9:00 am – 9:30 am CET
|
REGISTRATION
Check-In, Welcome Coffee & Light Bites
|
|
9:30 am – 9:35 am CET
|
WELCOME REMARKS
|
Future of Privacy Forum & Brussels Privacy Hub of VUB
|
9:35 am – 10:00 am CET
|
OPENING KEYNOTE
|
Speaker to be announced!
|
10:00 am – 10:45 am CET
|
PANEL I – The Data Protection Acquis: Retreat or Reinvention?
With Digital Omnibus negotiations going full steam ahead, proposed changes to the GDPR seek to recalibrate the scope of data protection law. Remaining areas of deliberation such as the personal data and scientific research definitions, and the scope of sensitive data processing, are clearly marked by evolving needs for AI development. At the same time, negotiations are embedded in the ongoing restructuring of global power dynamics, European digital sovereignty debates, and competitiveness, raising questions about the future of the EU data protection acquis and its role within an evolving digital regulatory framework. Panelists will debate:
- Retreat or reinvention: Which resonates more with the role of data protection in the Digital Rulebook?
- Are we seeing an evolution of the European data protection model or a more fundamental shift in its underlying philosophy
- How should we think about the role of data protection within the broader digital policy landscape?
- What are your non-negotiables in the Digital Omnibus, and solutions for ways forward?
|
MODERATOR:
- Vincenzo Tiani, EU Senior Policy Counsel, Future of Privacy Forum
PANELISTS:
- Monika Tomczak-Górlikowska, Group Head of Privacy, Digital & AI Governance, Prosus Group
- Laura Lazaro Cabrera, Deputy Director and Counsel, Center for Democracy and Technology (CDT) Europe
- Orla Lynskey, Chair of Law & Technology, UCL Laws
- Carolina Foglia, Head of Sector – Secretariat of the EDPB
|
10:45 am – 11:15 am CET
|
COFFEE BREAK
|
|
11:15 am – 11:40 am CET
|
MY DATA IS MINE 2026 – The Next Decade of Data Governance: Do GDPR and ePrivacy need an overhaul for the AI era, or are they still fit for purpose?
As artificial intelligence fundamentally reshapes the technological landscape, our regulatory frameworks face an unprecedented stress test. This brief panel exchange will bring together experts to debate whether current foundational frameworks like GDPR and the ePrivacy Directive remain resilient enough to govern AI, or if the next decade demands a radical overhaul of data privacy rules. During this session, we will also officially announce and celebrate the winner of the “My Data is Mine 2026” Award.
|
SPEAKERS:
- Marco Scialdone, Head of Litigation and Academic Outreach, Euroconsumers
- Wojciech Wiewiórowski, European Data Protection Supervisor
|
11:40 am – 12:25 pm CET
|
PANEL II – To Share or Not to Share? Platform Regulation Meets Privacy
In the broader context of digital market regulation, data-sharing and interoperability obligations are increasingly viewed as tools to enhance competition, reduce lock-in effects, improve market contestability, and foster innovation. At the same time, the increased flow of data between platforms, business users, and third parties raises important questions regarding privacy, data protection, and regulatory coherence, bringing into sharper focus the technical and legal challenges with data sharing in practice. Panelists will address:
- Are privacy and competition objectives increasingly aligned or increasingly in conflict?
- In the age of AI, could opening up systems to third parties increase cybersecurity risks?
- Is the concept of “data portability” still fit for purpose in ecosystems dominated by machine learning systems?
|
MODERATOR:
- Sophie Stalla-Bourdillon, co-Director, Brussels Privacy Hub
PANELISTS:
- Lukasz Olejnik, Founder, Stealth Venture
- Gary Davis, Senior Director, Regulatory Legal EMEA, Apple
- Friederike Schueuer, Head of EU and Global AI Governance, Ada Lovelace Institute
- Sebastiao Barros Vale, Legal Officer, European Data Protection Supervisor
|
12:25 pm – 1:30 pm CET
|
LUNCH BREAK
|
|
1:30 pm – 2:30 pm CET
|
BREAKOUT WORKSHOPS – HAVE YOUR SAY!
TOPIC 1: Practical Trilogue Simulation of Digital Omnibus Negotiations
Now a Brussels Privacy Symposium tradition, this workshop is a unique opportunity to take on the role of an EU Parliament, Commission or Council representative, and negotiate your position on key Digital Omnibus provisions.
TOPIC 2: When is data no longer personal? Revisiting anonymisation and pseudonymisation
The question of what constitutes personal data, and for whom, is central to the EU Digital Rulebook. Using practical use cases, this session examines the challenges of determining when data should be considered pseudonymised or anonymised, and explores what can realistically be expected from regulatory guidance and legislation in promoting good practice.
