
Helen Findlay
Data Protection Officer, Directorate for Internal Audit and Assurance- Scottish Government
Chaired by the Scottish Government, join data privacy and information governance professionals at Holyrood Insight’s third annual Data Protection in Scotland Conference in Edinburgh.
As we enter the final phases of DUAA implementation and looking ahead to new regulatory expectations for 2026/2027, this informative, timely conference will examine the changing data protection landscape and what it means for organisations across Scotland.
You’ll gain expert guidance and best practice, tailored to the Scottish context, to help you to ensure organisational readiness in a rapidly evolving regulatory environment.
Hear directly from the regulator, with an update from Jenny Brotchie of the Information Commissioner’s Office – on regulatory priorities, expectations, and upcoming guidance.
We will share best practice guidance to help you to help you map your cross-border data flows, and address the growing complexity of complaint handling, DSARs, and ADM controls.
For organisations seeking to grow through marketing, research, and innovation, we will unpack the latest developments in data privacy – including digital identity, biometrics, research access, legitimate interests, PECR, cookie use
A key focus of the day will be information governance in the age of AI. Through case studies and expert insights, we will explore how to develop and deploy AI systems responsibly, ensuring outputs are transparent, explainable, and aligned with regulatory expectations. With Scotland’s forthcoming AI Strategy for 2026–2031, deepen your understanding of emerging AI risks and opportunities. With a reworked ADM regime under the DUAA, we will provide guidance on using AI and automated decision-making lawfully and ethically.
Put your questions to a legal expert in a dedicated session on the future regulatory environment. We will cover the impact of the FOI Reform (Scotland) Bill, and the UK Cyber Security and Resilience Bill. We will explore the implications of the EU AI Act , and the EU’s Digital Omnibus initiative for organisations operating across EU markets.
Don’t miss this unique, one-day event – attend to gain a comprehensive update on DUAA, and upcoming Scottish, UK, and EU legislation. Identify clear priorities for your organisation, and leave equipped with the knowledge and confidence to comply with the latest regulations.
In-person: this conference will take place at the COSLA Conference Centre, Haymarket Yards, Edinburgh. Attend this full-day event to network, build relationships and learn from your peers.SponsorshipInterested in sponsoring this event? Click here for sponsorship opportunities. View all our conferences, events and training here. Group discountsContact us for group rates. |

Data Protection Officer, Directorate for Internal Audit and Assurance- Scottish Government

Head of the Digital Citizen Division, Scottish Government

Senior Project Manager, Digital Office for Scottish Local Government

Information Governance Manager and Data Protection Officer, Research Data Scotland

Head of Scottish Affairs (Acting), Information Commissioner's Office (ICO)

Cyber Security Operations Analyst, Aberdeen

Data Protection Officer, Crown Office and Procurator Fiscal Service (COPFS)

CEO, Our AI Collective

Senior Project Manager, Digital Office for Scottish Local Government

Director of Digital, Data and IT, Scottish Enterprise

Head of Digital and Data Risk, Lloyds Banking Group

Records and Information Security Manager, Perth and Kinross Council

Privacy Consultant, Financial Conduct Authority

Data Protection Officer, Social Security Scotland

Head of Products, Insightful Technology Limited

Data Protection Officer, Directorate for Internal Audit and Assurance- Scottish Government
Brodies is the largest independent UK law firm headquartered in Scotland, in terms of turnover, staff figures and rankings. The quality of our legal advice and our people is consistently recognised by the leading independent legal directories with 71 practice areas top ranked.
With more than 850 people across our offices in Aberdeen, Edinburgh, Glasgow, Inverness and London, we remain committed to ensuring our lawyers give, and our clients receive, top quality legal advice. In addition to the full range of Scots law services we also deliver English law services in all main practice areas.
Dapian is a cloud-based platform that simplifies information governance for organisations of all sizes. It provides a fully integrated suite to manage Data Protection Impact Assessments (DPIAs), Information Asset Registers (IARs), Records of Processing Activities (RoPAs), Data Subject Access Requests (DSARs), Freedom of Information (FOI) requests, Data Sharing Agreements (DSAs), Data Breaches and Vendor Onboarding. Designed for both experts and non-experts, Dapian automates complex processes, guides users through compliance, and updates all modules simultaneously to ensure accuracy and reduce duplication. By empowering teams to take ownership of their data protection responsibilities, Dapian enhances efficiency and ensures robust compliance with GDPR.
Dastra is the platform that brings data privacy and AI governance together in one place. It helps organisations take control of their data protection responsibilities with tools for Records of Processing Activities (RoPAs), Data Protection Impact Assessments (DPIAs), Data Subject Access Requests (DSARs), and Freedom of Information (FOI) requests, along with dedicated modules for AI system inventories and cookie consent.
Built for users of all levels, Dastra’s fully customisable workflows simplify compliance and make audits easier. Trusted across Europe and now tailored for the UK, Dastra helps organisations work efficiently, stay transparent, and build lasting trust
This conference is CPD Certified.
Contribute 6 hours towards your Continuing Professional Development (CPD) and receive a certificate of attendance.



