Leuven - Photo by <a href="https://unsplash.com/@liebezz?utm_source=unsplash&utm_medium=referral&utm_content=creditCopyText">kevin liebens</a> on <a href="https://unsplash.com/photos/patio-bistro-sets-near-bulding-Pr1ZTVXJz_8?utm_source=unsplash&utm_medium=referral&utm_content=creditCopyText">Unsplash</a> (modified)

Proceedings

The proceedings are expected to appear in spring 2027.

Call For Papers

Regulation and Innovation: Catalysts or Antagonists?

As digital technologies evolve at a rapid pace, the interplay between regulatory frameworks and technological innovation has become a defining challenge for privacy and identity management. Regulation seeks to protect individuals’ rights, ensure accountability, and establish norms for data use, while innovation drives new capabilities in areas such as identity verification, AI-assisted services, and decentralized systems. Papers examining whether regulation and innovation act as mutual enablers - steering technology toward ethical and human-centric outcomes - or as opposing forces that constrain progress and limit competitive potential are encouraged. On the other hand, regulation can drive innovation by posing requirements to be translated into concrete technological development. Standards play an important role in this process, however their governance framework has recently come under criticism for potentially being captured by key industry players. By exploring case studies, policy approaches, legal frameworks, and emerging technologies, the summer school will shed light on how regulation and innovation interact, and how this interaction impacts future developments in law, social sciences, and computer science.

The 21st IFIP Summer School on Privacy and Identity Management aims to facilitate the exchange of knowledge and insights from the multiple disciplines that deal with privacy, data protection, and identity management. We invite papers that present relevant research in computer science, the law, the social sciences, or other relevant fields for presentation at the summer school and possible inclusion in the proceedings that will be published by Springer.

About the Summer School

The IFIP Summer School on Privacy and Identity Management aims to create a platform for spreading awareness and facilitating interactions and knowledge exchanges around old and new issues by taking a holistic approach to society and technology. We support interdisciplinary research exchange and foster discussions through keynote lectures, tutorials, and workshops. Participants will benefit from presenting their research and receiving meaningful feedback. The IFIP Summer School culminates in the publication of selected papers by the participants as an edited volume published by Springer.

We welcome contributions addressing these issues from any of the following perspectives (and especially the interdisciplinary combination of more than one): sociological, legal, technical, ethical, political, surveillance, intersectional, anthropological, economic, historical, media & communication, regulatory, philosophical, critical, disabilities, and psychological studies in the areas of privacy, data protection, and identity management.

The IFIP Summer School encourages not only interdisciplinarity but also broader diversity. It particularly welcomes submissions on how to foster gender and cultural balance in privacy and identity research and policy, and notably, tutorials and workshops about how to raise awareness in these matters.

Submission and Review Process

Abstracts will undergo a lightweight review process before being invited for a presentation at the conference. Full versions of the submissions, incorporating also feedback received during the summer school, will then be comprehensively reviewed after the conference.

Submissions must be made via the Easychair conference management system.

Details on the review process and the submission link can be found below.

Paper Submission and Review Process

The research paper presentations focus on involving students and on encouraging the publication of high-quality, thorough research papers by students and young researchers. To this end, the school will have the following process for submissions:

  • Submit an extended abstract of at least 2 and at most 4 pages in Springer LNCS style. From these submissions, the PC chairs select papers within the scope of this call for presentation at the Summer School.
  • A full length submission (up to 16 pages, including references), also in Springer LNCS format, is required to be submitted before the Summer School by applicants whose abstract has been accepted. The full-length paper will be shared with the other participants of the Summer School to prepare for the presentations.
  • At the Summer School, each author will give a presentation followed by a discussion.
  • After the Summer School, authors are invited to submit to the proceedings (18 pages LNCS to have sufficient space for changes and updates after discussions). They are expected to consider the comments and discussions from the Summer School.
    • NEW 2026: Submissions for the post-proceedings must appropriately indicate the changes from the pre-proceedings version (e.g., by a cover letter, a diff, color-coding, etc.) to highlight how the feedback during the summer school was addressed.
  • The Programme Committee will review these submissions. Based on these reviews, papers might be accepted, conditionally accepted, or rejected.
  • Accepted and (after satisfactory revision) conditionally accepted papers will be included in the Summer School’s proceedings, which will be published by Springer.

Submissions have to be in English and must be submitted using the following link: link no longer available

Instructions for Workshop/Tutorial Proposals

  • Workshop and tutorial proposals must be up to 2 pages and follow the Springer LNCS style. They must include a description of the topic, the expected participants, the types of activities to be carried out, the expected duration, and what support (facilities, infrastructure, etc.) might be needed from the Summer School.
  • The title of the submission must start with “WORKSHOP: “ or “TUTORIAL: “, respectively.

