Print

IPEN event on post-quantum cryptography

The EDPS and the Paris Lodron University of Salzburg would like to invite you to the Internet Privacy Engineering Network (IPEN) event on post-quantum cryptography entitled "The leap to post-quantum data protection" that will take place in the Salzburg on 8 September 2026. 

Post-quantum cryptography

This conference will explore the emerging risks that quantum technologies pose to cybersecurity and data protection, with a particular focus on how these threats affect long-term confidentiality, integrity and trust.

This conference will bring together experts from industry, academia, and public institutions to examine practical strategies for transitioning to post-quantum cryptography (PQC), highlighting current standards, implementation challenges, and migration pathways.

Throughout the event, we will explore fundamental and practical questions, including:

  • What is the quantum threat (including the “Harvest now, decrypt later”)? 
  • Why current cryptography is vulnerable and how can PQC help?
  • Investment in transition: How to leverage transition to PQC at managerial level?
  • Prioritise: Which systems should transition first? What are the biggest hidden dependencies?
  • Choice: How to choose the right tools? Should procurement processes today start requiring PQC roadmaps from vendors? 
  • What lessons from past crypto transitions apply, or don’t apply, here?
  • Standardisation: How much has it leveraged adoption so far?
  • Accountability obligations: Could failure to migrate be considered negligence? 
  • Article 32 GDPR: How should “state of the art” under the GDPR be interpreted in a context where future risks (quantum) are known but timelines are uncertain?
  • Article 33 GDPR: What will happen when the first data quantum-based breach happens? How can organisations and SAs prepare for this?
  • Should DPIAs explicitly include quantum risk scenarios today?
  • What PETs will be (mostly) impacted by the quantum revolution? 
  • What is the level of maturity of PETs in adopting PQC?

Join us, in person or online, as we examine the risks quantum cryptography may pose to individuals, and how organisations can prepare. 

The city and state of Salzburg invite the IPEN participants to attend a concert at the Mirabell Palace on the evening of 8 September - admission to the concert is free, but attendees should indicate this in their IPEN registration form below.

If you would like to attend IPEN in person, please register here.
Online participants do not need to register. The connection link will be published shortly.

You may also wish to register for the Annual Privacy Forum on the APF website (https://privacyforum.eu/)
 

IPEN events bring together privacy experts and engineers from public authorities, industry, academia and civil society to discuss relevant challenges and developments for the engineering and technological implementation of data protection and privacy requirements into all phases of the development process.
 

PROGRAMME

14:00 - 14:20 Welcome introduction Wojciech Wiewiórowski, European Data Protection Supervisor (EDPS)
14:20 - 14:40

Keynote speech

“Protecting today's secrets against tomorrow's attacks: what’s the impact of quantum transition for everyone”

Bart Preneel, Professor at KU Leuven
14:40 - 15:40

Panel 1:

“Preparing for the quantum transition: possible approaches and implications”

 

  • Ludovic Perret, Professor, EPITA & Associate researcher, Sorbonne University

 

 

Moderator: Prokopios Drogkaris, European Union Agency for Cybersecurity (ENISA)

15:40 - 16:00 Coffee break  
16:00 - 17:00

Panel 2:

“The cost of inaction - data protection risks of a late quantum transition”

 

 

 

Moderator: Giuseppe D’Acquisto (Garante per la protezione dei dati personali)

17:00 - 17:15 Concluding remarks Massimo Attoresi, EDPS Technology and Privacy Unit

SPEAKERS

Wojciech Wiewiórowski

Wojciech Wiewiórowski has been the European Data Protection Supervisor (EDPS) since December 6th 2019.

He is also an adjunct professor in the Faculty of Law and Administration of the University of Gdańsk. He was, among others, an adviser in the field of e-government and information society for the Minister of Interior and Administration, and the Director of the Informatisation Department at the Ministry of Interior and Administration in Poland. He also represented Poland in the committee on Interoperability Solutions for European Public Administrations (the ISA Committee) assisting the European Commission.

Wojciech Wiewiórowski was also the Inspector General for the Protection of Personal Data (Polish Data Protection Commissioner) between 2010-2014 and the Vice Chair of the Working Party Article 29 in 2014. In December 2014, he was appointed Assistant European Data Protection Supervisor. After the death of the Supervisor - Giovanni Buttarelli in August 2019 - he replaced Mr. Buttarelli as acting EDPS.

His areas of scientific activity include first of all Polish and European IT law, processing and security of information, legal information retrieval systems, informatisation of public administration, and application of new IT tools (semantic web, legal ontologies, cloud, blockchain) in legal information processing.

 

Bart Preneel 

Prof. Bart Preneel is full professor heading the COSIC research group at the KU Leuven. His expertise lies in applied cryptography, cybersecurity, and privacy. Prof. Preneel has delivered over 150 invited talks across 50 countries and received the prestigious RSA Award for Excellence in Mathematics (2014). He is a fellow of the IACR (International Association for Cryptologic Research) and a member of the Royal Academy of Art and Sciences Belgium and the Academia Europea. He frequently consults for industry and government about cybersecurity and privacy technologies and he has testified multiple times for the Belgian and European Parliaments. Prof. Preneel founded the mobile authentication startup nextAuth and holds roles in Approach Belgium, Tioga Capital Partners, and Nym Technologies. He is actively engaged in cybersecurity policy debates.

