
Conference Programme
Nordic Privacy Arena 2026
Conference Programme and Speakers at Nordic Privacy Arena 2026
Read more about Nordic Privacy Arena 2026 and get your NPA 2026 tickets here!
This year’s conference theme is Innovation and Compliance in the Era of Cloud, AI and Geopolitical Uncertainty – Because Accountability Can’t Be Outsourced.
Agenda
Day 1: Monday 28 September 2026
Day 2: Tuesday 29 September 2026
This is an excerpt from the programme of Nordic Privacy Arena 2026 – more additions will follow! Please check back regularly, and please note that we reserve the right to make changes to the program at any time without prior notice.
Day 1: Monday 28 September 2026
Monday’s Chatmaster:
Karl-Fredrik Björklund, Deputy Chair, Swedish Data Protection Forum and Partner, Hellström Advokatbyrå
| Time | Session | Speaker |
|---|---|---|
| 08:00- 08:55 | Networking Breakfast Start the conference with coffee, breakfast, and conversations with fellow participants from across the privacy community. Before the NPA 2026 begins, take the opportunity to catch up with colleagues, meet new faces, and exchange views on the developments, challenges, and practical realities of privacy work. This is a relaxed setting to begin the day and the discussions that will continue throughout the conference. | You |
| 09:00- 09:15 | Opening NPA 2026 – Day 1 NPA 2026 opens with a welcome and an introduction to this year’s theme: Innovation and Compliance in the Era of Cloud, AI and Geopolitical Uncertainty – Because Accountability Can’t Be Outsourced. Over the next two days, we will look at how organisations are dealing with rapid technological change, evolving regulation and increasing geopolitical uncertainty – and what it takes to remain accountable in practice. | Caroline Olstedt Carlström Chair, Swedish Data Protection Forum, and Partner and Head of Data, Privacy and Information Security, Cirio Law Firm |
| 09:20- 09:45 | Keynote: Insights from the Swedish Authority for Privacy Protection (IMY) What are the key issues currently on the agenda of the Swedish Data Protection Authority? In this keynote, Director General Eric Leijonram shares reflections on developments in privacy and data protection, as well as the priorities and challenges facing the authority. The session provides an opportunity to hear directly from IMY about current regulatory developments, supervisory activities and other matters receiving increased attention from the Swedish data protection authority. | Eric Leijonram Director General, Swedish Authority for Privacy Protection (IMY) |
| 09:50- 10:15 | Keynote: The Bridge on a Stranger’s Face – Accountability in the Age of Cloud, AI and Geopolitical Tension Discussions about data protection have always been discussions about power and control. Hence, data protection legislation places the accountability of data protection with the person who controls the processing of personal data. This works in simple constructs, but is stress-tested extensively in the age of cloud, AI and geopolitical tensions, where scalable processing does not seem to lead to scaling accountability as well. In this keynote we tackle this topic by taking smart glasses as our example and go back to the basics of data protection and core concepts such as the household exemption and controllership to ask ourselves: does accountability in data protection scale? | Anna Berlee Professor of Data Protection and Privacy Law at Open University (NL) & Chair of Dutch Privacy Association Vereniging Privacy Recht |
| 10:20- 10:40 | Panel discussion: Data Protection Authorities Challenges in the Current Geopolitical Climate This panel explores how data protection authorities face the challenges of the current geopolitical climate. European politicians are attempting to address numerous challenges, with measures to boost innovation, improve digital sovereignty, and give public authorities stronger tools for surveillance. What does this demand from today’s data protection authorities, and the role they play? | Arman Borghem (moderator) Regulatory and Compliance Advisor, Cleura Anna Hänninen Team Manager International Legal Matters, Finnish Office of the Data Protection Ombudsman Marit Hansen State Data Protection Commissioner Land Schleswig-Holstein Additional DPAs may be announced. |
| 10:40- 11:10 | Coffee Break Recharge with coffee and take the opportunity to network with fellow attendees. Don’t miss the opportunity to speak with our sponsors and exhibitors, whose contributions are essential to making NPA what it is. | You |
| Block 1 – Digital Sovereignty | ||
| 11:10- 11:25 | Keynote: Swedish Government Agencies’ View on the Geopolitical Situation and Digital Sovereignty The Swedish public sector is feeling the pressure to innovate, while ensuring legal compliance and an appropriate use of digital solutions. Different government agencies have chosen different paths, based on different assessments. eSamverkansprogrammet (eSam) is an initiative of 40+ Swedish government agencies pooling resources to solve digitalisation challenges. What has been achieved to improve competition and access to sovereign digital solutions, for example in the area of interoperability? We may also get a glimpse of what the private sector can learn from how the public sector works together. | Erik Enocksson Security Coordinator, eSam |
