
Tilman Herbrich (CIPP/E) is an attorney at law and partner in the Data & Technology department at Spirit Legal. As a specialist in advertising technology and cloud services, he advises technology providers on product development and supports companies in the areas of procurement, customer management, and risk mitigation when adopting new technologies. He also leads the firm’s Privacy Litigation division at Spirit Legal.
Previously, he worked for many years in the legal department of a globally operating, market-leading textile group in the e-commerce sector and served as a research associate at the University of Leipzig.
Tilman is a member of the editorial board of the professional journal Datenschutz-Berater, member of the expert board of the Coalition for Privacy Compliance in Advertsing (CPCA) in UK, a lecturer at the University of Leipzig and a speaker for the German Lawyers' Institute (Deutsches Anwaltsinstitut) in Frankfurt as well as for the BECK Academy in Munich.
Sessions in which Tilman Herbrich participates
viernes 16 mayo, 2025
Every time we interact online, we leave behind tiny digital breadcrumbs, commonly referred to as cookies and trackers. They are powerful tools, but they also come with a big responsibility. In this session, which brings together legal professionals and DPAs, attendees will learn about the management of cookies and trackers in addition to innovative strategies and tools to handle cookies while staying compliant.
Sessions in which Tilman Herbrich attends
martes 5 abril, 2022
Session in English interpreted into Italian / Sessione in inglese con la traduzione in italiano
The Coffee Break for all participants will take place in Scuola Grande di San Rocco.
Session in English interpreted into Italian / Sessione in inglese con la traduzione in italianoIn an increasingly interconnected world, highly inter-dependent, dealing with the challenges of the modern data-driven and digital world, though bringing tremendous benefits for our economies and societies, also becomes increasingly challenging for privacy and the protection of personal data.
The Lunch Break for all participants will take place in Scuola Grande di San Rocco.
Sessione in italiano / Session in ItalianIT:L'intelligenza artificiale pare essere pervasiva in tutte le nuove tecnologie che raccolgono e trattano dati personali, in diverse forme, a supporto delle decisioni aziendali. La valutazione della compatibilità di tali tecnologie con i diritti e le libertà fondamentali è in carico al Titolare ...
Session in English interpreted into Italian / Sessione in inglese con la traduzione in italiano
Sessione in italiano / Session in ItalianIT:La contitolarità nel trattamento dei dati personali: occasione di efficienza organizzativa per imprese ed enti pubblici nei mercati internazionali o adempimento oneroso, tra obbligatori accordi di riparto interno (art. 26 GDPR) e problematici criteri applicativi della contitolarità ai sensi delle Linee Guida 7/2020 EDPB sul concetto di ...
Session in English interpreted into Italian / Sessione in inglese con la traduzione in italiano
Session in Italian / Sessione in italianoIT: Attorno al GDPR, l’Unione Europea sta mettendo a punto un ecosistema giuridico di protezione e valorizzazione delle informazioni: Regolamento 2018/1807, direttiva (UE) 2019/1024, direttiva (UE) 2019/770, Data Act, Data Governance Act, Digital Services Act, Digital Markets Act, Regolamento e-privacy, Regolamento Intelligenza Artificiale....
miércoles 6 abril, 2022
This session is devoted to a core aim of the GDPR: the rights of data subjects which were significantly strengthened. The speakers will present their views on different aspects of the rights, each from his own point of view. The aim of this session is to get a clearer picture: where do we stand now?
Session in English interpreted into Italian / Sessione in inglese con la traduzione in italiano
This session will be the opportunity to deepen the main aspects of Data Protection by Design in Practice.
jueves 7 abril, 2022
Session in English interpreted into Italian / Sessione in inglese con la traduzione in italianoA broad conversation about the impact of technology on society, regulation and what companies and policy makers can do to enable the use of technology for good while protecting individuals.
lunes 17 abril, 2023
For morning coffee breaks from Monday 17 to Friday 21 April, vouchers will be available to enjoy a typical Italian coffee at Caffè Rosso if you attend the sessions at Santa Margherita Auditorium or at Venice Eat if you attend the sessions at Ca’ Foscari or Ca' Dolfin.
The buffet lunch will take place at the Court of Ca’ Foscari University next to the Welcome and Registration Desk.
We will wait for you at the Caffè Margaret DuChamp located at D. Duro 3019 on Campo Santa Margherita as of 6.00pm.
martes 18 abril, 2023
Sicurezza della catena di fornitura ICT, conoscere e gestire in modo efficace il rischio Nella complessa realtà attuale il processo di esternalizzazione di una parte della gestione dei servizi ICT è da ritenersi scontato: l’affermazione crescente di piattaforme elaborative basate su servizi cloud ha impresso al mercato una rapida crescita, che nella maggior parte dei casi non risu...
