
Conference Programme
Nordic Privacy Arena 2026
Conference Programme and Speakers at Nordic Privacy Arena 2026
Read more about Nordic Privacy Arena 2026 and get your NPA 2026 tickets here!
This year’s conference theme is Innovation and Compliance in the Era of Cloud, AI and Geopolitical Uncertainty – Because Accountability Can’t Be Outsourced. We have two fully packed days ahead of us and couldn’t be more excited about this year’s NPA!
Agenda
Day 1: Monday 28 September 2026
Day 2: Tuesday 29 September 2026
Gallery of speakers and contributors
Day 1: Monday 28 September 2026
Monday’s Chatmaster:
Karl-Fredrik Björklund, Deputy Chair, Swedish Data Protection Forum and Partner, Hellström Advokatbyrå
| Time | Session | Speaker |
|---|---|---|
| 08:00- 08:55 | Networking Breakfast Start the conference with coffee, breakfast, and conversations with fellow participants from across the privacy community. Before the NPA 2026 begins, take the opportunity to catch up with colleagues, meet new faces, and exchange views on the developments, challenges, and practical realities of privacy work. This is a relaxed setting to begin the day and the discussions that will continue throughout the conference. | You |
| 09:00- 09:15 | Opening NPA 2026 – Day 1 NPA 2026 opens with a welcome and an introduction to this year’s theme: Innovation and Compliance in the Era of Cloud, AI and Geopolitical Uncertainty – Because Accountability Can’t Be Outsourced. Over the next two days, we will look at how organisations are dealing with rapid technological change, evolving regulation and increasing geopolitical uncertainty – and what it takes to remain accountable in practice. | Caroline Olstedt Carlström Chair, Swedish Data Protection Forum, and Partner and Head of Data, Privacy and Information Security, Cirio Law Firm |
| 09:20- 09:45 | Keynote: Data Protection Today – Reflections and Priorities from the Swedish Authority for Privacy Protection (IMY) What are the key issues currently on the agenda of the Swedish Data Protection Authority? In this keynote, Director General Eric Leijonram shares reflections on developments in privacy and data protection, as well as the priorities and challenges facing the authority. The session provides an opportunity to hear directly from IMY about current regulatory developments, supervisory activities and other matters receiving increased attention from the Swedish data protection authority. | Eric Leijonram Director General, Swedish Authority for Privacy Protection (IMY) |
| 09:50- 10:15 | Keynote: The Bridge on a Stranger’s Face – Accountability in the Age of Cloud, AI and Geopolitical Tension Discussions about data protection have always been discussions about power and control. Hence, data protection legislation places the accountability of data protection with the person who controls the processing of personal data. This works in simple constructs, but is stress-tested extensively in the age of cloud, AI and geopolitical tensions, where scalable processing does not seem to lead to scaling accountability as well. In this keynote we tackle this topic by taking smart glasses as our example and go back to the basics of data protection and core concepts such as the household exemption and controllership to ask ourselves: does accountability in data protection scale? | Anna Berlee Professor of Data Protection and Privacy Law at Open University (NL) & Chair of Dutch Privacy Association Vereniging Privacy Recht |
| 10:20- 10:45 | Panel discussion: Data Protection Authorities Challenges in the Current Geopolitical Climate This panel explores how data protection authorities face the challenges of the current geopolitical climate. Politicians across Europe are attempting to address numerous challenges, with measures to boost innovation, improve digital sovereignty, and give public authorities stronger tools for surveillance. What does this demand from today’s data protection authorities, and the role they play? | Arman Borghem (moderator) Regulatory and Compliance Advisor, Cleura Anna Hänninen Team Manager International Legal Matters, Finnish Office of the Data Protection Ombudsman Dijana Šinkūnienė Director, Lithuanian State Data Protection Inspectorate Marit Hansen State Data Protection Commissioner Land Schleswig-Holstein Pille Lehis Director General, Estonian Data Protection Inspectorate |
| 10:45- 11:15 | Coffee Break Recharge with coffee and take the opportunity to network with fellow attendees. Don’t miss the opportunity to speak with our sponsors and exhibitors, whose contributions are essential to making NPA what it is. | You |
