Summer Academy For Global Privacy Law 2026 Recap
Beyond the Omnibus: Legacy and Realignment in EU Digital Regulation
The 2026 edition of the Brussels Privacy Hub Summer Academy for Global Privacy Law, “Beyond the Omnibus”, is a wrap. Over five days at VUB, 22 sessions brought together participants from regulators, law firms, industry, and academia to take stock of EU data and AI regulation at a moment of simplification and geopolitical strain, and to ask what comes after the Omnibus.
From digital sovereignty to agentic AI, from the Data Act’s first year to comparative lessons from Brazil, Korea and the UK, the week combined keynotes, panels and hands-on workshops with the discussions in between that make the Academy what it is.
Day 1 Sovereignty and Supervision
Murielle Popa-Fabre (ENS) opened the week by charting Europe’s digital sovereignty and resilience, from the tech stack to your data. A panel with Sophie Stalla-Bourdillon, Hielke Hijmans, Bianca-Ioana Marcu (FPF), and Siún O’Keeffe (Dutch DPA) asked what remains to be done on AI-based processing against the backdrop of regulatory guidance, from getting controller and processor roles right to making DPIAs work in practice.
The afternoon belonged to AI agents. Rafael Galvez Vizcaino (KU Leuven) examined how to build privacy-respecting AI agents, before Pablo Trigo Kramcsák (VUB) and Vincenzo Tiani (VUB/FPF) closed the day asking what agentic AI processing means for data protection when systems no longer just answer, but act.
Day 2 Data Exchange and Transfers
Winnie Dongbou Wamba (Toulouse Capitole) opened Day 2 on health data reuse and sharing as the EHDS takes shape, before Nikolaos Theodorakis (WSGR) surveyed new developments in international data transfers.
After the break, a panel moderated by Barbara Lazarotto (VUB), with panelists Itxaso Domínguez (Edri), Stephanie Mihail (EDPB), and Maximilian von Grafenstein (Consenter), explored the legal frontiers in the governance of online information flows, where browsing data, ePrivacy, and digital sovereignty meet. The afternoon looked at data sharing by design. Andrés Chomczyk Penedo (BPH) traced the past, present, and future of the free flow of data in EU open finance. Simon Verschaeve and Heidi Waem (DLA Piper Belgium) then closed the day with a hands-on workshop taking stock of the Data Act, one year in.
Day 3 Safety, Competition and Cybersecurity in Data Markets
Day 3 asked what makes data markets trustworthy. Gianmarco Gori (VUB) opened with “AI Act 2.0”, tracing the Act’s evolution from a product-safety instrument to a fundamental-rights protection instrument. Innocenzo Genna then turned to competition in data markets and how the DMA reshapes who holds power over data. After the break, a panel moderated by Pablo Trigo Kramcsák (VUB), Mohammed Raiz Shaffique (Leiden Uni), Bernd Fiten (Cranium) and Corrado Giustozzi (Rexilience) examined the role of cybersecurity in strengthening data markets.
In the afternoon, Aleksandra Kuczerawy (KU Leuven) addressed online safety in the platform economy, before Mathias Hanson (VUB) closed the day with a workshop on making AI systems legible to law.
Day 4 A Day in the EU Institutions
Day 4 took the Academy out of the lecture hall and into the institutions shaping the rules. The morning began at the European Parliament, where Brando Benifei (MEP), co-rapporteur of the AI Act, discussed AI regulation in a new geopolitical era and what it takes to defend the European approach when the ground keeps shifting.
After lunch, the group headed to the European Commission AI Office, where Margherita Corrado and Joanna Jużak examined the AI Act at the crossroads of digital regulation and how the Office approaches its implementation. The institutional tour concluded with an Evening Tea at the EDPS, where Romain Robert invited participants to crack the regulatory puzzle from the supervisor’s perspective. The day and the conversations carried on over a networking reception with drinks and tapas, one of those informal moments when the Academy’s real exchanges happen.
Day 5 Lessons from Beyond the EU
The final day looked outward before looking back. Thiago Moraes (VUB) opened with recent developments in data protection and AI in Brazil, followed by Sunghyun Lee (KISA) on Korea, two jurisdictions whose choices increasingly speak back to the EU rather than merely following it. After the break, Andelka Phillips (Leicester Uni) asked whether the UK’s data and AI reforms amount to much ado about nothing.
Brendan Van Alsenoy (EDPS) then brought the week full circle with the closing keynote: EU data and AI regulation: what’s really been achieved? A fitting question to close an Academy that spent five days going beyond the Omnibus.
