Keynotes
The following keynote speakers confirmed their participation.
🇬🇧 King's College London
Title: Privacy, Reproductive Health, and FemHealth Apps: Insights from App Audits and User Interviews
Abstract:
Mobile applications that support women’s health (FemHealth apps) have grown rapidly alongside the increasing de-stigmatization of female reproductive health and wellbeing. While these technologies offer important benefits for managing menstrual, sexual, and reproductive health, their widespread adoption has also accelerated practices of intimate surveillance and the commodification of highly sensitive personal data. The overturning of Roe v. Wade has further intensified concerns about the privacy and safety implications of FemHealth apps, particularly regarding the collection, sharing, and potential misuse of reproductive health data.
In this talk, I will present findings from our recent investigation of the privacy practices of 20 popular FemHealth apps (ACM CHI 2024). Combining a thematic analysis of app privacy policies and Google Play Data Safety sections with a privacy-focused usability inspection, we identified several problematic practices, including inconsistencies between privacy disclosures and app functionality, inadequate consent and data deletion mechanisms, and the covert collection of sensitive user information.
I will also present findings from 14 in-depth semi-structured interviews with current and former FemHealth app users, conducted to explore their privacy experiences, concerns, and expectations (PoPETs 2026). Our findings reveal that participants were concerned about a broader range of privacy risks than previously reported in FemTech research. These concerns included the potential criminalization of abortion- or contraception-related activities, emotional harm associated with social stigma, third-party data sharing, and targeted advertising based on sensitive reproductive health information. Participants also expressed uncertainty regarding the effectiveness of existing data protection regulations and their interaction with increasingly restrictive reproductive health laws.
Drawing on evidence from both studies, I will discuss recommendations for improving privacy practices in FemHealth apps and argue for stronger technical, regulatory, and policy-based protections for sexual and reproductive health data.
Biography: Dr. Ruba Abu-Salma is a Senior Lecturer (Associate Professor) in Computer Science at King’s College London, where she is affiliated with the Cybersecurity Group and the Human-Centered Computing Group in the Department of Informatics. She also serves as Deputy Head of the Cybersecurity Group and Co-Champion of the department’s Security Hub. Her interdisciplinary research lies at the intersection of cybersecurity, privacy, human-computer interaction (HCI), emerging technologies, and public policy. Combining computational and social science methods, she investigates how people make security, privacy, and safety decisions, with a particular focus on supporting at-risk and vulnerable populations. Her work aims to design technologies that are both secure and usable, ensuring that security and privacy solutions better reflect users’ needs and experiences. Dr. Abu-Salma’s research has been published at leading venues, including IEEE Symposium on Security and Privacy, USENIX Security, ACM CHI, and ACM TOCHI, and has been featured in major international media outlets such as BBC News, the Financial Times, The New York Times, Euronews, and Science News. Before joining King’s College London in 2021, she held research positions at the International Computer Science Institute (ICSI) at the University of California, Berkeley, and at INRIA Sophia Antipolis. She received her Ph.D. in Computer Science from University College London (UCL), where her research focused on user-centered privacy-enhancing technologies.
Felix Bieker
🇩🇪 FIZ Karlsruhe - Leibniz Institute for Information Infrastructure
Title: Power is power: digital regulation in our current political moment
Biography: Dr. Felix Bieker, LL.M. is senior researcher at FIZ Karlsruhe – Leibniz Institute for Information Infrastructure. After studying law in Kiel, Germany and Edinburgh, UK, and obtaining a doctorate, Felix published the monograph The Right to Data Protection: Individual and Structural Dimensions of Data Protection in EU Law and co-edited a special issue of Internet Policy Review on feminist data protection. Felix is co-principal investigator of Infra-Souveraen and explores how digital infrastructures, platforms and the law itself structure power in society.
Abstract: The only recently assembled EU digital regulation is currently subject to intense reform discussions. Driven by AI FOMO, the legislator aims to reduce existing protections to chase the USA and China in a supposed race for AI. In this framing, regulation is but an obstacle to innovation in a narrow sense. I argue that this approach equates innovation with subscribing to Big Tech’s narratives about inevitable technologies and reshaping society based on business interests. Achieving this, but with European actors, is thus presented as the panacea of digital sovereignty. The vague notion of ‘European values’ is invoked to appease those troubled by the neoliberal edge of this grand European enterprise. I will challenge these prevailing narratives and explore alternative visions that build broader alliances.
