The following keynote speakers confirmed their participation.


Ruba Abu-Salma Ruba Abu-Salma

🇬🇧 King's College London

Title: Privacy, Reproductive Health, and FemHealth Apps: Insights from App Audits and User Interviews

Abstract: Mobile applications that support women’s health (FemHealth apps) have grown rapidly alongside the increasing de-stigmatization of female reproductive health and wellbeing. While these technologies offer important benefits for managing menstrual, sexual, and reproductive health, their widespread adoption has also accelerated practices of intimate surveillance and the commodification of highly sensitive personal data. The overturning of Roe v. Wade has further intensified concerns about the privacy and safety implications of FemHealth apps, particularly regarding the collection, sharing, and potential misuse of reproductive health data.
In this talk, I will present findings from our recent investigation of the privacy practices of 20 popular FemHealth apps (ACM CHI 2024). Combining a thematic analysis of app privacy policies and Google Play Data Safety sections with a privacy-focused usability inspection, we identified several problematic practices, including inconsistencies between privacy disclosures and app functionality, inadequate consent and data deletion mechanisms, and the covert collection of sensitive user information.
I will also present findings from 14 in-depth semi-structured interviews with current and former FemHealth app users, conducted to explore their privacy experiences, concerns, and expectations (PoPETs 2026). Our findings reveal that participants were concerned about a broader range of privacy risks than previously reported in FemTech research. These concerns included the potential criminalization of abortion- or contraception-related activities, emotional harm associated with social stigma, third-party data sharing, and targeted advertising based on sensitive reproductive health information. Participants also expressed uncertainty regarding the effectiveness of existing data protection regulations and their interaction with increasingly restrictive reproductive health laws.
Drawing on evidence from both studies, I will discuss recommendations for improving privacy practices in FemHealth apps and argue for stronger technical, regulatory, and policy-based protections for sexual and reproductive health data.

Biography: Dr. Ruba Abu-Salma is a Senior Lecturer (Associate Professor) in Computer Science at King’s College London, where she is affiliated with the Cybersecurity Group and the Human-Centered Computing Group in the Department of Informatics. She also serves as Deputy Head of the Cybersecurity Group and Co-Champion of the department’s Security Hub. Her interdisciplinary research lies at the intersection of cybersecurity, privacy, human-computer interaction (HCI), emerging technologies, and public policy. Combining computational and social science methods, she investigates how people make security, privacy, and safety decisions, with a particular focus on supporting at-risk and vulnerable populations. Her work aims to design technologies that are both secure and usable, ensuring that security and privacy solutions better reflect users’ needs and experiences. Dr. Abu-Salma’s research has been published at leading venues, including IEEE Symposium on Security and Privacy, USENIX Security, ACM CHI, and ACM TOCHI, and has been featured in major international media outlets such as BBC News, the Financial Times, The New York Times, Euronews, and Science News. Before joining King’s College London in 2021, she held research positions at the International Computer Science Institute (ICSI) at the University of California, Berkeley, and at INRIA Sophia Antipolis. She received her Ph.D. in Computer Science from University College London (UCL), where her research focused on user-centered privacy-enhancing technologies.


Felix Bieker Felix Bieker

đŸ‡©đŸ‡Ș FIZ Karlsruhe - Leibniz Institute for Information Infrastructure

Title: Power is power: digital regulation in our current political moment

Biography: Dr. Felix Bieker, LL.M. is senior researcher at FIZ Karlsruhe – Leibniz Institute for Information Infrastructure. After studying law in Kiel, Germany and Edinburgh, UK, and obtaining a doctorate, Felix published the monograph The Right to Data Protection: Individual and Structural Dimensions of Data Protection in EU Law and co-edited a special issue of Internet Policy Review on feminist data protection. Felix is co-principal investigator of Infra-Souveraen and explores how digital infrastructures, platforms and the law itself structure power in society.

Abstract: The only recently assembled EU digital regulation is currently subject to intense reform discussions. Driven by AI FOMO, the legislator aims to reduce existing protections to chase the USA and China in a supposed race for AI. In this framing, regulation is but an obstacle to innovation in a narrow sense. I argue that this approach equates innovation with subscribing to Big Tech’s narratives about inevitable technologies and reshaping society based on business interests. Achieving this, but with European actors, is thus presented as the panacea of digital sovereignty. The vague notion of ‘European values’ is invoked to appease those troubled by the neoliberal edge of this grand European enterprise. I will challenge these prevailing narratives and explore alternative visions that build broader alliances.