| Block 1 – Digital Sovereignty | ||
| 11:15- 11:30 | Keynote: Swedish Government Agencies’ View on the Geopolitical Situation and Digital Sovereignty The Swedish public sector is feeling the pressure to innovate, while ensuring legal compliance and an appropriate use of digital solutions. Different government agencies have chosen different paths, based on different assessments. eSamverkansprogrammet (eSam) is an initiative of 40+ Swedish government agencies pooling resources to solve digitalisation challenges. What has been achieved to improve competition and access to sovereign digital solutions, for example in the area of interoperability? We may also get a glimpse of what the private sector can learn from how the public sector works together. | Erik Enocksson Security Coordinator, eSam |
| 11:35- 11:55 | Keynote: Geopolitical Challenges for Data Protection Authorities On the one hand, there is increasing pressure from the EU to take on more responsibilities, as many of the new EU legislative acts assign additional tasks to DPAs. On the other hand, countries such as Estonia also have to address pressing national priorities: national security, inflation, rising energy costs and, increasingly, higher defence spending. The question, then, is how we can maintain strong and effective data protection supervision while resources and political attention are being pulled in so many different directions. How do we solve this equation with so many unknowns? | Pille Lehis Director General, Estonian Data Protection Inspectorate |
| 12:00- 12:25 | Panel discussion: How Does Europe Meet the Moment? How do European customers and tech providers meet the moment? How can customer organisations work together to find solutions that meet their needs? What changes in purchasing behaviour has a European tech provider noticed, and what can customers achieve without relying on US clouds? How should European organisations think about the risks and opportunities – whether in the realm of cybersecurity, innovation, vendor lock-in, or digital sovereignty? | Onur Korucu (moderator) Non-Executive Director, DataRep Erik Enocksson Security Coordinator, eSam Astor Nummelin Carlberg Director Open Source Sovereignty, SUSE Michael Bahar Partner and Co-Lead of Global Cybersecurity and Data Privacy, Eversheds Sutherland Marit Hansen State Data Protection Commissioner Land Schleswig-Holstein |
| 12:30- 12:50 | Keynote: A US view on Recent History How do US politicians and businesses view what is happening in Europe at the moment, particularly the push for digital sovereignty? Looking back a decade, what are the developments in the United States from then until now, and how do the three branches of government view the rule of law? This keynote gives a US perspective on how European organisations should think about their reliance on US tech providers. | Michael Bahar Partner and Co-Lead of Global Cybersecurity and Data Privacy, Eversheds Sutherland |
| 12:50- 13:50 | Lunch Break Enjoy a delicious lunch while engaging your fellow attendees in exciting discussions! | You |
| Block 2 – Procurement | ||
| 13:50- 14:15 | Keynote: No Competition, No Compliance: How Procurement Practices Decide Your Data Protection Outcomes No one sets out to procure unlawful processing. We get it anyway, because we write requirements that only one supplier can meet. This keynote addresses unsuitable and anti-competitive procurement practices that cause inappropriate data processing. Drawing on research from the University of Skövde, it specifically elaborates on how Sweden’s first Cloud Policy and the EU’s Cloud Sovereignty Framework can (and will) improve current practices and impact opportunities for managing risks. | Björn Lundell (Ph.D.) Professor of Computer Science, University of Skövde |
| 14:20- 14:50 | Fireside chat: Use of AI transcription in Healthcare There are high expectations that AI will innovate and solve the future challenges of healthcare. A current technique is Ambient scribes which transcribes conversations and uses generative AI to facilitate medical record documentation. At the same time, the new technique requires more individual data than before to be processed by AI and large language models (LMMs). This panel discusses where we stand today – what are our challenges and dilemmas? | Jukka Lång (moderator) Partner and Head of Innovation Powerhouse, Dittmar & Indrenius Milla Keller Head of Tech & Regulatory Legal, Terveystalo Manólis Nymark Chief Executive, Manólis Nymark Consulting Kathinka Theodore Aakenes Vik Senior Advisor at Section for investigations, analysis and politics, Norwegian Datatilsynet Michael Hopp Partner & Attorney-at-Law, Hopp & Partners, Copenhagen Lars Lindsköld President, European Federation for Medical Informatics |
