Skip to main page content

Tilman Herbrich

Partner
Spirit Legal
Participates in 1 Session

Tilman Herbrich (CIPP/E) is an attorney at law and partner in the Data & Technology department at Spirit Legal. As a specialist in advertising technology and cloud services, he advises technology providers on product development and supports companies in the areas of procurement, customer management, and risk mitigation when adopting new technologies. He also leads the firm’s Privacy Litigation division at Spirit Legal.

Previously, he worked for many years in the legal department of a globally operating, market-leading textile group in the e-commerce sector and served as a research associate at the University of Leipzig.

Tilman is a member of the editorial board of the professional journal Datenschutz-Berater, member of the expert board of the Coalition for Privacy Compliance in Advertsing (CPCA) in UK, a lecturer at the University of Leipzig and a speaker for the German Lawyers' Institute (Deutsches Anwaltsinstitut) in Frankfurt as well as for the BECK Academy in Munich.

Sessions in which Tilman Herbrich participates

viernes 16 mayo, 2025

Zona horaria: (GMT+01:00) Paris
11:30
11:30 - 13:00 | 1 hour 30 minutos
Deep Dive In
Deep dive in and capacity buildingData regulation in practice

Every time we interact online, we leave behind tiny digital breadcrumbs, commonly referred to as cookies and trackers. They are powerful tools, but they also come with a big responsibility. In this session, which brings together legal professionals and DPAs, attendees will learn about the management of cookies and trackers in addition to innovative strategies and tools to handle cookies while staying compliant. 

Sessions in which Tilman Herbrich attends

martes 5 abril, 2022

Zona horaria: (GMT+01:00) Paris
9:00
9:00 - 9:30 | 30 minutos
Italian Sessions

Session in English interpreted into Italian / Sessione in inglese con la traduzione in italiano

10:30
10:30 - 11:00 | 30 minutos

The Coffee Break for all participants will take place in Scuola Grande di San Rocco.

11:00
11:00 - 12:00 | 1 hour
Innovative Technologies and Data ProtectionData Protection in Practice
12:00
12:00 - 13:00 | 1 hour
International CooperationItalian Sessions

Session in English interpreted into Italian / Sessione in inglese con la traduzione in italianoIn an increasingly interconnected world, highly inter-dependent, dealing with the challenges of the modern data-driven and digital world, though bringing tremendous benefits for our economies and societies, also becomes increasingly challenging for privacy and the protection of personal data.  

13:00
13:00 - 14:00 | 1 hour

The Lunch Break for all participants will take place in Scuola Grande di San Rocco.

14:00
14:00 - 14:20 | 20 minutos
Italian SessionsCybersecurityInnovative Technologies and Data Protection

Sessione in italiano / Session in ItalianIT:L'intelligenza artificiale pare essere pervasiva in tutte le nuove tecnologie che raccolgono e trattano dati personali, in diverse forme, a supporto delle decisioni aziendali. La valutazione della compatibilità di tali tecnologie con i diritti e le libertà fondamentali è in carico al Titolare ...

15:00
16:00
16:00 - 17:00 | 1 hour
Italian SessionsRegulatory EvolutionData Protection in Practice

 Sessione in italiano / Session in ItalianIT:La contitolarità nel trattamento dei dati personali: occasione di efficienza organizzativa per imprese ed enti pubblici nei mercati internazionali o adempimento oneroso, tra obbligatori accordi di riparto interno (art. 26 GDPR) e problematici criteri applicativi della contitolarità ai sensi delle Linee Guida 7/2020 EDPB sul concetto di ...

16:00 - 16:30 | 30 minutos
16:30
16:30 - 16:45 | 15 minutos
Italian Sessions

Session in English interpreted into Italian / Sessione in inglese con la traduzione in italiano

17:00
17:00 - 18:00 | 1 hour
Italian SessionsRegulatory EvolutionSocio-economic Perspective

Session in Italian / Sessione in italianoIT: Attorno al GDPR, l’Unione Europea sta mettendo a punto un ecosistema giuridico di protezione e valorizzazione delle informazioni: Regolamento 2018/1807, direttiva (UE) 2019/1024, direttiva (UE) 2019/770, Data Act, Data Governance Act, Digital Services Act, Digital Markets Act, Regolamento e-privacy, Regolamento Intelligenza Artificiale....

18:00
18:00 - 20:00 | 2 hours
Social Events

miércoles 6 abril, 2022

Zona horaria: (GMT+01:00) Paris
9:00
9:00 - 10:00 | 1 hour
Regulatory EvolutionData Protection in Practice

This session is devoted to a core aim of the GDPR: the rights of data subjects which were significantly strengthened. The speakers will present their views on different aspects of the rights, each from his own point of view. The aim of this session is to get a clearer picture: where do we stand now?

