the future. This is why the Institute for Information Law, as one of the oldest and largest research institutes in information law, once launched the first edition of this competition in 2018, and since then the future of information has only become more intriguing.
Now, with the competition’s fourth edition, the level of submissions was higher than ever. Out of seven shortlisted stories already published at DigiCon’s Sci-Fi Section, three winners will be announced during the Award Ceremony. It is held at CPDP for the second time. The theme of this edition is The Technologised Future of Truth. The winning stories discussed during the ceremony will show how closely that theme aligns with CPDP's theme of this year, "Competing Visions, Shared Futures". Come and be provoked and haunted by the stories, immersed in the future.
Center for AI and Digital Policy (Europe)
Data Protection Scholars Network ()
Ready to test your data protection knowledge with fun yet challenging questions? Grab your phone and join us to compete for the "Ultimate CPDPub Quiz Champion" title. And wait, there is more - a surprise prize awaits the ultimate champion, along with esteemed international recognition!
Sponsored by Brasserie de la Senne.
Brasserie de la Senne
Anna Bochdreef 19-21
1000 Brussels
Join us for drinks, nibbles, and a chance to connect with others building a better digital future for all.
Academic
Business
Policy
Tilburg University - Tilburg Institute for Law, Technology and Society (TILT) (Netherlands)
Aimen Taimur (moderator, Tilburg University - Tilburg Institute for Law, Technology and Society (TILT), Netherlands), Virginia Mahieu (Centre for Future Generations, Belgium), Timo Istace (University of Antwerp, Belgium), Alexandra Ziaka (Tilburg University - Tilburg Institute for Law, Technology and Society (TILT), Netherlands), Jacopo Piemonte (LSTS, VUB, CDSL, Italy)
Neurotechnology is leaving the lab and entering offices, classrooms, clinics and consumer devices. Brain-derived signals and the inferences built on top of them create distinctive privacy risks that current compliance playbooks do not fully address. This panel examines how GDPR and Convention 108+ can be applied to neural signals and derived profiles, what to do about de-identification that rarely holds, and how to keep secondary use in check when inference pipelines are opaque. We will translate ethical guidance into enforceable practice, focusing on DPIAs, legal bases in research and employment, cross-border processing, and procurement criteria. The aim is practical: give regulators, researchers and firms clear choices that actually reduce risk while allowing careful innovation.
Academic
Business
Policy
Fraunhofer Institute for Systems and Innovation Research ISI (Germany)
Murat Karaboga (moderator, Fraunhofer ISI, Germany), Michael Raschke (Blickshift GmbH, Germany), Theresa Krampe (University of Tübingen, International Centre for Ethics in Science, Germany), Christian L. Geminn (University of Kassel, Germany)
Eye tracking refers to the recording of a person's eye movements, which mainly consist of fixations, saccades, and regressions. Eye tracking, integrated into HMDs such as the Meta Quest Pro, is now used in a range of applications, e.g., in computer games for more intuitive human-computer interaction, but also to improve graphics performance or game content. However, the technology also has the potential to violate privacy. Eye tracking can be used to draw conclusions about mental, physical, and emotional states, ethnic affiliations, and many other insights into the “inner workings” of users. In our panel, we will discuss:
LSTS, VUB (Belgium)
This workshop introduces “algo-rhythms” by Anastasia Karagianni to explore how data-driven systems used in maternity healthcare transform embodied experience into measurable forms that regulate (health)care. Contractions become time intervals, pain becomes a score, and risk becomes probability, data that are compared, modelled, and used to trigger decisions.
Through feminist epistemologies and using dance as both metaphor and method, participants will examine how continuous monitoring turns pregnant bodies into sites of surveillance, discipline, and normative control. Combining theoretical input with movement-based exploration, and featuring guest speaker Sean Mulcahy, the workshop investigates how law and AI organise the tempo of suffering. It invites participants to collectively imagine alternative rhythms of care grounded in lived experience, relational knowledge, and embodied resistance.
Maastricht University (Netherlands), European Centre on Privacy and Cybersecurity (ECPC), Maastricht University (Netherlands), Digital Constitutionalist (Netherlands)
From Frankenstein to Snow Crash, science fiction has long served as a mirror for our deepest ambitions—and fears—about technology. But what happens when these speculative warnings are misread as roadmaps? In this session, we’ll examine how foundational sci-fi novels, often crafted as dystopian cautionary tales, have been reinterpreted by today’s tech elite as aspirational visions: Elon Musk styling himself after Iron Man, Jeff Bezos chasing Star Trek-inspired space dominion, and Mark Zuckerberg branding his virtual empire with a term lifted from a dystopia of disconnection.
We’ll explore why these misreadings persist—and what alternatives we might imagine. Emerging genres like solarpunk and degrowth fiction offer radically different visions of the future: collaborative, regenerative, and grounded in ecological wisdom. What can we learn from Becky Chambers’ A Psalm for the Wild-Built, where humans and robots find harmony in mutual respect and simplicity? Or from Ursula K. Le Guin’s The Dispossessed, which challenges us to rethink ownership, productivity, and the very structure of society?