| 14:55- 15:20 | Keynote: Cooperation between the DPAs and within the EDPB – for the benefit of controllers and processors while upholding individuals’ fundamental rights. The session provides an opportunity to hear about the cooperation between the DPAs in general and within the EDPB. Anna Hänninen, Head of the EU and International Affairs Team at the Finnish DPA, the Data Protection Ombudsman, will talk about the development of cooperation between the DPAs and the EDPB, and highlight some of the key areas currently shaping their work. She will for example touch on the Helsinki Statement, which outlines new initiatives within the EDPB to make GDPR compliance easier, in particular for micro, small and medium-sized organisations, to strengthen consistency and boost cross-regulatory cooperation. She will provide a broader perspective on how cooperation between the DPAs and the EDPB supports organisations in navigating the evolving regulatory landscape and meeting their data protection obligations. | Anna Hänninen Team Manager International Legal Matters, Finnish Office of the Data Protection Ombudsman |
| 15:20- 15:50 | Coffee Break Recharge with coffee and take the opportunity to follow up on the afternoon discussions. Don’t miss the opportunity to speak with our sponsors and exhibitors, whose contributions are essential to making NPA what it is. | You |
| 15:50- 16:30 | Keynote: Trust and Safety in Technology – A Powerful History The speed of technological innovation challenges many facets of society. Policy makers and enforcement agencies scramble to understand the application of existing law while simultaneously struggling to predict future harms. Organisations, fearful of missing the growth and promise of emerging tech, move quickly to adopt, while often not fully assessing risk. Data protection professionals are caught in the middle of these forces. And too often, their work is characterised as friction – something that slows down progress. This session will argue that nothing could be further from the truth. Through historical analogy, we can see that trust and technological innovation are not only symbiotic – they are also essential to each other. | Trevor Hughes President, International Association of Privacy Professionals (IAPP) |
| 16:35- 17:05 | Keynote: Max Schrems Max Schrems provides the latest exciting updates from noyb – what’s on the agenda, which cases are cooking, and what’s ahead? | Max Schrems Founder, noyb |
| 17:10- 17:30 | Keynote: GDPR Roles in AI Fine-Tuning – Lessons from IMY’s Innovation Sandbox All privacy work starts with defining the GDPR roles and responsibilities. AI products and services can be structured and delivered in several ways. Introducing, adapting, and developing AI applications puts these fundamental questions into new perspectives. What are the implications if a supplier uses a pre-trained AI model and fine-tunes it— as part of its own product development, on behalf of a specific customer, or within the framework of a joint development effort with the customer? In this session, the Swedish Authority for Privacy Protection (IMY) will share lessons from a recent Innovation sandbox on GDPR roles in AI fine-tuning— to provide you with practical insights and guidance when implementing the roles and responsibilities within innovation projects. | David Suh Legal Counsel at IMY’s Innovation Hub, Swedish Authority for Privacy Protection (IMY) |
| 17:30 | Closing Remarks for Day 1 A brief wrap-up of Day 1 and a look ahead at Day 2. You will also be invited to our informal afterwork mingle. | Caroline Olstedt Carlström Chair, Swedish Data Protection Forum, and Partner and Head of Data, Privacy and Information Security, Cirio Law Firm |
| 17:30- 20:00 | Afterwork mingle, sponsored by filerskeepers Join fellow attendees for an informal afterwork mingle as we celebrate the first day of NPA and all the great speakers who have shared their insights throughout the day. Unwind with drinks and snacks, continue the conversations in a relaxed setting and connect with fellow attendees, speakers and sponsors. The mingle is sponsored by filerkeepers, who will welcome everyone to the evening. Don’t miss the chance to celebrate a great first day of NPA together! | You filerskeepers |