🇩🇪 SPRIND - Bundesagentur für Sprunginnovationen
Title: Innovation and Regulation in Practice: Lessons Learned from Building Digital Identity Wallets
Biography: Christian Bormann is a Digital Identity and Cryptography Architect heading the team responsible for technical standards in the German EU Digital Identity Wallet project. An alumnus of RWTH Aachen University, he specialises in distributed systems, privacy-enhancing technologies, and the IoT. Christian actively shapes international technical specifications through contributions to the IETF, OIDF, W3C, and ETSI. Operating at the intersection of cryptography, engineering, and global standards, he is dedicated to building secure, interoperable, and user-centric infrastructures for Europe’s digital future.
Pierre Dewitte
🇧🇪 European Data Protection Supervisor
🇵🇱 University of Warsaw
Title: How could data protection law inform the EU’s approach to competition/innovation nexus?
Abstract: Innovation is often presented as the ultimate goal of EU policies. Improving the EU’s competitiveness is seen as a means of achieving a higher level of innovation, and changing its approach to certain elements of competition law is one way of doing so. However, even within competition law enforcement, the relationship between mergers and innovation is not always straightforward. While allowing companies to merge is sometimes presented as a way to enable them to innovate more easily, other narratives also exist, emphasising that it is often smaller companies that develop the most innovative solutions.
One issue that is often overlooked in these considerations is the purpose that innovation should serve and the cost involved. Including broader considerations, such as data processing practices, within the scope of competition analysis could open up new ways of assessing companies’ behaviour within the area of competition law. As the Meta Platforms case illustrates, there is a place — or sometimes even an obligation — for including such considerations in proceedings. Thus, it seems worth asking what data protection law could offer in terms of the EU’s approach to the competition/innovation nexus.
Biography: Assistant Professor at the Faculty of Management at the University of Warsaw, analyst at DELab UW and the Center of Antitrust and Regulatory Studies. She defended her PhD thesis at the University of Warsaw in 2021. The thesis and the analysis conducted therein examined whether algorithms used in automated decision-making could be considered public information or official documents under European law. Since 2025, she has been a Principal Investigator in an OPUS project titled ‘New legal acts, old enforcement problems? Disentangling the complexities of the enforcement of EU law concerning digital technologies,’ funded by the National Science Centre, Poland. Her research interests include data protection law, algorithms, artificial intelligence and platforms regulation, and competition law. Her ORCID, where her publications can be found, is: 0000-0002-0417-5743.
🇸🇪 Chalmers University
Title: Privacy-Enhancing Cryptography? Uses, Misuses, and Myths
Abstract: Cryptography is often presented as a technical answer to privacy challenges. In practice, however, the effectiveness of cryptographic solutions depends on correct assumptions, precise system design, deployment choices, and the social and regulatory context in which they are deployed. Rather than treating cryptography as simply “good” or “bad,” this talk argues that its privacy value is contextual, perspective-dependent, and shaped as much by usability and regulation as by mathematics and technical constraints. The goal is to give participants a sharper way to reason about what cryptography can and cannot do for privacy, and to distinguish its intended uses from its misuse and from the consequences of its weakening or removal.
Biography: Dr. Elena Pagnin is an Associate Professor in the Department of Computer Science and Engineering at Chalmers University of Technology, Sweden, where she leads the CryptoTeam within the Security & Privacy Lab. Her research interests include the design of advanced public-key cryptosystems, with particular emphasis on authentication, transparency, privacy-enhancing technologies and verifiable systems. Her work addresses fundamental challenges in modern cryptography by developing practical and secure solutions for emerging applications. Dr. Pagnin has received competitive research funding, including a 2025 Swedish Research Council (VR) grant for her project on consistency protocols for transparency technologies. She is an active member of the international cryptography community, regularly invited to speak at academic and industry events, and is committed to bridging cutting-edge research with societal impact. Alongside her research, she is recognized for her dedication to teaching and mentoring and was nominated for Chalmers’ Pedagogical Prize in 2025.
🇧🇪 KU Leuven
🇩🇪 Max Plan Institute for Security and Privacy
Felix Bieker
Pierre Dewitte