💭 It starts with a question you cannot quite answer alone
Imagine you are a DPO, or simply a Clinical Manager who suddenly finds Data Privacy added to your list of responsibilities. A new Clinical Trial is being set up across three countries. Someone from the clinical team asks how patient data can be shared with a partner site abroad. Someone from IT wants to know if the new AI tool the organization is piloting is compliant. And you are the one expected to have the answer, ideally before the end of the day.
It is not that the information does not exist. It is that gathering it, making sense of it, and turning it into something actionable across clinical, legal, and technical teams takes time you rarely have.
This is exactly the gap the Data Privacy for Health Summit was built to fill: 1 day, 20+ expert speakers, 120 attendees, and multiple formats to learn and exchange, all focused on the realities of Data Privacy in Life Sciences.
📣 The questions Life Sciences Privacy Professionals are actually asking
Whether you are just starting to navigate Data Privacy in Life Sciences, or you have been dealing with it for years, the questions below reflect what the Summit’s community is actually discussing this year.
How do you manage international Data Transfers in Clinical Research?
Clinical Trials increasingly span several countries, each with its own transfer mechanism, from EU Standard Contractual Clauses to a patchwork of local model clauses, and few organizations have a single operational tool to manage all of it consistently. In practice, most Global DPOs rely on keeping a living data flow mapping updated in real time, since compliance depends less on picking the “right” clause and more on knowing exactly where data moves, and why, at any given moment.
What are the main Data Privacy risks in Clinical Trials?
Consent management, data minimization across multiple stakeholders, and the growing use of AI in trial design are among the most discussed risks today. One that is often underestimated: anonymization itself is not a fixed status but a moving target, datasets once considered safely de-identified, particularly imaging or rare disease data, can carry renewed re-identification risk as data linkage techniques evolve.
How do you structure a Data Protection Governance Program for a Life Sciences organization?
There is no single template, but a few building blocks tend to recur: a clear data flow mapping, defined governance roles, and increasingly, Privacy-Enhancing Technologies such as federated learning or differential privacy, which do not remove legal obligations but can meaningfully reduce risk when applied to the right use case. What often makes the real difference, though, is less the framework itself and more the lessons professionals rarely get to exchange outside their own organization.
Can Data Privacy actually become a competitive advantage instead of just a compliance cost?
Organizations that treat Data Privacy as a trust-building asset, rather than a box to tick, increasingly turn it into a real differentiator with partners, regulators, and patients. This logic sits behind emerging models like patient-controlled health data, where transparency and individual agency become the argument for participation, not just a legal safeguard.
For those who have been navigating these questions for years, the conversation goes further still.
Can AI actually replace the DPO role?
AI can already take over specific tasks such as first-level monitoring, drafting, or flagging potential risks, freeing up real time for DPOs. But replacing the role entirely raises a different question: the “Human Check”. Not all AI is equal, an open-source tool trained on unverified online data does not offer the same level of trust as a purpose-built, controlled solution designed specifically for Privacy use cases. But even the most reliable source still requires a qualified expert to review its output in depth.
Does synthetic data eliminate Data Privacy risks in Clinical Research?
Not entirely. In Clinical Research, full anonymization is often not even the goal: organizations frequently need to trace data back to a patient, notably for safety and pharmacovigilance reasons, which is why pseudonymization, not true anonymization, remains the norm for real patient data. Synthetic data reduces exposure by removing the direct link to real individuals, which is a genuine advantage for research, data sharing, and AI training. But it does not automatically mean zero risk: badly generated synthetic datasets can still leak patterns traceable to real patients, especially in rare disease research where small populations make re-identification easier.
Who is liable when an AI healthcare tool causes harm?
There is no simple label to determine liability here. Whether an organization acts as controller, processor, or joint controller depends on a granular, fact-based assessment of who actually holds decision-making power over the data, not on what a contract says. Bias, fairness, and model reliability add another layer of risk on top of that, which is why human-in-the-loop mechanisms remain essential to preserve clinical accountability.
🔬 Data Privacy through a Life Sciences lens
Data Privacy challenges in healthcare rarely exist in isolation. They sit at the intersection of legal obligations, technological evolution, scientific research, ethical considerations, and patient-centered care. That complexity is at the heart of the Data Privacy for Health Summit.
From Clinical Research and health data governance to AI, international data transfers, consumer health data, and emerging regulations, the program focuses on the questions professionals across Life Sciences are facing today. Rather than simply asking what regulations say, discussions go further, exploring what they actually mean in practice, through expert presentations, workshops, fireside chats, panels, and interactive discussions throughout the day.
🧩 Different perspectives, One shared challenge
The same health data question can look very different depending on who is answering it. A Privacy professional, a Clinical Research expert, a lawyer, and a technology specialist will each see a different part of the same problem. This is precisely the situation you may have recognized yourself in earlier: needing input from several functions just to answer one question.
The Summit connects professionals from Privacy, Legal, Compliance, Regulatory Affairs, Clinical Research, Data and Technology, academia, and the wider Life Sciences ecosystem. Previous editions have also welcomed representatives from regulatory and public institutions, adding another important perspective to the discussion.
For some participants, the value lies in discovering a topic or better understanding an emerging issue. For others, it is an opportunity to benchmark their Data Protection approach and hear how peers are addressing similar challenges. Sometimes, the most useful insight is not another explanation of a regulation, but discovering how someone else is dealing with the exact same problem you brought with you that morning.
💬 Beyond the sessions
The Data Privacy for Health Summit is intentionally limited to 120 attendees, creating an environment where the experience does not stop when a session ends. With 20+ experts contributing throughout the day, the people sharing their experience on stage remain part of the Summit, sitting alongside attendees and continuing conversations during breaks, lunch, and networking moments.
A question raised during a panel can continue over coffee, and someone whose experience resonates with a challenge you are facing can actually be approached afterward. Keeping the Summit at this scale creates room for meaningful exchanges with both experts and peers who understand the specific realities of working with health data.
🔭 Looking ahead together
The health data landscape will keep evolving. AI is creating new possibilities, regulations are changing, research increasingly crosses borders, and expectations around Data Protection and responsible data use continue to grow. Keeping up requires more than following regulatory updates, it also means understanding how these developments intersect, and learning from the people dealing with their practical consequences.
Through its editions in Europe and the United States, the Data Privacy for Health Summit has built a community around that idea. Data Privacy for Health, “DPH” exists as an independent platform, shaped by the professionals who take part in it year after year, with the support of sponsors such as MyData-TRUST, who bring hands-on expertise in Data Privacy and Life Sciences to the table.
So if you are that DPO, or that Clinical Manager, still looking for the answer you could not quite find alone, you will find that you are not the only one asking.
Discover the upcoming editions, programs, and DPH community on the official Data Privacy for Health website: https://dataprivacyforhealth.com/
Next edition on October 1, 2026 at The Row Hotel, Somerville (Boston Area), MA. Agenda and Registration
Authors: Mathilde Faure