Nordic Privacy Arena 2025

Conference Programme
Nordic Privacy Arena 2026

Conference Programme and Speakers at Nordic Privacy Arena 2026

Read more about Nordic Privacy Arena 2026 and get your NPA 2026 tickets here!

This year’s conference theme is Innovation and Compliance in the Era of Cloud, AI and Geopolitical Uncertainty – Because Accountability Can’t Be Outsourced.

Agenda

Day 1: Monday 28 September 2026
Day 2: Tuesday 29 September 2026

This is an excerpt from the programme of Nordic Privacy Arena 2026 – more additions will follow! Please check back regularly, and please note that we reserve the right to make changes to the program at any time without prior notice.

Day 1: Monday 28 September 2026

TimeSessionSpeaker
08:00-
08:55
Networking Breakfast

Start the conference with coffee, breakfast, and conversations with fellow participants from across the privacy community. Before the NPA 2026 begins, take the opportunity to catch up with colleagues, meet new faces, and exchange views on the developments, challenges, and practical realities of privacy work. This is a relaxed setting to begin the day and the discussions that will continue throughout the conference.
You
09:00-
09:15
Opening NPA 2026 – Day 1

NPA 2026 opens with a welcome and an introduction to this year’s theme: Innovation and Compliance in the Era of Cloud, AI and Geopolitical Uncertainty – Because Accountability Can’t Be Outsourced.

Over the next two days, we will look at how organisations are dealing with rapid technological change, evolving regulation and increasing geopolitical uncertainty – and what it takes to remain accountable in practice.
Caroline Olstedt Carlström
Chair, Swedish Data Protection Forum, and Partner and Head of Data, Privacy and Information Security, Cirio Law Firm
09:20-
09:45
Keynote: Insights from the Swedish Authority for Privacy Protection (IMY)

What are the key issues currently on the agenda of the Swedish Data Protection Authority? In this keynote, Director General Eric Leijonram shares reflections on developments in privacy and data protection, as well as the priorities and challenges facing the authority.

The session provides an opportunity to hear directly from IMY about current regulatory developments, supervisory activities and other matters receiving increased attention from the Swedish data protection authority.
Eric Leijonram
Director General, Swedish Authority for Privacy Protection (IMY)
09:50-
10:15
Keynote: Topic to be announcedAnna Berlee
Professor of Data Protection and Privacy Law at Open University (NL) & Chair of Dutch Privacy Association Vereniging Privacy Recht
10:20-
10:45
Panel discussion: Data Protection Authorities

This panel will explore how data protection authorities face challenges in the current geopolitical climate.
➢ Moderator: Arman Borghem
Regulatory and Compliance Advisor, Cleura
Data Protection Authorities to be announced
10:45-
11:15
Coffee Break

Recharge with coffee and take the opportunity to network with fellow attendees. Don’t miss the opportunity to speak with our sponsors and exhibitors, whose contributions are essential to making NPA what it is.
You
Block 1 – Digital Sovereignty
11:15-
11:30

Keynote: Swedish Government Agencies’ View on the Geopolitical Situation and Digital Sovereignty

The Swedish public sector is feeling the pressure to innovate, while ensuring legal compliance and an appropriate use of digital solutions. Different government agencies have chosen different paths, based on different assessments. eSamverkansprogrammet (eSam) is an initiative of 40+ Swedish government agencies pooling resources to solve digitalisation challenges. What has been achieved to improve competition and access to sovereign digital solutions, for example in the area of interoperability? We may also get a glimpse of what the private sector can learn from how the public sector works together.
Erik Enocksson
eSam
11:35-
11:55
Panel discussion – details to be announcedTo be announced
12:00-
12:20
Panel discussion: How Does Europe Meet the Moment?

How do European customers and tech providers meet the moment? How can customer organisations work together to find solutions that meet their needs? What changes in purchasing behaviour has a European tech provider noticed, and what can customers achieve without relying on US clouds? How should European organisations think about the risks and opportunities – whether in the realm of cybersecurity, innovation, vendor lock-in, or digital sovereignty?
➢ Moderator: Onur Korucu
DataRep
Erik Enocksson
eSam
Astor Nummelin Carlberg
SUSE
Michael Bahar
Partner and Co-Lead of Global Cybersecurity and Data Privacy, Eversheds Sutherland

Additional participants may be announced
12:25-
12:45
Keynote: A US view on Recent History

How do US politicians and businesses view what is happening in Europe at the moment, particularly the push for digital sovereignty? Looking back a decade, what are the developments in the United States from then until now, and how do the three branches of government view the rule of law? This keynote gives a US perspective on how European organisations should think about their reliance on US tech providers.
Michael Bahar
Partner and Co-Lead of Global Cybersecurity and Data Privacy, Eversheds Sutherland
12:45-
13:45
Lunch Break

