EHDPC 2026 Programme

14–16 October 2026 · Paris, France

4th European Health Data Protection Congress

Place du Trocadéro, 75016 Paris

Protecting Health Data. Enabling Innovation. Building Trust.

Three days bringing together regulators, hospitals, pharmaceutical and biotech companies, research institutions, technology leaders, Data Protection Officers and policy-makers around one question: how can Europe unlock the value of health data while maintaining trust, privacy, security and regulatory compliance?

Secure your spot

Speaker confirmed To be announced All times Paris time (CEST) · programme subject to change

Day 1 — Wednesday 14 October 2026

The new regulatory landscape

12:00 – 13:30
13:30 – 13:45
Opening ceremony

Congress opening

Opening remarks and strategic outlook on the future of health data governance in Europe and globally.

Pierre-Yves Lastic Opening Pierre-Yves Lastic, EFDPO / EHDPC Secretary General; EHDPC Chairman France
13:45 – 15:00
S01Opening plenary

Revolution or evolution in health data protection?

Focus · Guidelines 1/2026 on the processing of personal data for scientific research purposes

The health data ecosystem is undergoing unprecedented transformation. New regulations, technological breakthroughs and increasing societal expectations are reshaping the way organisations collect, share and protect health information.

This session will examine whether Europe is witnessing a regulatory revolution or a natural evolution of existing governance models, and what this means for healthcare organisations, researchers and innovators.

Introductory presentations (30 min) followed by a 45-minute panel discussion.

Pierre-Yves Lastic Co-chair Pierre-Yves Lastic, EFDPO / EHDPC Secretary General; EHDPC Chairman France
Giuseppe D’Acquisto Co-chair Giuseppe D’Acquisto, Garante (Italian DPA) Senior Technology Policy Adviser Italy
Keynote Owe Langfeldt, European Commission, DG SANTE Policy Officer, Digital Health Unit Belgium
Panellist Donovan Sheppard, UCB Head of Data Protection Advisory & Global DPO Belgium
Panellist Sarah Maalej, Aix-Marseille Université Data law counsel, CEDRE project France
15:00 – 16:00
S02Plenary 2

The Biotech Act and Europe’s innovation agenda

Europe’s ambition to remain globally competitive in life sciences depends on its ability to foster innovation while ensuring robust safeguards for patients and citizens.

This session will explore how the Biotech Act may influence research, investment, innovation and international competitiveness within the healthcare and pharmaceutical sectors.

Introductory presentation followed by a panel discussion.

Kristof Van Quathem Co-chair Kristof Van Quathem, Covington & Burling Of Counsel Belgium
Co-chair Martha Siemaszko, Data Privacy, Digital AI, Novartis (PL) Global Operations Director Germany
Keynote European Data Protection Board
Panellist Industry & biotech
Panellist Academic research
Panellist Hospital representative
16:00 – 16:30
16:30 – 17:30
S03Plenary 3

The Digital Omnibus

The Digital Omnibus package reopens parts of the European digital rulebook, from AI Act deadlines to transparency obligations. This session unpacks what changes, what stays, and what health data controllers should be doing now.

Introductory presentations (15 min) followed by a 45-minute panel discussion.

Anastasia Negrouk Co-chair Anastasia Negrouk, MyData-Trust COO & DPO Belgium
Keynote European Commission
Natalie Stockmann Panellist Natalie Stockmann, Ascensia Diabetes Care Data Protection Officer, PHC Group Europe Natalie is Data Protection Officer for the European companies in the PHC Group, including Ascensia Diabetes Care. In this role, Natalie heads the Data Privacy Office and advises on data-, AI- and cybersecurity related legal and policy matters globally (outside Japan). Prior to joining, she was Data Protection Officer and General Counsel at a tech scale-up.
Nathalie Poupaert Panellist Nathalie Poupaert, Fieldfisher Counsel, Technology & Data Belgium
17:30 – 18:30
Panel

To record or not to record: that is the question

Consultation recording, ambient scribes and clinical documentation tools are spreading faster than the guidance that governs them. Supervisory authorities, platform providers and practising clinicians compare positions.