Day 2: Tuesday 29 September 2026
Tuesday’s Chatmaster:
Karl-Fredrik Björklund, Deputy Chair, Swedish Data Protection Forum and Partner, Hellström Advokatbyrå
| Time | Session | Speaker |
|---|---|---|
| 07:30- 08:55 | THE INCIDENT ROOM: An interactive ransomware simulation It’s Tuesday morning. Your systems are down. Employees cannot access critical files. Operations are grinding to a halt. Then the message appears: “Your data has been encrypted. We have stolen your information. Pay the ransom.” The clock is ticking. Who do you call? What do you shut down? Do you involve law enforcement? Do you contact the attackers? And what happens when they threaten to publish the data? This time, the decisions are yours. On Day 2 of NPA 2026, Magnus Jelen, Director of Incident Response EMEA at Coveware, will take us into the heart of a developing cyber-extortion crisis. With more than 15 years’ experience in security, law enforcement and intelligence operations, and as a trained hostage negotiator, Magnus has spent years navigating situations where the stakes are high, information is incomplete and every decision can have consequences. Through live polls, the audience will determine how the situation unfolds. At critical moments, they will be asked to make the call, and Magnus will respond to the outcome. Contain or continue? Escalate or stay quiet? Engage or refuse? Negotiate or walk away? There is no predetermined outcome. Drawing on Coveware’s first-hand experience supporting organisations through cyber-extortion incidents around the world, Magnus will bring the realities of crisis response into the room, including the difficult decisions, competing priorities and unexpected turns that emerge when an organisation is under pressure. You are not watching from the outside. You are in the incident room, and the next move is yours. | Magnus Jelen Lead Director of Incident Response EMEA, Coveware |
| 09:00- 09:10 | Welcome to Day 2 of NPA 2026 Get ready for day 2 as we look at how organisations are dealing with rapid technological change, evolving regulation and increasing geopolitical uncertainty – and what it takes to remain accountable in practice. | Caroline Olstedt Carlström Chair, Swedish Data Protection Forum Partner and Head of Data, Privacy and Information Security, Cirio Law Firm |
| Block 3 – Product Development and DS(A)Rs | ||
| 09:15- 09:45 | Keynote: When AI Becomes the Requestor: Managing the New Wave of AI-Generated Data Subject Requests A dive into the influx of AI-generated data subject rights requests, and how to tackle them. | Tim Turner Data Protection Consultant, 2040 Training |
| 09:50- 10:20 | Panel discussion regarding DSARs More detailed description coming soon. | Tim Turner (moderator) Data Protection Consultant, 2040 Training Ängla Pändel Senior Associate tech, data protection and compliance, Mannheimer Swartling Advokatbyrå Nils G. Indahl Data Protection Officer, Church of Norway Riim Bchara Privacy Counsel, SEB |
| 10:25- 10:45 | Fireside chat: From Privacy Strategy to Product Reality How does privacy actually work inside one of the world’s leading technology companies? In this fireside chat, we take a look behind the scenes of Ericsson’s privacy organisation, how it is structured, how responsibilities are divided, and how privacy is embedded across the business. Joining us on stage will be representatives from Ericsson’s Global Privacy Office as well as Product Privacy Office, offering perspectives from both the broader privacy function and the teams working directly with privacy by design in customer-facing products. We will start by exploring how Ericsson has organised its privacy functions and the fundamental elements underpinning its privacy programme. From there, we move from strategy to practice, looking at how privacy considerations are translated into real products and business decisions. Using real-life examples, our speakers will share how they approach product privacy in practice, the challenges they encounter, and what it takes to turn privacy principles into something that works in the real world. | Helena Eriksvik Chief Privacy Officer, Ericsson Cathrine Abadji Head of Privacy Program Governance, Ericsson Heidi Wahl Senior Privacy Manager, Product Privacy Office, Ericsson |
| 10:45- 11:15 | Coffee Break Recharge with coffee and take the opportunity to network with fellow attendees. Don’t miss the opportunity to speak with our sponsors and exhibitors, whose contributions are essential to making NPA what it is. | You |