Enjoy a delicious lunch while engaging your fellow attendees in exciting discussions!
You
Block 2 – Procurement
13:45-
14:15
Keynote: No Competition, No Compliance: How Procurement Practices Decide Your Data Protection Outcomes

No one sets out to procure unlawful processing. We get it anyway, because we write requirements that only one supplier can meet. This keynote addresses unsuitable and anti-competitive procurement practices that cause inappropriate data processing. Drawing on research from the University of Skövde, it specifically elaborates on how Sweden’s first Cloud Policy and the EU’s Cloud Sovereignty Framework can (and will) improve current practices and impact opportunities for managing risks.
Björn Lundell (Ph.D.)
Professor of Computer Science, University of Skövde
14:20-
14:45
Fireside chat: Use of AI transcription in Healthcare

There are high expectations that AI will innovate and solve the future challenges of healthcare. A current technique is Ambient scribes which transcribes conversations and uses generative AI to facilitate medical record documentation. At the same time, the new technique requires more individual data than before to be processed by AI and large language models (LMMs). This panel discusses where we stand today – what are our challenges and dilemmas?
Milla Keller
Head of Tech & Regulatory Legal, Terveystalo
Manólis Nymark
Chief Executive, Manólis Nymark Consulting

Additional participants may be announced
14:50-
15:15
Keynote: How Do Apps Work?

An increasing number of organisations are providing their services through apps. Technical knowledge is key in understanding how apps work, but it also improves communication and cooperation with your stakeholder. This in turn enables accountability. So how do apps work? What are Software Development Kits (SDKs)? And how do developments relating to AI and supply chain affect the use and compliance apps? This session provides you with a technical deep-dive into apps, SDKs and developments ahead to help you ask the right questions.
Nick Leppänen Larsson
Technical Product Owner, Postnord
15:15-
15:45
Coffee Break

Recharge with coffee and take the opportunity to follow up on the afternoon discussions. Don’t miss the opportunity to speak with our sponsors and exhibitors, whose contributions are essential to making NPA what it is.
You
15:45-
16:25
Keynote: Trevor Hughes

Details to be announced.
Trevor Hughes
President, International Association of Privacy Professionals (IAPP)
16:30-
17:10
Keynote: Max Schrems

Max Schrems provides the latest exciting updates from noyb.
Max Schrems
Founder, noyb
17:15-
17:20
Closing Remarks for Day 1

A brief wrap-up of Day 1 and a look ahead at Day 2.
Caroline Olstedt Carlström
Chair, Swedish Data Protection Forum, and Partner and Head of Data, Privacy and Information Security, Cirio Law Firm
17:20-
20:00
After work

Join fellow attendees for an informal afterwork to unwind and continue the conversations in a more relaxed setting. Don’t miss the chance to talk to our esteemed sponsors that have helped make this year’s NPA possible.
You

Day 2: Tuesday 29 September 2026

TimeSessionSpeaker
07:30-
08:55
Morning Cybersecurity Workshop

Details to be announced
To be announced
09:00-
09:10
Welcome to Day 2 of NPA 2026

Get ready for day 2 as we look at how organisations are dealing with rapid technological change, evolving regulation and increasing geopolitical uncertainty – and what it takes to remain accountable in practice.
Caroline Olstedt Carlström
Chair, Swedish Data Protection Forum
Partner and Head of Data, Privacy and Information Security, Cirio Law Firm
Block 3 – Product Development and DS(A)Rs
09:15-
09:45
Keynote Topic: When AI Becomes the Requestor: Managing the New Wave of AI-Generated Data Subject Requests

A dive into the influx of AI-generated data subject rights requests, and how to tackle them.
Tim Turner
Data Protection Consultant, 2040 Training
09:50-
10:20
Panel discussion – details to be announcedTo be announced
10:25-
10:45
Fireside chat – details to be announcedTo be announced
10:45-
11:15
Coffee Break

Recharge with coffee and take the opportunity to network with fellow attendees. Don’t miss the opportunity to speak with our sponsors and exhibitors, whose contributions are essential to making NPA what it is.
You
11:15-
11:45
Keynote – details to be announcedTo be announced
11:50-
12:05
Keynote – details to be announcedTo be announced
12:10-
12:40
Fireside chat – details to be announcedTo be announced
12:40-
13:40
Lunch Break

Enjoy a delicious lunch while engaging your fellow attendees in exciting discussions!

