IAPP Europe Congress 2026
Privacy | AI governance | Cybersecurity law
Brussels
16-19 November
Conference
18-19 Nov.
Training
16-17 Nov.
Workshops
17 Nov.
Who Decides What Data an AI Agent Needs?
Wednesday, 18 Nov.
14:45 - 15:45 CET
Intermediate level
and decide their next steps toward a goal. That autonomy strains two of the GDPR's core principles: purpose limitation and data minimization. This session brings legal and technical perspectives together to examine how companies can define an agent's permissible scope through data access, tool permissions, memory boundaries and technical guardrails. We will look at open problems, including cross-border transfer assessments when an agent's path is nor predictable in advance and how run-level tracing can support GDPR Article 5(2) accountability, illustrated with real use cases.
What you will learn:
• How to translate purpose limitation and data minimization into concrete technical controls for agentic AI systems.
• What a cross-border transfer assessment looks like when an agent's processing path is not fixed in advance.
• How run-level tracing and logging can operationalize GDPR Article 5(2) accountability for autonomous agents.
Sponsored by EQS Group
Featured in this session

Luke Walker
Senior Product Marketer
Haystack by deepset

Alexander Hönsch Carpio
Solution Consultant Data Privacy
EQS Group