| 11:30- 11:50 | Keynote: Pille Lehis Details to be announced. | Pille Lehis Director General, Estonian Data Protection Inspectorate |
| 11:55- 12:20 | Panel discussion: How Does Europe Meet the Moment? How do European customers and tech providers meet the moment? How can customer organisations work together to find solutions that meet their needs? What changes in purchasing behaviour has a European tech provider noticed, and what can customers achieve without relying on US clouds? How should European organisations think about the risks and opportunities – whether in the realm of cybersecurity, innovation, vendor lock-in, or digital sovereignty? | Onur Korucu (moderator) Non-Executive Director, DataRep Erik Enocksson Security Coordinator, eSam Astor Nummelin Carlberg Director Open Source Sovereignty, SUSE Michael Bahar Partner and Co-Lead of Global Cybersecurity and Data Privacy, Eversheds Sutherland |
| 12:25- 12:45 | Keynote: A US view on Recent History How do US politicians and businesses view what is happening in Europe at the moment, particularly the push for digital sovereignty? Looking back a decade, what are the developments in the United States from then until now, and how do the three branches of government view the rule of law? This keynote gives a US perspective on how European organisations should think about their reliance on US tech providers. | Michael Bahar Partner and Co-Lead of Global Cybersecurity and Data Privacy, Eversheds Sutherland |
| 12:45- 13:45 | Lunch Break Enjoy a delicious lunch while engaging your fellow attendees in exciting discussions! | You |
| Block 2 – Procurement | ||
| 13:45- 14:15 | Keynote: No Competition, No Compliance: How Procurement Practices Decide Your Data Protection Outcomes No one sets out to procure unlawful processing. We get it anyway, because we write requirements that only one supplier can meet. This keynote addresses unsuitable and anti-competitive procurement practices that cause inappropriate data processing. Drawing on research from the University of Skövde, it specifically elaborates on how Sweden’s first Cloud Policy and the EU’s Cloud Sovereignty Framework can (and will) improve current practices and impact opportunities for managing risks. | Björn Lundell (Ph.D.) Professor of Computer Science, University of Skövde |
| 14:20- 14:45 | Fireside chat: Use of AI transcription in Healthcare There are high expectations that AI will innovate and solve the future challenges of healthcare. A current technique is Ambient scribes which transcribes conversations and uses generative AI to facilitate medical record documentation. At the same time, the new technique requires more individual data than before to be processed by AI and large language models (LMMs). This panel discusses where we stand today – what are our challenges and dilemmas? | Milla Keller Head of Tech & Regulatory Legal, Terveystalo Manólis Nymark Chief Executive, Manólis Nymark Consulting Kathinka Theodore Aakenes Vik Senior Advisor at Section for investigations, analysis and politics, Norwegian Datatilsynet |
| 14:50- 15:15 | Keynote: Anna Hänninen Topic to be announced. | Anna Hänninen Director General, Estonian Data Protection Inspectorate |
| 15:15- 15:45 | Coffee Break Recharge with coffee and take the opportunity to follow up on the afternoon discussions. Don’t miss the opportunity to speak with our sponsors and exhibitors, whose contributions are essential to making NPA what it is. | You |
| 15:45- 16:25 | Keynote: Trust and Safety in Technology – A Powerful History The speed of technological innovation challenges many facets of society. Policy makers and enforcement agencies scramble to understand the application of existing law while simultaneously struggling to predict future harms. Organisations, fearful of missing the growth and promise of emerging tech, move quickly to adopt, while often not fully assessing risk. Data protection professionals are caught in the middle of these forces. And too often, their work is characterised as friction – something that slows down progress. This session will argue that nothing could be further from the truth. Through historical analogy, we can see that trust and technological innovation are not only symbiotic – they are also essential to each other. | Trevor Hughes President, International Association of Privacy Professionals (IAPP) |
| 16:30- 17:00 | Keynote: Max Schrems Max Schrems provides the latest exciting updates from noyb. | Max Schrems Founder, noyb |
| 17:05- 17:30 | Keynote: To be announced | To be announced |
| 17:35- 17:40 | Closing Remarks for Day 1 A brief wrap-up of Day 1 and a look ahead at Day 2. You will also be invited to our informal afterwork mingle. | Caroline Olstedt Carlström Chair, Swedish Data Protection Forum, and Partner and Head of Data, Privacy and Information Security, Cirio Law Firm |