Panellist Katharina A. Weimer, Fieldfisher Lawyer Germany
Panellist To be announced
Panellist To be announced
Panellist To be announced
19:00 – 20:30
20:30

Day 2 — Thursday 15 October 2026

Innovation, risk and operational challenges

08:30 – 09:00
09:00 – 10:15
Morning plenary

Regulatory data protection sandboxes: how they work and what organisations gain from them

What exactly is a regulatory data protection sandbox, how does the process run, and what are the benefits for a company or a healthcare institution taking part in one?

  • Legal framework of a regulatory data protection sandbox
  • Data protection sandboxes in Europe — overview and comparison
  • How the LfDI Rheinland-Pfalz sandbox works, step by step
  • First participants in the health area

Interactive segment: what does the audience expect from a sandbox? Which innovations would you submit — or did you shelve because of data protection uncertainty?

Nils G. Indahl Chair Nils G. Indahl, Norwegian Association of DPOs Chair; DPO, Church of Norway Norway Nils G. Indahl is chair of the Norwegian Association of Data Protection Officers and DPO of the Church of Norway. He holds a M.Sc. degree in political science from the University of Copenhagen.
Erik Boucher Speaker Erik Boucher, CNIL Senior health expert engineer France Erik Boucher de Crèvecoeur is an information technology expert at the CNIL, the French data protection authority. With nearly 30 years of experience in software development, quality and security management, he is currently involved in the compliance checking of personal data processing for the French Health Sector, subject to authorization by the CNIL. As a representative of the CNIL, he also takes part in several working groups in charge of defining national data protection frameworks, as well as international standards for privacy management, such as ISO/IEC 27701.
Elisabeth Herzog Speaker Elisabeth Herzog, LfDI Rheinland-Pfalz Research Associate, Data Protection Sandbox Germany Elisabeth Herzog studied at the universities of Trier and Bergen. Since 2021, she is a PhD student at Göttingen University, writing about “Access to Health Data in Germany, Norway and under the EHDS”, for which she also spent time at the University of Bergen as a guest researcher. Following placements at Göttingen University and a law firm in Frankfurt am Main, she has been working for the project “Die Datenschutz-Sandbox” at the Authority for Data Protection and Freedom of Information Rhineland-Palatinate since 2025.
Dr Dieter Kugelmann Speaker Dr Dieter Kugelmann, LfDI Rheinland-Pfalz State Commissioner for Data Protection Germany Prof. Dr. Dieter Kugelmann studied at the universities of Mainz and Dijon. After his Pd.D. in European media law he qualified at the university of Mainz. He is author of numerous publications especially on European fundamental rights, European law, media law, security law and data protection law. In 2008 he became a fully tenured professor at the German Police University with a specialization for public law with a focus on police law including international and European Law. In 2015 he was elected for President of the Authority for the protection of data and the freedom of information of Rhineland-Palatinate and in 2023 he was re-elected for a second term. He is the editor of a commentary on the data protection law of Rhineland-Palatinate and co-editor of a commentary on the GDPR.
Rafal Yeisen Speaker Rafal Yeisen, Helse Stavanger HF Data Protection Officer Norway
10:15 – 10:45
10:45 – 11:45

Parallel workshop session 1 — choose one

S04Workshop 1

Relative identifiability in health data: pseudonymisation and secondary use governance

Where does pseudonymised data stop being personal data? A panel on re-identification risk, defensible thresholds and the governance that makes secondary use workable.

Khaled El Emam Panellist Khaled El Emam, University of Ottawa Canada Research Chair in Medical AI; Professor, School of Epidemiology and Public Health Canada Dr. Khaled El Emam is the Canada Research Chair (Tier 1) in Medical AI at the University of Ottawa, where he is a Professor in the School of Epidemiology and Public Health. He is also a Senior Scientist at the Children's Hospital of Eastern Ontario Research Institute, and in 2024-2025 was the Scholar-in-Residence at the Office of the Information and Privacy Commissioner of Ontario (IPC). Khaled has founded or co-founded eight product and services companies involved with data management and data analytics, with some having successful exits. Prior to his academic roles, he was a Senior Research Officer at the National Research Council of Canada. He also served as the head of the Quantitative Methods Group at the Fraunhofer Institute in Kaiserslautern, Germany. He has a PhD from the Department of Electrical and Electronics Engineering, King's College, at the University of London, England.
Panellist CNIL representative, CNIL Commission nationale de l’informatique et des libertés France
Panellist MyData-Trust speaker
S05Workshop 2 · roundtable

Connected glasses in care and at work

Smart glasses are moving from pilot to ward. A roundtable between platform, industry and hospital privacy leads on capture, consent and the boundary between clinical benefit and surveillance.