Submissions have to be in English and must be submitted using the following link: link no longer available

Possible Topics

Possible topics include, but are not limited to:

  • Technical and Organisational Measures, Methods, and Tools for Privacy and Data Protection that address:
    • Transparency and information provision to data subjects
    • Intervenability and control over personal data
    • Unlinkability and anonymization, including, e.g., EU Digital Identity Wallet
    • Confidentiality in generative AI tools
    • Accuracy in AI-generated personal data
    • Integrity of generative models
    • Explainability of AI models
    • Purpose limitation in data processing
    • Evaluation and performance assessment
    • Trustworthiness and Privacy by Design
  • Law, Regulation and Governance:
    • Data Protection and/or privacy implications of recent political, legal and technological developments
    • European and other legislation on data and data governance (Data Act, Data Governance Act, Digital Services Act, Digital Markets Act, eIDAS II, Artificial Intelligence Act etc.) and the planned simplification thereof (Digital Omnibus Proposal)
    • The interaction of data protection with liability regulation (product liability reform) and/or AI (AI Act)
    • Governance institutions and policy processes, and regulatory bodies at different levels (e.g., national. regional, global)
    • Data justice, data fairness and equality
    • Digital human rights and accountability in technology and data practices
    • Certification and standardisation and the interplay of standards and legislation
    • Automated compliance and regulatory technology
  • Effects and Impacts (negative or positive):
    • Discriminatory effects of technology
    • Technology-enabled social profiling and social exclusion
    • Digital divides, digital dividends, data sovereignty
    • Communities, societies, cultures, and technological mediation
    • Data practices, AI, and the Global South
  • Socio-Technical Perspectives:
    • Awareness, attitudes, skills, and behavior of citizens and public and private organizations
    • Approaches for diversity, non-discrimination and democratic enhancement
    • Surveillance, surveillance pressures, chilling effects
    • Critical perspectives on data practices
    • Welfare, solidarity, and care
    • Data economy and ecosystems, new business models
    • Trade-offs, tensions and conflicts between participation in digital cultures and privacy aspects
    • Historical development of data practices
    • Training, awareness, and empowerment of end-users, focusing on educating and equipping them to recognize and address privacy issues in AI effectively

Why should I submit?

Accepted papers will receive thorough discussions during the school and will allow students to publish their papers in the IFIP AICT series by Springer.

All individual members of IFIP member societies (over 40 national IT societies plus ACM and others) plus all members of IFIP Technical Committees and Working Groups are entitled to a discount of at least 10% on all registration fees.

A course certificate for 1,5 ECTS can be granted to students who attend the Summer School and write a short essay on how their research is relevant to or can be inspired by the Summer School sessions. A course certificate for 3 ECTS can be granted to students who attend the Summer School, submit and present an extended abstract for a research article, and demonstrate that they have addressed the feedback from the Summer School in an extended version or rebuttal, and write a short essay on how their research is relevant to or can be inspired by the Summer School sessions. Students whose papers were accepted as full papers for the proceedings, can receive a certificate confirming the equivalence to 6 ECTS points at the PhD level. The certificate can state the topic of the paper so as to demonstrate its relationship (or otherwise) to the student’s master or PhD thesis

We encourage submissions from students from emerging economies: applying for support from the IFIP Digital Equity Fund is possible to ease student travel.

Call for Workshops and Tutorials Proposals

A workshop is an interactive session scheduled for one or two hours and focuses on involving students in discussion. In it, participants jointly work on a topic or project related to the Summer School theme. Workshop activities are summarized in short papers that recapitulate the outcome and the kinds of discussion raised in the Summer School for inclusion in the proceedings. Proposals for workshops should contain a 2-page statement presenting the topic and summarising the planned activity and the expected contributions from the audience members, e.g., responding to a questionnaire or conducting a small experiment. Proposers should indicate whether any special equipment is needed for the workshop, such as audio-visual systems or computational equipment and support.

Tutorials are one or two-hour-long presentations. They should deal with topics that interest the interdisciplinary audience in the Summer School. Tutorials should provide knowledge on theoretical, empirical, methodological, practical, or other aspects relevant to the Summer School. Tutorial Proposals should contain a 2-page summary and state the level and background required for audience members to follow the tutorial.

Workshop and tutorial proposals need to be in English language, and must be submitted electronically.

Important Dates

All dates are AoE (anywhere on earth).