| 17:45- 20:00 | Afterwork mingle Join fellow attendees for an informal afterwork mingle to unwind and continue the conversations in a more relaxed setting. Don’t miss the chance to talk to our esteemed sponsors that have helped make this year’s NPA possible. | You |
Day 2: Tuesday 29 September 2026
Tuesday’s Chatmaster:
Karl-Fredrik Björklund, Deputy Chair, Swedish Data Protection Forum and Partner, Hellström Advokatbyrå
| Time | Session | Speaker |
|---|---|---|
| 07:30- 08:55 | Coveware Cybersecurity Session More details to come! We are very excited to have Magnus Jelen back. | Magnus Jelen Lead Director of Incident Response UK & EMEA, Coveware |
| 09:00- 09:10 | Welcome to Day 2 of NPA 2026 Get ready for day 2 as we look at how organisations are dealing with rapid technological change, evolving regulation and increasing geopolitical uncertainty – and what it takes to remain accountable in practice. | Caroline Olstedt Carlström Chair, Swedish Data Protection Forum Partner and Head of Data, Privacy and Information Security, Cirio Law Firm |
| Block 3 – Product Development and DS(A)Rs | ||
| 09:15- 09:45 | Keynote: When AI Becomes the Requestor: Managing the New Wave of AI-Generated Data Subject Requests A dive into the influx of AI-generated data subject rights requests, and how to tackle them. | Tim Turner Data Protection Consultant, 2040 Training |
| 09:50- 10:20 | Panel discussion regarding DSARs | Tim Turner (moderator) Data Protection Consultant, 2040 Training Ängla Pändel Senior Associate tech, data protection and compliance, Mannheimer Swartling Advokatbyrå Nils G. Indahl Data Protection Officer, Church of Norway |
| 10:25- 10:45 | Fireside chat – details to be announced | To be announced |
| 10:45- 11:15 | Coffee Break Recharge with coffee and take the opportunity to network with fellow attendees. Don’t miss the opportunity to speak with our sponsors and exhibitors, whose contributions are essential to making NPA what it is. | You |
| 11:15- 11:45 | Fireside chat: C-199/24, Lexbase judgement: a Swedish David vs Goliath case at the highest EU Court (Chapter 2) The Swedish principles of transparency and the European fundamental right to privacy have clashed. Goled Raabi, also known as GDPRWarrior, has taken on both Lexbase and the Swedish state before the European Court of Justice. This is a David vs Goliath case where one person is fighting a battle against the Swedish legal system which allows companies to sell personal data of millions of Swedes, including criminal records, without restrictions by GDPR. On July 9, 2026, Goled won the case in the Court of Justice of the European Union (CJEU). Joakim Söderberg will give us a legal background of the case and what effect the judgement will have in the future. Thereafter Joakim will have a discussion with Goled about his journey and what the judgement will mean for all people in Goled’s situation. | Joakim Söderberg Legal counsel and GDPR expert, consultant, formerly at noyb Goled Raabi GDPRWarrior is the plaintiff in EU case C-199/24 against Lexbase and the Swedish state |
| 11:50- 12:10 | How Do We Interpret Criminal Offences in the GDPR? The processing of data on criminal offences is becoming increasingly important, in relation to inter alia background checks and anti-money laundering. However, there is a lack of harmonisation as regards the interpretation of Article 10 which provides enhanced protection for such data. To reach harmonisation, the Swedish Authority for Privacy Protection (IMY) has raised this issue in the EDPB. IMY has also looked into how national legislation could be designed in view of the evolving need to process data on criminal offences. | David Törngren Head of Department for Legal Services, Swedish Authority for Privacy Protection (IMY) |
| 12:15- 12:40 | Keynote: Dijana Šinkūnienė Details to be announced. | Dijana Šinkūnienė Director, Lithuanian State Data Protection Inspectorate |
| 12:40- 13:40 | Lunch Break Enjoy a delicious lunch while engaging your fellow attendees in exciting discussions! During the lunch, Team Rynkeby will briefly speak about its work. The Swedish Data Protection Forum is a proud sponsor of Team Rynkeby and its contribution to the Swedish Childhood Cancer Fund. | You Team Rynkeby |
| Block 4 – Enabling IT | ||
| 13:40- 14:00 | Keynote: Demystifying the EU AI Act: Translating Legal Requirements Into Business Reality This presentation examines the EU AI Act as a practical framework for enabling effective AI governance within organisations. The session explores how companies can map and classify their AI systems, assess risk levels, and navigate role-specific responsibilities across the AI value chain. It also looks at how transparency requirements can be embedded into system design, how risk and incident registers strengthen oversight and accountability, and how privacy and data protection can be integrated into AI decision-making – helping organisations build trustworthy, compliant AI systems that support innovation while protecting individuals. | Petruta Pirvan Founder, EU Digital Partners AI Governance Specialist, E.ON |