Designed for storytellers, technologists, and policy makers alike, this interactive session invites you to consider the narratives shaping our future—and to co-create new ones. Join us as we reimagine speculative fiction not as escapism, but as a toolkit for envisioning just, sustainable, and humane alternatives
Academic
Business
Policy
Privacy International (International)
Ilia Siatitsa (moderator, Privacy International, International), Chantal Joris (Article 19, International), Joelle Rizk (International Committee of the Red Cross (ICRC), International), Frank Slijper (PAX, Europe), Iverna McGowan (Office of the United Nations High Commissioner for Human Rights, United Kingdom)
The integration of AI-driven decision support systems (AI DSS) and other AI models into military operations is transforming the conduct of war. Marketed as tools for faster, more precise decision-making and compliance with international humanitarian law, these systems depend on vast amounts of data—fuelling unprecedented surveillance practices. From Gaza to Ukraine, AI technologies are shaping targeting decisions and risk assessments, while tech giants and defence start-ups emerge as pivotal actors in this ecosystem. This panel will interrogate the normalisation of surveillance in armed conflict, the tension between humanitarian and human rights law, and the export of militarised AI technologies to non-conflict contexts. Experts will explore implications for civilian protection, privacy, and freedom of expression, and critically assess the responsibilities of private companies driving these technologies and their accountability under international norms.
Academic
Business
Policy
Open Future (Netherlands)
Zuzanna Warso (moderator, Open Future, Netherlands), Ana Ornelas (European Sex Workers Alliance, Brazil), Marcel Kolaja (Access Now, International), Fanny Hidvegi (AI Collaborative, Europe), Svea Windwehr (Mozilla, Germany)
In previous mandates of the European Commission, progressive tech policy circles established a loose modus operandi: follow the Commission’s regulatory agenda, build coalitions, collectively establish positions, and advocate for tweaks to improve these legislative proposals. There were certainly exceptions to this, such as the Chat Control proposal, but the situation has changed radically under the current mandate. The flavour of the day is radical deregulation of human rights safeguards, misleadingly labelled as ‘simplification,’ coupled with an aggressively anti-rights regulatory agenda aiming to undermine encryption, facilitate abuses of migrants, and funnel public resources into a naive project of AI-boosterism. Policy practitioners’ tried and tested approaches don’t feel sufficient to advance justice-centred policy impact, so what options are on the table? This panel will unpack the complexities of this changing landscape, with insight from panelists representing civil society, industry and philanthropy
Academic
Business
Policy
Gesellschaft für Freiheitsrechte (GFF) (Germany)
Jürgen Bering (moderator, Gesellschaft für Freiheitsrechte (GFF), Germany), Maria Luisa Stasi (Article 19, Europe), Vanessa Turner (O’Melveny & Myers, International), Lucas Lasota (Free Software Foundation Europe (FSFE), Europe), Filomena Chirico (European Commission, Europe)
Two years after the DMA ‘compliance day’, the public enforcement machine is on. Regulators have been active with selected enforcement actions and market investigations. Concrete outcomes are becoming visible on digital markets both for businesses and users. However, there is an area which remains nearly unexplored: private litigation. As the DMA provides also for individual rights, its effective application cannot rest exclusively on the public enforcers’ shoulders. Yet, to this day, multiple barriers prevent the useful deployment of both collective redress actions and business to business litigation under the DMA. A robust private enforcement system can contribute to deterrence, damages redistribution, and can help users to regain agency in business relationships. To this aim, public and private enforcement need not to happen in silos but to rather deploy in a harmonious and coordinated exercise of pulls and pushes.
Academic
Business
Policy
Centre for Research into Information, Surveillance and Privacy, University of St Andrews (International)
William Webster (moderator, Office of the Biometrics and Surveillance Camera Commissioner, International), Cristina Vannini- Goodchild (CVG Solutions, International), Emmanuelle Brun (European Agency for Safety and Health at Work (EU-OSHA), Europe), Davide Villani (Joint Research Centre of the European Commission, Europe), Kirstie Ball (Centre for Research into Information, Surveillance and Privacy, University of St Andrews, International)
Digital employee monitoring has intensified across Europe and has known employee health, safety and wellbeing concerns. Yet the considerable variation in the application of GDPR in the workplace across the EU affects the way digital monitoring can be governed in practice. Some countries prohibit all but basic time and attendance monitoring, whereas others permit employers greater autonomy to monitor employees so that employment contracts are fulfilled. The panel aims to explore how Data Protection can help to promote healthy, safe and equitable working conditions where employees are digitally monitored. The ways in which Data Protection Professionals can make a difference to monitored employees will be discussed. Speakers will set out the extent of digital monitoring in Europe, the health, safety and wellbeing concerns and cases where intervention and outreach by data protection professionals has made a difference.
University of Amsterdam (Netherlands)
Kristina Irion (moderator, Institute for Information Law, University of Amsterdam, Netherlands), Joana Mazur (University of Warzaw, Poland), Ruoxin Su (LSTS, VUB, Belgium), Dave Mitchels (Queen Mary University of London, International), Romain Robert (EDPS, Europe), Christopher Millard (Queen Mary University of London, International)
Privacy Law Scholars Conference (PLSC) Europe is full of fresh, timely ideas, and we want to support these ideas gaining visibility in front of policymakers. Top Policy Provocations are papers that are most likely to make policymakers think, and potentially, make them act. This panel assembles the authors of the three Top Policy Provocation selected at the 2025 edition of PLSC Europe, hosted by the University of Leiden in fall last year: 1. "How experienced are Data Protection Authorities in enforcement concerning AI? Lessons for the enforcement system of the AI Act", by Joanna Mazur, Claudio Novelli & Zuzanna Choińska 2. "Beyond Individual Privacy: A Layered Model to Reassess the Legal Nature of Genetic Data", by Ruoxin Su 3. "Beyond Schrems: The Unresolved Tensions Between US Government Access and the GDPR", by Johan David Michels, Ian Walden, Christopher Millard and Ulrich Wuermeling The authors' presentation of their research will be followed by reflections from a policy practitioner and a discussion with the audience.