Event Deadline
Abstracts Deadline: 30.04.2026 15.05.2026
Workshops and Tutorials Proposal Deadline: 30.04.2026 15.05.2026
Acceptance Decision: 05.06.2026 08.06.2026
Early bird registration Deadline: 19.06.2026
Full Paper Deadline: 31.07.2026
Summer School: 10.-14.08.2024
Revised Full Paper Deadline: 25.09.2026
Full Paper Feedback: 20.11.2026
Camera Ready Deadline: 11.12.2026

Program

Program at a Glance

IFIP Summer School 2026 Program

Detailed Program

Monday, August 10, 2026

Time Track I
Room number: DV3 01.07
13:45-14:00 Opening session
14:00-15:00 Keynote I

Bart Preneel
The Long Crypto Wars: Fifty Years of Encryption Policy
15:00-15:30 Coffee break
15:30-17:00 Paper Session I
Session Chair: Ina Schiering · Room: DV3 01.07

Wiktor Wilkołaski
Reconstructing Liability in Distributed Architectures: The Revised Product Liability Directive vs. Federated Machine Learning

Arlette Houndji, Alfonso Iacovazzi, Jaap-Henk Hoepman, Simone Fischer-Hübner and Shahid Raza
Towards a privacy-preserving PKI for Satellite Communications

Pratham Ajmera
Schrödinger’s Crisis: Evaluating the possibility of a standards-driven power creep in IoT cybersecurity
17:00-18:00 Welcoming Reception

Tuesday, August 11, 2026

Time Track I
Room number: DV3 01.07
Track II
Room number: DV3 01.10
9:00-9:15 Registration  
9:15-10:15 Keynote II

Joanna Mazur
How could data protection law inform the EU’s approach to competition/innovation nexus?
 
10:15-10:30 Coffee break  
10:30-12:30 Paper Session II.a — Generative AI, Data Protection, and Sectoral Applications
Session Chair: Stefan Schiffner

Jonah Bellemans, Qianying Liao, Laurens Sion, Lieven Desmet and Wouter Joosen
The Right Tool for the Job: On the Selection of Mitigations for GenAI Privacy Threats

Mohammad Mafizul Islam
Data Sharing with Generative AI: Privacy Calculus, Trust, and Cybersecurity Behaviour in Germany from a Multilateral Security Perspective

Tea Georgieva
To Art or Not to Art: How AI Can Pivot from Shakespearean Villain to a Restorative and Structural Hero in the Creative Industries
Paper Session II.b — Digital Identity, Wallets, and Decentralized Systems
Session Chair: Simone Fischer-Hübner

Evelyne Putz and Nicholas Stifter
Com(m)itology in the Making: Regulating Through Technical Architecture in the European Digital Identity Wallet

Marlin Kisia, Beatriz Esteves and Ruben Verborgh
Trusted Data Exchanges Across Regulatory Boundaries: A Research Agenda for Personal Data Vault Interoperability

Maha Omar
Biometric Verification Systems in Ride-Hailing and Delivery Platforms: A Critical Analysis of the EU AI Act’s Exclusion from the High-Risk Classification

Adéla Felcmanová, Calvin Pärn, Pavel Loutocký and Jan Hajný
Overview of Post-Quantum Attribute-Based Credential Schemes
12:30-14:00 Lunch  
14:00-15:00 Keynote III

Yixin Zou
How Much Regulation is Enough? What the Public Thinks About AI and What That Means for AI Governance
 
15:00-15:30 Coffee break  
15:30-17:00 Workshop I

Felix Bieker and Marit Hansen
A Loving Home for PETs? Surveillance States and Big Tech Co-Opting Privacy-Enhancing Technologies
Workshop II

Mike McCabe
Zero-Knowledge Technology as a Foundation for Digital Sovereignty

Wednesday, August 12, 2026

Time Track I
Room number: DV3 01.07
Track II
Room number: DV3 01.10
9:00-9:15 Registration  
9:15-10:15 Keynote IV

Felix Bieker
Power is power: digital regulation in our current political moment
 
10:15-10:30 Coffee break  
10:30-12:30 Paper Session III — Privacy Literacy, Digital Divide, and Technical Vulnerabilities
Session Chair: Michael Friedewald

Tomasz Banaszewski, Ramona Adair and Ina Schiering
Serious Games for Privacy Literacy: An Overview

Dmitry Prokhorenkov and Dimitrios Tsolovos
Privacy Risk Identification in Organ-on-Chip: From Re-identification to Pseudo-Reidentification

Bulut Ulukapi, Anna Sperotto and Ralph Holz
Beneath the Divide: A Measurement Study of Minority-Serving Web Infrastructure

Paola Cardozo-Solano
Datafication and Vulnerability: Patients and Farmers in the Common European Data Spaces
 