Daniela Will Chair Daniela Will, München Klinik DPO and Head of the Data Protection Unit Germany Daniela Will is a Certified Data Protection Officer (TÜV®), Data Protection Auditor DSA-TÜV, GDDcert.EU and Certified Information Privacy Professional/Europe (CIPP/E). She heads the GDD-ERFA-Kreis Bayern as well as the VBW Arbeitskreis Datenschutz and lectures on data protection law at the Hochschule Aalen. Daniela draws her knowledge from over 30 years of professional experience in various areas of the IT, automotive and media industries and has many years of in-depth knowledge in the field of data protection. Since June 2024, she is head of the data protection department at München Klinik gGmbH. Her questions regularly centre on the establishment and management of an agile, maturity-oriented data protection organisation based on IDW 9.860.1, the legal enabling of the use of patient data in medical research projects, and, of course, the EHDS.
Portrait of Aleksandra Aytova Speaker Alaksandra Aytova, Applegreen Group Head of Privacy Dr. Aleksandra Aytova is the Group Head of Privacy and AI Governance at Applegreen and an internationally recognised expert in human rights, digital ethics, and technology law. With over 15 years of legal and corporate leadership experience, she helps organisations navigate the intersection of innovation, regulation, and risk. Dr. Aytova holds a Ph.D. in Fundamental Rights from Sofia University, a Master’s in IT Law from Tartu University, and a specialisation in AI and Machine Learning from MIT. A passionate advocate for responsible innovation, her work focuses on safeguarding human rights and advancing ethical AI-assisted decision-making in the digital age.
Portrait of Georgia Voudoulaki Speaker Georgia Voudoulaki, Bosch Senior Legal Counsel
11:45 – 12:45

Parallel workshop session 2 — choose one

S06Workshop 3

Tokenisation: privacy by design for medical research

How tokenisation lets research datasets be linked across sources without moving identifiers — and what regulators expect from the key management around it.

Anne Bahr Chair Anne Bahr, Sanofi R&D Privacy Officer France
Speaker CNIL representative, CNIL Commission nationale de l’informatique et des libertés France
Khaled El Emam Speaker Khaled El Emam, University of Ottawa Canada Research Chair in Medical AI; Professor, School of Epidemiology and Public Health Canada Dr. Khaled El Emam is the Canada Research Chair (Tier 1) in Medical AI at the University of Ottawa, where he is a Professor in the School of Epidemiology and Public Health. He is also a Senior Scientist at the Children's Hospital of Eastern Ontario Research Institute, and in 2024-2025 was the Scholar-in-Residence at the Office of the Information and Privacy Commissioner of Ontario (IPC). Khaled has founded or co-founded eight product and services companies involved with data management and data analytics, with some having successful exits. Prior to his academic roles, he was a Senior Research Officer at the National Research Council of Canada. He also served as the head of the Quantitative Methods Group at the Fraunhofer Institute in Kaiserslautern, Germany. He has a PhD from the Department of Electrical and Electronics Engineering, King's College, at the University of London, England.
S07Workshop 4

Cybersecurity incidents and communication strategy

Cybersecurity incidents increasingly affect healthcare organisations and critical infrastructures. Participants will discuss resilience strategies, incident management, NIS2 requirements and what to say — to regulators, staff and patients — in the first 72 hours.

Chair To be announced
Speaker Heiko Roth Germany
Speaker To be announced
Speaker To be announced
12:45 – 14:00
14:00 – 15:00

Parallel workshop session 3 — choose one

S08Workshop 5

Genetic data: handling genomic data and biobanks in practice

Genetic data presents some of the most complex legal, ethical and operational challenges in healthcare. This workshop looks at governance frameworks, research opportunities and the safeguards needed for responsible use of genomic information.