ID Law, University of Vienna (Austria)
Ibrahim Sabra (Department of Innovation and Digitalisation in Law, University of Vienna, Austria), Alexandra Maria Mărginean (Department of Innovation and Digitalisation in Law, University of Vienna, Austria), Kseniia Guliaeva (Department of Innovation and Digitalisation in Law, University of Vienna, Austria), Rodessa May Marquez (Department of Innovation and Digitalisation in Law, University of Vienna, Austria), Selen Yakar (ID Law, University of Vienna, Austria)
Marking almost a decade of GDPR, the workshop will follow a debate format, examining re-identification risks in pseudonymised and synthetic health data following EUCJ EDPS v. SRB decision. Drawing on the PHASE IV AI and COMMUTE projects, which focus on Medical AI privacy risks, participants will debate the regulatory status of using health datasets of COVID-19 cohorts for AI training to assess Alzheimer’s risk. Putting a health-tech firm against patient advocates, the trial scrutinises whether secondary data use or its synthetic derivatives circumvents GDPR obligations. Divided into counsel arguments, expert interventions, and judgment, the workshop will explore two issues: 1) Does the secondary use of pseudonymised longitudinal datasets for AI training without consent violate GDPR under the SRB "reasonably likely" test? 2) Does synthetic data generated from these datasets fall entirely outside GDPR scope, or do inherent linkage potentials retain a nexus to original subjects that necessitates ongoing protection?
Privacy Salon ()
The emergence and spreading of the electronic communication media during XX century had a huge impact on societies all over the world, completely changing the ways of information exchange. But in the Soviet Union and Eastern Bloc countries, these technologies evolved in a specific socioeconomical climate, from the very beginning affected by Marxist-Leninist ideology, military communism, and red terror, which influenced attitudes towards them in the post-Soviet states to the present day.
The “infra” artistic research project by Boris Shershenkov uses the applied media archaeology toolkits to unravel the design patterns, technomythologies and governmental social engineering methods used for the exploitation of any civil scientific, cultural, and technological developments as total propaganda and mass surveillance tools for the sake of the “state security”.
The talk will focus on the dystopian symbiosis of the authoritarian “secret police state” and Western electronic media technologies, fueling the cold civil war and governmental terrorism, which was predicted by Evgeny Zamyatin in 1920, and implemented almost 100 years later in contemporary Russia.
Onset - Anna Engelhardt & Mark Cinkevich (2023, 25')
A demon roams through an ominous synthetic environment, reconstructed from satellite images of Russian air bases: Khmeimim in Syria, Baranovichi in Belarus, and Belbek in Ukraine. This parasitic force pervades the air bases, passing through their deserted corridors, interrogation rooms and electricity substations. Devastation follows in its wake. In this single-channel video installation, Engelhardt and Cinkevich use an unholy alliance of medieval demonology, open-source intelligence and CGI animation to uncover the hidden life of these military outposts. Over the course of the film, the true horror of Russian colonialism becomes manifest in the process of possession – the imposition of external control that gradually destroys an organism from within.
Chronosphere - Lesia Vasylchenko (2024, 31')
Using CGI animation, Synthetic-aperture radar data from space satellites, filmed footage and AI-generated imagery, Chronosphere is a witness statement to be presented before a speculative court of Time. From the gradual melting of glaciers to the enduring scars of oil and lithium extraction, from the devastation of bomb-scarred grain fields to the instability of the occupied Zaporizhzhia nuclear power plant, we see the speculative apocalyptic future threaten to unfold at every timescale.
The Pegasus Stories - Forensic Architecture (2021, 30')
First detected in 2015, the NSO Group’s Pegasus malware has reportedly been used in at least 45 countries worldwide to infect the phones of activists, journalists and human rights defenders. Having learnt that former collaborators and close associates were hacked by Pegasus, Forensic Architecture undertook 15 months of extensive open-source research, interviews assisted by Laura Poitras, and developed bespoke software to present this data as an interactive 3D platform, along with video investigations narrated by Edward Snowden to tell the stories of the individuals targeted and the web of corporate affiliations within which NSO is nested.
Academic
Business
Policy
noyb (Europe)
Jennifer Baker (moderator, journalist and presenter, Belgium), Herwig Hofmann (University of Luxembourg, Luxembourg), Alexandra Jaspar (Data Protection Authority of Belgium, Director of the Authorization and Opinion Service, member of the Executive Committee, Belgium), Max Schrems (noyb, Austria), Rosalia Anna D’Agostino (Spirit Legal, Netherlands)
Under the heading of simplification, competitiveness and burden reduction for business, the European Commission in November 2025 published its proposal for the "Digital Omnibus”. Legal analysis shows that several proposed changes to the GDPR would not only undermine its core principles and deviate from settled ECJ case law but conflict with the European Charter of Fundamental Rights. The panel will explore how Charter rights granted under Article 8 for personal data and Article 7 for privacy would be overturned and what the practical implications would be on data subjects, supervisory authorities and controllers. It will examine the limitations the Charter imposes on the EU legislator when establishing secondary EU law affecting fundamental rights through the principle of proportionality under Article 52 of the Charter, but also regarding the choice of regulatory techniques like Omnibus laws.