12:30-14:00 Lunch  
14:00-15:00 Keynote V

Elena Pagnin
Privacy-Enhancing Cryptography? Uses, Misuses, and Myths
 
15:00-15:30 Coffee break  
15:30-17:00 Paper Session IV.a — Digital Identity, Wallets, and Decentralized Systems
Session Chair: Laura Drechsler

Tamara Drucks, Patrick Indri, Sebastian Heil and Martin Gaedke
Towards automated compliance verification

Thijmen van Gend
On the Agile Nature of the European Digital Identity Framework: Happily Marrying Privacy, Innovation, and Democracy

Abdullah Elbi, Bilgesu Sumer and Ezgi Eren
PETs meet Biometric Identity: The case of World(coin) through the lens of evolving EU Data Protection Law and the Digital Omnibus Proposal
Paper Session IV.b — Generative AI, Data Protection, and Sectoral Applications
Session Chair: Silvia De Conca

Tahoora Heydari
Product Liability and Privacy Protection in the Digital Age: Bridging the Gap Between the PLD and GDPR by Addressing Harm Caused by Software and AI

Harry Halpin
Preserving Privacy with Technology: A data protection analysis of the Nym mixnet

Derya Sözen Esen
From Principles to Controls: A Design-Science Justification of an AI Auditing Meta-Framework

Thursday, August 13, 2026

Time Track I
Room number: DV3 01.07
Track II
Room number: DV3 01.10
9:00-9:15 Registration  
9:15-10:15 Keynote VI

Ruba Abu-Salma
Privacy, Reproductive Health, and FemHealth Apps: Insights from App Audits and User Interviews
 
10:15-10:30 Coffee break  
10:30-12:30 Paper Session V — Data Protection Principles
Session Chair: Anna Berlee

Dmitry Prokhorenkov and Dimitrios Tsolovos
Invisible Data Subjects, Visible Personal Data: A Systematic Review of Privacy Implications for Organs-on-a-Chip in the EU

Chenyu Xiao
Privacy Protection in CBDCs: Theoretical Foundations and Legal Responses

Marcos Moran, David Rodriguez and Jose M Del Alamo
A Scalable Platform for Dynamic Privacy Analysis of iOS Applications on Physical Devices

Arne Vincken and Bente Schockaert
The principles of data minimisation and purpose limitation in Common European Data Spaces: sharing is caring?
 
12:30-14:00 Lunch  
14:00-15:00 Keynote VII

Pierre Dewitte
Enforcing data protection law in the age of AI
 
15:00-15:30 Coffee break  
15:30-17:00 Workshop III

Gurvirender Tejay, Kai Rannenberg, Sara Foresti, Ümit Cali, Andrew McGettrick, Ernesto Cuadross-Vargas, Travis Breaux, Rajendra Raj, Tamara Bonaci and Hana Habib
Bridging the Gap - Toward a Global Graduate Curriculum for Digital Privacy
Workshop IV

Meem Arafat Manab, Beatriz Esteves and Marlin Kisia
Solid Pods for AI Agents: Building GDPR-Compliant Data Backends
17:00-18:00 Social activity
City Golf Tour
 
After 18:00 Social dinner
Zarza
 

Friday, August 14, 2026

Time Track I
Room number: DV3 01.07
9:00-9:15 Registration
9:15-10:15 Keynote VIII

Christian Bormann
Innovation and Regulation in Practice: Lessons Learned from Building Digital Identity Wallets
10:15-10:30 Coffee break
10:30-12:30 Paper Session VI — AI Governance, Regulation, and Institutional Frameworks
Session Chair: Stefan Schiffner

Rui Zhang and Dimitri Van Landuyt
Are Guardrails in Current Agentic AI Systems Implementing Privacy by Design?

Martin Petr Erlebach
Ex-ante Access Regulation for Foundation AI Models: An Access-Justice Approach

Hanna Schaff, Simone Fischer-Hübner, Ala Sarah Alaqra, Leonardo Horn Iwaya and Farzaneh Karegar
What’s really important? Priorities of trustworthy AI requirements in healthcare: the perspective of clinicians in Sweden

Isabela Maria Rosal
Can Data Accuracy Survive Someone’s Death? A post-mortal privacy study
12:30-13:00 Closing remarks & Best Presentation Award
13:00-14:00 Lunch

Keynote Speakers

We are grateful to following keynote speakers for their contributions to the 21st IFIP Summer School on Privacy and Identity Management (listed in alphabetical order).