| 11:15- 11:45 | Fireside chat: C-199/24, Lexbase judgement: a Swedish David vs Goliath case at the highest EU Court (Chapter 2) The Swedish principles of transparency and the European fundamental right to privacy have clashed. Goled Raabi, also known as GDPRWarrior, has taken on both Lexbase and the Swedish state before the European Court of Justice. This is a David vs Goliath case where one person is fighting a battle against the Swedish legal system which allows companies to sell personal data of millions of Swedes, including criminal records, without restrictions by GDPR. On July 9, 2026, Goled won the case in the Court of Justice of the European Union (CJEU). Joakim Söderberg will give us a legal background of the case and what effect the judgement will have in the future. Thereafter Joakim will have a discussion with Goled about his journey and what the judgement will mean for all people in Goled’s situation. | Joakim Söderberg Privacy Advisor, Secify Goled Raabi GDPRWarrior is the plaintiff in EU case C-199/24 against Lexbase and the Swedish state |
| 11:50- 12:10 | How Do We Interpret Criminal Offences in the GDPR? The processing of data on criminal offences is becoming increasingly important, in relation to inter alia background checks and anti-money laundering. However, there is a lack of harmonisation as regards the interpretation of Article 10 which provides enhanced protection for such data. To reach harmonisation, the Swedish Authority for Privacy Protection (IMY) has raised this issue in the EDPB. IMY has also looked into how national legislation could be designed in view of the evolving need to process data on criminal offences. | David Törngren Head of Department for Legal Services, Swedish Authority for Privacy Protection (IMY) |
| 12:15- 12:40 | Keynote: Criminal-Offence Data: Balancing Protection and Legitimate Use The processing of personal data relating to criminal convictions and offences is becoming increasingly relevant across both the public and private sectors. While Article 10 GDPR requires specific legal safeguards, national legislation plays a crucial role in balancing legitimate use with the protection of individuals’ rights. This keynote will explore how Lithuanian legislation and guidance issued by the Lithuanian State Data Protection Inspectorate address these challenges in the employment context and demonstrate how national legislation can provide practical safeguards while enabling legitimate processing of criminal-offence data. | Dijana Šinkūnienė Director, Lithuanian State Data Protection Inspectorate |
| 12:40- 13:40 | Lunch Break Enjoy a delicious lunch while engaging your fellow attendees in exciting discussions! During the lunch, Team Rynkeby will briefly speak about its work. The Swedish Data Protection Forum is a proud sponsor of Team Rynkeby and its contribution to the Swedish Childhood Cancer Fund. | You Team Rynkeby |
| Block 4 – Enabling IT | ||
| 13:40- 14:00 | Keynote: Demystifying the EU AI Act: Translating Legal Requirements Into Business Reality This presentation examines the EU AI Act as a practical framework for enabling effective AI governance within organisations. The session explores how companies can map and classify their AI systems, assess risk levels, and navigate role-specific responsibilities across the AI value chain. It also looks at how transparency requirements can be embedded into system design, how risk and incident registers strengthen oversight and accountability, and how privacy and data protection can be integrated into AI decision-making – helping organisations build trustworthy, compliant AI systems that support innovation while protecting individuals. | Petruta Pirvan Founder, EU Digital Partners AI Governance Specialist, E.ON |
| 14:05- 14:25 | Keynote: Privacy Professionals as Forerunners of Change – How Do We Become Pioneers in the Rapidly Changing Digital Environment? This session explores how privacy professionals can become effective leaders in an era of constant digital transformation. Gain an overview of the organisational changes driving the need for stronger change management, understand the principles behind leading change successfully, and take away practical tips for influencing stakeholders, embedding privacy into business transformation, and positioning privacy as a catalyst for innovation rather than simply a compliance function. | Oona Matinpalo Data Protection Officer, Sanoma Media Finland |