10:10
10:10 - 10:30 | 20 minutos
Italian Sessions

Session in English interpreted into Italian / Sessione in inglese con la traduzione in italiano

10:30
10:30 - 11:00 | 30 minutos
11:00
11:00 - 12:00 | 1 hour
International CooperationData Protection in Practice
12:00
12:00 - 13:00 | 1 hour
Data Protection in Practice
13:00
13:00 - 14:00 | 1 hour
14:00
14:00 - 15:00 | 1 hour
Innovative Technologies and Data ProtectionData Protection in Practice
15:00
15:00 - 16:00 | 1 hour
CybersecurityData Protection in Practice

This session will be the opportunity to deepen the main aspects of Data Protection by Design in Practice.

16:00
16:00 - 16:30 | 30 minutos
16:30
16:30 - 17:30 | 1 hour
Data Protection in Practice

jueves 7 abril, 2022

Zona horaria: (GMT+01:00) Paris
9:30
9:30 - 10:30 | 1 hour
Regulatory EvolutionData Protection in Practice
10:10
10:10 - 10:30 | 20 minutos
Italian Sessions

Session in English interpreted into Italian / Sessione in inglese con la traduzione in italianoA broad conversation about the impact of technology on society, regulation and what companies and policy makers ​can do to enable the use of technology for good while protecting individuals. 

10:30
10:30 - 11:00 | 30 minutos
11:00
11:00 - 12:00 | 1 hour
International CooperationRegulatory EvolutionData Protection in PracticeCybersecurity

lunes 17 abril, 2023

Zona horaria: (GMT+01:00) Paris
10:30
10:30 - 11:00 | 30 minutos

For morning coffee breaks from Monday 17 to Friday 21 April, vouchers will be available to enjoy a typical Italian coffee at  Caffè Rosso if you attend the sessions at Santa Margherita Auditorium or at Venice Eat if you attend the sessions at Ca’ Foscari or Ca' Dolfin. 

11:00
11:00 - 12:00 | 1 hour
Making Data Secure
CybersecurityData protection in practice
12:00
12:00 - 13:00 | 1 hour
Making Data Secure
Regulatory evolutionCybersecurity
13:00
13:00 - 14:00 | 1 hour

The buffet lunch will take place at the Court of Ca’ Foscari University next to the Welcome and Registration Desk.

14:00
14:00 - 15:00 | 1 hour
Making Data Secure
CybersecurityCross-border data transfers
14:00 - 15:00 | 1 hour
Convention 108+ special program
Convention 108+Regulatory evolutioninternational cooperationCross-border data transfers
18:00
18:00 - 18:30 | 30 minutos

We will wait for you at the Caffè Margaret DuChamp located at D. Duro 3019 on Campo Santa Margherita as of 6.00pm.  

martes 18 abril, 2023

Zona horaria: (GMT+01:00) Paris
9:30
9:30 - 10:30 | 1 hour
Data Protection in Italy
Sessions available in ItalianCybersecurity

Sicurezza della catena di fornitura ICT, conoscere e gestire in modo efficace il rischio Nella complessa realtà attuale il processo di esternalizzazione di una parte della gestione dei servizi ICT è da ritenersi scontato: l’affermazione crescente di piattaforme elaborative basate su servizi cloud ha impresso al mercato una rapida crescita, che nella maggior parte dei casi non risu...

10:30
10:30 - 11:00 | 30 minutos

For morning coffee breaks from Monday 17 to Friday 21 April, vouchers will be available to enjoy a typical Italian coffee at  Caffè Rosso if you attend the sessions at Santa Margherita Auditorium or at Venice Eat if you attend the sessions at Ca’ Foscari or Ca' Dolfin.In addition we will also offer a coffee break at Scuola Grande di San Rocco on Tuesday 18 April.

12:00
12:00 - 13:00 | 1 hour
International Cooperation
international cooperationCross-border data transfersData protection in practice

This panel will explore the interconnected nature of transatlantic cross-border data transfers with a variety of stakeholders. It will touch upon the EU-US Data Privacy Framework and other adequacy decisions as a means to bridge the gap between transatlantic data flows and standards. The panel will also explore key challenges to transatlantic data transfers, such as government access to data, and discuss international initiatives taken to develop a co...

13:00
13:00 - 14:00 | 1 hour

The buffet lunch will take place at Scuola Grande di San Rocco.

