The Croatian Personal Data Protection Agency (AZOP) hosted the 24th Meeting of Central and Eastern Europe Data Protection Authorities (CEEDPA) in Zadar on 25–26 September 2026, under the auspices of the Croatian Parliament. The event brought together representatives of data protection authorities from across Europe, alongside senior representatives of the European Data Protection Supervisor (EDPS), the European Data Protection Board (EDPB) and the Council of Europe.
Launched by the Polish data protection authority in Warsaw in 2001, CEEDPA provides an annual forum for authorities from Central and Eastern Europe to exchange knowledge, experience and good practices. The initiative aims to strengthen cooperation and raise awareness of personal data protection.
Opening the conference, AZOP Director and EDPB Deputy Chair Zdravko Vukić highlighted the opportunities offered by artificial intelligence, alongside the complex questions it raises about protecting individuals and ensuring accountability among those who develop and use AI systems.
“The challenges ahead are too great for any authority to tackle alone. More than ever, we need to work together to safeguard European values, human rights, freedoms and the rule of law. We may operate within different legal systems, but we share a responsibility towards the people who rely on us to protect their rights,” Vukić said.
Mirosław Wróblewski, President of the Polish Personal Data Protection Office, which founded the initiative, described the meeting as a valuable opportunity to explore the implications of emerging technologies for fundamental rights and data protection. “With authorities from across Europe taking part in this year’s workshops, we will all return home with practical knowledge that we can apply in our daily work,” he said.
In his keynote address, European Data Protection Supervisor Wojciech Wiewiórowski discussed the challenges of assessing the impact of AI systems on personal data protection and fundamental rights. He explained that fundamental rights impact assessments (FRIAs) under the AI Act, data protection impact assessments (DPIAs) and cybersecurity risk assessments increasingly overlap, while each serves a distinct purpose. He also stressed that the AI Act does not displace existing data protection and cybersecurity frameworks.
“The real measure of compliance is whether these assessments have improved how an AI system is designed, deployed, monitored and governed, and whether fundamental rights are effectively protected as a result—not simply whether an organisation has completed the required forms,” the Supervisor said. He concluded by emphasising the need for a coordinated approach to these assessments, while ensuring that the protection of fundamental rights does not become a purely procedural exercise.
The keynote session also addressed the European Health Data Space (EHDS) Regulation. Professor Paul Quinn of Vrije Universiteit Brussel described a pivotal transition from an approach to sharing health data based primarily on informed consent towards a framework in which consent is no longer the default legal basis for making those data available. He noted that many doctors remain unfamiliar with the EHDS and continue to place strong emphasis on the long-established principle of medical confidentiality.
Ana Tokhadze, representing the Council of Europe, highlighted the opportunities created by AI alongside the growing risks to privacy and personal data protection, particularly in healthcare. She explained that AI can reveal highly sensitive aspects of people’s lives, including genetic information and mental health conditions, and can infer health information from other data. Describing privacy protection as a democratic imperative, she stressed that technological progress must remain consistent with human rights, democracy and the rule of law. Tokhadze highlighted the complementary roles of Convention 108+ and the Council of Europe’s Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, and called for the prompt entry into force of the modernised data protection convention. She also drew attention to the Council of Europe’s ongoing work on data protection guidelines for large language models and neuroscience, as well as its practical support for responsible AI governance through the HUDERIA methodology and related training initiatives. Ana Tokhadze also thanked Anamarija Mladinić, a Vice-Chair of the Consultative Committee of Convention 108, for her work as rapporteur for the Council of Europe’s guidelines on data protection in the context of large language models (LLMs).
Two parallel workshops took place on the first day: one on data protection and fundamental rights impact assessments for AI systems, and the other on implementing the EHDS Regulation. The workshops were moderated by AZOP’s Anamarija Mladinić and Marko Trošelj, respectively.
During the DPIA and FRIA workshop, Isabel Barberá of the Dutch data protection authority explored how to ensure accountability and effective control over agentic AI systems, which can independently plan, use tools and carry out tasks. She presented a framework covering six areas of control, emphasising that accountability and safeguards must be built into systems from the outset and maintained throughout their life cycle. She highlighted the importance of clearly assigned responsibilities, effective human oversight, limits on AI agents’ permissions and the ability to monitor their actions, halt systems promptly and address the consequences of incidents.
Ana Tokhadze presented HUDERIA, the Council of Europe’s flexible, non-binding methodology for assessing the risks and impacts of AI systems on human rights, democracy and the rule of law. She explained how it combines an analysis of the context in which an AI system is developed and used with stakeholder engagement, detailed impact assessment and mitigation planning. Particular attention was given to involving people who may be affected, especially vulnerable groups, and tailoring safeguards to the severity and likelihood of potential harm. She also emphasised that assessments should be reviewed throughout an AI system’s life cycle as the technology and its wider context evolve.
Isabelle Vereecken, Head of the EDPB Secretariat, presented the DPIA template and discussed coordination with the European Commission on FRIAs and the DPIA template, as well as the joint guidelines on the interplay between the AI Act and data protection legislation.
Professor Alessandro Mantelero of Politecnico di Torino introduced a methodology for conducting fundamental rights impact assessments, developed in cooperation with the Catalan data protection authority and other partners. Participants then applied the methodology to two practical scenarios: the use of AI agents in public-sector recruitment and the use of AI to assess creditworthiness.
In the EHDS workshop, representatives of the Croatian, Irish and Dutch data protection authorities shared their countries’ experiences of preparing for implementation. Justin Ansotte of the Belgian Health Data Agency provided practical guidance on data minimisation, pseudonymisation, anonymisation and data linkage.
These presentations were followed by exercises involving two scenarios: access to a patient’s health data while receiving treatment in another Member State, and the use of health data for cross-border research. Participants explored how the EHDS and the GDPR apply to cross-border healthcare and research, focusing on access to and protection of health data, patients’ rights, secondary use, emergency access and access logs.
The practical sessions in both workshops gave participants an opportunity to exchange views, compare approaches and develop knowledge they could apply in their everyday work.
On the second day, representatives of the data protection authorities of Albania, Bosnia and Herzegovina, Czechia, Georgia, Croatia, Kosovo, Hungary, Poland, North Macedonia and Slovenia presented the challenges currently facing their authorities. AZOP representatives shared their experience of enforcing the General Data Protection Regulation in the context of AI systems.
The meeting also adopted the Zadar Declaration on Strengthening Regional Cooperation on Data Protection, Artificial Intelligence and Health Data, reaffirming the commitment of CEEDPA members to closer cooperation, particularly on artificial intelligence and health data. The Declaration calls for stronger cooperation, the responsible use of health data and careful assessment of the impacts of AI. It also underlines the need for data protection authorities to have the independence, expertise and resources required to fulfil their responsibilities.
The final part of the meeting focused on evaluating the effectiveness of the EDPB’s work. Dr Steffen Wiederhold, representing the Office of the German Federal Commissioner for Data Protection and Freedom of Information (BfDI), presented work on developing key performance indicators for the EDPB’s activities.
The meeting concluded with closing remarks from Isabelle Vereecken, who reflected on the main outcomes of this year’s gathering. She described the adoption of the Zadar Declaration as an affirmation of the authorities’ shared commitment to high standards of personal data protection and stronger regional cooperation. Thanking participants for their contributions to the meeting and workshops, she highlighted the value of exchanging knowledge and experience. The discussions in Zadar, she noted, demonstrated how cooperation and a shared approach can help authorities respond more effectively to the challenges posed by emerging technologies.