For morning coffee breaks from Monday 17 to Friday 21 April, vouchers will be available to enjoy a typical Italian coffee at Caffè Rosso if you attend the sessions at Santa Margherita Auditorium or at Venice Eat if you attend the sessions at Ca’ Foscari or Ca' Dolfin.In addition we will also offer a coffee break at Scuola Grande di San Rocco on Tuesday 18 April.
This panel will explore the interconnected nature of transatlantic cross-border data transfers with a variety of stakeholders. It will touch upon the EU-US Data Privacy Framework and other adequacy decisions as a means to bridge the gap between transatlantic data flows and standards. The panel will also explore key challenges to transatlantic data transfers, such as government access to data, and discuss international initiatives taken to develop a co...
We will have inaugurate the second edition of the Privacy Symposium on Tuesday 18th of April and enjoy the Official Welcome Reception at Scuola Grande di San Rocco at 6:00 pm.This Reception will take place In this magnificent building, dating back to the 15th century with of numerous artworks by the famous Venetian painter TintorettoFor your co...
miércoles 19 abril, 2023
For morning coffee breaks from Monday 17 to Friday 21 April, vouchers will be available to enjoy a typical Italian coffee at Caffè Rosso if you attend the sessions at Santa Margherita Auditorium or at Venice Eat if you attend the sessions at Ca’ Foscari or Ca' Dolfin.
The buffet lunch will take place at the Court and the Spazi Espositivi at Ca’ Foscari University next to the Welcome and Registration Desk.
As new data privacy regulations continue to emerge around the globe at the same time as digital transformation drives more business processes online, it's critical that there are trusted frameworks that allow companies to build trust and efficiently demonstrate compliance. This panel will dive into the EU Cloud Code of Conduct and discuss best practices for future interoperability between the EU Cloud CoC and other proposed frameworks.
Technical and Legal Aspects Relating to the (Re)Use of Health Data when Repurposing Machine Learning Models in the EU
jueves 20 abril, 2023
For morning coffee breaks from Monday 17 to Friday 21 April, vouchers will be available to enjoy a typical Italian coffee at Caffè Rosso if you attend the sessions at Santa Margherita Auditorium or at Venice Eat if you attend the sessions at Ca’ Foscari or Ca' Dolfin.
The buffet lunch will take place at the Court and the Spazi Espositivi at Ca’ Foscari University next to the Welcome and Registration Desk.
viernes 21 abril, 2023
The buffet lunch will take place at the Court and the Spazi Espositivi at Ca’ Foscari University next to the Welcome and Registration Desk.
lunes 12 mayo, 2025
Generative AI development and deployment is exploding, but the recent EDPB Opinion 28/2024 and early enforcement actions (notably the fine against OpenAI by the Garante in Italy) signal that compliance with the GDPR must be taken seriously from the outset. Against this backdrop, our panel will explore how to build trust and avoid pitfalls when developing and deploying LLMs in Europe. We’ll examine the evolving legal landscape—and whether it leaves enough room for meaningful innovation....
The rapid expansion of Artificial Intelligence is reshaping the digital landscape, introducing both opportunities and challenges for consumer autonomy and data protection. AI has the potential to deliver highly relevant services, enhancing consumer engagement and satisfaction, but it can also generate outputs that may be misleading, inaccurate, or manipulative, potentially exacerbating consumer vulnerabilities and reducing consumer agency.
This session brings together industry leaders and regulators to explore the essential aspects of designing compliant AI training models. In the discussion, panelists will provide a comprehensive overview of the intersection between regulatory requirements and innovative AI practices, offering practical advice and actionable insights for professionals in the field. Key topics include:
AI systems are becoming more integrated into critical decision-making processes, which makes questions of liability and accountability more pressing than ever. If an AI-based decision goes wrong, who is responsible? This session will unite experts from Meta, Italian Institute for Privacy and Data Valorisation, AI Law Tech Institute, SGS, and CNPD to explore the evolving frameworks for AI liability and the role of certification in building respons...
We will inaugurate the fourth edition of the Privacy Symposium at the Official Welcome Reception. This event marks the beginning of a week rich in insightful discussions and open exchange, set in the inspiring atmosphere of Venice. Guests will have the opportunity to admire the remarkable works of Tintoretto, one of the city’s most celebrated painters, while connecting with professionals from diverse backgrounds and engaging in fruitful discussions. The evening will be enriched by...
martes 13 mayo, 2025
The session will begin with the presentation of research work on the evaluation of the benefits of compliance (combining costs, returns, gains of compliance analysis). The objective will be then to discuss on the KPIs that can be used to measure the positive returns of compliance by incorporating the perspectives of stakeholders who advocate, monitor, implement, control, or finance compliance actions.
