
Conference Programme
Nordic Privacy Arena 2026
Conference Programme and Speakers at Nordic Privacy Arena 2026
Read more about Nordic Privacy Arena 2026 and get your NPA 2026 tickets here!
This year’s conference theme is Innovation and Compliance in the Era of Cloud, AI and Geopolitical Uncertainty – Because Accountability Can’t Be Outsourced.
Agenda
Day 1: Monday 28 September 2026
Day 2: Tuesday 29 September 2026
This is an excerpt from the programme of Nordic Privacy Arena 2026 – more additions will follow! Please check back regularly, and please note that we reserve the right to make changes to the program at any time without prior notice.
Day 1: Monday 28 September 2026
| Time | Session | Speaker |
|---|---|---|
| 08:00- 08:55 | Networking Breakfast Start the conference with coffee, breakfast, and conversations with fellow participants from across the privacy community. Before the NPA 2026 begins, take the opportunity to catch up with colleagues, meet new faces, and exchange views on the developments, challenges, and practical realities of privacy work. This is a relaxed setting to begin the day and the discussions that will continue throughout the conference. | You |
| 09:00- 09:15 | Opening NPA 2026 – Day 1 NPA 2026 opens with a welcome and an introduction to this year’s theme: Innovation and Compliance in the Era of Cloud, AI and Geopolitical Uncertainty – Because Accountability Can’t Be Outsourced. Over the next two days, we will look at how organisations are dealing with rapid technological change, evolving regulation and increasing geopolitical uncertainty – and what it takes to remain accountable in practice. | Caroline Olstedt Carlström Chair, Swedish Data Protection Forum, and Partner and Head of Data, Privacy and Information Security, Cirio Law Firm |
| 09:20- 09:45 | Keynote: Insights from the Swedish Authority for Privacy Protection (IMY) What are the key issues currently on the agenda of the Swedish Data Protection Authority? In this keynote, Director General Eric Leijonram shares reflections on developments in privacy and data protection, as well as the priorities and challenges facing the authority. The session provides an opportunity to hear directly from IMY about current regulatory developments, supervisory activities and other matters receiving increased attention from the Swedish data protection authority. | Eric Leijonram Director General, Swedish Authority for Privacy Protection (IMY) |
| 09:50- 10:15 | Keynote: Topic to be announced | Anna Berlee Professor of Data Protection and Privacy Law at Open University (NL) & Chair of Dutch Privacy Association Vereniging Privacy Recht |
| 10:20- 10:45 | Panel discussion: Data Protection Authorities This panel will explore how data protection authorities face challenges in the current geopolitical climate. | ➢ Moderator: Arman Borghem Regulatory and Compliance Advisor, Cleura ➢ Data Protection Authorities to be announced |
| 10:45- 11:15 | Coffee Break Recharge with coffee and take the opportunity to network with fellow attendees. Don’t miss the opportunity to speak with our sponsors and exhibitors, whose contributions are essential to making NPA what it is. | You |
| Block 1 – Digital Sovereignty | ||
| 11:15- 11:30 | Keynote: Swedish Government Agencies’ View on the Geopolitical Situation and Digital Sovereignty The Swedish public sector is feeling the pressure to innovate, while ensuring legal compliance and an appropriate use of digital solutions. Different government agencies have chosen different paths, based on different assessments. eSamverkansprogrammet (eSam) is an initiative of 40+ Swedish government agencies pooling resources to solve digitalisation challenges. What has been achieved to improve competition and access to sovereign digital solutions, for example in the area of interoperability? We may also get a glimpse of what the private sector can learn from how the public sector works together. | Erik Enocksson eSam |
| 11:35- 11:55 | Panel discussion – details to be announced | To be announced |
| 12:00- 12:20 | Panel discussion: How Does Europe Meet the Moment? How do European customers and tech providers meet the moment? How can customer organisations work together to find solutions that meet their needs? What changes in purchasing behaviour has a European tech provider noticed, and what can customers achieve without relying on US clouds? How should European organisations think about the risks and opportunities – whether in the realm of cybersecurity, innovation, vendor lock-in, or digital sovereignty? | ➢ Moderator: Onur Korucu DataRep ➢ Erik Enocksson eSam ➢ Astor Nummelin Carlberg SUSE ➢ Michael Bahar Partner and Co-Lead of Global Cybersecurity and Data Privacy, Eversheds Sutherland Additional participants may be announced |