Ruba Abu-Salma Ruba Abu-Salma

🇬🇧 King's College London

Title: Privacy, Reproductive Health, and FemHealth Apps: Insights from App Audits and User Interviews

Abstract: Mobile applications that support women’s health (FemHealth apps) have grown rapidly alongside the increasing de-stigmatization of female reproductive health and wellbeing. While these technologies offer important benefits for managing menstrual, sexual, and reproductive health, their widespread adoption has also accelerated practices of intimate surveillance and the commodification of highly sensitive personal data. The overturning of Roe v. Wade has further intensified concerns about the privacy and safety implications of FemHealth apps, particularly regarding the collection, sharing, and potential misuse of reproductive health data.
In this talk, I will present findings from our recent investigation of the privacy practices of 20 popular FemHealth apps (ACM CHI 2024). Combining a thematic analysis of app privacy policies and Google Play Data Safety sections with a privacy-focused usability inspection, we identified several problematic practices, including inconsistencies between privacy disclosures and app functionality, inadequate consent and data deletion mechanisms, and the covert collection of sensitive user information.
I will also present findings from 14 in-depth semi-structured interviews with current and former FemHealth app users, conducted to explore their privacy experiences, concerns, and expectations (PoPETs 2026). Our findings reveal that participants were concerned about a broader range of privacy risks than previously reported in FemTech research. These concerns included the potential criminalization of abortion- or contraception-related activities, emotional harm associated with social stigma, third-party data sharing, and targeted advertising based on sensitive reproductive health information. Participants also expressed uncertainty regarding the effectiveness of existing data protection regulations and their interaction with increasingly restrictive reproductive health laws.
Drawing on evidence from both studies, I will discuss recommendations for improving privacy practices in FemHealth apps and argue for stronger technical, regulatory, and policy-based protections for sexual and reproductive health data.

Biography: Dr. Ruba Abu-Salma is a Senior Lecturer (Associate Professor) in Computer Science at King’s College London, where she is affiliated with the Cybersecurity Group and the Human-Centered Computing Group in the Department of Informatics. She also serves as Deputy Head of the Cybersecurity Group and Co-Champion of the department’s Security Hub. Her interdisciplinary research lies at the intersection of cybersecurity, privacy, human-computer interaction (HCI), emerging technologies, and public policy. Combining computational and social science methods, she investigates how people make security, privacy, and safety decisions, with a particular focus on supporting at-risk and vulnerable populations. Her work aims to design technologies that are both secure and usable, ensuring that security and privacy solutions better reflect users’ needs and experiences. Dr. Abu-Salma’s research has been published at leading venues, including IEEE Symposium on Security and Privacy, USENIX Security, ACM CHI, and ACM TOCHI, and has been featured in major international media outlets such as BBC News, the Financial Times, The New York Times, Euronews, and Science News. Before joining King’s College London in 2021, she held research positions at the International Computer Science Institute (ICSI) at the University of California, Berkeley, and at INRIA Sophia Antipolis. She received her Ph.D. in Computer Science from University College London (UCL), where her research focused on user-centered privacy-enhancing technologies.


Felix Bieker Felix Bieker

🇩🇪 FIZ Karlsruhe - Leibniz Institute for Information Infrastructure

Title: Power is power: digital regulation in our current political moment

Biography: Dr. Felix Bieker, LL.M. is senior researcher at FIZ Karlsruhe – Leibniz Institute for Information Infrastructure. After studying law in Kiel, Germany and Edinburgh, UK, and obtaining a doctorate, Felix published the monograph The Right to Data Protection: Individual and Structural Dimensions of Data Protection in EU Law and co-edited a special issue of Internet Policy Review on feminist data protection. Felix is co-principal investigator of Infra-Souveraen and explores how digital infrastructures, platforms and the law itself structure power in society.

Abstract: The only recently assembled EU digital regulation is currently subject to intense reform discussions. Driven by AI FOMO, the legislator aims to reduce existing protections to chase the USA and China in a supposed race for AI. In this framing, regulation is but an obstacle to innovation in a narrow sense. I argue that this approach equates innovation with subscribing to Big Tech’s narratives about inevitable technologies and reshaping society based on business interests. Achieving this, but with European actors, is thus presented as the panacea of digital sovereignty. The vague notion of ‘European values’ is invoked to appease those troubled by the neoliberal edge of this grand European enterprise. I will challenge these prevailing narratives and explore alternative visions that build broader alliances.


Christian Bormann Christian Bormann

🇩🇪 SPRIND - Bundesagentur für Sprunginnovationen

Title: Innovation and Regulation in Practice: Lessons Learned from Building Digital Identity Wallets

Biography: Christian Bormann is a Digital Identity and Cryptography Architect heading the team responsible for technical standards in the German EU Digital Identity Wallet project. An alumnus of RWTH Aachen University, he specialises in distributed systems, privacy-enhancing technologies, and the IoT. Christian actively shapes international technical specifications through contributions to the IETF, OIDF, W3C, and ETSI. Operating at the intersection of cryptography, engineering, and global standards, he is dedicated to building secure, interoperable, and user-centric infrastructures for Europe’s digital future.