With evolving regulations and shifting privacy frameworks, how can businesses and privacy professionals navigate the global advancements of cross-border data transfers? This insightful session will explore the latest developments on a global scale, in addition to the latest trends and practical strategies for ensuring compliance. The panel includes high-level professionals from DG Justice, Information Commissioner’s Office, European Digital Right...
Standard Contractual Clauses (SCCs) have long been a go-to mechanism for ensuring compliance, but as different jurisdictions update their frameworks, the landscape is shifting fast. SCCs are defined as standardized clauses that allow data transfers outside of the European Economic Area. This insightful session explores the latest developments in SCCs across EU and beyond, with a special focus on the path towards in...
Modern vehicles are more than just simple transportation; they are data hubs constantly collecting and transmitting information. From GPS tracking and in-car entertainment systems to AI-powered assistance, connected cars are revolutionizing the concept of mobility. The exceptional panel of this session will explore the fine line between convenience and surveillance, geolocation tracking, and how regulations are adapting.
This panel will discuss emergent technologies that may reduce AI risks and possible regulatory responses to such technology.
There is a lack of consensus among governments about what it means to be trusted and how to determine what constitutes a trusted cloud service provider in the context of data protection and cybersecurity. Without a common framework and criteria to assess trustworthiness, there will continue to be a lack of trust in data flows, hindering innovation and growth in today’s data-driven economy. This panel will discuss the development of a criteria-bas...
After a productive day of engaging sessions, what better way to refresh than by enjoying a traditional Aperol Spritz at the Privacy Professionals’ Meet-up? Join us for a relaxed evening of conversation and connection over this iconic Italian cocktail. It’s a unique opportunity to get to know other participants of the Privacy Symposium, while enjoying a taste of the dolce vita in true Venetian style.
miércoles 14 mayo, 2025
This session promises to dive deep into the real-world impact of data anonymization and synthetic data, exploring how these techniques are being used to protect privacy in different industries. Experts of the panel will break down the myths and realities of these privacy-enhancing technologies, tackling their benefits, limitations, and regulatory challenges head-on. Key questions&nbsp...
Aiming to balance a safe and competitive digital space with the right of free expression, the interplay of these two Acts forms a critical discussion when considering the place of freedom of expression in the broader topic of privacy and data regulation. Hearing from representatives from the European Commission and legal experts, attendees of this session will gain an insight into the interplay of the Acts and how they currently sit in relation t...
The panel of this session will investigate the growing debate around social media platforms placing, or not placing, restrictions on what can be posted online. Attendees will gain an insight into how these restrictions impact both individual users of the platforms and wider society through the perspectives of individual creatives and stakeholders. Key questions
With international data transfers under increasing regulatory and judicial scrutiny, organizations must adapt to evolving compliance challenges. From the European General Court’s ruling in Bindl v Commission to ongoing discussions around the EU-US Data Privacy Framework, the need for redundancy in GDPR transfer tools to avoid overreliance on a single transfer mechanism is crucial. This panel will explore key legal developments, risks, and ...
Imagine this: A multinational company grappling with an unexpected ransomware attack. Stakeholders are on edge, the clock is ticking, and swift decisions are paramount. This isn’t just a test of your expertise, but also a measure of how well you can handle pressure, make crucial decisions with your team, and lead during chaos. This two times award finalist service (Finnish Comms Awards 2025 and 2025 SABRE EMEA ...
jueves 15 mayo, 2025
If you are interested in how to turn the principle of privacy into marketing practices that not only comply with the law but also resonate with the audience, then this session is for you. The panel will explore how to build privacy-first marketing strategies that respect consumer data while still driving engagement and delivering results. Key questions
This session will cover the legal implications and real-world use cases of anonymization, pseudonymization, and synthetic data. From enabling secure data sharing for research and ensuring compliance in clinical trials, the panel will dive into how some techniques can help meet privacy requirements while still fostering scientific progress. Key questions
Under European law, a Transfer Impact Assessment is required when transferring personal data to third countries that are not recognized as having adequate data protection standards. It is the responsibility of the data controller to conduct the Assessment, ensuring among other factors that they evaluate the legal framework of the recipient country. This session will provide practical, hands-on guidance on how to effectively carry out a Transfer I...