Academic
Business
Policy
CPDP (Belgium)
Nóra Ni Loideain (moderator, Institute of Advanced Legal Studies, University of London, International), Karolina Mojzesowicz (DG Just, Europe), Anu Talus (European Data Protection Board, Europe), Matthias Spielkamp (AlgorithmWatch, Germany), Maximilian von Grafenstein (Berlin University of the Arts/Alexander von Humboldt Institute for Internet and Society, Germany), Charly Helleputte (King & Spalding, Belgium)
Last year, CPDP hosted a panel focused on the question of how the EU digital framework – the range of laws, many newly enacted, regulating the digital, including, for example, the AI Act, the DMA the DSA, and now the EHDS Regulation – might be realised in practice. Now, one year on from that panel, the realisation of the digital framework remains the subject of significant uncertainty. In particular, questions now emerge as to the ways in which, and the degree to which, patterns and regularities can be identified in the implementation of the framework. In this regard, this panel assembles representatives from legal practice, politics, academia, and civil society, to consider the current state of implementation of the digital framework, and what this means moving forward. The panel will consider, amongst others, the following questions:
Academic
Business
Policy
CNIL (France)
Aymeric PONTVIANNE (moderator, CNIL, France), Leon Schumacher (DigitalEkho, Luxembourg), Rita Camporeale (ABI, Italy), Philipp Täufer (Deutsche Bundesbank, Germany), Dr. Andrés CHOMCZYK PENEDO (School of Law (ICADE) - Universidad Pontificia Comillas, International)
The discussions between EU institutions for the adoption of a legal framework and technical infrastructure for a retail digital euro are progressing, with a Council position defined in December 2025 and a vote within the European Parliament by June 2026, whereas the ECB has announced the launching of a pilot phase for 2027. The digital euro, with both an online and an offline modality, is announced to be a digital equivalent of cash and to secure a high level of confidentiality. As a strong request from citizens, given the risks of tracing and reuse of transaction data the project entails, confidentiality is indeed a key feature of the digital euro design. But the devil is in the details : what is meant by confidentiality exactly, for which actors and with the help of what techniques, can this political promise be upheld?
University College London (International)
Michael Veale (moderator, UCL Faculty of Laws, International), Sophie Stalla-Bourdillon (Brussels Privacy Hub, Belgium), Alexandra Potts (University College London, International), Thomas Vandamme (Université libre de Bruxelles, Belgium), Luc Rocher (University of Oxford, United Kingdom)
Indiscriminate scraping of data from digital environments — a new form of ‘dragnet’ data collection — has fuelled both the latest generation of AI research and practice as well as leading to widespread public controversy around extraction from the public sphere and surveillance of online communities. Universities are more important than ever when research methods are societally controversial, as they can remain able to discover and innovate by establishing and maintaining a social license. They do this through their focus on the public interest, their key educational and outreach roles, and the care and leadership in meeting regulatory and ethical obligations. Yet universities are struggling on multiple fronts to work out what their own collection and use of this data should look like. At the same time, large firms, especially content delivery networks (CDNs) such as Cloudflare and Akamai are operating bot blockers which both protect sites against unwanted commercial scraping, but hinder bone fide researchers' ability to understand, appraise, and archive the digital world. In this panel, we bring together practitioners, computational researchers and legal scholars to discuss the ways forward for ethics and legality in web scraping.
Academic
Business
Policy
eLaw Leiden University / RESOCIAL Project (Netherlands)
Gianclaudio Malgieri (moderator, Leiden University, Netherlands), Nina Baranowska (eLaw Leiden University / RESOCIAL Project, Netherlands), Helen Vossen (Utrecht University, Netherlands), Alexandra Geese (European Parliament (Member of the European Parliament), Belgium), Christos Floros (Monnett, )
The European Union is debating rules on minors’ protection, manipulative design, and platform responsibility. This panel connects three perspectives: wellbeing, fairness, and vulnerability to ask what enforceable standards and minimum duties could look like under the Digital Services Act, the Digital Fairness Act, and the AI Act, and what evidence would make them auditable. The panel will discuss addictive interface patterns (autoplay, infinite scroll, loot-box mechanics), building on the European Parliament’s work on protection of minors online, age assurance, and accountability for recommender systems. It will then connect these debates to fairness research on algorithmic decision-making and to data protection’s concept of vulnerability. The goal is to identify metrics, audit evidence, and remedies that regulators and platforms can apply while safeguarding autonomy, dignity, and fundamental rights, and to test whether these measures reduce harm.
Academic
Business
Policy
Friedrich-Ebert-Stiftung Competence Centre on the Future of Work (Belgium)
Justin Nogarede (moderator, Friedrich-Ebert-Stiftung Competence Centre on the Future of Work, Belgium), Giovanni Gaudio (University of Turin, Italy), Marta Otto (University of Warsaw, Poland), Okşan Karakuş (Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI), Germany), Thomas Zerdick (EDPS, Europe)
This panel builds on an empirical report on Worker Data Rights under the GDPR and Beyond, commissioned by the Friedrich-Ebert-Stiftung Future of Work, analysing the enforcement of data protection in employment across the EU. It highlights enforcement gaps, cross-national fragmentation, and the disconnect between the GDPR’s formal guarantees and their practical effectiveness in contexts of workplace surveillance and data-driven management. The panel assesses the GDPR as a tool for protecting workers’ data rights, its interaction with national labour law, and the untapped potential of collective and representative enforcement mechanisms under Article 80 GDPR. Bringing together perspectives from academia, regulators and civil society, the discussion will reflect on enforcement practices and future regulatory pathways, including the implementation of the Platform Work Directive, GDPR reform under the Digital Omnibus, and a potential Directive on Algorithmic Management.
Academic
Business
Policy
Institute for Information Law (IViR) (Netherlands)
Kristina Irion (moderator, Institute for Information Law (IViR), Netherlands), Zuzanna Warso (Open Future, Netherlands), Yordanka Ivanova (European Commission, Europe), Lucie-Aimée Kaffee (HuggingFace, Germany), Arriën Molema (International Council of Music Creators (CIAM), Netherlands)
It is an open secret that generative AI models have also been trained on any kind of datasets developers could get hold of and regardless of the legality of their practice. Concerns about the conformity with copyrights law and the General Data Protection Regulation abound. In relation to general-purpose AI (GPAI) models the European Union's Artificial Intelligence Act foresees the disclosure of public information about training data. Soon the providers of GPAI models will have to publish a sufficiently detailed summary of the data used to train their models. What this summary should look like is subject to ongoing debate as the EU’s AI Office is developing a template for the summary. In this panel we will take a closer look at the emerging contours of the template in light of the purpose of this summary.