Pierre Dewitte Pierre Dewitte

🇧🇪 European Data Protection Supervisor

Title: Enforcing data protection law in the age of AI

Biography: Pierre Dewitte is a Legal Officer at the European Data Protection Supervisor (EDPS) and a Research Fellow at the KU Leuven Centre for IT & IP Law (CITIP). He holds a Bachelor and Master degree of Laws with a specialisation in Corporate and Intellectual Property law from the Université Catholique de Louvain, and an Advanced Master in Intellectual Property and from KU Leuven. Pierre started his career at CITIP, where he conducted interdisciplinary research on privacy engineering, smart cities and algorithmic transparency, and defended his PhD on data protection by design. He then joined the Supervision and Enforcement Unit at the EDPS, where he now supervises the operational activities of Europol and Frontex. Pierre remains affiliated to CITIP, where he teaches data protection law as a guest lecturer in various courses and supervises students in their research track.


Joanna Mazur Joanna Mazur

🇵🇱 University of Warsaw

Title: How could data protection law inform the EU’s approach to competition/innovation nexus?

Abstract: Innovation is often presented as the ultimate goal of EU policies. Improving the EU’s competitiveness is seen as a means of achieving a higher level of innovation, and changing its approach to certain elements of competition law is one way of doing so. However, even within competition law enforcement, the relationship between mergers and innovation is not always straightforward. While allowing companies to merge is sometimes presented as a way to enable them to innovate more easily, other narratives also exist, emphasising that it is often smaller companies that develop the most innovative solutions.

One issue that is often overlooked in these considerations is the purpose that innovation should serve and the cost involved. Including broader considerations, such as data processing practices, within the scope of competition analysis could open up new ways of assessing companies’ behaviour within the area of competition law. As the Meta Platforms case illustrates, there is a place — or sometimes even an obligation — for including such considerations in proceedings. Thus, it seems worth asking what data protection law could offer in terms of the EU’s approach to the competition/innovation nexus.

Biography: Assistant Professor at the Faculty of Management at the University of Warsaw, analyst at DELab UW and the Center of Antitrust and Regulatory Studies. She defended her PhD thesis at the University of Warsaw in 2021. The thesis and the analysis conducted therein examined whether algorithms used in automated decision-making could be considered public information or official documents under European law. Since 2025, she has been a Principal Investigator in an OPUS project titled ‘New legal acts, old enforcement problems? Disentangling the complexities of the enforcement of EU law concerning digital technologies,’ funded by the National Science Centre, Poland. Her research interests include data protection law, algorithms, artificial intelligence and platforms regulation, and competition law. Her ORCID, where her publications can be found, is: 0000-0002-0417-5743.


Elena Pagnin Elena Pagnin

🇸🇪 Chalmers University

Title: Privacy-Enhancing Cryptography? Uses, Misuses, and Myths

Abstract: Cryptography is often presented as a technical answer to privacy challenges. In practice, however, the effectiveness of cryptographic solutions depends on correct assumptions, precise system design, deployment choices, and the social and regulatory context in which they are deployed. Rather than treating cryptography as simply “good” or “bad,” this talk argues that its privacy value is contextual, perspective-dependent, and shaped as much by usability and regulation as by mathematics and technical constraints. The goal is to give participants a sharper way to reason about what cryptography can and cannot do for privacy, and to distinguish its intended uses from its misuse and from the consequences of its weakening or removal.

Biography: Dr. Elena Pagnin is an Associate Professor in the Department of Computer Science and Engineering at Chalmers University of Technology, Sweden, where she leads the CryptoTeam within the Security & Privacy Lab. Her research interests include the design of advanced public-key cryptosystems, with particular emphasis on authentication, transparency, privacy-enhancing technologies and verifiable systems. Her work addresses fundamental challenges in modern cryptography by developing practical and secure solutions for emerging applications. Dr. Pagnin has received competitive research funding, including a 2025 Swedish Research Council (VR) grant for her project on consistency protocols for transparency technologies. She is an active member of the international cryptography community, regularly invited to speak at academic and industry events, and is committed to bridging cutting-edge research with societal impact. Alongside her research, she is recognized for her dedication to teaching and mentoring and was nominated for Chalmers’ Pedagogical Prize in 2025.


