Skip to Content

IAPP Europe Congress 2026

Privacy | AI governance | Cybersecurity law

BRUSSELS

16-19 November

Back to conference agenda

DSARs at a Breaking Point: Inside the New Reality of Employee Access Requests

Wednesday, 18 Nov.

14:45 - 15:45 CET

Intermediate level

BREAKOUT SESSIONPRIVACYDATA SECURITYEMPLOYMENT AND HRLAW AND REGULATIONPROGRAM MANAGEMENTREGULATORY GUIDANCEFINANCE AND BANKINGGOVERNMENTHEALTHCARE

Employee DSARs are no longer routine. They are now one of the most complex, resource draining and strategically sensitive challenges facing companies and institutions. With DSAR volumes rising, adversarial requests increasing and data spread across sprawling systems, DPOs are under pressure to deliver fast, defensible responses without overwhelming internal teams. In this lively, practical session, join four seasoned DPOs to reveal what really happens behind the scenes: the hidden pitfalls in HR and communication data, the new expectations around redaction accuracy and auditability and why employee DSARs increasingly intersect with litigation strategy. Panelists will share real world cases, mistakes that companies do not know they are making, and emerging best practices for scaling DSAR operations using smarter workflows and technology. Attendees will leave with actionable insights for transforming DSAR handling, from chaotic and reactive to structured, consistent and resilient.

What you will learn:

  • How to manage high‑risk employee DSARs involving litigation, grievances and complex communications while ensuring fairness, consistency and defensible outcomes. 
  • How to reduce operational burden through clearer scoping, classification and automation without breaching timelines or transparency requirements. 
  • How to make robust, auditable redaction and exemption decisions that withstand regulatory or court scrutiny.

Featured in this session

generic profile silhouette

Alistair Cole

CIPP/E

CEO

Privacy Culture

headshot of Cristina Costache

Cristina Costache

AIGP, CIPP/E, CIPM, CIPT, FIP

Global Data Protection Officer and Chief Information Security Officer

Noventiq

generic profile silhouette

James Hawkins

Chief Privacy Officer

headshot of Monica Simoes de Almeida

Monica Simoes de Almeida

CIPP/E

Vice President - Data Protection Officer

State Street Bank International