Christian Bormann Christian Bormann

đŸ‡©đŸ‡Ș SPRIND - Bundesagentur fĂŒr Sprunginnovationen

Title: Innovation and Regulation in Practice: Lessons Learned from Building Digital Identity Wallets

Biography: Christian Bormann is a Digital Identity and Cryptography Architect heading the team responsible for technical standards in the German EU Digital Identity Wallet project. An alumnus of RWTH Aachen University, he specialises in distributed systems, privacy-enhancing technologies, and the IoT. Christian actively shapes international technical specifications through contributions to the IETF, OIDF, W3C, and ETSI. Operating at the intersection of cryptography, engineering, and global standards, he is dedicated to building secure, interoperable, and user-centric infrastructures for Europe’s digital future.


Pierre Dewitte Pierre Dewitte

🇧đŸ‡Ș European Data Protection Supervisor

Title: Enforcing data protection law in the age of AI

Biography: Pierre Dewitte is a Legal Officer at the European Data Protection Supervisor (EDPS) and a Research Fellow at the KU Leuven Centre for IT & IP Law (CITIP). He holds a Bachelor and Master degree of Laws with a specialisation in Corporate and Intellectual Property law from the Université Catholique de Louvain, and an Advanced Master in Intellectual Property and from KU Leuven. Pierre started his career at CITIP, where he conducted interdisciplinary research on privacy engineering, smart cities and algorithmic transparency, and defended his PhD on data protection by design. He then joined the Supervision and Enforcement Unit at the EDPS, where he now supervises the operational activities of Europol and Frontex. Pierre remains affiliated to CITIP, where he teaches data protection law as a guest lecturer in various courses and supervises students in their research track.


Joanna Mazur Joanna Mazur

đŸ‡”đŸ‡± University of Warsaw

Title: How could data protection law inform the EU’s approach to competition/innovation nexus?

Abstract: Innovation is often presented as the ultimate goal of EU policies. Improving the EU’s competitiveness is seen as a means of achieving a higher level of innovation, and changing its approach to certain elements of competition law is one way of doing so. However, even within competition law enforcement, the relationship between mergers and innovation is not always straightforward. While allowing companies to merge is sometimes presented as a way to enable them to innovate more easily, other narratives also exist, emphasising that it is often smaller companies that develop the most innovative solutions.

One issue that is often overlooked in these considerations is the purpose that innovation should serve and the cost involved. Including broader considerations, such as data processing practices, within the scope of competition analysis could open up new ways of assessing companies’ behaviour within the area of competition law. As the Meta Platforms case illustrates, there is a place — or sometimes even an obligation — for including such considerations in proceedings. Thus, it seems worth asking what data protection law could offer in terms of the EU’s approach to the competition/innovation nexus.

Biography: Assistant Professor at the Faculty of Management at the University of Warsaw, analyst at DELab UW and the Center of Antitrust and Regulatory Studies. She defended her PhD thesis at the University of Warsaw in 2021. The thesis and the analysis conducted therein examined whether algorithms used in automated decision-making could be considered public information or official documents under European law. Since 2025, she has been a Principal Investigator in an OPUS project titled ‘New legal acts, old enforcement problems? Disentangling the complexities of the enforcement of EU law concerning digital technologies,’ funded by the National Science Centre, Poland. Her research interests include data protection law, algorithms, artificial intelligence and platforms regulation, and competition law. Her ORCID, where her publications can be found, is: 0000-0002-0417-5743.


Elena Pagnin Elena Pagnin

🇾đŸ‡Ș Chalmers University

Title: Privacy-Enhancing Cryptography? Uses, Misuses, and Myths

Abstract: Cryptography is often presented as a technical answer to privacy challenges. In practice, however, the effectiveness of cryptographic solutions depends on correct assumptions, precise system design, deployment choices, and the social and regulatory context in which they are deployed. Rather than treating cryptography as simply “good” or “bad,” this talk argues that its privacy value is contextual, perspective-dependent, and shaped as much by usability and regulation as by mathematics and technical constraints. The goal is to give participants a sharper way to reason about what cryptography can and cannot do for privacy, and to distinguish its intended uses from its misuse and from the consequences of its weakening or removal.