Bart Preneel Bart Preneel

🇧🇪 KU Leuven

Title: The Long Crypto Wars: Fifty Years of Encryption Policy

Abstract: The “Crypto Wars” describe the enduring tension between government demands for access to encrypted data in the name of national security and the protection of privacy and civil liberties. This talk traces the history of these conflicts, from efforts to suppress cryptographic research and restrict secure communications (such as the Clipper Chip), to high‑profile disputes over device access (Apple vs. FBI), and the deployment of commercial spyware (e.g., NSO Group).

More recently, attention has shifted to client-side scanning: filtering content on user devices before encryption or after decryption, ostensibly to detect child sexual abuse material (CSAM), but increasingly framed as a tool for counterterrorism and crime prevention. However, client-side scanning weakens end‑to‑end encryption, is vulnerable to misuse, and lacks demonstrated effectiveness. Our recent research shows that perceptual hash techniques used to identify known CSAM have high false positive/negative rates and are invertible. Proposals to use AI to detect AI‑generated CSAM raise additional concerns about reliability and accountability.

In Spring 2025, the EU’s ProtectEU initiative launched a roadmap to explore “lawful access” technologies by late 2026, marking a new phase of the crypto wars. While encryption poses challenges for law enforcement, authorities already possess extensive surveillance capabilities and metadata access. Rather than undermining encryption, policy efforts should prioritize strong cybersecurity, transparency around surveillance practices, and an open societal debate on balancing security with fundamental rights.

Biography: Bart Preneel is full professor heading the COSIC research group at the KU Leuven. His expertise lies in applied cryptography, cybersecurity, and privacy. He has delivered over 150 invited talks across 50 countries and received the RSA Award for Excellence in Mathematics (2014) and the ESORICS Outstanding Research Award (2017). He served as president of IACR (International Association for Cryptologic Research) and is also a fellow of the IACR. In 2024 he was elected member of the Royal Academy of Art and Sciences Belgium. He frequently consults for industry and government about cybersecurity and privacy technologies and he has testified multiple times for the Belgian and European Parliaments. Prof. Preneel founded the mobile authentication startup nextAuth and holds roles in Approach Belgium, Tioga Capital Partners, and Nym Technologies. He is actively engaged in cybersecurity policy debates.


Yixin Zou Yixin Zou

🇩🇪 Max Planck Institute for Security and Privacy

Title: How Much Regulation is Enough? What the Public Thinks About AI and What That Means for AI Governance

Abstract: Narratives around AI tend to split into two camps: one sees it as a catalyst for progress, championed largely by AI companies; the other sees it as a source of harm, voiced by critical scholars and regulators. I’ll trace this divide through several recent studies from my group: first, how AI companies construct their own narrative of AI safety in public statements; then, how exposing ordinary people to these competing narratives shapes what they come to believe about AI; and finally, what happens when we ask the public directly, revealing a striking gap between how people actually perceive AI risk and how the EU AI Act categorizes it. Together, these studies suggest that the public’s own view of AI doesn’t map neatly onto either the “AI as progress” or “AI as harm” narrative. Even though the public wants more regulation than the status quo provides, few possess the technical understanding to assess that risk accurately. This leaves us with a puzzle central to this summer school’s theme: whose narrative should count in AI governance, and how might that answer shift as we move into the era of agentic AI?

Biography: Dr. Yixin Zou (she/her) is a tenure-track faculty member at the Max Planck Institute for Security and Privacy, where she leads the human-centered security and privacy group. Her research interests span human-computer interaction, privacy, and security, aiming to make technology safer and more equitable for underserved communities. Her research has been recognized with the ACM SIGCHI Outstanding Dissertation Award (2024), the John Karat Usable Privacy and Security Student Research Award (2022), and several best paper and honorable mention awards at top venues such as ACM SIGCHI Conference on Human Factors in Computing (CHI) and the Symposium on Usable Privacy and Security (SOUPS). Her research has also generated broader impacts on public policy, including the rule-making process for the California Consumer Privacy Act. She earned a Ph.D. in Information from the University of Michigan in 2022.

Best Presentation Award

Two best presentation awards were awarded at this year’s summer school:

  • Jonah Bellemans for his paper entitled “The Right Tool for the Job: On the Selection of Mitigations for GenAI Privacy Threats”
  • Maha Omar for her paper entitled “Biometric Verification Systems in Ride-Hailing and Delivery Platforms: A Critical Analysis of the EU AI Act’s Exclusion from the High-Risk Classification”

Furthermore, Martin Petr Erlebach received an honorable mention for his paper on “Ex Ante Access Regulation for Foundation AI Models: An Access-Justice Approach”.

Congratulations!