| 12:25- 12:45 | Keynote: A US view on Recent History How do US politicians and businesses view what is happening in Europe at the moment, particularly the push for digital sovereignty? Looking back a decade, what are the developments in the United States from then until now, and how do the three branches of government view the rule of law? This keynote gives a US perspective on how European organisations should think about their reliance on US tech providers. | Michael Bahar Partner and Co-Lead of Global Cybersecurity and Data Privacy, Eversheds Sutherland |
| 12:45- 13:45 | Lunch Break Enjoy a delicious lunch while engaging your fellow attendees in exciting discussions! | You |
| Block 2 – Procurement | ||
| 13:45- 14:15 | Keynote: No Competition, No Compliance: How Procurement Practices Decide Your Data Protection Outcomes No one sets out to procure unlawful processing. We get it anyway, because we write requirements that only one supplier can meet. This keynote addresses unsuitable and anti-competitive procurement practices that cause inappropriate data processing. Drawing on research from the University of Skövde, it specifically elaborates on how Sweden’s first Cloud Policy and the EU’s Cloud Sovereignty Framework can (and will) improve current practices and impact opportunities for managing risks. | Björn Lundell (Ph.D.) Professor of Computer Science, University of Skövde |
| 14:20- 14:45 | Fireside chat: Use of AI transcription in Healthcare There are high expectations that AI will innovate and solve the future challenges of healthcare. A current technique is Ambient scribes which transcribes conversations and uses generative AI to facilitate medical record documentation. At the same time, the new technique requires more individual data than before to be processed by AI and large language models (LMMs). This panel discusses where we stand today – what are our challenges and dilemmas? | ➢ Milla Keller Head of Tech & Regulatory Legal, Terveystalo ➢ Manólis Nymark Chief Executive, Manólis Nymark Consulting Additional participants may be announced |
| 14:50- 15:15 | Keynote: How Do Apps Work? An increasing number of organisations are providing their services through apps. Technical knowledge is key in understanding how apps work, but it also improves communication and cooperation with your stakeholder. This in turn enables accountability. So how do apps work? What are Software Development Kits (SDKs)? And how do developments relating to AI and supply chain affect the use and compliance apps? This session provides you with a technical deep-dive into apps, SDKs and developments ahead to help you ask the right questions. | Nick Leppänen Larsson Technical Product Owner, Postnord |
| 15:15- 15:45 | Coffee Break Recharge with coffee and take the opportunity to follow up on the afternoon discussions. Don’t miss the opportunity to speak with our sponsors and exhibitors, whose contributions are essential to making NPA what it is. | You |
| 15:45- 16:25 | Keynote: Trevor Hughes Details to be announced. | Trevor Hughes President, International Association of Privacy Professionals (IAPP) |
| 16:30- 17:10 | Keynote: Max Schrems Max Schrems provides the latest exciting updates from noyb. | Max Schrems Founder, noyb |
| 17:15- 17:20 | Closing Remarks for Day 1 A brief wrap-up of Day 1 and a look ahead at Day 2. | Caroline Olstedt Carlström Chair, Swedish Data Protection Forum, and Partner and Head of Data, Privacy and Information Security, Cirio Law Firm |
| 17:20- 20:00 | After work Join fellow attendees for an informal afterwork to unwind and continue the conversations in a more relaxed setting. Don’t miss the chance to talk to our esteemed sponsors that have helped make this year’s NPA possible. | You |
Day 2: Tuesday 29 September 2026
| Time | Session | Speaker |
|---|---|---|
| 07:30- 08:55 | Morning Cybersecurity Workshop Details to be announced | To be announced |
| 09:00- 09:10 | Welcome to Day 2 of NPA 2026 Get ready for day 2 as we look at how organisations are dealing with rapid technological change, evolving regulation and increasing geopolitical uncertainty – and what it takes to remain accountable in practice. | Caroline Olstedt Carlström Chair, Swedish Data Protection Forum Partner and Head of Data, Privacy and Information Security, Cirio Law Firm |
| Block 3 – Product Development and DS(A)Rs | ||
| 09:15- 09:45 | Keynote Topic: When AI Becomes the Requestor: Managing the New Wave of AI-Generated Data Subject Requests A dive into the influx of AI-generated data subject rights requests, and how to tackle them. | Tim Turner Data Protection Consultant, 2040 Training |
| 09:50- 10:20 | Panel discussion – details to be announced | To be announced |
| 10:25- 10:45 | Fireside chat – details to be announced | To be announced |
| 10:45- 11:15 | Coffee Break Recharge with coffee and take the opportunity to network with fellow attendees. Don’t miss the opportunity to speak with our sponsors and exhibitors, whose contributions are essential to making NPA what it is. | You |
| 11:15- 11:45 | Keynote – details to be announced | To be announced |
| 11:50- 12:05 | Keynote – details to be announced | To be announced |
| 12:10- 12:40 | Fireside chat – details to be announced | To be announced |