14:30
14:30 - 15:30 | 1 hour
Data Protection in Italy
Sessions available in ItalianInnovative technologies and data protection
18:00
18:00 - 18:30 | 30 minutos

We will have inaugurate the second edition of the Privacy Symposium on Tuesday 18th of April and enjoy the Official Welcome Reception at Scuola Grande di San Rocco at 6:00 pm.This Reception will take place In this magnificent building, dating back to the 15th century with of numerous artworks by the famous Venetian painter TintorettoFor your co...

miércoles 19 abril, 2023

Zona horaria: (GMT+01:00) Paris
10:30
10:30 - 11:00 | 30 minutos

For morning coffee breaks from Monday 17 to Friday 21 April, vouchers will be available to enjoy a typical Italian coffee at  Caffè Rosso if you attend the sessions at Santa Margherita Auditorium or at Venice Eat if you attend the sessions at Ca’ Foscari or Ca' Dolfin. 

12:00
12:00 - 13:00 | 1 hour
Accountability, Trust and PET
Regulatory evolutionData protection in practiceAccountability, trust and certificationFundamental rights
12:00 - 13:00 | 1 hour
Data Protection in Practice
Data protection in practice
13:00
13:00 - 14:00 | 1 hour

The buffet lunch will take place at the Court and the Spazi Espositivi at Ca’ Foscari University next to the Welcome and Registration Desk.

14:00
14:00 - 15:00 | 1 hour
Data Protection in Practice
Data protection in practiceFundamental rights
15:00
15:00 - 16:00 | 1 hour
Data Protection in Practice
Innovative technologies and data protectionData protection in practiceAccountability, trust and certification

As new data privacy regulations continue to emerge around the globe at the same time as digital transformation drives more business processes online, it's critical that there are trusted frameworks that allow companies to build trust and efficiently demonstrate compliance. This panel will dive into the EU Cloud Code of Conduct and discuss best practices for future interoperability between the EU Cloud CoC and other proposed frameworks.

15:00 - 16:00 | 1 hour
Technology and Compliance
Regulatory evolutionInnovative technologies and data protectionData protection in practiceFundamental rights
15:00 - 16:00 | 1 hour
Call for Papers

Technical and Legal Aspects Relating to the (Re)Use of Health Data when Repurposing Machine Learning Models in the EU

16:00
16:00 - 16:30 | 30 minutos
16:30
16:30 - 17:30 | 1 hour
Accountability, Trust and PET
CybersecurityInnovative technologies and data protectionData protection in practice
16:30 - 17:30 | 1 hour
Data Protection in Practice
Regulatory evolutionInnovative technologies and data protectionData protection in practiceFundamental rights

jueves 20 abril, 2023

Zona horaria: (GMT+01:00) Paris
10:00
10:00 - 10:30 | 30 minutos
International Cooperation
international cooperationRegulatory evolution
10:30
10:30 - 11:00 | 30 minutos

For morning coffee breaks from Monday 17 to Friday 21 April, vouchers will be available to enjoy a typical Italian coffee at  Caffè Rosso if you attend the sessions at Santa Margherita Auditorium or at Venice Eat if you attend the sessions at Ca’ Foscari or Ca' Dolfin. 

13:00
13:00 - 14:00 | 1 hour

The buffet lunch will take place at the Court and the Spazi Espositivi at Ca’ Foscari University next to the Welcome and Registration Desk.

14:00
14:00 - 15:30 | 1 hour 30 minutos
Technology and Compliance
Innovative technologies and data protectionFundamental rights
16:00
16:00 - 16:30 | 30 minutos
16:00 - 17:30 | 1 hour 30 minutos
Accountability, Trust and PET
17:00
17:00 - 18:00 | 1 hour
International Cooperation
international cooperationRegulatory evolution

viernes 21 abril, 2023

Zona horaria: (GMT+01:00) Paris
11:00
13:00
13:00 - 14:00 | 1 hour

The buffet lunch will take place at the Court and the Spazi Espositivi at Ca’ Foscari University next to the Welcome and Registration Desk.

lunes 12 mayo, 2025

Zona horaria: (GMT+01:00) Paris
11:00
11:00 - 11:40 | 40 minutos
AI and Compliance
Artificial IntelligenceRegulatory evolutionInnovative TechnologiesEnforcementInterpretation available

Generative AI development and deployment is exploding, but the recent EDPB Opinion 28/2024 and early enforcement actions (notably the fine against OpenAI by the Garante in Italy) signal that compliance with the GDPR must be taken seriously from the outset. Against this backdrop, our panel will explore how to build trust and avoid pitfalls when developing and deploying LLMs in Europe. We’ll examine the evolving legal landscape—and whether it leaves enough room for meaningful innovation....