| 14:30- 15:00 | Panel discussion: IT vs US Technology teams want to innovate. Organisations want to grow. Data protection teams have an important role to play. So why do tensions sometimes arise? Join our panel as we examine perceptions, challenge accepted wisdom and explore how organisations can turn competing demands into shared success. | Liz Smith (moderator) Senior Consultant and Public Affairs Manager, DataGuard Anna Badaeva Data Protection Officer, Tonybet Viktorya Martirosyan Data Protection Specialist, Interpol Lucie Škopková Senior Privacy Analyst, Informa |
| 15:00- 15:20 | Coffee Break Recharge with coffee and take the opportunity to follow up on the afternoon discussions. Don’t miss the opportunity to speak with our sponsors and exhibitors, whose contributions are essential to making NPA what it is. | You |
| 15:20- 15:40 | Keynote: Change Ahead – Finally, a Proper Foundation for Accountability: GDPR Meets the Cyber Resilience Act Boring. So boring! Not exactly pleasant bedtime reading, and certainly not something to wake you up in the morning. What are we talking about? Technical documentation. And the GDPR’s accountability principle. Hold on – is it really boring? For starters, accountability is absolutely crucial – a point emphasized by the CJEU. The goal is to ensure that processing of personal data proceeds as it should and that, ideally, nothing goes wrong. And if something does go wrong? That you react correctly right away to manage the risk for the data subjects and, also important, safeguard the company’s reputation. Accountability entails compliance documentation and more. Until now, this has been difficult because hardware and software were often, to a significant extent, ”black boxes” regarding data protection and security. But that is set to change. The Cyber Resilience Act is on the horizon, mandating ”security by design” across the supply chain. Technical documentation plays a major role in this. This provides a foundation which enables real accountability. And then, all of a sudden… accountability doesn’t have to be boring after all. At the time of the conference, Marit Hansen is finishing her final term as State Data Protection Commissioner of Schleswig-Holstein. | Marit Hansen State Data Protection Commissioner, Schleswig-Holstein |
| 15:45- 16:05 | Keynote: Privacy by Automation: How IT Enables Effective Retention and Deletion Programs This session explores how IT can enable effective retention and deletion programs through process automation and governance. It will examine how organisations can transform retention and deletion from policy documents into repeatable, scalable business processes, while addressing common implementation challenges and organisational barriers. Drawing on practical experience, the session highlights how automation can strengthen privacy compliance, operational efficiency, and information governance. | Majekodunmi Abayomi Privacy Counsel, Uniper |
| 16:10- 16:30 | Keynote: The Hardest Privacy Problems Aren’t Legal: Seven Lessons from Running Privacy at Scale This keynote draws on real-world experience of building and operating privacy capabilities in a large organisation. Through seven practical lessons, the session explores how to make sound privacy decisions without creating bottlenecks, remain accountable in an environment shaped by AI, vendors, and distributed decision-making, and design governance and organisational structures that enable privacy to scale across countries, technologies, and business units. | Heidi Mäkelä Vice President & Head of Legal Technology, Telia |
| 16:35 | Closing Remarks by the Chair of the Swedish Data Protection Forum We close our two fully packed conference days with some reflections on our many exciting keynotes, panels and discussions. | Caroline Olstedt Carlström Chair, Swedish Data Protection Forum Partner and Head of Data, Privacy and Information Security, Cirio Law Firm |
please note that we reserve the right to make changes to the program at any time without prior notice.

Some of the topics which will be discussed at NPA 2026:
AI Transcription in Healthcare
Data Subject Access Requests
Digital Sovereignty
Emerging Cybersecurity Threats
Practical Implementation of Privacy Programmes
Privacy Professionals as Pioneers of Change
Public Sector Views on the Cloud
Supervisory Authority Agendas
Tackling Innovation and Data Protection
Our distinguished contributors at NPA 2026
Whether as speakers, panel discussion members, hosts or moderators, the following people will contribute to Nordic Privacy Arena 2026, besides our phenomenal attendees.

