14–16 October 2026 · Paris, France
4th European Health Data Protection Congress
Place du Trocadéro, 75016 Paris
Protecting Health Data. Enabling Innovation. Building Trust.
Three days bringing together regulators, hospitals, pharmaceutical and biotech companies, research institutions, technology leaders, Data Protection Officers and policy-makers around one question: how can Europe unlock the value of health data while maintaining trust, privacy, security and regulatory compliance?
Secure your spotSpeaker confirmed To be announced All times Paris time (CEST) · programme subject to change
Day 1 — Wednesday 14 October 2026
The new regulatory landscape
Congress opening
Opening remarks and strategic outlook on the future of health data governance in Europe and globally.
Revolution or evolution in health data protection?
Focus · Guidelines 1/2026 on the processing of personal data for scientific research purposes
The health data ecosystem is undergoing unprecedented transformation. New regulations, technological breakthroughs and increasing societal expectations are reshaping the way organisations collect, share and protect health information.
This session will examine whether Europe is witnessing a regulatory revolution or a natural evolution of existing governance models, and what this means for healthcare organisations, researchers and innovators.
Introductory presentations (30 min) followed by a 45-minute panel discussion.
The Biotech Act and Europe’s innovation agenda
Europe’s ambition to remain globally competitive in life sciences depends on its ability to foster innovation while ensuring robust safeguards for patients and citizens.
This session will explore how the Biotech Act may influence research, investment, innovation and international competitiveness within the healthcare and pharmaceutical sectors.
Introductory presentation followed by a panel discussion.
The Digital Omnibus
The Digital Omnibus package reopens parts of the European digital rulebook, from AI Act deadlines to transparency obligations. This session unpacks what changes, what stays, and what health data controllers should be doing now.
Introductory presentations (15 min) followed by a 45-minute panel discussion.
To record or not to record: that is the question
Consultation recording, ambient scribes and clinical documentation tools are spreading faster than the guidance that governs them. Supervisory authorities, platform providers and practising clinicians compare positions.
Day 2 — Thursday 15 October 2026
Innovation, risk and operational challenges
Regulatory data protection sandboxes: how they work and what organisations gain from them
What exactly is a regulatory data protection sandbox, how does the process run, and what are the benefits for a company or a healthcare institution taking part in one?
- Legal framework of a regulatory data protection sandbox
- Data protection sandboxes in Europe — overview and comparison
- How the LfDI Rheinland-Pfalz sandbox works, step by step
- First participants in the health area
Interactive segment: what does the audience expect from a sandbox? Which innovations would you submit — or did you shelve because of data protection uncertainty?
Parallel workshop session 1 — choose one
Relative identifiability in health data: pseudonymisation and secondary use governance
Where does pseudonymised data stop being personal data? A panel on re-identification risk, defensible thresholds and the governance that makes secondary use workable.
Connected glasses in care and at work
Smart glasses are moving from pilot to ward. A roundtable between platform, industry and hospital privacy leads on capture, consent and the boundary between clinical benefit and surveillance.
Speaker
Alaksandra Aytova,
Applegreen
Group Head of Privacy
Dr. Aleksandra Aytova is the Group Head of Privacy and AI
Governance at Applegreen and an internationally recognised
expert in human rights, digital ethics, and technology law.
With over 15 years of legal and corporate leadership
experience, she helps organisations navigate the
intersection of innovation, regulation, and risk. Dr.
Aytova holds a Ph.D. in Fundamental Rights from Sofia
University, a Master’s in IT Law from Tartu
University, and a specialisation in AI and Machine
Learning from MIT. A passionate advocate for responsible
innovation, her work focuses on safeguarding human rights
and advancing ethical AI-assisted decision-making in the
digital age.
Speaker
Georgia Voudoulaki,
Bosch
Senior Legal Counsel
Parallel workshop session 2 — choose one
Tokenisation: privacy by design for medical research
How tokenisation lets research datasets be linked across sources without moving identifiers — and what regulators expect from the key management around it.
Cybersecurity incidents and communication strategy
Cybersecurity incidents increasingly affect healthcare organisations and critical infrastructures. Participants will discuss resilience strategies, incident management, NIS2 requirements and what to say — to regulators, staff and patients — in the first 72 hours.
Parallel workshop session 3 — choose one
Genetic data: handling genomic data and biobanks in practice
Genetic data presents some of the most complex legal, ethical and operational challenges in healthcare. This workshop looks at governance frameworks, research opportunities and the safeguards needed for responsible use of genomic information.
Neuroprivacy and robotics: new technology in health data protection
Brain–computer interfaces and care robotics generate categories of data that existing frameworks were never written for. This workshop examines what governance for neural and behavioural data should look like.
Parallel workshop session 4 — choose one
Medical digital twins and synthetic data
Synthetic cohorts and patient digital twins promise research value without exposing real records. The panel tests that promise against re-identification risk, validity and regulatory acceptance.
From lab to launch: data protection in bringing new medical devices to market
This session explores the range of data protection issues to consider when designing, testing and commercialising new medical devices — and how those issues shift from one device type to another, from implantables to capital equipment to consumer wearables.
Panellist
Mirella Kavadaki,
MedTech Europe
Manager Legal & Compliance
Mirella Kavadaki is a qualified lawyer and Manager for
Legal & Compliance and Legal Counsel at MedTech Europe,
the European trade association representing the medical
technology industry. She leads the organisation’s
work on data protection and privacy, with a particular
focus on health data processing and the interaction
between the GDPR, EU digital legislation and medical
device regulation. Mirella holds an Advanced LL.M. in
Intellectual Property & ICT Law from KU Leuven and an
MSc in European Public Law from Panteion University of
Social and Political Sciences.