Biography: Dr. Elena Pagnin is an Associate Professor in the Department of Computer Science and Engineering at Chalmers University of Technology, Sweden, where she leads the CryptoTeam within the Security & Privacy Lab. Her research interests include the design of advanced public-key cryptosystems, with particular emphasis on authentication, transparency, privacy-enhancing technologies and verifiable systems. Her work addresses fundamental challenges in modern cryptography by developing practical and secure solutions for emerging applications. Dr. Pagnin has received competitive research funding, including a 2025 Swedish Research Council (VR) grant for her project on consistency protocols for transparency technologies. She is an active member of the international cryptography community, regularly invited to speak at academic and industry events, and is committed to bridging cutting-edge research with societal impact. Alongside her research, she is recognized for her dedication to teaching and mentoring and was nominated for Chalmers’ Pedagogical Prize in 2025.


Bart Preneel Bart Preneel

🇧đŸ‡Ș KU Leuven

Title: The Long Crypto Wars: Fifty Years of Encryption Policy

Abstract: The “Crypto Wars” describe the enduring tension between government demands for access to encrypted data in the name of national security and the protection of privacy and civil liberties. This talk traces the history of these conflicts, from efforts to suppress cryptographic research and restrict secure communications (such as the Clipper Chip), to high‑profile disputes over device access (Apple vs. FBI), and the deployment of commercial spyware (e.g., NSO Group).

More recently, attention has shifted to client-side scanning: filtering content on user devices before encryption or after decryption, ostensibly to detect child sexual abuse material (CSAM), but increasingly framed as a tool for counterterrorism and crime prevention. However, client-side scanning weakens end‑to‑end encryption, is vulnerable to misuse, and lacks demonstrated effectiveness. Our recent research shows that perceptual hash techniques used to identify known CSAM have high false positive/negative rates and are invertible. Proposals to use AI to detect AI‑generated CSAM raise additional concerns about reliability and accountability.

In Spring 2025, the EU’s ProtectEU initiative launched a roadmap to explore “lawful access” technologies by late 2026, marking a new phase of the crypto wars. While encryption poses challenges for law enforcement, authorities already possess extensive surveillance capabilities and metadata access. Rather than undermining encryption, policy efforts should prioritize strong cybersecurity, transparency around surveillance practices, and an open societal debate on balancing security with fundamental rights.

Biography: Bart Preneel is full professor heading the COSIC research group at the KU Leuven. His expertise lies in applied cryptography, cybersecurity, and privacy. He has delivered over 150 invited talks across 50 countries and received the RSA Award for Excellence in Mathematics (2014) and the ESORICS Outstanding Research Award (2017). He served as president of IACR (International Association for Cryptologic Research) and is also a fellow of the IACR. In 2024 he was elected member of the Royal Academy of Art and Sciences Belgium. He frequently consults for industry and government about cybersecurity and privacy technologies and he has testified multiple times for the Belgian and European Parliaments. Prof. Preneel founded the mobile authentication startup nextAuth and holds roles in Approach Belgium, Tioga Capital Partners, and Nym Technologies. He is actively engaged in cybersecurity policy debates.


Yixin Zou Yixin Zou

đŸ‡©đŸ‡Ș Max Planck Institute for Security and Privacy

Title: How Much Regulation is Enough? What the Public Thinks About AI and What That Means for AI Governance

Abstract: Narratives around AI tend to split into two camps: one sees it as a catalyst for progress, championed largely by AI companies; the other sees it as a source of harm, voiced by critical scholars and regulators. I’ll trace this divide through several recent studies from my group: first, how AI companies construct their own narrative of AI safety in public statements; then, how exposing ordinary people to these competing narratives shapes what they come to believe about AI; and finally, what happens when we ask the public directly, revealing a striking gap between how people actually perceive AI risk and how the EU AI Act categorizes it. Together, these studies suggest that the public’s own view of AI doesn’t map neatly onto either the “AI as progress” or “AI as harm” narrative. Even though the public wants more regulation than the status quo provides, few possess the technical understanding to assess that risk accurately. This leaves us with a puzzle central to this summer school’s theme: whose narrative should count in AI governance, and how might that answer shift as we move into the era of agentic AI?

Biography: Dr. Yixin Zou (she/her) is a tenure-track faculty member at the Max Planck Institute for Security and Privacy, where she leads the human-centered security and privacy group. Her research interests span human-computer interaction, privacy, and security, aiming to make technology safer and more equitable for underserved communities. Her research has been recognized with the ACM SIGCHI Outstanding Dissertation Award (2024), the John Karat Usable Privacy and Security Student Research Award (2022), and several best paper and honorable mention awards at top venues such as ACM SIGCHI Conference on Human Factors in Computing (CHI) and the Symposium on Usable Privacy and Security (SOUPS). Her research has also generated broader impacts on public policy, including the rule-making process for the California Consumer Privacy Act. She earned a Ph.D. in Information from the University of Michigan in 2022.