LeADS Year in Review: 2022

As the year 2022 is coming to an end it is a good point in time to look back at the first LeADS year of our 15 ESRs. In November 2021 their collective research journey started to become Legality Attentive Data Scientists and to engage in research in four crossroads, i. e. major challenges that still need to be addressed in data-driven societies: 1. Privacy vs Intellectual Property 2. Trust in Data Processing & Algorithmic Design 3. Data Ownership 4. Empowering Individuals.

More than 7 Weeks of Intensive Interdisciplinary Training

On four occasions the ESRs met to attend a cross-interdisciplinary training program which constitutes a fundamental part of the LeADS project. Being capable of fully understanding the challenges posed by the digital transformation and data economy requires knowledge in different fields such as computer science, law, and economics. The project has therefore been structured around various training modules that together aim at training a new generation of researchers that become experts in both law and data science capable of working within and across the two disciplines.

Between November-December 2021, the ESRs first met each other in Pisa at Scuola Superiore Sant’Anna for their first three weeks of training focusing on a variety of topics ranging from big data analytics and applications, data mining and machine learning, or research ethics and methodology.

Between March and April 2022, the ESRs met again for two weeks Pisa. Whereas the first training modules involved mainly subjects related to computer and data science, this training module focussed more on the legal perspective. The ESRs were taught various topics such as EU cybersecurity law, data protection law, and how AI technology challenges the regulatory framework of intellectual property.

The next training module brought the ESRs to the beautiful island of Crete. In addition to courses on law and data science, the ESRs were divided into interdisciplinary groups for practical sessions to deploy a smart contract and to analyse and identify weaknesses in a security protocol.

Finally, the last module brought the ESRs together in Kraków at Jagiellonian University in September. The last training module concluded with reflections on data and ownership as well as discussions on problems the ESRs have encountered throughout their first year of research.

ESRs on their first day in Kraków

Throughout all training modules, the ESRs benefitted from the combined academic expertise that is available at the 7 beneficiaries of the Leads project (Scuola Superiore Sant’Anna, University of Luxembourg, Université Toulouse III – Paul Sabatier, Vrije Universiteit Brussel, Jagiellonian University, University of Piraeus, and Italian National Research Council (CNR)). In addition to courses taught by academics, the ESRs also had the chance to get insights into how problems and current discussions in the data economy are perceived by businesses, thanks to the active participation of the LeADS partners (Innov-Acts, ΒΥΤΕ COMPUTER S.A., Intel, the Italian Data Protection Authority, the Italian Competition Authority, Tellu, INDRA, and MMI).

Finally, in addition to these conventional learning practices, the ESRs also met at IRIT, Toulouse for the Technology Innovation in Law Laboratories (TILL) workshop. These two-part workshop series in the LeADS training program present the ESRs with the opportunity to do hands-on exploration of practical cases. Three different groups of ESRs had to solve challenges that were provided by LeADS partners (Indra, TELLU, and the Italian Competition Authority). The workshop provided the ESRs with the opportunity to translate their knowledge to concrete cases and receive feedback on the solutions which they developed.

The First year of Research

One of the first tasks of the ESRs consisted of drafting an individual personal career and skills development plan circlewhere they had to individually outline their planned activities and an evaluation of training needs and career goals for the upcoming years. Furthermore, the ESRs launched their research by drafting a research plan where they detailed research questions, methods, and proposed a first state-of-the-art analysis of the field of their own topic. During periodic meetings in the four crossroads of the LeADS project, the researchers presented their individual advances and discussed potential challenges. These early discussions allowed the ESRs to identify synergies and how their individual research could contribute to these four overarching challenges.

In addition to their individual research, the ESRs started collaborating closely together within the four crossroads since the beginning of their research journeys. The ESRs engaged with each other’s topics to create a collective report that has been nourished from the individual and collective research. Since the crossroads are composed of researchers from different academic backgrounds, discussions surrounding the different topics were interdisciplinary involving diverse perspectives from law, computer and data science, and economics. During regular meetings the Crossroads were therefore shaped through different perspectives. The result of this intensive process has been a 180-pages long report that constituted the first scientific output of the LeADS project and functions as a backbone for the upcoming research activities. Currently, the ESRs are working in inter-crossroads groups to collectively write working papers on diverse topics such as data governance models, data portability, or data ownership by design that will be published during the second trimester of 2023.

The First Year of Discussing and Presenting Research

Throughout 2022, several conferences have been organised by the LeADS consortium to discuss the latest developments in regulating the data economy. For Data Privacy Day an awareness conference on the explainability of AI was organised in collaboration with Brussels Privacy Hub and involved a panel of distinguished speakers such as Paul Nemitz of the European Commission, and Fosca Giannotti of Scuola Normale Superiore and CNR.

On two occasions in Crete and Toulouse, the ESRs had the opportunity to present their research at conferences during collective poster sessions. Further conferences and awareness panels were oftentimes organised with active participation of ESRs, such as the SoBigData++ and LeADS joint awareness panel on dynamic consent.