Striking the right balance: don’t throw the baby out with the bath water
Ensuring privacy regulation achieves its purpose without holding back innovation and treatment
This session brings together privacy leaders in the life sciences industry and data protection authorities to consider the evolving regulatory landscape, including EU regulations such as the EHDS, the AI Act, the GDPR and MDR/IVDR. Panellists will address regulatory complexity, and how companies and regulators can partner to achieve shared goals by building trust and enabling responsible data use.
Industry leaders will also discuss why internal partnerships with senior management and IT leaders are essential in navigating regulatory requirements while committing to a strategy that embraces innovation and competition. Panellists will share lessons learned, including case studies from the pharmaceutical and medical technology industries where regulation either created barriers to treatment and best practice, or achieved a healthy balance.
Chair
Mary Devlin Capizzi,
Faegre Drinker
Partner
United States
Mary Devlin Capizzi is a partner at the law firm of Faegre
Drinker Biddle & Reath and based in Washington, DC. Mary
has nearly three decades of experience building relationships
at the intersection of law, regulation, science, and policy,
advising pharmaceutical, biotechnology, medical device, and
consumer health clients on complex compliance, legislative,
scientific, and agency-facing matters. She currently serves
Faegre Drinker as the leader of its global life sciences
consortia management team and has held numerous firm
leadership roles over her career, including as a longtime firm
Board member, an executive partner, and co-leader of the
firm’s health and life sciences sector. For almost 30
years, Mary has partnered with industry leaders to establish
and operate pre-competitive collaborative initiatives on a
wide range of topics, including data governance, cyber
security, AI and federated learning, innovation in drug
development, supply chain security, patient safety, product
quality, clinical trials, and data sharing. Mary enjoys
solving complex problems collaboratively. She and the
consortia management team proactively align industry leaders
around shared goals, maintain rigorous, efficient coordination
among stakeholders, and build and sustain trust to ensure
flourishing of industry initiatives and achieving identified
objectives. Mary, along with her colleague, Peter Blenkinsop,
worked with global industry leaders to establish the
International Pharmaceutical and Medical Device Privacy
Consortium (IPMPC) in 2001–2002. Mary received her law
degree from Emory University School of Law in Atlanta,
Georgia, her BA, and MBA from the University of Dallas, in
Irving, Texas. She is a fluent Spanish speaker who has lived
and worked in Spain, France, Italy and Mexico.
Day 3 — Friday 16 October 2026
From regulation to implementation
EHDS: never-ending story — are we any closer?
With implementation approaching, organisations across Europe are asking the same question: are we truly ready for the European Health Data Space?
The European Commission speaker will give a reminder of the current situation and an update on the latest developments. Together with health data holders, health data users from academia and the life sciences, and patient representatives, the session will assess implementation progress, operational readiness and the challenges facing healthcare institutions.
Speaker
Guillaume Byk,
European Commission · DG Health
Legal and Policy Officer · Unit C1 Digital Health
Guillaume Byk is a legal and policy officer at the European
Commission, DG Health, Unit C1 on Digital Health. He is a
lawyer specialised in data protection and biomedical law.
Prior to joining DG Health, Guillaume worked at the office of
the European Data Protection Supervisor and at the national
data protection authority of Luxembourg on the implementation
of the GDPR. Previously, he worked for more than 10 years as a
data protection officer and legal counsel in a public
biomedical research centre in Luxembourg.
Speaker
Yann Heyer,
European Patients’ Forum
Policy Officer
Belgium
In his role as Policy Officer, Yann contributes to
EPF’s policy and advocacy work, including formulating
positions in consultation with patient organisations and
engaging with external stakeholders. He covers mainly topics
such as digital health and artificial intelligence. Yann is
Franco-German and holds a Franco-German degree from Sciences
Po Lille and the University of Münster.
Becoming EHDS ready: the operational roadmap
A European Commission update on the implementing acts and on progress across Member States, followed by a panel on what it actually takes to deliver.
Speakers each take a different perspective on one question: how should a DPO help their organisation get EHDS ready?
- Meeting the primary use obligations
- Acting as a data holder
- Acting as a data user
- Responding to the new rights of patients
Panel discussion: what operational steps deliver on the EHR obligations, what are the capacity-building challenges, and how can the costs be met?
Artificial intelligence, global health data governance and the future of healthcare
A forward-looking keynote examining how AI, health data governance and international cooperation will shape healthcare systems over the next decade.
Who should attend
- Data Protection Officers
- Chief Data Officers
- Privacy professionals
- Compliance officers
- Digital health leaders
- Healthcare providers
- Hospitals and university hospitals
- Pharmaceutical and biotech companies
- Medical device manufacturers
- Researchers and academic institutions
- Health data access bodies
- Regulators and supervisory authorities
- EHDS implementation project managers
- AI governance and risk professionals
2026 key themes
- European Health Data Space
- Artificial intelligence and health data
- Health data governance
- Scientific research
- Secondary use of health data
- Cybersecurity and resilience
- Medical devices
- Genetic and genomic data
- Data protection compliance
- International data transfers
- Emerging technologies
- Operational readiness and capacity building
Sessions, timings and speakers may change. Speakers shown as “to be announced” are being confirmed and will be published as soon as they are.