During the lunch, Team Rynkeby will briefly speak about its work. The Swedish Data Protection Forum is a proud sponsor of Team Rynkeby and its contribution to the Swedish Childhood Cancer Fund.
You

Team Rynkeby
Block 4 – Enabling IT
13:40-
14:00
Keynote: Demystifying the EU AI Act: Translating Legal Requirements Into Business Reality

This presentation examines the EU AI Act as a practical framework for enabling effective AI governance within organisations. The session explores how companies can map and classify their AI systems, assess risk levels, and navigate role-specific responsibilities across the AI value chain. It also looks at how transparency requirements can be embedded into system design, how risk and incident registers strengthen oversight and accountability, and how privacy and data protection can be integrated into AI decision-making – helping organisations build trustworthy, compliant AI systems that support innovation while protecting individuals.
Petruta Pirvan
Founder, EU Digital Partners
AI Governance Specialist, E.ON
14:05-
14:25
Keynote: Privacy Professionals as Forerunners of Change – How Do We Become Pioneers in the Rapidly Changing Digital Environment?

This session explores how privacy professionals can become effective leaders in an era of constant digital transformation. Gain an overview of the organisational changes driving the need for stronger change management, understand the principles behind leading change successfully, and take away practical tips for influencing stakeholders, embedding privacy into business transformation, and positioning privacy as a catalyst for innovation rather than simply a compliance function.
Oona Matinpalo
Data Protection Officer, Sanoma Media Finland
14:30-
15:00
Panel discussion: IT vs US
Technology teams want to innovate. Organisations want to grow. Data protection teams have an important role to play. So why do tensions sometimes arise? Join our panel as we examine perceptions, challenge accepted wisdom and explore how organisations can turn competing demands into shared success.
➢ Moderator: Liz Smith
Senior Consultant and Public Affairs Manager, DataGuard
Anna Badaeva
Data Protection Officer, Tonybet
Viktorya Martirosyan
Data Protection Specialist, Interpol
Lucie Škopková Senior Privacy Analyst, Informa
15:00-
15:20
Coffee Break

Recharge with coffee and take the opportunity to follow up on the afternoon discussions. Don’t miss the opportunity to speak with our sponsors and exhibitors, whose contributions are essential to making NPA what it is.
You
15:20-
15:40
Keynote: Marit Hansen

Topic and details to be announced. At the time of the conference, Marit Hansen will have just completed her final term as State Data Protection Commissioner of Schleswig-Holstein.
Marit Hansen
State Data Protection Commissioner, Schleswig-Holstein
15:45-
16:05
Keynote: Privacy by Automation: How IT Enables Effective Retention and Deletion Programs

This session explores how IT can enable effective retention and deletion programs through process automation and governance. It will examine how organisations can transform retention and deletion from policy documents into repeatable, scalable business processes, while addressing common implementation challenges and organisational barriers. Drawing on practical experience, the session highlights how automation can strengthen privacy compliance, operational efficiency, and information governance.
Majekodunmi Abayomi
Privacy Counsel, Uniper
16:10-
16:30
Keynote: The Hardest Privacy Problems Aren’t Legal: Seven Lessons from Running Privacy at Scale

This keynote draws on real-world experience of building and operating privacy capabilities in a large organisation. Through seven practical lessons, the session explores how to make sound privacy decisions without creating bottlenecks, remain accountable in an environment shaped by AI, vendors, and distributed decision-making, and design governance and organisational structures that enable privacy to scale across countries, technologies, and business units.
Heidi Mäkelä
Vice President & Head of Legal Technology, Telia
16:35-
16:45
Closing Remarks by the Chair of the Swedish Data Protection Forum

We close our two fully packed conference days with some reflections on our many exciting keynotes, panels and discussions.
Caroline Olstedt Carlström
Chair, Swedish Data Protection Forum
Partner and Head of Data, Privacy and Information Security, Cirio Law Firm

Some of the topics which will be discussed at NPA 2026…

AI Transcription in Healthcare

Data Subject Access Requests

Digital Sovereignty

Emerging Cybersecurity Threats

Privacy Professionals as Pioneers of Change

Public Sector Views on the Cloud

Supervisory Authority Agendas

Some of our distinguished contributors at NPA 2026

Besides our phenomenal conference attendees, the following people will contribute to Nordic Privacy Arena 2026, whether as speakers, panel discussion members or moderators.

Please note that we reserve the right to make changes to the programme and participating speakers at any time without prior notice.

Sponsors

We extend our sincerest gratitude to our esteemed sponsors for their generous support. We also want to express that we remain open to further sponsorships and can be reached at info@dpforum.se.

Cirio
Hellström Advokatbyrå
Advisense
Harvest Advokatbyrå
GDPR Tech
Responsum