At the annual Computers, Privacy and Data Protection conference (CPDP), ESRs were participating in a dissemination and public engagement activity and many of the LeADS project beneficiaries’ contributed to the conference during panels and talks. During Researchers’ Night ESRs participated in various events in different countries, such as in Greece, Italy, Poland, or France. ESRs also individually applied and went to international conferences to present their research like in WarsawSeoul, Roskilde, Madrid, or Utrecht. ESRs filmed research pitches and used the LeADS blog to communicate on diverse topics such as critical reflections on Europol, European Health Data Spaces, predictive justice, data property, the data act, or data portability.

Finally, the research by ESRs got published in journals on topics such as consent, child protection in online games, the Data Act and B2G data sharing or consumer protection.

The first year of the ESRs research journey has been an exciting, challenging, and rewarding experience for all participating researchers. It brought together academics from different scientific and cultural backgrounds who are united in their passion on doing research across disciplines. We are very much grateful for the commitment of the multitude of people who have been actively contributing to the advancement and ongoing success of the LeADS project. We are looking forward to the upcoming year which is shaping up to be an even more productive year, with further opportunities for research and new collaborations.


LeADS Organises TILL Workshop and Conference on Data Sciences & EU Regulations

On the 7th and 8th of December 2022, the 15 Early Stage Researchers (ESRs) met again for the Conference on Data Sciences and EU Regulations and for the Technology Innovation in Law Laboratories (TILL) workshop in Toulouse, France. The events took place under the auspices of IRIT, Université Toulouse III – Paul Sabatier, one of the beneficiaries of the LeADS project.


Conference on Data Sciences and EU Regulations

The two-day LeADS event kicked off with the Conference on Data Sciences and EU Regulations organised by IRIT.The conference was divided into three sessions. The opening session consisted of two keynote talks. The first keynote was entitled “Technological Barriers & Opportunities for Data Sciences” by Jean-Michel Loubes from IMT-ANITI who presented his research on algorithmic bias. The second keynote, entitled “Barriers and opportunities for Data Sciences brought by EU Regulations” by Emanuel Weitschek from the Italian Competition Authority made an analysis of the current EU Regulations that provide opportunities for data sciences, such as the Data Markets Act.

The conference continued with the LeADS ESRs’ poster session, where they presented the development of their research.

The third and final session was a panel discussion on “Best practices for digital technology development in the era of big regulation” with Gabriele Lenzini from University of Luxembourg, Jessica Eynard from Université Toulouse 1 Capitole, Nicolas Viallet from Université de Toulouse, and Teesta Bhandare from Art Garde. The panel covered many topics such as AI for art tokens, online age verification and children’s safety on the internet, and the relevant EU policy and regulatory measures.


Technology Innovation in Law Laboratories (TILL) Workshop

On the second day, the ESRs gathered at IRIT again for the Technology Innovation in Law Laboratories (TILL)workshop. These two-part workshop series in the LeADS training program present the ESRs with the opportunity to do hands-on exploration of practical cases. The goal of the TILL workshops is to go beyond the conventional learning practices and focus on horizontal interactions and collaborative learning. TILLs also aim to prepare the ESRs for their upcoming secondments (at companies and regulators) in terms of knowledge transfer and in a more general pedagogical context seeking to reconcile the different vocabularies and practices around technology and law. 

The first one of the TILL workshops was co-organised by the LeADS beneficiaries Vrije Universiteit Brussel (VUB) and University of Luxembourg. The practical cases to be worked on were provided by the LeADS partners TELLU, Italian Competition Authority (AGCM) and INDRA.

The workshop kicked off with an introduction by Imge Ozcan from VUB and Arianna Rossi and Marietjie Botes from University of Luxembourg. Following this introductory session, the workshop continued in breakout sessions where the ESR teams worked on the practical cases.


Team 1 was composed of ESRs Xengie Doan, Fatma Sumeyra Dogan, Aizhan Abdrassulova, and Soumia Elmestari. They worked on a use case on health personnel access to e-health data provided by TELLU. Supported by their mentors Arianna Rossi (University of Luxembourg) and Katarzyna Południak-Gierz (Jagiellonian University), the group of ESRs discussed solutions and proposed a health data management prototype that offers read access only to patient data, 2F authentication, encryption, and easy opt-out solutions.

Team 2, formed of ESRs Tommaso CrepaxBarbara LazarottoMitisha GaurQifan Yang, and Louis Sahiworked on a practical case related to data portability provided by the Italian Competition Authority. With the support of their mentors, Marietjie Botes (University of Luxembourg) and Ali Mohamed Kandi (Toulouse III-Paul Sabatier University), the team worked on an Instagram story as a case study and came up with a data portability proposal, covering several crucial aspects such data protection, IP Law, technical standards and economic implications.



Team 3, formed by ESRs Armend Duzha, Onntje Hinrichs, Cristian Lepore, Maciej Zuziak, and Robert Poe, worked on a practical case on biometrics deployment in security systems provided by INDRA. Supported by their mentors Gloria González Fuster (VUB) and Gabriele Lenzini (University of Luxembourg), the team proposed a holistic solution providing innovative technical recommendations in line with the security rules for attaining Facility Security Clearance (FSC) and data protection rules embodied in the GDPR​.

