IAPP Europe Congress 2026
Privacy | AI governance | Cybersecurity law
BRUSSELS
16-19 November
DSARs at a Breaking Point: Inside the New Reality of Employee Access Requests
Wednesday, 18 Nov.
14:45 - 15:45 CET
Intermediate level
Employee DSARs are no longer routine. They are now one of the most complex, resource draining and strategically sensitive challenges facing companies and institutions. With DSAR volumes rising, adversarial requests increasing and data spread across sprawling systems, DPOs are under pressure to deliver fast, defensible responses without overwhelming internal teams. In this lively, practical session, join four seasoned DPOs to reveal what really happens behind the scenes: the hidden pitfalls in HR and communication data, the new expectations around redaction accuracy and auditability and why employee DSARs increasingly intersect with litigation strategy. Panelists will share real world cases, mistakes that companies do not know they are making, and emerging best practices for scaling DSAR operations using smarter workflows and technology. Attendees will leave with actionable insights for transforming DSAR handling, from chaotic and reactive to structured, consistent and resilient.
What you will learn:
- How to manage high‑risk employee DSARs involving litigation, grievances and complex communications while ensuring fairness, consistency and defensible outcomes.
- How to reduce operational burden through clearer scoping, classification and automation without breaching timelines or transparency requirements.
- How to make robust, auditable redaction and exemption decisions that withstand regulatory or court scrutiny.
Featured in this session

Alistair Cole
CIPP/E
CEO
Privacy Culture

Cristina Costache
AIGP, CIPP/E, CIPM, CIPT, FIP
Global Data Protection Officer and Chief Information Security Officer
Noventiq

James Hawkins
Chief Privacy Officer

Monica Simoes de Almeida
CIPP/E
Vice President - Data Protection Officer
State Street Bank International