28 May 2025

Reflecting on the Inaugural CILIP Data Protection Conference 

By Jess Pembroke, Director of Information Law Service

I had the privilege of chairing our inaugural CILIP Data Protection Conference. It was a fantastic engaging day where we discussed the fast-evolving intersections of data protection, AI governance, and the practical realities of managing information as library and information processionals. Our thanks to the fantastic speakers for their insights and also CILIP for facilitating the event.  

The day was filled with rich discussion, thoughtful questions, and a shared sense of both urgency and opportunity. While many of us admitted to feeling overwhelmed by the pace of change, there was also a strong current of curiosity, resilience, and professional confidence. 

Key Themes and Takeaways 

🧠 The Role of Data Protection in AI Governance 

We opened with a keynote from Dr Kit Good (The Alan Turing Institute), who explored the evolving role of data protection in AI. His talk raised critical questions about accountability without authority—especially when AI tools make decisions that affect people’s rights.  

📜 Legislative Shifts and Global Implications 

Sue White (Naomi Korn Associates) unpacked recent and upcoming changes to UK data protection law. Her session sparked debate around the UK’s adequacy status with the EU, and whether organisations are truly aware of changes like Privacy and Electronic Communications Regulations PECR fine increased.  

🏛️ Public Sector Perspectives 

Sara Stock (DVSA) delivered a standout session, offering practical advice as an experienced Data Protection Professional. Her “7 tips for success” reminded us to frame advice positively, know the legislation, and build internal networks to support resilience. 

👧 Children as (Copy)Rights Holders: Canaries in the Coal Mine 

Jen Persson (Defend Digital Me) delivered a powerful and thought-provoking talk on the role of children as early indicators of systemic issues in data protection. She challenged us to consider how children’s data is often the first to be exploited or mishandled—and how this reflects broader societal trends. Her framing of children as “canaries in the coal mine” resonated deeply, especially in the context of AI-driven education tools and surveillance in schools. It was a timely reminder that data protection is not just a legal issue—it’s a human rights issue. 

📈 Improving Delivery Through IG Training and Development 

Catherine Cooper (Digital Notts) explored how Information Governance training and professional development can transform not just back-office functions, but also how organisations engage with the public. She highlighted the importance of embedding IG into project and programme delivery, and how this can empower teams to make better, more ethical decisions. She gave some great tips on engaging with professionals in procurement and project management and how they can help challenge suppliers and processors on their use of personal data. 

Lightning Talks: Fast, Focused, and Full of Insight 

We heard from a brilliant lineup of speakers on topics ranging from DPIAs in libraries to supplier due diligence, training techniques and research into data subject rights. A few standout reflections: 

  • Long-established skills of information governance professionals are relevant and reassuring in a fast-paced sector. 
  • There’s a growing tension between ethics, environmental concerns, and data protection and where these responsibilities lie. 
  • We need to develop the workforce’s knowledge and engage with work experience and professionals across the organisation within which we work. 

Panel Discussion: The Future of Data Protection 

Our closing panel brought together diverse voices to reflect on the biggest challenges ahead. The discussion included: 

  • What are the most significant challenges in data protection with the advancement of AI technologies? 
  • The impact of ICO’s approach to not fining the public sector? And the ICO’s approach to individuals and data subjects’ concerns.  
  • Do people trust AI systems to protect their privacy? 
  • The public attitude to cyber-attacks? 

There was consensus that existing processes like DPIAs are still useful—but need to evolve. We also discussed the importance of professional judgement, organisational context, and the confidence to represent our roles at the decision-making table. 

A huge thank you to all our speakers, panellists, and attendees for making this such a thought-provoking and energising event.  

Future Opportunities  

Take a look at our fantastic CPD Accredited courses including our beginner/refresher level Data Protection and Copyright Basics Bundle (running 16 & 17 June, 9:30am-1pm both days), for more information and to book your ticket go to: https://www.eventbrite.co.uk/e/copyright-basics-and-data-protection-basics-16-17-june-2025-930am-1pm-tickets-1038941892167 and our intermediate level AI, Information Security & Data Breach Management (running 24 September 2025, 9:30am-1pm) for more information and to book your ticket go to: https://www.eventbrite.co.uk/e/ai-and-information-law-privacy-24-september-2025-930am-1pm-tickets-1046750056597 

Resources 

For further resources on the topics covered during the event please see: Resources — Naomi Korn Associates including AI-DPIA.docx 

Recent News

Back to News

Discover more from Naomi Korn Associates

Subscribe now to keep reading and get access to the full archive.

Continue reading