EU AI ACT IN PRACTICE: Bringing data protection into your action plan
20
3:00 PM - 3:45 PM
Most of the EU AI Act’s provisions now apply, with high-risk obligations taking effect from December 2027. The extended timeline gives organisations more time to prepare, but AI Act compliance shouldn’t be looked at in isolation. Where AI involves personal data, existing data protection obligations also need to form part of the plan as well as compliance and audit processes.
AI is also starting to support your GRC areas, such as policy reviews, control assessments and ongoing compliance monitoring. This makes the choice of technology, and how it is used, increasingly important, especially where accuracy, context, and professional judgement matter.
Join experts from CoreStream GRC (former Big 4 leader) and the DPO Centre to understand how data protection should fit into your EU AI Act compliance planning. This session will connect regulation and day-to-day governance, exploring how technology can be used effectively in GRC and wider business operations, without losing sight of accountability and oversight.
The discussion will explore:
- What the EU AI Act means for existing data protection and compliance programmes
- Where the AI Act and existing data protection obligations overlap
- How NIST AI RMF can support AI risk assessment and ongoing governance
- Where AI can support privacy teams, and where human judgement remains critical
The session will finish with an open Q&A, where you can put your AI governance and data protection questions to the panel.
Speakers
Michael McCagh
Data Protection Officer, DPO Centre
Michael is a highly qualified Data Protection Officer and certified AI Governance Professional. He has over 10 years’ experience advising organisations on global data protection legislation and AI compliance. Michael develops cross-jurisdictional privacy programmes and governance frameworks that support innovation while managing regulatory risk. With deep expertise in the EU AI Act and emerging technologies, he helps organisations stay ahead of rapidly evolving legal and compliance expectations.
David Smith
Data Protection Officer/AI Sector Lead, DPO Centre
David brings a wealth of data protection expertise, shaped by his in-depth DPO experience working across Technology and Healthcare sectors. As AI Sector Lead, he advises organisations on the responsible deployment of AI systems and compliance with global regulations. Known for his strategic approach to complex issues, David has supported high-stakes projects and contributed to national policy development within the NHS.
Aga Michalik
Data Protection Officer, DPO Centre
Aga is a CIPP/E and CIPM-certified data protection professional with strong, hands-on experience across EU data protection frameworks. She provides risk-based, business-focused advice that supports the development of effective privacy programmes within global organisations. With experience in the Financial Services and Legal sectors, Aga helps organisations embed practical controls and respond to evolving regulatory expectations in a clear and scalable way.
Lionel Matsuya
Head of Client Solution Design, Corestream
Lionel has 14 years’ experience helping organisations address risk and compliance challenges through effective governance, risk, and control frameworks. A Chartered Accountant with a background in professional services, he combines regulatory knowledge with extensive experience advising on technology-based solutions. Lionel takes an advisory-led approach to solution design, helping organisations translate their requirements into technology solutions that reflect industry best practice and support effective risk and compliance management.
20
3:00 PM - 3:45 PM