Skip to Content

IAPP Europe Congress 2026

Privacy | AI governance | Cybersecurity law

Brussels

16-19 November

Conference

18-19 Nov.

Training

16-17 Nov.

Workshops

17 Nov.

Back to conference agenda

Who Decides What Data an AI Agent Needs?

Wednesday, 18 Nov.

14:45 - 15:45 CET

Intermediate level

BREAKOUT SESSIONAI GOVERNANCEAI AND MACHINE LEARNINGINTERNATIONAL DATA TRANSFERSLAW AND REGULATIONPRIVACY ENGINEERINGRISK MANAGEMENTSTRATEGY AND GOVERNANCETESTING AND EVALUATIONTECHNOLOGY

and decide their next steps toward a goal. That autonomy strains two of the GDPR's core principles: purpose limitation and data minimization. This session brings legal and technical perspectives together to examine how companies can define an agent's permissible scope through data access, tool permissions, memory boundaries and technical guardrails. We will look at open problems, including cross-border transfer assessments when an agent's path is nor predictable in advance and how run-level tracing can support GDPR Article 5(2) accountability, illustrated with real use cases.

What you will learn:

• How to translate purpose limitation and data minimization into concrete technical controls for agentic AI systems.

• What a cross-border transfer assessment looks like when an agent's processing path is not fixed in advance.

• How run-level tracing and logging can operationalize GDPR Article 5(2) accountability for autonomous agents.

 

Sponsored by EQS Group

Featured in this session

headshot of Luke Walker

Luke Walker

Senior Product Marketer

Haystack by deepset

headshot of Alexander Hönsch Carpio

Alexander Hönsch Carpio

Solution Consultant Data Privacy

EQS Group