Tania Palmariello Diviney Chair Tania Palmariello Diviney Data Protection Officer
Veronica Mino Speaker Veronica Mino, First Privacy
Anastasia Negrouk Speaker Anastasia Negrouk, MyData-Trust COO & DPO Belgium
S09Workshop 6

Neuroprivacy and robotics: new technology in health data protection

Brain–computer interfaces and care robotics generate categories of data that existing frameworks were never written for. This workshop examines what governance for neural and behavioural data should look like.

Chair To be announced
Baroum Mrad Speaker Baroum Mrad, Ente Ospedaliero Cantonale Chief Privacy & Compliance Officer; Head of Data Protection & Compliance Switzerland “The last private frontier: brain data governance in the age of AI and quantum risk” Baroum Mrad is the Chief Privacy and Compliance Officer (CPCO) and Head of the Data Protection & Compliance Department at the Ente Ospedaliero Cantonale (EOC) - Healthcare System of South of Switzerland. He is an expert in compliance and privacy, with particular expertise in neuroprivacy, brain-computer interfaces (BCI), and healthcare. He has a diverse background in business, data science engineering, and law, and with 20 years of experience in data science and privacy—particularly in the healthcare sector—he has effectively navigated the complexities of technology, strategy, and data protection. His expertise lies at the intersection of legal and technological aspects of healthcare, making him a unique asset in the industry. He is the author of the Springer book Healthcare Services Management: A Practical Guide.
Speaker Selma Nabulsi
Speaker Spanish data protection authority
15:00 – 15:30
15:30 – 16:30

Parallel workshop session 4 — choose one

S10Workshop 7 · panel

Medical digital twins and synthetic data

Synthetic cohorts and patient digital twins promise research value without exposing real records. The panel tests that promise against re-identification risk, validity and regulatory acceptance.

Chair Cécile Théard-Jallu, De Gaulle Fleurance France
Panellist To be announced
Panellist To be announced
Panellist To be announced
S11Workshop 8

From lab to launch: data protection in bringing new medical devices to market

This session explores the range of data protection issues to consider when designing, testing and commercialising new medical devices — and how those issues shift from one device type to another, from implantables to capital equipment to consumer wearables.

Peter A. Blenkinsop Chair Peter A. Blenkinsop, Faegre Drinker
Panellist Océane Bayrou, GE HealthCare Deputy Privacy Officer
Efi Gkika Panellist Efi Gkika Compliance, Privacy, AI & Cyber Executive; former Global Chief Privacy Officer, Baxter International Greece Efi Gkika is a multi-lingual Lawyer who started her career with an international law firm of one of the Big Four. For the last 18+ years she has been dedicated to the pharma/medical devices sector in Legal/Compliance and Data Privacy roles having worked for Roche and Novartis in various regional and global positions, and served also at the role of the Deputy General Counsel and Global Chief Privacy Officer of Baxter International. Throughout her career Efi has been acting as a strategic partner of the C-Suite and the global and regional stakeholders supporting both privacy compliance, AI, digital transformation, digital health, connected care and M&A matters from the privacy side. She held the position of the Chair of MedTech Europe Privacy Committee. Efi studied law in the University of Athens in Greece and holds an LLM from the Université libre de Bruxelles in European Law and an LLM from the Economic University of Athens in International Business Taxation. She has also completed a course on Digital Disruption, Digital Transformation with the Cambridge Judge Business School, has attended the IAPP AI Governance training and the ETH course on AI and Health Data. Recently Efi completed the Digital and AI Transformation course with the IMD.
Portrait of Mirella Kavadaki Panellist Mirella Kavadaki, MedTech Europe Manager Legal & Compliance Mirella Kavadaki is a qualified lawyer and Manager for Legal & Compliance and Legal Counsel at MedTech Europe, the European trade association representing the medical technology industry. She leads the organisation’s work on data protection and privacy, with a particular focus on health data processing and the interaction between the GDPR, EU digital legislation and medical device regulation. Mirella holds an Advanced LL.M. in Intellectual Property & ICT Law from KU Leuven and an MSc in European Public Law from Panteion University of Social and Political Sciences.
16:30 – 18:00
S12Plenary 4 · industry

Striking the right balance: don’t throw the baby out with the bath water

Ensuring privacy regulation achieves its purpose without holding back innovation and treatment

This session brings together privacy leaders in the life sciences industry and data protection authorities to consider the evolving regulatory landscape, including EU regulations such as the EHDS, the AI Act, the GDPR and MDR/IVDR. Panellists will address regulatory complexity, and how companies and regulators can partner to achieve shared goals by building trust and enabling responsible data use.