Academic
Business
Policy
Institute for Information Law (IViR) (Netherlands)
Kristina Irion (moderator, Institute for Information Law (IViR), Netherlands), Zuzanna Warso (Open Future, Netherlands), Yordanka Ivanova (European Commission, Europe), Lucie-Aimée Kaffee (HuggingFace, Germany), Arriën Molema (International Council of Music Creators (CIAM), Netherlands)
It is an open secret that generative AI models have also been trained on any kind of datasets developers could get hold of and regardless of the legality of their practice. Concerns about the conformity with copyrights law and the General Data Protection Regulation abound. In relation to general-purpose AI (GPAI) models the European Union's Artificial Intelligence Act foresees the disclosure of public information about training data. Soon the providers of GPAI models will have to publish a sufficiently detailed summary of the data used to train their models. What this summary should look like is subject to ongoing debate as the EU’s AI Office is developing a template for the summary. In this panel we will take a closer look at the emerging contours of the template in light of the purpose of this summary.
Coalition for Independent Technology Research (International)
Ramsha Jahangir (Tech Policy Press, International), Svea Windwehr (CODE 2026, International), Clare Melford (Global Disinformation Index, International), Bence Kertesz (The European Commission, International)
A 90-minute interactive presentation/discussion round examining how geopolitical tensions, particularly recent U.S. administration actions targeting civil society organisations, researchers and regulators involved in EU Digital Services Act (DSA) implementation, threaten the integrity and independence of the digital rights ecosystem. This session aims to reflect on the relationship between policymakers, regulators and civil society in the midst of these attacks, and provide actionable next steps to ensure cross-sector collaboration.
Digital Societies - University of Graz (Austria)
Erasure Poetry is a literary form that takes pre-existing text to surface new meanings and interpretations through the act of deletion, drawing, highlighting and annotating. In this participatory session, we will take passages from the EU AI Act and mess with it. In two rounds, we will create poems from the Act and discuss what becomes interesting, irritating, obvious or peculiar. Intervening in the legal text in a creative way helps us to re-examine its intentions, re-shape its narratives, and interfere with the prevailing discourses that dominate policy-making. This workshop creatively engages with the EU AI Act, a cornerstone of Europe’s digital rulebook, exploring its narratives, assumptions, and implications through the lens of erasure poetry. We will discuss ethical dilemmas, policy tensions, and accountability challenges. The aim of this workshop is to spark fresh discussions on AI regulation. No prior knowledge is required, and all materials will be provided.
This panel brings artistic and investigative perspectives on OSINT into dialogue with its real-world practice. Focusing on open-source investigation as a form of proving and exposing accountabillity in contexts of ongoing violence, it explores OSINT as legal and artistic evidence.
Join film maker Peter Porta, People versus Big Tech and Global Witness for a screening of ‘The Click Trap’ a documentary about the underlying business model of the internet – digital advertisement – and how it links to global disinformation flows, privacy breaches and online scams. Following the screening a panel discussion will explore how existing EU policies such as the Digital Services Act (DSA) and the General Data Protection Regulation (GDPR) can be used to tackle these issues - and how ordinary citizens can be part of the fight back against the ever-expanding surveillance of social media and advertising companies, how
Questions to be answered?
This Culture Club session will explore the evolving landscape of digital governance, with a particular focus on Brazil and its interaction with European regulatory frameworks. The discussion will begin with an introduction to the central ideas of the featured book, highlighting its relevance and offering a broader overview of digital governance in Brazil, using the Brazilian General Data Protection Law (LGPD) as a key reference point.
Academic
Business
Policy
Université Paris 8 - CÉMTI (France)
Julien Rossi (moderator, Université Paris 8 - CÉMTI, France), René Mahieu (Open Universiteit, Netherlands), Jessica Pidoux (Personaldata.io, Switzerland), Florence Gaullier (Cabinet Vercken & Gaullier, AFCDP and CEDPO, France), Jacob Gursky (Privacy Company, Netherlands)
The right to access personal data is one of the oldest pillars of data protection law, dating back all the way to the world’s first data protection laws of the 1970s. Yet, in its Digital Omnibus proposed in November 2025, the European Commission proposed to significantly restrict this right. Taking stock of decades of case law and experience, as well as results of research projects on the subject matter, this panel aims at bringing perspectives from academia, civil society and the industry to ask two questions: what is the value of this right? Do the proposed changes provide real and meaningful simplification for data controllers?
Academic
Business
Policy
European Digital Rights (EDRi) x Rules to Protect (Europe)
Olivier Hoedeman (moderator, Corporate Europe Observatory (CEO), Europe), Alyna Smith (Equinox Racial Justice Initiative, Europe), Diana Vlad-Calcic (European Commission (DG CONNECT), Europe), Isabelle Schömann (European Trade Union Confederation (ETUC), Europe)
This panel brings together those concerned about protecting a democratic, privacy-respecting and liveable future, to dissect different digital deregulation efforts in the context of the EU’s broader attack on rights- and justice-based protections. We will interrogate how concurrent Omnibus proposals and other ‘simplification’ initiatives stack up to forms a wholesale backsliding of essential guarantees in the digital age: from dignified and safe working conditions, to breathable air, to due process in policing, increased concentration of power for big industry players and much more. Through this lens, we aim to show how the Digital Omnibus cannot be understood outside of its broader context, and emphasise the real cost of watering down hard-fought protections across the spectrum. At the same time, we will explore what genuine simplification which serves the public interest ought to look like, if it were truly to serve the enjoyment of rights, access to justice, the dignity of all communities and respect for the environment.