| 14:05- 14:25 | Keynote: Privacy Professionals as Forerunners of Change – How Do We Become Pioneers in the Rapidly Changing Digital Environment? This session explores how privacy professionals can become effective leaders in an era of constant digital transformation. Gain an overview of the organisational changes driving the need for stronger change management, understand the principles behind leading change successfully, and take away practical tips for influencing stakeholders, embedding privacy into business transformation, and positioning privacy as a catalyst for innovation rather than simply a compliance function. | Oona Matinpalo Data Protection Officer, Sanoma Media Finland |
| 14:30- 15:00 | Panel discussion: IT vs US Technology teams want to innovate. Organisations want to grow. Data protection teams have an important role to play. So why do tensions sometimes arise? Join our panel as we examine perceptions, challenge accepted wisdom and explore how organisations can turn competing demands into shared success. | Liz Smith (moderator) Senior Consultant and Public Affairs Manager, DataGuard Anna Badaeva Data Protection Officer, Tonybet Viktorya Martirosyan Data Protection Specialist, Interpol Lucie Škopková Senior Privacy Analyst, Informa |
| 15:00- 15:20 | Coffee Break Recharge with coffee and take the opportunity to follow up on the afternoon discussions. Don’t miss the opportunity to speak with our sponsors and exhibitors, whose contributions are essential to making NPA what it is. | You |
| 15:20- 15:40 | Keynote: Change Ahead – Finally, a Proper Foundation for Accountability: GDPR Meets the Cyber Resilience Act Boring. So boring! Not exactly pleasant bedtime reading, and certainly not something to wake you up in the morning. What are we talking about? Technical documentation. And the GDPR’s accountability principle. Hold on – is it really boring? For starters, accountability is absolutely crucial – a point emphasized by the CJEU. The goal is to ensure that processing of personal data proceeds as it should and that, ideally, nothing goes wrong. And if something does go wrong? That you react correctly right away to manage the risk for the data subjects and, also important, safeguard the company’s reputation. Accountability entails compliance documentation and more. Until now, this has been difficult because hardware and software were often, to a significant extent, ”black boxes” regarding data protection and security. But that is set to change. The Cyber Resilience Act is on the horizon, mandating ”security by design” across the supply chain. Technical documentation plays a major role in this. This provides a foundation which enables real accountability. And then, all of a sudden… accountability doesn’t have to be boring after all. At the time of the conference, Marit Hansen is finishing her final term as State Data Protection Commissioner of Schleswig-Holstein. | Marit Hansen State Data Protection Commissioner, Schleswig-Holstein |
| 15:45- 16:05 | Keynote: Privacy by Automation: How IT Enables Effective Retention and Deletion Programs This session explores how IT can enable effective retention and deletion programs through process automation and governance. It will examine how organisations can transform retention and deletion from policy documents into repeatable, scalable business processes, while addressing common implementation challenges and organisational barriers. Drawing on practical experience, the session highlights how automation can strengthen privacy compliance, operational efficiency, and information governance. | Majekodunmi Abayomi Privacy Counsel, Uniper |
| 16:10- 16:30 | Keynote: The Hardest Privacy Problems Aren’t Legal: Seven Lessons from Running Privacy at Scale This keynote draws on real-world experience of building and operating privacy capabilities in a large organisation. Through seven practical lessons, the session explores how to make sound privacy decisions without creating bottlenecks, remain accountable in an environment shaped by AI, vendors, and distributed decision-making, and design governance and organisational structures that enable privacy to scale across countries, technologies, and business units. | Heidi Mäkelä Vice President & Head of Legal Technology, Telia |
| 16:35- 16:45 | Closing Remarks by the Chair of the Swedish Data Protection Forum We close our two fully packed conference days with some reflections on our many exciting keynotes, panels and discussions. | Caroline Olstedt Carlström Chair, Swedish Data Protection Forum Partner and Head of Data, Privacy and Information Security, Cirio Law Firm |

Some of the topics which will be discussed at NPA 2026…
AI Transcription in Healthcare
Data Subject Access Requests
Digital Sovereignty
Emerging Cybersecurity Threats
Privacy Professionals as Pioneers of Change
Public Sector Views on the Cloud
Supervisory Authority Agendas
Some of our distinguished contributors at NPA 2026
Besides our phenomenal conference attendees, the following people will contribute to Nordic Privacy Arena 2026, whether as speakers, panel discussion members or moderators.

