25th Annual
Data Protection Compliance Conference
Workshop Topics
Workshops: Day 2 & Day 3
Thursday, 24th & Friday, 25th September 2026
Led by industry Experts, each Workshop is designed to be highly-practical and to explore a range of topics through interactive case-studies, scenarios and group activities.
Day 2 - Thursday, 24th September 2026
Day 3 - Friday, 25th September 2026
Workshops – Virtual (Teams) Sessions
Workshop Topics
Morning Workshops (Day 2 & Day 3) - Select one:
Workshop A
AI Adoption in Practice
Day 2: In-Person
Day 3: Virtual (Teams)
Workshop Overview:
AI tools are being adopted across organisations at pace, presenting practitioners with compliance challenges at every stage of the AI lifecycle. In this interactive practical Workshop, delegates work in groups through a realistic AI procurement and deployment, and will:
- consider how to identify and map AI-driven processing across an organisation, including unsanctioned use
- understand lawful basis and proportionality considerations from pilot to full deployment
- consider the contractual and supply chain issues arising from AI procurement
- work through a realistic compliance incident arising from the deployment
Workshop B
Cookies, Consent and (Marketing) Communications: What You Need To Know Post-DUAA
Day 2: In-Person
Day 3: Virtual (Teams)
Workshop Overview:
E-privacy law is evolving, while continuing to be an area of regulatory focus. Now more than ever, data protection practitioners need a clear, practical understanding of the Privacy and Electronic Communications Regulations and how those Regulations are changed by the Data (Use and Access) Act 2025. This Workshop explores the current legal framework and how it is being amended in 2026, through the use of real world case studies and war stories. The Workshop focuses specifically on:
- The current PECR regime for cookies, tracking technologies and electronic direct marketing, and where organisations most commonly fall short—from poorly configured consent banners to misalignment with the soft opt-in exemption
- What the Data (Use and Access) Act 2025 changes in practice, including new cookie consent exemptions and the expansion of the electronic mail soft opt-in regime to charities
- Practical compliance strategies, including consent management tools, dark pattern avoidance, and risk based decision making
- Enforcement trends, regulator expectations, and what’s next on the horizon, including the European Commission’s Digital Omnibus regulation proposal
Workshop C
Data Protection Contracts – Ensuring Compliance and Taking Advantage of Opportunities
Day 2: In-Person
Day 3: Virtual (Teams)
Workshop Overview:
There are many instances of personal data moving from one organisation to another, outsourcing and data sharing being two primary examples. Understanding how to negotiate data protection terms, as either a controller or processor, is now more important than ever, particularly in terms of opportunities that exist for maximising revenue and limiting internal expense. This Workshop analyses the practical issues which arise in contract negotiations, including:
- processor and sub-processor models
- provision of assistance by the processor, including recovery of costs
- international transfer permissions
- descriptions of data processing
- liability – including indemnities and liability caps
- data sharing and joint controller agreements – what to look for and what to include
Afternoon Workshops (Day 2 & Day 3) - Select one:
Workshop D
DSARs: Adapting searches and understanding redactions
Day 2: In-Person
Day 3: Virtual (Teams)
Workshop Overview:
Data Subject Access Requests can be incredibly resource intensive for organisations, and searching for information can be one of the biggest headaches. This practical session takes you through the legal requirements and guidance on searches, using real life examples to help identify search strategies from the outset of a request. Following this, delegates look at some of the most common DSAR exemptions, and how to redact material that falls within these. This workshop cover:
- What do the changes under the Data (Use and Access) Act 2025 mean in practice?