Industry leaders will also discuss why internal partnerships with senior management and IT leaders are essential in navigating regulatory requirements while committing to a strategy that embraces innovation and competition. Panellists will share lessons learned, including case studies from the pharmaceutical and medical technology industries where regulation either created barriers to treatment and best practice, or achieved a healthy balance.

Portrait of Mary Devlin Capizzi Chair Mary Devlin Capizzi, Faegre Drinker Partner United States Mary Devlin Capizzi is a partner at the law firm of Faegre Drinker Biddle & Reath and based in Washington, DC. Mary has nearly three decades of experience building relationships at the intersection of law, regulation, science, and policy, advising pharmaceutical, biotechnology, medical device, and consumer health clients on complex compliance, legislative, scientific, and agency-facing matters. She currently serves Faegre Drinker as the leader of its global life sciences consortia management team and has held numerous firm leadership roles over her career, including as a longtime firm Board member, an executive partner, and co-leader of the firm’s health and life sciences sector. For almost 30 years, Mary has partnered with industry leaders to establish and operate pre-competitive collaborative initiatives on a wide range of topics, including data governance, cyber security, AI and federated learning, innovation in drug development, supply chain security, patient safety, product quality, clinical trials, and data sharing. Mary enjoys solving complex problems collaboratively. She and the consortia management team proactively align industry leaders around shared goals, maintain rigorous, efficient coordination among stakeholders, and build and sustain trust to ensure flourishing of industry initiatives and achieving identified objectives. Mary, along with her colleague, Peter Blenkinsop, worked with global industry leaders to establish the International Pharmaceutical and Medical Device Privacy Consortium (IPMPC) in 2001–2002. Mary received her law degree from Emory University School of Law in Atlanta, Georgia, her BA, and MBA from the University of Dallas, in Irving, Texas. She is a fluent Spanish speaker who has lived and worked in Spain, France, Italy and Mexico.
Dorotea Alessandra De Marco Panellist Dorotea Alessandra De Marco, Garante (Italian DPA) Senior Officer, Digital Technologies & IT Security Italy Dorotea Alessandra de Marco Senior official at the Italian Data Protection Authority since 2014 within the Digital technology and IT security department. Her role includes providing technical consultancy to the legal Departments regarding complaints, inspections on lawfulness and security measures of data processing, data breaches, prescriptions and opinions with a focus on personal data protection in the health sector. She is in charge of any activity related to accreditation, certification and code of conduct under the GDPR. She has been appointed expert in the international, european and national standardization bodies (ISO/IEC JTC 1/SC 27/WG 5 “Information technology - Security techniques - Identity management and privacy technologies”, former ISO PC 317 “Consumer protection - Privacy by design for consumer goods and services”, CEN/CENELEC JTC 13/WG5 “Privacy management in products and services”) and she is also involved in the development of many privacy standards. She worked for the Ministry of Health, IT Division (2004-2013), Ministry of Economic Development, IT division (2000-2004) and Telecom Italia, Network Division (1995-2000). She is an electronic engineer and graduated at “Tor Vergata” University of Rome, she also achieved a Master's Degree in Telecommunications from the High School of Specialization in Telecommunications.
Panellist Donovan Sheppard, UCB Head of Data Protection Advisory & Global DPO Belgium
Panellist Data protection authority
18:00 – 20:00
20:30 – 22:00

Day 3 — Friday 16 October 2026

From regulation to implementation

09:00 – 10:30
Strategic plenary

EHDS: never-ending story — are we any closer?

With implementation approaching, organisations across Europe are asking the same question: are we truly ready for the European Health Data Space?

The European Commission speaker will give a reminder of the current situation and an update on the latest developments. Together with health data holders, health data users from academia and the life sciences, and patient representatives, the session will assess implementation progress, operational readiness and the challenges facing healthcare institutions.