Academic
Business
Policy
Norwegian University of Science and Technology (Norway)
Frida Englund Sandvik (moderator, Norwegian University of Science and Technology, Norway), Eduard Fosch-Villaronga (Leiden University, Netherlands), Rania Wazir (Leiwand.ai, Austria), Adam L. Smith (AIQI Consortium, Spain), Irene Kamara (TILT, Tilburg University, Netherlands)
AI systems are increasingly used to streamline hiring and HR processes, while raising significant concerns about trustworthiness. Given their influence on life opportunities and their potential to reproduce historical discrimination or compromise data protection (Recital 57), Regulation (EU) 2024/1689 classifies these systems as high-risk and establishes obligations to ensure human-centric, trustworthy AI that protects health, safety, and fundamental rights while supporting innovation. Article 40 further specifies that harmonised standards developed by bodies like CEN-CENELEC may serve as key instruments for demonstrating compliance, with ongoing work on fairness, inclusiveness, and non-discrimination led by Joint Technical Committee 21. This panel, organised within the Horizon Europe BIAS project, advances the policy debate on how standards can move beyond technical benchmarks to embed normative protections. It will examine current ambitions and limitations, identify essential conditions for future standards, and explore interdisciplinary strategies.
Academic
Business
Policy
Politecnico di Torino (Italy)
Alessandro Mantelero (moderator, Politecnico di Torino, Italy), Gloria Gonzalez Fuster (Vrije Universiteit Brussel, Belgium), Gianclaudio Malgieri (Leiden University, Netherlands), Yordanka Ivanova (European Commission - AI Office, Europe), Sonia Perez Romero (EDPS, Europe)
In 2024, the AI Act was announced as a milestone towards global AI regulation, reaffirming the so-called 'Brussels effect'. Two years on, what impact has AI regulation had in Europe and at the global level? To address this key question, the panellists will examine the core elements of the AI Act (AIA) and how they are being implemented in a world characterised by geopolitical tensions. While several features of EU regulation, such as the risk-based approach and protection of fundamental rights, are being endorsed by other legislators, their concrete implementation has suffered from shortcomings, partially reshaping their scope by leveraging the broad definitions provided by the AIA provisions, as well as the lack of concrete methodological implementation. The AIA is both too young and quite old. A paradox that only a crucial regulation in a very complex moment can experience.
Academic
Policy
ETUI (Belgium)
Aida Ponce Del Castillo (moderator, ETUI, Belgium), Dimitra Kotouza (Researcher at Labour Research Department, International), Oliver Marsh (AlgorithmWatch, Germany), Irmak Erdogan (KU Leuven, Belgium), Pablo Trigo Kramcsák (Vrije Universiteit Brussel (VUB), Belgium)
Controversies surrounding Palantir Technologies, including its role in the NHS Federated Data Platform, illustrate how a small number of vendors can mediate workplace surveillance, , creating technical and contractual lock-in and increasingly embedded in data infrastructures that connect employment data with health, insurance, finance and public services. In these configurations, employers and intermediaries can derive insights that extend beyond productivity or location, including behavioural, biometric, health-related and emotion-linked inferences. The panel examines which legal, institutional and collective tools are needed to contest these infrastructures, how power imbalances between employers, intermediaries and workers can be reduced. It asks whether EU frameworks, notably GDPR, the AI Act, and competition regulation, can address cross-domain profiling and infrastructural power, and what role regulators can play.
MyData Global and the MyTerms Alliance (International)
Iain Henderson (MyTerms Alliance, International), Eric Pol (MyData Global, Belgium)
The IEEE 7012 standard, also known as 'MyTerms' for personal privacy policies was published in January 2026. It offers breakthrough thinking. both conceptually and technically, placing the individual as a central organising force in their own data exchange. We would plan to use this workshop to enable a wider, expert audience to see and feedback on the latest status in deployment. We would also seek to engage with potential deployers of the standard to share our thinking on how this could work in practice. One further audience that we would seek to engage would be privacy and data protection regulators; the new standard both challenges existing assumptions, and also offers new possibilities for discussion and then guided implementation.
Kenniscentrum Data & Maatschappij (Belgium)
Nikolaos Papadopoulos (KU Leuven Centre for IT & IP Law, Belgium), Sultan Erdogan (Kenniscentrum Data & Maatschappij, Belgium)
Digital technologies are transforming the employment relationship. Work is increasingly mediated by algorithmic management, AI-based evaluation systems, productivity analytics, biometric tools, and remote monitoring. These systems shape hiring, task allocation, performance assessment, and termination, reshaping workplace power dynamics. While the GDPR, the AI Act, labour law, and the Platform Workers Directive provide safeguards, workplace data practices are often defined through internal policies and collective agreements. Social dialogue must therefore evolve to address the digital dimension of work. This interactive workshop shifts from regulatory interpretation to normative design. After a brief framing of the legal landscape and key principles (necessity, proportionality, transparency, participation), participants collaborate in groups organised by employment model (platform, industrial, knowledge work) to draft enforceable model clauses: non-negotiable rights, conditional safeguards, oversight mechanisms, and enforcement provisions. A plenary synthesis identifies minimum safeguards, sectoral variations, and regulatory gaps, generating practical, transferable clauses adaptable across employment contexts.
