Aligning Cybersecurity Information Sharing with the European Data Protection Framework

  • Panel
  • Le Baixu
  • Wednesday 21.05 — 11:50 - 13:05

Organising Institution

TILT (Tilburg Institute for Law, Technology and Society)

Netherlands

  • Academic 2
  • Business 2
  • Policy 2
Cybersecurity, a rapidly evolving regulatory domain, has seen an explosion of legislative developments in recent years (NIS2, DORA, CRA). Effective cooperation and information sharing is crucial for strengthening the overall level of cybersecurity and is increasingly mandated by law. Cybersecurity is a multistakeholder endeavour characterised by a complex institutional landscape whereby information sharing occurs between various (decentralised) EU bodies, Member States, and an array of actors, such as CSIRTs, SOCs, public authorities, private actors, and occasionally law enforcement authorities. Importantly, such information-sharing ought to be done in accordance with EU data protection law. Inappropriate sharing and disclosure of cybersecurity information not only poses risks to cybersecurity itself but also to users. The panel will discuss the data protection challenges arising from cybersecurity information sharing and how these shall be addressed to ensure compliance with the EU data protection framework.

Questions to be answered

  1. How does the European cybersecurity legislative framework mandate the sharing of cybersecurity information?
  2. What are the data protection risks arising from cybersecurity information sharing and how can these best be addressed?
  3. How can cybersecurity information sharing across institutions with a different focus (i.e. business continuity, law enforcement investigations, national security) lead to cybersecurity and data protection risks?
  4. What are the main elements to consider when designing and implementing information sharing systems in line with cybersecurity and data protection obligations?

Moderator

Suzanne Nusselder

TILT (Tilburg Institute for Law, Technology and Society) - Netherlands

Suzanne Nusselder is a PhD researcher at the Tilburg Institute for Law, Technology and Society (TILT, Tilburg University). Her research focuses on the interplay and reconciliation of data protection and cybersecurity law. Her PhD is part of the NWO-funded INTERSECT project on the cybersecurity of the internet of things.

Speaker

Lokke Moerel

Morrison & Foerster - Netherlands

Among the world’s best-known privacy & cyber advisers, Lokke Moerel is regularly called upon by some of the world’s most complex multinational organizations to confront their global privacy and ethical challenges when implementing new technologies and digital business models and to assist them with their global cyber incident response and regulatory investigations. Lokke is Co-Academic Director (together with Freddy Dezeure) of the Tilburg University professional learning program Advanced Cyber Security & Governance as well as of the professional learning program AI & Law (teaching Algorithmic Accountability). Lokke is a member of the Dutch Cyber Security Council (the advisory body of the Dutch cabinet on cybersecurity), expert on cyber of the European Commission’s Horizon2020 Innovation Program, member of the Advisory Boards of the Dutch Academic Cyber Security Society (ACCSS) and The Hague Security Delta (HSD) and chair of the board of the Netherlands Atlantic Association. She was a member of the latest Monitoring Committee Dutch Corporate Governance Code.

Speaker

Renate Verheijen

ENISA - Europe

Renate Verheijen is a double qualified lawyer: she has a master's degree in International & European Law and obtained a master's degree in Private Law (specialization in business law with bar qualifications). With a solid back ground in consulting sector (EY) she built up her professional career as strategic advisor for the Board of Directors of a large hospital. She specialized in Cyberlaw and worked as legal counsel for Secura B.V. (Cybersecurity Services), respectively as Data Privacy Manager Europe for Fox-IT B.V./NCC (Cybersecurity Services) located in the Netherlands, before joining the EU Agency for Cybersecurity in Athens, Greece. Cybersecurity and more specifically EU Cybersecurity, is her true passion. She is a lead Implementer for ISO/IEC 27002 and 27701 and is CIPP/E certified. She guided Cybersecurity Certification teams and their Ad Hoc Working Groups of experts that develop an EU Cybersecurity Certification Framework, from legal perspective and guided and supported the Member States (the EU Cybersecurity Certification Group: ECCG) and the European Commission in this respect. She was the central contact point for the EU Stakeholder Cybersecurity Certification Group (SCCG) on behalf of the Agency and as such closely involved in their activities. Recently she has been promoted as Head of Resources of the Agency dealing with legal, privacy and cybersecurity matters from the Agency’s internal organization as well as procurement, finance and HR matters"

Speaker

Pier Giorgio Chiara

University of Bologna, School of Law and ALMA-AI Research Center - Italy

Pier Giorgio Chiara is assistant professor junior (ricercatore a tempo determinato di tipo a)) of the School of Law and CIRSFID – ALMA AI Center at the University of Bologna. In March 2023, he obtained a Joint PhD degree in Law Science and Technology from the University of Bologna and in Law from the University of Luxembourg, with the mark ‘excellent’ (Marie Sklodowska-Curie ‘Last-JD-RIoE’ project). His research mainly focuses on the normative issues (ethical, legal and social) of emerging digital technologies, with a particular focus on cybersecurity, privacy and personal data protection and ethics and governance of artificial intelligence. He is associate editor at the international journal ‘AIRe - Journal of AI Law and Regulation’ (Lexxion publisher).

Speaker

Niovi Vavoula

University of Luxembourg - Luxembourg

Niovi Vavoula is Associate Professor and Chair in Cyber Policy at the University of Luxembourg. Prior to her appointment she was Senior Lecturer at Queen Mary University of London. Her expertise lies at the intersection of law and technology with focus on cybersecurity, data protection and AI in various contexts, primarily in immigration and law enforcement.