| 12:40- 13:40 | Lunch Break Enjoy a delicious lunch while engaging your fellow attendees in exciting discussions! During the lunch, Team Rynkeby will briefly speak about its work. The Swedish Data Protection Forum is a proud sponsor of Team Rynkeby and its contribution to the Swedish Childhood Cancer Fund. | You Team Rynkeby |
| Block 4 – Enabling IT | ||
| 13:40- 14:00 | Keynote: Demystifying the EU AI Act: Translating Legal Requirements Into Business Reality This presentation examines the EU AI Act as a practical framework for enabling effective AI governance within organisations. The session explores how companies can map and classify their AI systems, assess risk levels, and navigate role-specific responsibilities across the AI value chain. It also looks at how transparency requirements can be embedded into system design, how risk and incident registers strengthen oversight and accountability, and how privacy and data protection can be integrated into AI decision-making – helping organisations build trustworthy, compliant AI systems that support innovation while protecting individuals. | Petruta Pirvan Founder, EU Digital Partners AI Governance Specialist, E.ON |
| 14:05- 14:25 | Keynote: Privacy Professionals as Forerunners of Change – How Do We Become Pioneers in the Rapidly Changing Digital Environment? This session explores how privacy professionals can become effective leaders in an era of constant digital transformation. Gain an overview of the organisational changes driving the need for stronger change management, understand the principles behind leading change successfully, and take away practical tips for influencing stakeholders, embedding privacy into business transformation, and positioning privacy as a catalyst for innovation rather than simply a compliance function. | Oona Matinpalo Data Protection Officer, Sanoma Media Finland |
| 14:30- 15:00 | Panel discussion: IT vs US Technology teams want to innovate. Organisations want to grow. Data protection teams have an important role to play. So why do tensions sometimes arise? Join our panel as we examine perceptions, challenge accepted wisdom and explore how organisations can turn competing demands into shared success. | ➢ Moderator: Liz Smith Senior Consultant and Public Affairs Manager, DataGuard ➢ Anna Badaeva Data Protection Officer, Tonybet ➢ Viktorya Martirosyan Data Protection Specialist, Interpol ➢ Lucie Škopková Senior Privacy Analyst, Informa |
| 15:00- 15:20 | Coffee Break Recharge with coffee and take the opportunity to follow up on the afternoon discussions. Don’t miss the opportunity to speak with our sponsors and exhibitors, whose contributions are essential to making NPA what it is. | You |
| 15:20- 15:40 | Keynote: Marit Hansen Topic and details to be announced. At the time of the conference, Marit Hansen will have just completed her final term as State Data Protection Commissioner of Schleswig-Holstein. | Marit Hansen State Data Protection Commissioner, Schleswig-Holstein |
| 15:45- 16:05 | Keynote: Privacy by Automation: How IT Enables Effective Retention and Deletion Programs This session explores how IT can enable effective retention and deletion programs through process automation and governance. It will examine how organisations can transform retention and deletion from policy documents into repeatable, scalable business processes, while addressing common implementation challenges and organisational barriers. Drawing on practical experience, the session highlights how automation can strengthen privacy compliance, operational efficiency, and information governance. | Majekodunmi Abayomi Privacy Counsel, Uniper |
| 16:10- 16:30 | Keynote: The Hardest Privacy Problems Aren’t Legal: Seven Lessons from Running Privacy at Scale This keynote draws on real-world experience of building and operating privacy capabilities in a large organisation. Through seven practical lessons, the session explores how to make sound privacy decisions without creating bottlenecks, remain accountable in an environment shaped by AI, vendors, and distributed decision-making, and design governance and organisational structures that enable privacy to scale across countries, technologies, and business units. | Heidi Mäkelä Vice President & Head of Legal Technology, Telia |
| 16:35- 16:45 | Closing Remarks by the Chair of the Swedish Data Protection Forum We close our two fully packed conference days with some reflections on our many exciting keynotes, panels and discussions. | Caroline Olstedt Carlström Chair, Swedish Data Protection Forum Partner and Head of Data, Privacy and Information Security, Cirio Law Firm |

Some of the topics which will be discussed at NPA 2026…
AI Transcription in Healthcare
Data Subject Access Requests
Digital Sovereignty
Emerging Cybersecurity Threats
Privacy Professionals as Pioneers of Change
Public Sector Views on the Cloud
Supervisory Authority Agendas
Some of our distinguished contributors at NPA 2026
Besides our phenomenal conference attendees, the following people will contribute to Nordic Privacy Arena 2026, whether as speakers, panel discussion members or moderators.

