
Samantha Seaton
Co-Chair, Smart Data Council
This year’s Data Protection Conference focuses on privacy in the age of AI.
With a new Code of Practice on AI and automated decision-making (ADM) on the horizon, regulators are moving towards requiring greater transparency around the use of AI and automated decision-making.
The regulatory landscape is evolving rapidly. The ICO’s final guidance on ADM is expected this summer, followed by a statutory Code of Practice on AI and ADM later in 2026. The EU AI Act’s transparency obligations take effect in August 2026, with requirements for high-risk AI systems following in December 2027. At the same time, the Government’s Smart Data 2035 Strategy is reshaping data-sharing obligations across the economy.
We will explore what the new ADM guidance and Code of Practice will mean in practice, including data flow mapping, bias assessment, explainability, meaningful human oversight, third-party accountability, and individuals’ rights to challenge automated decisions and seek redress.
High-risk AI processing will almost certainly require a Data Protection Impact Assessment (DPIA) before deployment. The conference will provide practical guidance on what an effective AI Impact Assessment looks like, what it should cover, how to update your privacy notices, and how to conduct due diligence on third-party AI vendors.
We will also examine the ICO’s expectations for the responsible use of ADM in recruitment, including what constitutes meaningful human involvement and how organisations should protect candidate rights.
With a focus on responsible digital advertising, we will examine the ICO’s expanded framework for storage and access technologies, covering not only cookies but also pixels, scripts, tags and fingerprinting, and what this means for consent. We will also discuss potential changes to PECR consent requirements and the practical implications for online advertising.
With updated ICO guidance on children’s information now in force, we will share good practice on processing children’s personal data and adopting privacy-friendly approaches to age assurance.
As volumes of AI-generated DSARs, FOI requests and data protection complaints continue to rise, we will explore how organisations can manage responses at scale, where AI can support the process, and the circumstances in which requests may be refused.
Backed by ÂŁ36 million of government investment, the Smart Data Strategy aims to establish five or more active Smart Data schemes by 2030 and at least 20 by 2035. We will examine what participation means for priority sectors and the new data protection obligations organisations should prepare for.
Looking ahead to emerging technologies and the advent of agentic AI, existing governance models will need to evolve. We will consider how current AI standards and risk management frameworks apply, where gaps remain, and how organisations can prepare for the next generation of AI.
There is significant change ahead. Don’t miss this opportunity to network with peers, hear directly from regulators and experts, evaluate your organisation’s current risks and governance arrangements, and future-proof your approach to data protection.
Choose to attend in-person or online.
We will share updates and good practice guidance in the following areas:
Benefits of attending
Interested in sponsoring this event? Click here for sponsorship opportunities.
View all our conferences, events and training here.
Contact us for group rates.

Co-Chair, Smart Data Council

Senior Privacy Officer and Senior Legal and Compliance Counsel, Hexagon Autonomous Solutions

Privacy and Security- Data Protection and Sovereignty Process Manager, TikTok

Head of Group Privacy and UK Data Protection Officer, Admiral Group Plc

Head of Information Governance and Data Protection Officer , The Guinness Partnership

Professor of Law and Personal Chair, University of Exeter, Evaluator and External Expert for the European Commission

Director, Data Driven Legal

Chief Commissioner, Data and Marketing Commission

Data Privacy Manager , Oxfam
Hear best practices on utilising AI with compliance in areas including recruitment and children’s services.

Data Protection Officer, Arsenal Football Club

Privacy and Security- Data Protection and Sovereignty Process Manager, TikTok

Data Protection Manager, London Borough of Camden, FOI Team of the Year Award Winners

Head of Information Governance and Data Protection Officer , The Guinness Partnership
Data Driven Legal is a boutique legal practice specialising in data protection advice and AI governance. We years of experience working for large organisations and multinationals, from cruise lines to cloud storage providers.
Data Driven Legal assists clients with the full range of data protection advice including reviewing and updating contracts, handling complicated data subject requests and advising on cookie compliance. We often work alongside data protection officers as an extension of the inhouse team.
We also assist clients with AI governance: providing training, drafting AI usage policies, supporting AI impact assessments and contract review.
Tkm Consulting and Associates provide high quality consultancy and training in all aspects of information governance including data protection, freedom of information and records management. We also support organisations with implementing governance and compliance requirements within the Microsoft 365 environment.
We have courses and qualifications at a range of levels in data protection, FOI, FOISA and records management. Recognising the need for quality products that offer great value for money which help people learn at their own pace and when they have time, we have also launched our online on demand e-learning products, which are also available through corporate packages.
Dapian is a cloud-based platform that simplifies information governance for organisations of all sizes. It provides a fully integrated suite to manage Data Protection Impact Assessments (DPIAs), Information Asset Registers (IARs), Records of Processing Activities (RoPAs), Data Subject Access Requests (DSARs), Freedom of Information (FOI) requests, Data Sharing Agreements (DSAs), Data Breaches and Vendor Onboarding. Designed for both experts and non-experts, Dapian automates complex processes, guides users through compliance, and updates all modules simultaneously to ensure accuracy and reduce duplication. By empowering teams to take ownership of their data protection responsibilities, Dapian enhances efficiency and ensures robust compliance with GDPR.
eCase: Reimagining case management
eCase is the trusted, comprehensive and scalable case management platform for data protection, correspondence and complaints across the UK public sector.
It helps teams work more efficiently while staying fully compliant. Widely adopted, intuitive and easy to use, eCase adapts to any structure or process. eCase’s whole-life customer commitment ensures its customers achieve more: from successful onboarding to delivering continuous, measurable benefits.
Organisations including DWP, HMRC, MOD, DEFRA, HM Treasury, local authorities, police forces and the NHS rely on eCase to manage DPRs/SARs, EIRs, FOIs, Complaints, MCs and PQs.
This conference is CPD certified.



