Home
Library
Blog Post 

Ireland's Privacy, Security & Trust Forum recap: a full room, a strong community and a date in the diary every year

What's in this article

Key Takeaways

Introduction

On 17 September, more than 100 privacy, security and legal professionals joined us in Dublin for Ireland's Privacy, Security & Trust Forum. TrustWorks organised the day in collaboration with the Association of Data Protection Officers (ADPO) and William Fry, who also hosted us at their offices. Registrations filled up quickly, and we had to keep people on a waiting list.

The day opened with an update from the Data Protection Commission (DPC), delivered by Paul McDonagh-Forde. Over six sessions, 23 speakers then worked through the questions privacy teams are dealing with right now.

What we discussed

Digital Omnibus: what a new regulatory stack means for day-to-day compliance
Moderated by Boris Selak (Law Society of Ireland), with Jennifer Walsh (National Screening Service), Dora Endreffy (UPS) and James Kneale (The Bar of Ireland). The panel moved past the headlines to the practical question: what would the proposed changes actually mean for teams running compliance programmes today? The answer depends heavily on how obligations under GDPR, the AI Act and the wider digital rulebook end up fitting together, so it pays to map them across frameworks now.

DSARs in practice: managing growing volumes and complexity
Moderated by Dr Pádraig O'Leary (TrustWorks), with Maria Moraes (Premier Lotteries Ireland), Marcelo Canha (Organon) and Gillian Traynor (Ambit Compliance). The panel covered the everyday realities of access requests: scoping, redaction, deadlines, tooling and the pitfalls that catch teams out. The teams coping best are the ones who know where personal data lives before a request arrives, not the ones searching for it once the clock has started.

A brave new world of cybersecurity: incident response in the current landscape
Moderated by Rachel Hayes (William Fry), with Onur Korucu (DataRep), Eoin O'hEochaidh (Carne Group) and Eoin Fleming (Stealthy Squirrel). AI was part of this discussion too, as a new tool for defenders and a new route for attackers. When an incident hits, privacy and security teams share the same clock, the same evidence and often the same regulators, so they can't afford to work from separate pictures of risk.

Vendor and processor management: governing tools that act on their own
Moderated by Maeve Dunne (ADPO), with David Normoyle (Indeed), Adi Gilad (Stripe) and Kieran Harte (Central Statistics Office). One idea kept coming back throughout the panel. As David put it afterwards, the profession has spent years building privacy and AI governance "for tools that people use," but hasn't properly caught up with tools that act on their own. Third-party oversight was designed for software that waits for a human. It now has to account for vendors whose products make decisions and take actions independently.

Keynote: AI is changing everything
Dr Barry Scannell (William Fry) in conversation with Kate Colleary (Pembroke Privacy), followed by an interactive audience debate on AI, the GDPR and the EU AI Act. Several speakers said afterwards that this session set the bar for the day. AI literacy came up, as it always does, and it led to one of the day's most memorable exchanges (more below).

The future of privacy governance: where the function is heading
Moderated by Lisa Power (Carne Group), with Alyssa Cervantes (Dell), Dr Aleksandra Aytova (Applegreen) and Gonzalo Caro (Meta). The closing panel took on the big question of where the privacy function goes next, as its remit grows to take in AI, security and data strategy. It was thought-provoking and, by the panellists' own account, full of laughter. Maeve Dunne then closed the day with the key takeaways from every session.

An idea worth taking further: an AI driving licence

During the fireside chat's Q&A, Dr Barry Scannell reminded the room of the ECDL, the European Computer Driving Licence that a generation of Irish workers put on their CVs to show they could actually use a computer. Tom O'Sullivan, chief executive of the Irish Computer Society (ICS), which ran the ECDL in Ireland, then asked the obvious question: could something similar work for AI?

Barry has since argued that it should. He suggests a recognised, vendor-neutral qualification that tests whether someone can use AI well in practice. That would mean prompting effectively, checking outputs, protecting confidential information, understanding hallucinations and bias, knowing when a human needs to step in, and using AI agents safely within legal and ethical limits. Education initiatives like the Government's AIReady.ie are a strong start, but he points out that certification does a different job. It gives employers something tangible and gives people a portable credential that means something.

The foundations already exist. The ECDL Foundation was set up in Dublin in 1997, and today's ICDL already offers an AI Essentials module. With generative AI adoption in Ireland among the highest in the EU, it's the kind of idea that could start in Dublin and spread across Europe, just as the ECDL did.

‍

The best part is the people

Speakers and attendees said the same thing afterwards: the best part of the day was the community. Several of our speakers went straight from Dublin to IAPP's Data Protection Congress in Brussels and changed their flights so they could all travel together on the 6am departure. That says a lot about the privacy community in Ireland.

A sincere thank you to every speaker, moderator and attendee, to ADPO for their collaboration, and to William Fry for their collaboration and for hosting us so generously.

Save the date: the Forum is now an annual event

Ireland's Privacy, Security & Trust Forum will now take place every year. We'll announce the date for next year's edition soon. Subscribe to our newsletter o be the first to hear 👇

< More Stories You’ll Love >

Explore Additional Insights and Tips

No items found.
No items found.
No items found.
No items found.