Anna Badaeva
Group Data Protection Officer/Security Expert
Tonybet
LinkedIn
Anna Berlee
Professor of Data Protection and Privacy Law
Open University
LinkedIn
Arman Borghem
Regulatory and Compliance Advisor
Cleura
LinkedIn
Astor Nummelin Carlberg
Director Open Source Sovereignty
SUSE
LinkedIn
Björn Lundell (Ph.D.)
Professor of Computer Science
University of Skövde
LinkedIn
Caroline Olstedt Carlström
Chair Swedish Data Protection Forum
Partner, Cirio Law Firm
LinkedIn
David Törngren
Director of Legal Affairs
Swedish Authority for Privacy Protection (IMY)
LinkedIn
Dijana Šinkūnienė
Director
Lithuanian State Data Protection Inspectorate
LinkedIn
Eric Leijonram
Director General
Swedish Authority for Privacy Protection (IMY)
LinkedIn
Erik Enocksson
IT Security Coordinator
eSamverkansprogrammet
LinkedIn
Heidi Mäkelä
Vice President & Head of Legal Technology
Telia
LinkedIn
Joakim Söderberg
Data Protection Lawyer
noyb
LinkedIn
Karl-Fredrik Björklund
Partner
Hellström Advokatbyrå KB
LinkedIn
Liz Smith
Senior Consultant and Public Affairs Manager
DataGuard
LinkedIn
Lucie Škopková
Senior Privacy Analyst
Informa
LinkedIn
Majekodunmi Abayomi
Privacy Counsel
Uniper
LinkedIn
Manólis Nymark
Chief Executive & Consultant
Manolis Nymark Consulting
LinkedIn
Marit Hansen
State Data Protection Commissioner
Land Schleswig-Holstein
LinkedIn
Max Schrems
Founder of noyb, lawyer and author
noyb
LinkedIn
Michael Bahar
Global Co-Lead of Cybersecurity and Data Privacy Practice
Eversheds Sutherland
LinkedIn
Milla Keller
Head of Tech & Regulatory Legal
Terveystalo
LinkedIn
Nick Leppänen Larsson
Technical Product Owner
PostNord
LinkedIn
Onur Korucu
Non-Executive Director
DataRep
LinkedIn
Oona Matinpalo
Data Protection Officer
Sanoma Media Finland
LinkedIn
Petruta Pirvan
AI Governance Specialist
E.ON
LinkedIn
Pille Lehis
Director General
Estonian Data Protection Inspectorate
LinkedIn
Tim Turner
Data Protection Consultant
2040 Training
LinkedIn
Trevor Hughes
President / CEO
IAPP
LinkedIn
Viktorya Martirosyan
Data Protection Specialist
INTERPOL
LinkedIn
Please note that we reserve the right to make changes to the programme and participating speakers at any time without prior notice.
Sponsors
We extend our sincerest gratitude to our esteemed sponsors for their generous support. We also want to express that we remain open to further sponsorships and can be reached at info@dpforum.se.







