On 14 October 2025, the Brussels Privacy Hub (VUB) and the Future of Privacy Forum convened the ninth Brussels Privacy Symposium, gathering EU and international regulators, academics, civil society, and industry to examine whether Europe is heading toward a data-protection (r)evolution. Opening remarks from Dr Gabriela Zanfir-Fortuna and Prof. Sophie Stalla-Bourdillon framed the day around two forces reshaping the digital rulebook: the European Commission’s drive for regulatory simplification and the competitiveness agenda in the age of AI.
In the opening keynote, Ana Gallego (Director-General, DG JUST) set out the policy context for the Commission’s work, followed by a fireside exchange with Dr Zanfir-Fortuna on the centrality of data protection in the broader acquis.
Panel I then made an overall assessment of the GDPR’s role as a cornerstone of EU digital regulation while probing where friction has emerged with newer instruments. The speakers, Itxaso Domínguez de Olazábal (EDRi), Olivier Micol (DG JUST), Stephan Geering (Trustworthy AI, Anthology), Prof. Gloria González Fuster (LSTS, VUB), moderated by Bianca-Ioana Marcu (FPF), reflected on calls and proposals to “re-open” the GDPR and evaluated its achievements to date.
After a short break, a lightning talk by Isabel Barberá (Dutch DPA/DCA) focused on LLM-based systems, arguing for an iterative lifecycle approach to risk management to address model- and system-level harms that escape one-off testing. Panel II turned to the GDPR–AI Act interface: the legal basis for training (including for GPAI), the use of special-category data for bias detection and correction, and the limits of anonymisation and technical/policy controls as universal solutions. The discussion was moderated by Prof. Sophie Stalla-Bourdillon with the panelists Lorelien Hoet (Microsoft), Prof. Theodore Christakis (Université Grenoble Alpes), Laura Lázaro Cabrera (CDT), and Rafaela Nicolazzi (OpenAI) surfaced emerging practice while underscoring areas where converging guidance and harmonisation remain necessary.
Following a lunch break, participants moved into three practitioner workshops: on explanation rights across GDPR and the AI Act led by Prof. Gianclaudio Malgieri (Leiden University); on concrete, limited amendments that could improve GDPR operability led by Bárbara Lazarotto (BPH) and Pablo Trigo Kramcsák (BPH); and on “agentic” AI under the GDPR and AI Act led by Vincenzo Tiani (FPF) and Monika Tomczak-Gorlikowska (Prosus). The plenary report-back distilled actionable safeguards for explanation and meaningful human oversight that work in real deployments.
An honored guest talk by Prof. Norman Sadeh (Carnegie Mellon University) offered research-driven insights into privacy engineering and human-AI interaction, before a second lightning talk by Ylja Remmits (Algorithm Audit) mapped the grey zone between decision support and “solely automated” decisions and set out criteria for assessing meaningful human intervention in practice. Panel III, moderated by Dr. Gabriela Zanfir-Fortuna, placed Data Protection Authorities in the spotlight. Representatives of different DPAs, such as Sarah Artola (CNIL), Guido Scorza (Garante), Sven Stevenson (Dutch DPA, DCA), and Paul McDonagh-Forde (Irish DPA), reflected on guidance and enforcement trends in AI contexts and explored pathways for coordination that could deliver de facto harmonization without necessarily amending the GDPR.
The day closed with an “In Dialogue” session between EDPS Wojciech Wiewiórowski and Prof. Gianclaudio Malgieri, reflecting on supervisory cooperation and the future of the EU’s data-protection architecture, followed by closing remarks from Bianca-Ioana Marcu and Prof. Malgieri, and an informal reception. Across sessions, a consistent thread emerged: maintain and enforce GDPR fundamentals while addressing interplay through joint guidance and collaboration.