- How to identify a search strategy that meets legal requirements
- How to use sampling and other techniques for evidencing search decision
- Understanding, and applying, some of the most common exemptions
- Redaction v extraction – which to use and why
- How AI can help with DSARs
Workshop E
Geopolitics at play: Legitimising international data transfers in 2026
Day 2: In-Person
Day 3: Virtual (Teams)
Workshop Overview:
While international data transfers are essential for today’s digitally connected world, the rules governing such data transfers have never been more rigorously applied or more politically charged. This workshop identifies the direction of travel of policy makers and regulators in this area and provides practical recommendations to address this challenge. Delegates will learn:
- How to respond in practice to the growth of digital sovereignty
- What data transfers mechanisms may be more suitable to diverse use cases
- What level of risk may be acceptable for the purposes of a transfer impact assessment
- How to future-proof an international data transfers strategy
Workshop F
Cybersecurity & Data Breach Prevention, Detection & Notification in AI-Enabled Organisations
Day 2: In-Person
Day 3: Virtual (Teams)
Workshop Overview:
This Workshop examines the critical intersection of data security, cybersecurity and breach notification obligations under the UK GDPR. It also focuses on emerging challenges posed by AI systems, third-party vulnerabilities and evolving regulatory expectations from the ICO. The Workshop covers the following key topics:
- Article 32 security requirements and AI-specific risks
- Third-party and supply chain security
- Documentation and accountability obligations
- Breach response procedures and incident management
- Breach notification timelines and triggers
- Documentation and accountability obligations
- ICO enforcement trends
< Back to Conference Overview
FREE Data Protection Book
(RRP: £110 – Due to be published in
Autumn 2026)
Conference Contributors & Sponsors:
Testimonials
“Excellent!”
Simon Hall
IBM
“The updates on existing subjects were particularly useful.”
David Pickersgill
Johnson & Johnson
“The networking opportunities were very good. Very useful. Will attend again.”
John Pendleton
Old Mutual
“Very informative and well executed conference”
Claire Robson
Kent & Medway NHS Trust
“Speakers delivered good insights into various aspects of the GDPR”
Paul Woods
Government Legal Department
“The hotel facilities were excellent”
Andrew Dyke
Operation Mobilisation
“An interesting day packed with a plethora of useful materials. The conference never disappoints with the quality of speakers, providing insightful and pragmatic views and interpretations.”
Stephanie Allen
Shop Direct Group
“Very enjoyable day! Well worth attendance. Very good speakers.”
Sarah Rudge
OFQUAL
“All the sessions were informative and well presented. Very enjoyable!”
Fiona Cadger
Standard Life Aberdeen PLC
“Great conference with diverse topics”
Catherine Bowen-Walker
Close Brothers
“A very well put together and well run conference”
Helen Worthington
Jerrold Holdings
“This conference cannot be improved. Excellent!”
Caroline Mair
Registers of Scotland
“A very useful and well organised conference”
Alistair Browne
British Council
“Very useful, practical and thought provoking”
Ben Moreland
LV=
“I’m extremely impressed by the quality of speakers and content covered. An excellent balance of public and private sectors”
Julie Hinault
States of Jersey Taxes Office
“The mix of speakers meant that a lot of ground was covered effectively.”
Karen Russell
British Arab Commercial Bank
“As usual the Conference was very well organised”
Paul Byrne
British Airways
“Excellent”
Greg Steel
Confused.com
“The conference content was excellent and thought provoking”
Kim Walker
Royal Air Force
“A very helpful conference. Took away some good ideas.”
Lesley Richardson
Financial Conduct Authority
“I found all the presentations very useful. The discussion panel was excellent… thoroughly enjoyed this conference and would not hesitate on coming back”
Scott McFarlane
National Trust for Scotland
“Good variety of relevant topics discussed throughout the day. Speakers were engaging!”
Ellis Bryant
Saga Plc
“Great to see so many different sectors represented. Well organised!”
Jane Davy
University of Southampton
“Overall, an excellent, informative and useful day. Well worth attending”
Colin Cluney
Department of Finance and Personnel
“All fantastic”
Leslie Waghorn
Virgin Media
“Another excellent year – very current and topical”
Stuart Gittings
Eli Lilly and Co.
“A very useful conference, a good broad range of speakers that were able to give practical advice”
David Mayers
Lisburn City Council
“All topics very relevant – most particularly the bits about social networking and security breaches.”
Jackie Evans
South Wales Fire & Rescue
“Once again a great conference, which gives me plenty to think about and implement!”
Kevin Giles
Glasgow Housing Association
“Very useful conference”
Alan White
Pitney Bowes
“Excellent. A well run event.”
David Higginson
ING Direct
“Great venue, superbly organised, very professional.”
Julie Barclay
Gambro Lundia
“Another excellent conference.”
Lynn Young
British Library
“Excellent venue, delegate packs and catering. Very focussed, practical and relevant.”
Albert Chan
Greater London Authority