 

Sebastian Ramacher 

Sebastian Ramacher is a Senior Scientist in the Quantum-Safe Cryptography group at AIT Austrian Institute of Technology in Vienna, Austria. He received a PhD degree with distinction from Graz University of Technology in 2019. Sebastian's main research interests are in the field of public key cryptography with a focus on post-quantum signature schemes and their integration into protocols and applications. He is a co-designer of the post-quantum secure digital signature schemes FAEST, a 3rd round candidate in NIST's call for additional signature schemes, and PICNIC.

 

Ludovic Perret

Ludovic Perret is Professor (HDR) at EPITA, an associate member of LIP6 at Sorbonne University, and an associate researcher with the Cyber and Digital Sovereignty Chair – IHEDN, where he has led a working group on the impact of quantum computing on cybersecurity since 2023. He is also an alumnus of IHEDN's 5th National Session on "Digital Sovereignty and Cybersecurity" (SNC) (2022–2023).

With more than 100 academic publications, Ludovic specializes in the design and standardization of post-quantum cryptography, the security analysis of post-quantum primitives, their practical deployment, and the industrial and geopolitical issues surrounding this technology. He received the first Atos & Joseph Fourier Prize in quantum technologies in 2018 for his work and was ranked among the 100 most influential French innovators by Le Point magazine in 2022. 

He recently published the book “Post-quantum cryptography”.

 

Gamze Tillem

Dr. Gamze Tillem is a Security Architect at the Global CISO team of ING. With a Ph.D. in Applied Cryptography from Delft University of Technology, she now applies her expert knowledge in the banking sector, previously looking at innovative applications of cryptography and now focusing on architectural aspects.

 

Prokopios Drogkaris

Dr. Prokopios Drogkaris is a Cybersecurity Expert and deputy Data Protection Officer at the European Union Agency for Cybersecurity (ENISA). He is currently working in the areas of data protection engineering, PQC migration and Cyber Resilience Act Before joining ENISA in 2015, he was involved in several EU funded research projects in the greater area of Information Security within the Hellenic Ministry of Citizen Protection and he held teaching assistant positions in higher education institutions.

 

Christiane Peters

Dr. Christiane Peters is a Senior Cryptography Expert and Cloud Security Architect with nearly 20 years of hands-on expertise in post-quantum cryptography (PQC) and data security. She specializes in guiding enterprises through extensive digital transformations and leads Google Cloud's platform-wide PQC migration. She is a co-author of "Classic McEliece" - a NIST PQC standardization finalist.

 

Matthieu Lequesne

Matthieu Lequesne is a technological expert at the Commission Nationale de l'Informatique et des Libertés (CNIL), the French data protection authority. He holds a Ph.D. in computer science from Sorbonne Université (France), focused on the cryptanalysis of post-quantum cryptosystems. He worked as a postdoctoral researcher at CWI (Netherlands), where he contributed to the "PQC Migration Handbook". His current interests include the application of novel cryptographic techniques to personal data protection, security and privacy in digital healthcare systems, and the protection of neurodata.

 

Sofía Serrat Vallespín

Sofía Serrat is Senior Manager, Group Legal for Data & AI at Banco Santander and a member of the governance team supporting the Group's Quantum Security Programme. Over the past seven years, she has advised on the legal, governance and regulatory aspects of technology initiatives across Santander Group, including cybersecurity, data protection, artificial intelligence, quantum security and digital transformation. In her current role, she provides legal advice on Data & AI initiatives across the Group and contributes to the governance of Santander's quantum security programme. Previously, she advised Santander's Technology, Digital & Data and Cybersecurity functions. Before joining Santander, she served as Senior Lawyer and DPO within International Airlines Group (IAG) and worked in PwC's Technology Legal practice.

 

Jaime Gómez García 

Jaime Gómez García is a recognized expert in quantum security, with an extensive professional background within the financial sector. He is known for advancing strategic awareness, industry coordination, and practical adoption of quantum-safe cryptography, helping organizations and critical infrastructures prepare for the transition to the quantum era. His influence in the field has been recognized through multiple distinctions, including inclusion in Quantum Security 25: The Top 25 Most Influential People in Quantum Security (2026) and the 2025 Quantum Leap Award from Keyfactor. Currently, Jaime serves as the Global Head of the Santander Quantum Threat Program, addressing the transition to a quantum-safe economy. Additionally, he holds the role of Chair of the Europol Quantum Safe Financial Forum, working to facilitate collaboration and coordinate the transition to quantum-safe cryptography within the financial sector.

 

Giuseppe D’Acquisto

Giuseppe D’Acquisto is senior technology policy advisor for the Italian Data Protection Authority. He is the national delegate within the Technology Expert Group of the EDPB and the International Working Group on Data Protection in Technology. He has been appointed ENISA expert for Data Protection Engineering and EDPB representative on Artificial Intelligence within the High-Level Group of the European Commission for the Digital Markets Act. He is professor in Artificial intelligence at the University LUISS in Rome. He holds a degree in electronic engineering and a PhD in computer science.

 

Massimo Attoresi

Massimo is the Deputy Head of the Technology & Privacy unit of the EDPS, which he joined in 2012. From October 2014 to September 2020 he was also the Data Protection Officer of the EDPS. He provides advice on the impact of technology developments on privacy and other fundamental rights due to the processing of personal data. Among the topics he has been focussing on: cloud computing, online tracking and profiling, privacy of electronic communications, identity management, privacy and data protection by design and by default, data protection engineering, AI technologies and the protection of personal data. He graduated as an Electronic Engineer. After some years in the private ICT sector, he joined the European Anti-fraud Office. From 2007 to 2012 he worked as Data Protection Coordinator and Local Informatics Security Officer in a Directorate General of the European Commission.