In the late afternoon, the ESR teams presented their findings in an interactive session and received questions and feedback from the LeADS members and other participants. Claudia Castillo Arias (INDRA), José Francisco Suárez Mulero(INDRA), Liubov Kokorina (TELLU) and Emanuel Weitschek (AGCM) also joined the interactive session to provide feedback on behalf of the partners that provided the practical cases.

The ESRs were encouraged to build on the work developed during this workshop and were offered further collaboration opportunities by LeADS partners and beneficiaries. The second TILL workshop will take place in December 2023.

Further information

Conference overview  | Blog post on the topic

ESRs Bárbara and Onntje at Digital Legal Talks 2022

On November 24th 2022, ESRs Bárbara Lazarotto and Onntje Hinrichs participated in the Digital Legal Talks in Utrecht. The event was the third annual conference organised by the Digital Legal Lab, which is a research network that is constituted of Tilburg University, University of Amsterdam, Radbound University Nijmegen, and Maastricht University. The topic of the conference was dedicated to law and technology and focused on a wide variety of topics such as responsible data sharing, enforcement and the use of technology, the recently proposed and passed EU data laws, and involved as keynote speakers Sandra Wachter from the Oxford Internet Institute and Thomas Streinz from NYU School of Law (for more information consult the program of the conference). Onntje and Bárbara both presented their research in relation to the Data Act Proposal (DA proposal). However, each focussed on different aspects. Whereas Onntje discussed what the DA does or does not do for consumers, Bárbara focused on the Business-to-Government data sharing aspects of the proposal.

In his presentation “The Data Act Proposal: A Missed Opportunity for Consumers”, Onntje presented his perspective on why the DA might fail its objective of “empowering individuals with regard to their data” (a more extensive version of his findings has been published in Privacy in Germany 06/2022 (PinG)). His presentation therefore focussed on the B2C data sharing provisions in chapter II of the proposal. The DA contains various provisions that are supposed to strengthen consumer protection such as (i) an obligation to design IoT products in a way that data are accessible by default (ii) pre-contractual information obligations on data generated by IoT products (iii) obligation for data holders to make data available free of charge upon request by consumers (iv) data holders can only use any non-personal data generated by IoTs on basis of a contract (v) right to share data with third parties (including various provisions that offer protection to consumers in their relation to third-parties). 

Onntje concluded, however, that these provisions might not be sufficient to empower consumers with regard to ‘their’ data as claimed by the proposal – instead, they might strengthen (or at least confirm) the position of data holders as de-facto owners of IoT-generated data in B2C relations: First, the access rights are likely to be designed in a very restrictive way. Instead of allowing consumers to port data, data holders will likely only be obliged to ‘make data available’. Second, the obligation imposed on data holders to conclude a contract as the basis for use of any non-personal data generated by IoT devices would not provide any meaningful protection to consumers. Due to the complete lack of any safeguards with regard to that contract, it would not solve any problems related to control but only legitimize them. By confirming the de facto ownership position of data holders as de facto owners of IoT data, the DA would therefore fail to create any incentives for data holders to design their products in a more privacy-friendly way. To provide more meaningful protection, the DA could have introduced, for instance, provisions that sanction unfair contract terms with regard to devices that excessively collect and process data which are entirely unrelated to the product or the services it provides.

In her presentation “The implications of the Proposed Data Act to B2G data sharing in smart cities”, Barbara made an analysis of how business-to-government data sharing provisions of the DA can be applicable to smart cities contexts. Chapter V creates a general obligation to make privately held data available based on “exceptional needs”, highlighting the circumstances in which those needs would exist, namely public emergencies and situations in which the lack of data prevents the public sector from fulfilling a specific task in the public interest. In a general analysis of Chapter V, Barbara expressed that some recent modifications made by the Czech Presidency gave the Proposal a different dimension especially when it comes to the possibility of the development of smart cities. The adoption of a more detailed Recital 58, which now defines guidance on what can be considered lawful tasks in the public interest, opens the path to a discreet development of smart cities. The modifications also have enhanced the connections of the Act with other regulations, especially with the GDPR, demanding stricter personal data protection measures by the public sector, a matter that was a source of criticism by many opinions on the Proposal.

Overall, Bárbara concluded that the recent changes can be considered a good step when it comes to enhancing personal data protection in business-to-government data sharing and also creating a lawful basis for the sharing of data in the public interest which can benefit the development of smart cities. Nevertheless, she highlighted that the Proposal still falls short of having a broad impact on these contexts since it does not fight against the power imbalance between municipalities and the private sector, nor creates measures against the “silo mentality” that infiltrates data-sharing provisions between the businesses and governments in smart cities contexts. Bárbara was also invited to participate in a Panel on “Transparency Rules for Digital Infrastructures” organized by Max van Drunen and Jef Ausloos. The Panel started with a general comparison between the Data Act and Digital Services Act on access to data for research purposes. The issues with labeling “vetted researchers” and what it means to be a researcher was topic of discussion. At last, the “dependence on data” to conduct research was debated.