Ängla Pändel
Senior Associate tech, data protection and compliance
Mannheimer Swartling Advokatbyrå
LinkedIn
Anna Badaeva
Group Data Protection Officer/Security Expert
Tonybet
LinkedIn
Anna Berlee
Professor of Data Protection and Privacy Law
Open University
LinkedIn
Anna Hänninen
Team Manager – International Legal Matters
Finnish Office of the Data Protection Ombudsman
LinkedIn
Arman Borghem
Regulatory and Compliance Advisor
Cleura
LinkedIn
Astor Nummelin Carlberg
Director Open Source Sovereignty
SUSE
LinkedIn
Björn Lundell (Ph.D.)
Professor of Computer Science
University of Skövde
LinkedIn
Caroline Olstedt Carlström
Chair Swedish Data Protection Forum
Partner, Cirio Law Firm
LinkedIn
David Törngren
Head of Department for Legal Services
Swedish Authority for Privacy Protection (IMY)
LinkedIn
Dijana Šinkūnienė
Director
Lithuanian State Data Protection Inspectorate
LinkedIn
Eric Leijonram
Director General
Swedish Authority for Privacy Protection (IMY)
LinkedIn
Erik Enocksson
Security Coordinator
eSamverkansprogrammet
LinkedIn
Goled Raabi
Cloud & Automation Engineer | GDPR & Digital Rights Advocate
LinkedIn
Heidi Mäkelä
Vice President & Head of Legal Technology
Telia
LinkedIn
J. Trevor Hughes
President / CEO
IAPP
LinkedIn
Joakim Söderberg
Legal counsel and GDPR Consultant
Datajurist.se
LinkedIn
Karl-Fredrik Björklund
Deputy Chair, Swedish Data Protection Forum
Partner, Hellström Advokatbyrå
LinkedIn
Kathinka Theodore Aakenes Vik
Senior Advisor at Section for investigations, analysis and politics
Norwegian Datatilsynet
LinkedIn
Liz Smith
Senior Consultant and Public Affairs Manager
DataGuard
LinkedIn
Lucie Škopková
Senior Privacy Analyst
Informa
LinkedIn
Magnus Jelen
Lead Director of Incident Response UK & EMEA
Coveware
LinkedIn
Majekodunmi Abayomi
Privacy Counsel
Uniper
LinkedIn
Manólis Nymark
Chief Executive & Consultant
Manolis Nymark Consulting
LinkedIn
Marit Hansen
State Data Protection Commissioner
Land Schleswig-Holstein
LinkedIn
Max Schrems
Founder of noyb, lawyer and author
noyb
LinkedIn
Michael Bahar
Global Co-Lead of Cybersecurity and Data Privacy Practice
Eversheds Sutherland
LinkedIn
Milla Keller
Head of Tech & Regulatory Legal
Terveystalo
LinkedIn
Nils G. Indahl
Data Protection Officer
Church of Norway
LinkedIn
Onur Korucu
Non-Executive Director
DataRep
LinkedIn
Oona Matinpalo
Data Protection Officer
Sanoma Media Finland
LinkedIn
Petruta Pirvan
AI Governance Specialist
E.ON
LinkedIn
Pille Lehis
Director General
Estonian Data Protection Inspectorate
LinkedIn
Tim Turner
Data Protection Consultant
2040 Training
LinkedIn
Viktorya Martirosyan
Data Protection Specialist
INTERPOL
LinkedIn
Please note that we reserve the right to make changes to the programme and participating speakers at any time without prior notice.
Sponsors
We extend our sincerest gratitude to our esteemed sponsors for their generous support. We also want to express that we remain open to further sponsorships and can be reached at info@dpforum.se.