I3LUNG Project (International)
Halid Kayhan (Centre for IT & IP Law (CiTiP), KU Leuven, Belgium), Eylem Karakaya (Centre for IT & IP Law (CiTiP), KU Leuven, Belgium), Francesco Trovò (Politecnico di Milano (PoliMi), Italy)
While the GDPR aims to facilitate research by providing some related exceptions (cf. Art. 89), experiences since its adoption raise questions as to whether it really achieves that goal. Several challenges have been identified so far including the fragmentation of research-related rules in the national laws, uncertainty about international data transfer frameworks (e.g. the adequacy decisions for the US), etc. The recent case law (i.e. SRB case) re-opens the debate on what is to be understood as personal data. Although the AI Act was adopted not-so-long-ago, the Digital Omnibus Proposal has several points related to personal data, research, innovation, AI training. However, the implications of all these are unclear regarding international medical research developing AI, which require vast amount of health data. Through small group discussions, this workshop will be a platform for lawyers and researchers to exchange and, collaboratively, propose best practices for research, considering the evolving regulatory environment.
Mobile apps have transformed how we live, work and connect – but at what cost?
This book examines the immense power Apple and Google wield over society, arising from their control of app stores as well as mobile operating systems and browsers. With the EU’s new Digital Services Act defining their influence as a potential “systemic risk,” Konrad Kollnig unpacks the implications for competition, privacy and regulation.
Offering a clear roadmap for scholars as well as policy-makers, this book not only reveals the hidden risks of app ecosystems but also outlines practical solutions for ensuring fairer digital markets.
Stanford (United States), Tilburg Law School (Netherlands)
In The Tech Coup, Marietje Schaake offers a behind-the-scenes account of how technology companies crept into nearly every corner of our lives and our governments. She takes us beyond the headlines to high-stakes meetings with human rights defenders, business leaders, computer scientists, and politicians to show how technologies—from social media to artificial intelligence—have gone from being heralded as utopian to undermining the pillars of our democracies. To reverse this existential power imbalance, Schaake outlines game-changing solutions to empower elected officials and citizens alike. Democratic leaders can—and must—resist the influence of corporate lobbying and reinvent themselves as dynamic, flexible guardians of our digital world.
Academic
Business
Policy
Check My Ads (International)
Lex Zard (moderator, Check My Ads, International), Arielle Garcia (Check My Ads, International), Alexandros Papanikolaou (European Commission, Europe), Mathilde Fiquet (European Publishers Council, Europe), Tasos Stampelos (Mozilla, United States)
Google, the world’s second most profitable company, has been found to have abused its dominant position in the online advertising intermediation (“adtech”) market in both the United States and the European Union. These cases have unfolded in parallel on both sides of the Atlantic and have become landmark competition proceedings in the digital economy. Over the years, Google’s conduct has shown a pattern of strategic adaptation, morphing from one anticompetitive practice to another to maintain control over the industry’s core infrastructure. With remedy decisions expected soon, this is a pivotal moment to take stock of what has happened, what these decisions will actually change, and what they imply for the future of online advertising and digital markets more broadly. This panel examines whether these interventions mark a genuine structural turning point or business as usual.
Academic
Business
Policy
EPIC (United States)
Maria Villegas Bravo (moderator, EPIC, United States), Calli Schroeder (EPIC, United States), Tomaso Falchetta (Privacy International, International), Alexandra Geese (European Parliament, Europe), Michael Veale (UCL Faculty of Laws, International)
This panel will review the U.S. efforts to deregulate privacy and technology protections and explore how these efforts are affecting other parts of the world. We will look at trade agreements, subsequent deregulatory efforts, changes in enforcement efforts (particularly against U.S.-based companies), and how some are pushing back. We will also explore how political partnerships internationally are shifting in response to the administration's positions and the increasing rise of U.S. Big Tech influence directly in government.
Academic
Business
Lawgorithm Research Association (Brazil)
Fernanda Galera Soler (moderator, London College of Contemporary Music, International), Juliano Souza de Albuquerque Maranhão (University of São Paulo / Lawgorithm Research Association, Brazil), Mariana Giorgetti Valente (University of St. Gallen Law School, Switzerland), Saskia Ostendorff (Wikimedia Germany, Germany)
The advancement of generative artificial intelligence brought debates on whether model training - based on large volumes of digital data - can or cannot be classified as a use of copyrighted works. Recent discussions highlight issues such as the distinction between digital data and authorial expression; the nature of computational processing not intended for human-to-author communication; potential impacts on creative markets; and legislative proposals across different jurisdictions, including Brazil, the European Union, and the United States. This panel will bring together experts from multiple fields to map these questions, present divergent legal approaches, and analyze regulatory, technical, and governance alternatives. The goal is to provide a multidisciplinary and balanced understanding of an evolving debate, without adopting definitive conclusions.
Academic
Business
Policy
ALTI (Netherlands)
Vardâyani Djwalapersad (moderator, ALTI - VU Amsterdam, Netherlands), Kave Noori (European Disability Forum, Belgium), Bahija Aarrass (Vrije Universiteit Amsterdam, Netherlands), Ellen Lefley (JUSTICE, International), Pia Groenewolt (d.pia.lab, LSTS, VUB, Canada)
Rules on data protection, access and sharing across the EU are being revised to support innovation and new digital services. Changing these rules interacts with deeply rooted asymmetries in power. This panel examines how the potential changes to the EU’s data protection and digital regulatory framework can affect historically marginalized communities, including women, queer people, migrants, people of color and low-income groups. A focal point is to think about the structural inequalities that shape the exposure of these groups to harm, when a deregulatory agenda or an effort to “simplify” the law overlooks protections for certain groups. When rules expand access to data vulnerable categories are exposed to greater risks. We will also explore what happens when systems built under EU law are used in times of democratic regress, turned into a tool against specific groups, threatening democracy itself.