Committee

Programme Chairs

  • Anna Berlee (🇳🇱 Open Universiteit)
  • Agnieszka Kitkowska (🇸🇪 Jönköping University)
  • Stephan Krenn (🇦🇹 AIT Austrian Institute of Technology)

General Chairs

  • Laura Drechsler (🇧🇪 KU Leuven)
  • Stefan Schiffner (🇩🇪 Hochschule Bonn-Rhein-Sieg University of Applied Sciences)

Steering Committee

  • Simone Fischer-Hübner (🇸🇪 Karlstad University) – Chair
  • Felix Bieker (🇩🇪 FIZ Karlsruhe - Leibniz Institute for Information Infrastructure)
  • Silvia De Conca (🇳🇱 Vrije Universiteit Amsterdam)
  • Michael Friedewald (🇩🇪 Fraunhofer ISI)
  • Marit Hansen (🇩🇪 ULD)
  • Eleni Kosta (🇳🇱 Tilburg University)
  • Stephan Krenn (🇦🇹 AIT Austrian Institute of Technology)
  • Charles Raab (🇬🇧 University of Edinburgh)
  • Kai Rannenberg (🇩🇪 Goethe University Frankfurt)
  • Ina Schiering (🇩🇪 Ostfalia University of Applied Sciences)
  • Stefan Schiffner (🇩🇪 Hochschule Bonn-Rhein-Sieg University of Applied Sciences)
  • Diane Whitehouse (🇧🇪 EHTEL)

Programme Committee

  • Felix Bieker (🇩🇪 FIZ Karlsruhe - Leibniz Institute for Information Infrastructure)
  • Tatiana Duarte Nicolau (🇧🇪 KU Leuven)
  • Michael Friedewald (🇩🇪 Fraunhofer ISI)
  • Tommaso Fia (🇩🇪 University of Tübingen)
  • Simone Fischer-Hübner (🇸🇪 Karlstad University) – Chair
  • Jesús García-Rodríguez (🇪🇸 University of Murcia)
  • Tejay Gurvirender (🇺🇸 Hofstra University)
  • Stefan Katzenbeisser (🇩🇪 University of Passau)
  • Marco Antonio Lasmar Almada (🇱🇺 University of Luxembourg)
  • Nicola Leschke (🇦🇹 University of Salzburg)
  • Konstantinos Limniotis (🇬🇷 National and Kapodistrian University of Athens)
  • Stefan More (🇦🇹 Graz University of Technology)
  • Davy Preuveneers (🇧🇪 DistriNet, KU Leuven)
  • Arnold Roosendaal (🇳🇱 Privacy Company)
  • Andrej Savin (🇩🇰 Copenhagen Business School)
  • Ina Schiering (🇩🇪 Ostfalia University of Applied Sciences)
  • Hanna Schraffenberger (🇳🇱 Radboud University)
  • Yefim Shulman (🇳🇱 Erasmus University Rotterdam)

Venue

The summer school will be hosted by the Centre for IT and IP Law (CITIP) at KU Leuven. The school will take place at the Faculty of Law and Criminology, Tiensestraat 41, 3000 Leuven link.

Specifically, all sessions will take place in rooms DV3 01.07 and DV3 01.10.

Important Facts & Useful Information

Emergency Numbers:

  • 112 – European emergency number for ambulance, fire brigade and urgent assistance
  • 101 – Police emergency number in Belgium
  • 1733 – Non-emergency medical assistance / doctor on call

Currency & Payments: Belgium uses the Euro (€). Credit and debit cards are widely accepted, although carrying a small amount of cash can be useful.

Public Transport: Leuven is well connected by train and bus. The conference venue is located approximately 1 km from Leuven Central Station and can be reached on foot in about 15 minutes. Local buses are operated by De Lijn. Bus tickets can be purchased on board using contactless payment (bank card, smartphone or smartwatch).

Language: The official language in Leuven is Dutch (Flemish). English is widely spoken, particularly at the university, hotels, restaurants and conference venues. French is also commonly understood.

Time Zone: Leuven follows Central European Summer Time (CEST) during the period of the summer school.

Electricity: Belgium uses 230 V / 50 Hz electricity with Type C and Type E plugs. Visitors from countries using other plug types may need an adapter.

Registration

Please note that for each accepted abstract, at least one (co-)author has to attend the summer school and register by the early-bird registration deadline.

Registration type Early bird1 Late registration1
Regular registration 500€ 550€
IFIP Member registration2 450€ 500€

1 Early bird registration fees apply until June 19.
2 All individual members of IFIP member societies as well as all members of IFIP Technical Committees (TCs) and Working Groups (WGs) are entitled to a discount of 10% on registration fees. To claim the discount, you will need to state which IFIP member society/TC/WG you belong to during the registration process.

Registration to this event is no longer possible.

Organizers

KU Leuven

Sponsors

IFIP Platform Privatheit logo

Supporters

Horizon Europe LICORICE