Skip to Content

IAPP Europe Congress 2026

Privacy | AI governance | Cybersecurity law

BRUSSELS

16-19 November

Back to conference agenda

One Incident, Three Investigations: The Governance Challenge Beyond Notification

Thursday, 19 Nov.

09:45 - 10:45 CET

Advanced level

BREAKOUT SESSIONAI GOVERNANCECYBERSECURITY LAWPRIVACYAI AND MACHINE LEARNINGENFORCEMENTFRAMEWORKS AND STANDARDSINCIDENT MANAGEMENTRISK MANAGEMENTHEALTHCAREPROFESSIONAL SERVICESTECHNOLOGY

As the EU Digital Omnibus signals convergence toward unified incident intake across GDPR, NIS2 and the AI Act, a harder governance problem emerges: what happens after the notification is made? A single AI-enabled incident triggers three parallel regulatory investigations by the DPA, the competent NIS2 authority and the AI market surveillance authority, each with different evidentiary standards, different disclosure timelines and different closure mechanisms. Managing these as three independent processes creates three specific failure modes: inconsistent factual disclosure across parallel investigations, timeline asymmetry that forces premature or incomplete disclosure, and closure asymmetry that leaves residual liability open long after the incident is formally resolved under each individual framework. This session builds the governance architecture for end-to-end incident management across all three frameworks simultaneously: a unified documentation standard, a consistency protocol for parallel regulatory dialogues and a coordinated closure framework designed to reduce residual exposure.

What you will learn:

  • Why parallel post-notification management across GDPR, NIS2 and the AI Act creates three specific failure modes: inconsistent disclosure, timeline asymmetry and closure gaps, and what each one costs in practice. 
  • How to build a unified post-notification documentation standard that produces consistent factual accounts across three simultaneous regulatory investigations of the same event. 
  • What a coordinated closure architecture looks like and how to design it so that resolution under one framework. 

Featured in this session

generic profile silhouette

Camille Schneider

AIGP, CIPP/E

Senior Privacy Manager, Corporate Counsel

Thermo Fisher Scientific

headshot of Arnav Joshi

Arnav Joshi

Partner

Perkins Coie

generic profile silhouette

Caroline Kimber Zurawska

AIGP, CIPP/E, CIPM

Senior Consultant, GDPR and AI Governance

generic profile silhouette

Gianluca Martinelli

AIGP, CIPP/E, CIPM, CIPT

Privacy and AI Governance Professional