CPDP (Belgium)
Frederik Zuiderveen Borgesius (moderator, Radboud University, Netherlands), Giulia Campaioli (University of Amsterdam, Netherlands), Eduardo Brito (Cybernetica AS, University of Tartu, Estonia), Xu Xu (InnerMongolia University, China), Àndrés Chomczyk Penedo (School of Law (ICADE) - Universidad Pontificia Comillas/LSTS/VUB, Spain)
The three academic sessions are an integral part of CPDP's mission to connect scholarship with practice and policymaking. In 2026, Academic Session II examines questions of data protection, privacy, and digital governance more broadly. Papers were selected through an open call and presented to foster exchange beyond academia. The session features Inequality by Infrastructure: How Regulatory Data Infrastructures Produce Infrastructural Inequalities (Giulia Campaioli, Sruthi Vanguri, Mattéo Bard & Stefania Milan), Where Trust Fails: Mapping Location-Data Provenance Risks in Europe (Eduardo Brito & Liina Kamm), Beyond Modern Dualisms: Reconstructing Techno-Theology through Animism and Divine Ethics (Xu Xu & Qiao Yan), and Permission Impossible? Consent, Competition, and the Future of Financial AI under the European Financial Data Space (Àndrés Chomczyk Penedo).
In collaboration with IMPAKT [Centre for Media Culture], Utrecht, the Netherlands (impakt.nl)
Warning: Flashing lights
After Scarcity is a sci-fi video-essay that tracks Soviet cyberneticians (1950s – 1980s) in their attempt to build a fully-automated planned economy. If history at its best is a blueprint for science fiction, revisiting contingent histories of economic technology might enable access to the future. Vindicating this other internet, the work presents the economic application of socialist cybernetic experiments as extraordinary to the financial arrangements and imaginations of our time. It addresses urgent issues such as broadband idealism, regulated networks of data, high-speed capitalism, and the urgency of time. Blurring the line between sci-fi and history, the work serves as both a reality check and a glimmer of hope, allowing us to consider a future that does not necessarily have to rely on speculation or an overemphasis on financialisation.
This film introduces a conversation between Paola Verhaert and Marc Tuters, who will discuss the (ir)relevance of one of the largest cybernetic-socialist projects in history: Project Cybersyn. They will examine the project from the philosophical perspective of Yuk Hui’s “technodiversity”
LSTS, VUB (Belgium)
As the fortification of Europe's borders and its hostile immigration terrain has taken shape, so too have the biometric and digital surveillance industries. And when US Immigration Customs Enforcement aggressively reinforced its program of raids, detention, and family separation, it was powered by Silicon Valley corporations. In cities of refuge, where communities on the move once lived in anonymity and proximity to familial and diaspora networks, the possibility for escape is diminishing. As cities rely increasingly on tech companies to develop digital urban infrastructures for accessing information, identification, services, and socioeconomic life at large, they also invite the border to encroach further on migrant communities, networks, and bodies. In this book, Matt Mahmoudi unveils how the unsettling convergence of Silicon Valley logics, austere and xenophobic migration management practices, and racial capitalism has allowed tech companies to close in on the final frontiers of fugitivity—and suggests how we might counteract their machines through our own refusal.
Academic
Business
Policy
CPDP (Belgium)
Fanny Coudert (moderator, EDPS, Europe), Bart Preneel (KU Leuven, Belgium), Svea Windwehr (Mozilla, Germany), Camiel De Schutter (European Commission, Europe)
Dedicated to Caspar Bowden, the visionary privacy advocate whose work illuminated the geopolitical dynamics of surveillance and digital power, this panel brings together experts from EU policy and computer science to examine the proposed CSAM regulation and its far-reaching implications for encryption, privacy, and fundamental rights. Co-organised with Professor Bart Preneel of KU Leuven, it continues the tradition of interdisciplinary dialogue that Bowden so forcefully championed.
Presentations and discussions on digital rights, algorithmic power, censorship, ownership, and technological autonomy, featuring speculative demonstrations, artistic research, and critical reflections developed within the CODE programme. From experiments exposing the hidden biases embedded in AI systems, to artistic strategies of silence and refusal within surveillance culture, to proposals for decentralised communication infrastructures beyond corporate control, the session brings together emerging perspectives on how technology shapes behaviour, language, identity, and political agency. Blurring the boundaries between artistic practice, activism, and technological critique, the presentations invite audiences to question who designs our digital realities — and whether alternative futures can still be imagined.
In a world shaped by powerful digital systems, how can we reclaim a sense of agency—and what role should art play in that effort? This panel brings together contributors from the CODE network and beyond to explore how creative, critical, and research-based practices can help us push back against the dominance of digital platforms.
We’ll focus on why it’s essential to approach digital challenges—such as surveillance, loss of privacy, algorithmic injustice, and shrinking digital rights—through interdisciplinary collaboration. We’ll also ask what makes working across fields like art, law, technology, and activism so difficult in practice, even when it’s widely encouraged in theory.
Together, we’ll explore how artistic and imaginative work can open up new ways of understanding and resisting digital systems—and why that work deserves to stand alongside legal, technical, and scientific approaches.
EDPS (Europe)
Wojciech Wiewiórowski (European Data Protection Supervisor, Europe)
As is tradition, European Data Protection Supervisor Wojciech Wiewiórowski is closing CPDP2026.
Centre for Future Generations (Belgium)
Unpacking the realities of mental health and well-being in the digital age. This cocktail will be paired with a short and provocative Q&A with Virginia Mahieu, neurotechnology director at the Centre for Future Generations, about what is happening to our brains on tech, and what we can do about it to protect and promote mental health for current and future generations.
Privacy Salon (Belgium)