TOPIC 3: From Age Assurance to Age Verification
As discussions on youth online protection intensify, the European Commission is encouraging Member States to make age verification solutions available at national level. Through practical use-cases, this workshop explores technical methods for age verification, engaging with ongoing debates at the intersection of privacy and children protection/empowerment in digital spaces.
TOPIC 4: Agentic AI at the Seam: Hidden Instructions, Irreversible Actions, and Memory Manipulation
Agentic AI is where data protection and AI governance have stopped being adjacent disciplines. It’s not hard to imagine a future with agentic systems that are always running in the background, interacting across organizational boundaries with access to personalized and confidential information. The promise of new productive capability is real, as are the new vulnerabilities that traverse safety, security, and privacy, and can’t be managed in isolation. This working session puts short, de-identified scenarios drawn from publicly reported incidents in front of the room and works them through live — an agent that follows a hidden instruction; an agent that acts irreversibly on a false fact, whether hallucinated or planted; an agent whose memory retains more than it should. Participants will leave with concrete positions rather than principles.
|
TOPIC 1 FACILITATORS:
- Vincenzo Tiani, EU Senior Policy Counsel, Future of Privacy Forum
- Gianclaudio Malgieri, Full Professor of AI, Data Governance and Fundamental Rights, Maastricht University
TOPIC 2 FACILITATORS:
- Sophie Stalla-Bourdillon, co-Director, Brussels Privacy Hub
- Lukasz Olejnik, Founder, Stealth Venture
TOPIC 3 FACILITATORS:
- Barbara Lazarotto, Co-Director, Brussels Privacy Hub
- Pablo Trigo Kramcsák, Researcher, LSTS – VUB
TOPIC 4 FACILITATORS:
- Brian Quirk, Data Protection Officer, Microsoft
- Alex Kessler, Director of Policy & Practice, Office of Responsible AI, Microsoft
|
2:30 pm – 2:45 pm CET
|
REPORTING BACK FROM WORKSHOPS
Join us back in plenary as we share key learnings and take-aways from the Breakout Workshops.
|
Workshop Facilitators
|
2:45 pm – 3:05 pm CET
|
HONORED GUEST SPEAKER TALK
|
Lokke Moerel, Professor of Global ICT Law, Tilburg University
|
3:05 pm – 3:30 pm CET
|
COFFEE BREAK
|
|
3:30 pm – 3:45 pm CET
|
LIGHTNING TALK
|
Stacey Gray, Senior Director for Artificial Intelligence, Future of Privacy Forum
|
3:45 pm – 4:30 pm CET
|
PANEL III – Visions for the Next Decade of Tech: From Uncertainty to Solutions
From advances in AI, robotics, quantum computing to new digital and scientific discoveries, the next decade will bring opportunities and risks that extend beyond today’s debates. We are now facing a growing challenge: how to govern a future that remains difficult to predict. The next decade will test the resilience of the principles that have thus far shaped EU data protection law. The challenge is not only how to regulate new technologies, but how to ensure that the values underpinning data protection remain effective in an era defined by a rapidly changing technological and geopolitical landscape.
- Where is technology going over the next decade, and where should resources be invested?
- What are the panelists’ proposals for regulatory solutions to address the technological and regulatory needs of the next decade?
- Which guiding principles should remain constant and which should evolve?
- What are the panelists’ non-negotiables for the future of privacy and data protection within the evolving technological landscape?
|
MODERATOR:
- Bianca-Ioana Marcu, Managing Director for Europe, Future of Privacy Forum
PANELISTS:
- Itxaso Dominguez de Olazabal, Policy Advisor, EDRi
- William Malcolm, Executive Director of Regulatory Risk & Innovation, UK ICO
- Daniel Gueorguiev, Head of Global Institutional Affairs, Domyn
- Yordanka Ivanova, Head of Sector, Legal Oversight of the AI Act Implementation, EU AI Office
|
4:30 pm – 4:50 pm CET
|
“IN DIALOGUE” SERIES
|
SPEAKERS:
- Joris van Hoboken, Full Professor of Information Law, University of Amsterdam
- Fabiana Da Pieve, Team Lead for Post-Quantum Cryptography and Manager for Quantum Networks, DG Connect, European Commission
|
4:50 pm – 5:00 pm CET
|
CLOSING REMARKS
Thank you from the Organisers.
|
Future of Privacy Forum & Brussels Privacy Hub of VUB
|
5:00 pm – 6:00 pm CET
|
BITES & COCKTAIL RECEPTION
We invite you to close the 10th edition of the Brussels Privacy Symposium with us, and join us for cocktails.
|
|