Dipak Kalra Chair Dipak Kalra, i~HD President United Kingdom
Portrait of Guillaume Byk Speaker Guillaume Byk, European Commission · DG Health Legal and Policy Officer · Unit C1 Digital Health Guillaume Byk is a legal and policy officer at the European Commission, DG Health, Unit C1 on Digital Health. He is a lawyer specialised in data protection and biomedical law. Prior to joining DG Health, Guillaume worked at the office of the European Data Protection Supervisor and at the national data protection authority of Luxembourg on the implementation of the GDPR. Previously, he worked for more than 10 years as a data protection officer and legal counsel in a public biomedical research centre in Luxembourg.
Yacine Daquin Speaker Yacine Daquin, Health Data Hub Head of Legal France Yacine Daquin is the Health Data Hub's head of legal. He is in charge of legal matters relating to the secondary use of healthcare data, both at national and European level. In particular, he supports the Health Data Hub's activities in prefiguring and preparing for the future European health data space. Previously, he pursued a PhD on the regulation of artificial intelligence in healthcare, investigating the legal and ethical issues associated with the design and deployment of these systems.
Speaker Dr Sofia Tsekeridou, Netcompany Senior Research & Innovation Manager Greece
Portrait of Yann Heyer Speaker Yann Heyer, European Patients’ Forum Policy Officer Belgium In his role as Policy Officer, Yann contributes to EPF’s policy and advocacy work, including formulating positions in consultation with patient organisations and engaging with external stakeholders. He covers mainly topics such as digital health and artificial intelligence. Yann is Franco-German and holds a Franco-German degree from Sciences Po Lille and the University of Münster.
Speaker Hospital DPO
10:30 – 11:00
11:00 – 12:00
Closing panel

Becoming EHDS ready: the operational roadmap

A European Commission update on the implementing acts and on progress across Member States, followed by a panel on what it actually takes to deliver.

Speakers each take a different perspective on one question: how should a DPO help their organisation get EHDS ready?

  • Meeting the primary use obligations
  • Acting as a data holder
  • Acting as a data user
  • Responding to the new rights of patients

Panel discussion: what operational steps deliver on the EHR obligations, what are the capacity-building challenges, and how can the costs be met?

Nathan Lea Chair Nathan Lea, i~HD Data-driven health innovation, regulation and ethics expert
Speaker Dr Sofia Tsekeridou, Netcompany Senior Research & Innovation Manager Greece
Speaker CNIL EHDS specialist
Speaker To be announced
12:00 – 12:30
Closing keynote

Artificial intelligence, global health data governance and the future of healthcare

A forward-looking keynote examining how AI, health data governance and international cooperation will shape healthcare systems over the next decade.

Eric Sutherland Keynote Eric Sutherland, OECD Senior Health Economist, Digital Health France Eric is a Senior Health Economist leading the OECD’s work in Digitalisation of Health, bringing together policy guidance for digital security, integrated data, and responsible analytics including artificial intelligence. In that role, he is accountable for measuring and evolving the OECD’s Recommendation on Health Data Governance (2016) and supporting policy for digitalisation of health that provides data protection (e.g. security and privacy) and timely access to quality data to optimize the use of data for information, insights, and impact among individuals, health workers, policy makers, researchers, and innovators.

Who should attend

  • Data Protection Officers
  • Chief Data Officers
  • Privacy professionals
  • Compliance officers
  • Digital health leaders
  • Healthcare providers
  • Hospitals and university hospitals
  • Pharmaceutical and biotech companies
  • Medical device manufacturers
  • Researchers and academic institutions
  • Health data access bodies
  • Regulators and supervisory authorities
  • EHDS implementation project managers
  • AI governance and risk professionals

2026 key themes

  • European Health Data Space
  • Artificial intelligence and health data
  • Health data governance
  • Scientific research
  • Secondary use of health data
  • Cybersecurity and resilience
  • Medical devices
  • Genetic and genomic data
  • Data protection compliance
  • International data transfers
  • Emerging technologies
  • Operational readiness and capacity building

Sessions, timings and speakers may change. Speakers shown as “to be announced” are being confirmed and will be published as soon as they are.

Scroll to Top