AGENDA

10:00 AM to 2:30 PM CENTRAL EUROPEAN SUMMERTIME (CEST)
LINK FOR TIME CONVERSION: HTTPS://WWW.THETIMEZONECONVERTER.COM/

8th GDPR Anniversary

GUIDANCE ON CURRENT, TOPICAL AND TIMELY GLOBAL GDPR, DATA PRIVACY, PROTECTION, IT, CYBERSECURITY, DATA CONTROLLER,  PROCESSOR AND GLOBAL DPO ISSUES

Approximate timings due to the online nature and the Q/A sessions at the event
Timing Topics/Speakers
10:00 – 10:05 Introduction, welcome and opening remarks
10:05- 10:45
GDPR at 8: Making Compliance Stick — From Programme to Operating Model
  • Operationalising GDPR
    Embedding privacy into processes, systems, and product design—not one-off programmes
  • From Controls to Continuous Assurance
    Moving to real-time monitoring, auditability, and evidence-driven compliance
  • From Legal Requirement to Operating Model
    Integrating GDPR into data, AI, cyber, and enterprise risk management
Darine Fayed, Global Counsel and DPO, Mailjet/Synch
10:45 – 11:15
Enhancing and Structuring  The Sustainable GDPR Journey
  • Move from project to monitoring function
  • Build a data privacy culture and active awareness
  • What does it take to succeed in the implementation phase
Fred Oberholzer, Group DPO, Canon EMEA
11:15 – 11:45
The concept of Data-, Privacy and Protection business performance,  IT dashboards for the DPO, Controller and Management
  • How to integrate GDPR KPIs if  the board and management want to get value from GDPR execution
Emmanuel Fragnière, Director of the CAS HES-SO. Treasury Management at the University of Applied Sciences, Sierre, Valais, Switzerland
11:45 – 12:15
AI-Driven Processing and the GDPR Accountability Gap: Who Is Liable When the Algorithm Decides?
  • How to identify and address the above gaps.
  • The GDPR was designed for human-driven data processing. However, AI fundamentally changes the accountability chain,
  • Why most organisations cannot trace accountability/responsibility when an algorithm influences decisions about data subjects.
Advocate Remy Takang (CAPA, LLM, MSc, CAIO).
Break
12:15-12:45
What about: ” Privacy and Whistleblowing Compliance – A Possible Framework Based on the Italian Model”?
  • How to ensure the legal basis has not changed?
Advokat Lorenza Villa, DPO, Consulente Privacy, Legal designer, Formatore, Esperto ISDP 10003

12:45 – 13:15

 


GDPR at 8: Trust, Data, and Decisions — What Boards Must Get Right Now
  • From Risk Avoidance to Decision Integrity
    Data protection now underpins trusted, defensible decisions in an AI-driven world
  • From Data Volume to Data Trust
    Competitive edge lies in governed, high-quality, decision-ready data—not scale alone
  • From Legal Obligation to Strategic Growth Enabler
    GDPR has evolved into a foundation for digital trust, resilience, and sustainable growth
Stephen Pullum Ensuring AI is Secure, Safe & Understandable | Chief AI Officer | AIMP | CAIE | AIGA | AISA | AICMS | IEEE Senior Member |
12:45 – 13:15
The Automated Privacy Guardrail. From Manual Impact Assessments to Continuous Workflow Orchestration for Cross-Border Data Transfers and Global AI Compliance
  • Change static, document-based DPIAs to continuous, event-driven assessments triggered by system changes or model drift.
  • Link machine-readable processing records directly to SaaS discovery and cloud environments to eliminate manual spreadsheet updates.
  • Automate cross-border transfer decisions by distinguishing between data storage, processing, and remote admin access locations.
  • Shift from simple rights ticketing to full orchestration of identity verification and deletion propagation across vendor chains.
Prof. Hernan Huwyler, MBA, CPA, CAIO,  Academic Director at IE Law School, AI, Compliance, Governance, Risk Management, AI GRC Sr. Manager at Capgemini
13:15-13:45
GDPR in Practice: From Privacy by Design to Operational Trust in Digital Systems
  • How ICT organisations operationalise GDPR across governance, systems, and business processes
  • Embedding privacy, security, and accountability directly into products, platforms, and digital architectures
  • Moving from documentation to continuous compliance validation and assurance
  • How to assess, verify, and monitor ICT providers and third-party GDPR compliance in practice
  • Building defensible, audit-ready privacy controls across cloud, AI, and enterprise environments
13:45 – 14:15
Protecting both Personal and Organisational data in one system.
Raju Rajendran, Tata Steel
14:15 – 14:30

GDPR at 8: From Privacy Compliance Programme as a DPO  to Operational Reality of AI as CAIO

  • From Project to Practice: Embedding privacy into processes, systems, and culture

  • From Static Controls to Continuous Assurance: Real-time monitoring, KPIs, and AI-driven accountability
  • From Regulation to Performance: Integrating GDPR into AI, data, cyber, and enterprise risk management

Kersi Porbunderwala, CEO The EUGDPR Institute and Secretary General Copenhagen Compliance
14:30 – 14:45
Questions From Participants, Answered By The Panel Of All Speakers.
  • Closing, Networking and Final Q&A
*Conference Program is subject to change. The conference language is English