Ängla Pändel
Senior Associate tech, data protection and compliance
Mannheimer Swartling Advokatbyrå
LinkedIn
Anna Badaeva
Group Data Protection Officer/Security Expert
Tonybet
LinkedIn
Anna Berlee
Professor of Data Protection and Privacy Law
Open University
LinkedIn
Anna Hänninen
Team Manager – International Legal Matters
Finnish Office of the Data Protection Ombudsman
LinkedIn
Arman Borghem
Regulatory and Compliance Advisor
Cleura
LinkedIn
Astor Nummelin Carlberg
Director Open Source Sovereignty
SUSE
LinkedIn
Björn Lundell (Ph.D.)
Professor of Computer Science
University of Skövde
LinkedIn
Caroline Olstedt Carlström
Chair Swedish Data Protection Forum
Partner, Cirio Law Firm
LinkedIn
Cathrine Abadji
Head of Privacy Program Governance
Ericsson
LinkedIn
David Suh
Legal Counsel at IMY’s Innovation Hub
Swedish Authority for Privacy Protection (IMY)
LinkedIn
David Törngren
Head of Department for Legal Services
Swedish Authority for Privacy Protection (IMY)
LinkedIn
Dijana Šinkūnienė
Director
Lithuanian State Data Protection Inspectorate
LinkedIn
Eric Leijonram
Director General
Swedish Authority for Privacy Protection (IMY)
LinkedIn
Erik Enocksson
Security Coordinator
eSamverkansprogrammet
LinkedIn
Goled Raabi
Cloud & Automation Engineer | GDPR & Digital Rights Advocate
LinkedIn
Heidi Mäkelä
Vice President & Head of Legal Technology
Telia
LinkedIn
Heidi Wahl
Senior Privacy Manager, Product Privacy Office
Ericsson
LinkedIn
Helena Eriksvik
Chief Privacy Officer
Ericsson
LinkedIn
J. Trevor Hughes
President / CEO
IAPP
LinkedIn
Joakim Söderberg
Privacy Advisor
Secify
LinkedIn
Jukka Lång
Partner and Head of Innovation Powerhouse
Dittmar & Indrenius
LinkedIn
Karl-Fredrik Björklund
Deputy Chair, Swedish Data Protection Forum
Partner, Hellström Advokatbyrå
LinkedIn
Kathinka Theodore Aakenes Vik
Senior Advisor at Section for investigations, analysis and politics
The Norwegian Data Protection Authority
LinkedIn
Lars Lindsköld
President
European Federation for Medical Informatics
LinkedIn
Liz Smith
Senior Consultant and Public Affairs Manager
DataGuard
LinkedIn
Lucie Škopková
Senior Privacy Analyst
Informa
LinkedIn
Magnus Jelen
Lead Director of Incident Response EMEA
Coveware
LinkedIn
Majekodunmi Abayomi
Privacy Counsel
Uniper
LinkedIn
Manólis Nymark
Chief Executive & Consultant
Manolis Nymark Consulting
LinkedIn
Marit Hansen
State Data Protection Commissioner
Land Schleswig-Holstein
LinkedIn
Max Schrems
Founder of noyb, lawyer and author
noyb
LinkedIn
Michael Bahar
Global Co-Lead of Cybersecurity and Data Privacy Practice
Eversheds Sutherland
LinkedIn
Michael Hopp
Partner, Attorney-at-Law
Hopp & Partners, Copenhagen
LinkedIn
Milla Keller
Head of Tech & Regulatory Legal
Terveystalo
LinkedIn
Nils G. Indahl
Data Protection Officer
Church of Norway
LinkedIn
Onur Korucu
Non-Executive Director
DataRep
LinkedIn
Oona Matinpalo
Data Protection Officer
Sanoma Media Finland
LinkedIn
Petruta Pirvan
AI Governance Specialist
E.ON
LinkedIn
Pille Lehis
Director General
Estonian Data Protection Inspectorate
LinkedIn
Riim Bchara
Privacy Counsel
SEB
LinkedIn
Tim Turner
Data Protection Consultant
2040 Training
LinkedIn
Viktorya Martirosyan
Data Protection Specialist
INTERPOL
LinkedIn
Sponsors
We extend our sincerest gratitude to our esteemed sponsors for their generous support. We also want to express that we remain open to further sponsorships and can be reached at info@dpforum.se.