13:00
13:00 - 14:00 | 1 hour
15:00
15:00 - 16:00 | 1 hour
Research and Innovation
Fundamental rights

The rapid expansion of Artificial Intelligence is reshaping the digital landscape, introducing both opportunities and challenges for consumer autonomy and data protection. AI has the potential to deliver highly relevant services, enhancing consumer engagement and satisfaction, but it can also generate outputs that may be misleading, inaccurate, or manipulative, potentially exacerbating consumer vulnerabilities and reducing consumer agency.

15:15
15:15 - 16:00 | 45 minutos
AI and Compliance
Artificial IntelligenceInnovative Technologies

This session brings together industry leaders and regulators to explore the essential aspects of designing compliant AI training models. In the discussion, panelists will provide a comprehensive overview of the intersection between regulatory requirements and innovative AI practices, offering practical advice and actionable insights for professionals in the field. Key topics include:  

16:00
16:00 - 16:30 | 30 minutos
17:15
17:15 - 18:15 | 1 hour
AI and ComplianceData Protection Certification
Artificial IntelligenceCertificationInnovative TechnologiesInterpretation available

AI systems are becoming more integrated into critical decision-making processes, which makes questions of liability and accountability more pressing than ever. If an AI-based decision goes wrong, who is responsible? This session will unite experts from Meta, Italian Institute for Privacy and Data Valorisation, AI Law Tech Institute, SGS, and CNPD to explore the evolving frameworks for AI liability and the role of certification in building respons...

18:30
18:30 - 19:30 | 1 hour
Social Events

We will inaugurate the fourth edition of the Privacy Symposium at the Official Welcome Reception. This event marks the beginning of a week rich in insightful discussions and open exchange, set in the inspiring atmosphere of Venice. Guests will have the opportunity to admire the remarkable works of Tintoretto, one of the city’s most celebrated painters, while connecting with professionals from diverse backgrounds and engaging in fruitful discussions. The evening will be enriched by...

martes 13 mayo, 2025

Zona horaria: (GMT+01:00) Paris
9:00
9:00 - 10:30 | 1 hour 30 minutos
Socio-economic Perspective
CertificationCross-border data transfers

The session will begin with the presentation of research work on the evaluation of the benefits of compliance (combining costs, returns, gains of compliance analysis). The objective will be then to discuss on the KPIs that can be used to measure the positive returns of compliance by incorporating the perspectives of stakeholders who advocate, monitor, implement, control, or finance compliance actions. 

10:30
10:30 - 11:00 | 30 minutos
11:00
11:00 - 11:50 | 50 minutos
International Cooperation
Cross-border data transfersInterpretation available

With evolving regulations and shifting privacy frameworks, how can businesses and privacy professionals navigate the global advancements of cross-border data transfers? This insightful session will explore the latest developments on a global scale, in addition to the latest trends and practical strategies for ensuring compliance. The panel includes high-level professionals from DG Justice, Information Commissioner’s Office, European Digital Right...

11:50
11:50 - 12:40 | 50 minutos
International Cooperation
Data regulation in practiceCross-border data transfersEnforcementInterpretation available

Standard Contractual Clauses (SCCs) have long been a go-to mechanism for ensuring compliance, but as different jurisdictions update their frameworks, the landscape is shifting fast. SCCs are defined as standardized clauses that allow data transfers outside of the European Economic Area. This insightful session explores the latest developments in SCCs across EU and beyond, with a special focus on the path towards in...

12:00
12:00 - 13:00 | 1 hour
Technology and Compliance
Innovative TechnologiesData regulation in practiceFundamental rights

Modern vehicles are more than just simple transportation; they are data hubs constantly collecting and transmitting information. From GPS tracking and in-car entertainment systems to AI-powered assistance, connected cars are revolutionizing the concept of mobility. The exceptional panel of this session will explore the fine line between convenience and surveillance, geolocation tracking, and how regulations are adapting.  

13:00
13:00 - 14:00 | 1 hour
14:00
14:00 - 15:00 | 1 hour
Technology and Compliance
Artificial IntelligenceInnovative Technologies

This panel will discuss emergent technologies that may reduce AI risks and possible regulatory responses to such technology. 

15:00
15:00 - 16:00 | 1 hour
Technology and Compliance
Innovative TechnologiesCross-border data transfers

There is a lack of consensus among governments about what it means to be trusted and how to determine what constitutes a trusted cloud service provider in the context of data protection and cybersecurity. Without a common framework and criteria to assess trustworthiness, there will continue to be a lack of trust in data flows, hindering innovation and growth in today’s data-driven economy. This panel will discuss the development of a criteria-bas...

16:00
16:00 - 16:30 | 30 minutos
18:00
18:00 - 19:30 | 1 hour 30 minutos
Social Events

After a productive day of engaging sessions, what better way to refresh than by enjoying a traditional Aperol Spritz at the Privacy Professionals’ Meet-up? Join us for a relaxed evening of conversation and connection over this iconic Italian cocktail. It’s a unique opportunity to get to know other participants of the Privacy Symposium, while enjoying a taste of the dolce vita in true Venetian style.

miércoles 14 mayo, 2025

Zona horaria: (GMT+01:00) Paris
9:00
9:00 - 10:30 | 1 hour 30 minutos
Deep Dive In
Deep dive in and capacity buildingInnovative TechnologiesData regulation in practice

This session promises to dive deep into the real-world impact of data anonymization and synthetic data, exploring how these techniques are being used to protect privacy in different industries. Experts of the panel will break down the myths and realities of these privacy-enhancing technologies, tackling their benefits, limitations, and regulatory challenges head-on. Key questions&nbsp...

10:30
10:30 - 11:00 | 30 minutos
11:00
11:00 - 11:45 | 45 minutos
Freedom of Expression and Data Regulation
Fundamental rightsRegulatory evolutionEnforcementInterpretation available

Aiming to balance a safe and competitive digital space with the right of free expression, the interplay of these two Acts forms a critical discussion when considering the place of freedom of expression in the broader topic of privacy and data regulation. Hearing from representatives from the European Commission and legal experts, attendees of this session will gain an insight into the interplay of the Acts and how they currently sit in relation t...

11:45
11:45 - 13:00 | 1 hour 15 minutos
Freedom of Expression and Data Regulation
Fundamental rightsRegulatory evolutionEnforcementInterpretation available

The panel of this session will investigate the growing debate around social media platforms placing, or not placing, restrictions on what can be posted online. Attendees will gain an insight into how these restrictions impact both individual users of the platforms and wider society through the perspectives of individual creatives and stakeholders. Key questions 

12:00
12:00 - 13:00 | 1 hour
Data Regulations in Practice
Cross-border data transfers

With international data transfers under increasing regulatory and judicial scrutiny, organizations must adapt to evolving compliance challenges. From the European General Court’s ruling in Bindl v Commission to ongoing discussions around the EU-US Data Privacy Framework, the need for redundancy in GDPR transfer tools to avoid overreliance on a single transfer mechanism is crucial. This panel will explore key legal developments, risks, and ...

13:00
13:00 - 14:00 | 1 hour
14:00
14:00 - 16:00 | 2 hours
Deep Dive In
CybersecurityDeep dive in and capacity building

Imagine this: A multinational company grappling with an unexpected ransomware attack. Stakeholders are on edge, the clock is ticking, and swift decisions are paramount. This isn’t just a test of your expertise, but also a measure of how well you can handle pressure, make crucial decisions with your team, and lead during chaos. This two times award finalist service (Finnish Comms Awards 2025 and 2025 SABRE EMEA ...

16:00
16:00 - 16:30 | 30 minutos

jueves 15 mayo, 2025

Zona horaria: (GMT+01:00) Paris
12:00
12:00 - 13:00 | 1 hour
Deep Dive In
Deep dive in and capacity buildingData regulation in practice

If you are interested in how to turn the principle of privacy into marketing practices that not only comply with the law but also resonate with the audience, then this session is for you. The panel will explore how to build privacy-first marketing strategies that respect consumer data while still driving engagement and delivering results.  Key questions 

15:00
15:00 - 16:00 | 1 hour
Health and Medical Data Compliance
Artificial IntelligenceInnovative TechnologiesData regulation in practiceInterpretation available

This session will cover the legal implications and real-world use cases of anonymization, pseudonymization, and synthetic data. From enabling secure data sharing for research and ensuring compliance in clinical trials, the panel will dive into how some techniques can help meet privacy requirements while still fostering scientific progress.  Key questions 

16:30
16:30 - 18:00 | 1 hour 30 minutos
Deep Dive In
Cross-border data transfersDeep dive in and capacity building

Under European law, a Transfer Impact Assessment is required when transferring personal data to third countries that are not recognized as having adequate data protection standards. It is the responsibility of the data controller to conduct the Assessment, ensuring among other factors that they evaluate the legal framework of the recipient country. This session will provide practical, hands-on guidance on how to effectively carry out a Transfer I...