November 19, 2026
08:30am - 3:30pm
Conrad Hotel New York Downtown

New York Data Protection & Security Summit 2026

150+ data protection, privacy, security, and governance leaders. One room, one day. A fast-moving, peer-led summit on the pressures reshaping data protection and security: AI systems copying sensitive information into new environments, rising regulatory scrutiny, breach response, and growing third-party and cross-border risk. Free to attend. Register now.

New York Data Protection & Security Summit 2026
Sensitive data is spreading faster than most protection programs can track it.

RAG pipelines, copilots, vector stores, prompt logs, SaaS platforms, and cloud environments are duplicating, caching, and moving sensitive information into places traditional privacy and security programs were never built to see.

At the same time, regulatory expectations are rising, third-party exposure is becoming harder to assess, and teams are being asked to support AI adoption without losing control of the data underneath it.

You are still expected to perform the same impossible balancing act: keep the business moving, reduce risk, satisfy regulators, and prove that the right controls are working at any moment.

The New York Data Protection and Security Summit is a closed-door, practitioner-led event for the people carrying that responsibility every day. Privacy, security, governance, risk, legal, and data leaders come together to talk candidly about what is working, what is not, and what needs to change before today's blind spot becomes tomorrow's incident.

If you want to understand how your program compares with other leading organizations across New York, this is where you will find out.

This is not a conference you sit through. It is a working session with people facing the same pressures you are.

We keep it deliberately small and hands-on. The real value is in the conversations that are difficult to have anywhere else.

Here is how the day actually runs:

  • Practitioner keynotes from people who have dealt with these challenges firsthand
  • Peer roundtables where you tackle real problems alongside people in similar roles
  • Live scenarios the whole room works through together
  • Interactive panels you help steer from your phone
  • Structured networking designed to lead somewhere
  • Optional one-to-one meetings matched to your challenges
  • Knowledge challenges and prizes to put your thinking to the test

Free to attend. No vendor pitching. Just a room full of people who understand the responsibility.

Register now to secure your seat.

Our Speakers

No items found.

Agenda

8:30 AM
Registration Opens & Networking Breakfast

Beat the rush and join us early for complimentary barista-made coffee and breakfast.

No items found.
9:15 AM
Welcome & Opening Remarks
No items found.
9:20 AM
Opening Keynote: AI Has Already Copied Your Data. Can You Still Find It?

The hardest data security problem rightnow is not protecting the databases you know about. It is finding every placeAI has quietly copied what was inside them.

RAG pipelines, copilots, vector stores,evaluation sets, and AI-powered SaaS all duplicate, cache, and log sensitivedata faster than most teams can map it. Much of that data lands in systemstraditional security programs were never built to inspect.

This keynote is a practical look at how teams regain visibility across an AI-enabled environment. Where sensitive data turns up, which copies are hardest to pin down, and how to reduce the blindspots before they become part of the next breach.

We’ll cover

  • Where sensitive data now hides, from vector stores and prompt logs to evaluation sets and SaaS AI features
  • How to discover and classify AI-created copies without slowing adoption
  • Practical ways to remove, restrict, or protect exposed data before it becomes an incident
No items found.
9:40 AM
Keynote: The Future of Data Protection in an AI-Driven World

Explore the evolving challenges and opportunities that artificial intelligence introduces to data protection, emphasising risk management and ethical AI deployment.

  • Navigating new data vulnerabilities and AI-specific cyber threats such as deepfake fraud and automated phishing.
  • Balancing AI automation with human oversight to maintain security and ethical standards.
  • Leveraging AI technologies to enhance data protection capabilities without compromising privacy compliance.
No items found.
10:10 am
Panel: Can You Prove You Control Your Data?

Finding sensitive data is no longer enough. The harder question is whether you can prove it is governed.

Boards, auditors, and regulators want evidence. Who owns the data, who can reach it, how long it is kept, whether access is reviewed, and whether deletion really happened. In New York, this ismoving from an operational expectation to signed accountability. Since November1, 2025, DFS-covered entities have needed written policies for maintaining an inventory of their information systems, while annual Part 500 submissions aresigned by the highest-ranking executive and the CISO.

This panel gets into what defensible data governance actually looks like, and why programs that stop at discovery often fall apart when someone asks for proof.

We’ll discuss:

  • Moving from periodic discovery to continuous, evidence-based governance
  • Proving retention, access reviews, and deletion are happening across cloud, legacy, and AI environments
  • What senior leaders need to know before they put their names behind the organization’s controls
No items found.
10:40 am
How I Solved: Controlling What AI Can Reach and Do

Once AI can retrieve data, call tools, and take actions, access control stops being only about people.

Agents, copilots, and internal AI platforms often inherit broad permissions from the systems around them. That creates a new problem for security teams: controlling not only who can access sensitive data, but what an AI system can see, combine, and act on once it has that access.

This session looks at the guardrails that hold up when AI moves into daily use. How teams control agent identities, limit permissions, and keep humans involved when an AI system is allowed to do more than generate an answer.

We’ll cover:

  • The gateways, runtime controls, and approval points teams are putting around enterprise AI
  • Controlling the data, tools, and actions available to agents, copilots, and internal platforms
  • Keeping agent identities, permissions, and human sign-off under control as AI becomes more autonomous
No items found.
10:55 am
Morning Tea & Networking
No items found.
11:25 am
Audience Activity

In this innovative session, attendees will be faced with a series of scenarios that they may face in their roles. Attendees will discuss the possible courses of action with their peers to consider the ramifications of each option before logging their own course of action.

Results will be tallied and analysed by our session facilitator and results will impact the way the group moves through the activity.

Will we collectively choose the right course of action?

No items found.
11:40 am
How I Solved... Encrypting Data at Rest and in Transit: Practical Techniques

Discover how one organization strengthened its data protection posture by implementing encryption across critical systems without compromising performance, usability, or business operations.

  • Embed encryption into applications, cloud environments, and data storage to protect sensitive information.
  • Balance strong security controls with operational efficiency and user experience.
  • Overcome implementation challenges while meeting compliance and regulatory requirements.
No items found.
11:55 am
How I Solved... Data Loss Prevention Strategies in a Remote Work Environment

Remote work has transformed how organizations share and access information, but it's also created new opportunities for data loss. Learn how one organisation strengthened its DLP strategy to protect sensitive data without slowing down its workforce.

  • Protect sensitive data across endpoints, cloud applications, and collaboration platforms.
  • Reduce insider risk with intelligent monitoring, automation, and user education.
  • Balance strong security controls with the flexibility employees expect.
No items found.
12:10 pm
Panel: Where Privacy and Security Draw the Line on AI

Privacy and security protect the same data, but they do not start from the same question.

Privacy asks whether data should be collected, retained, or reused at all. Security asks who can reach it and how it should be protected. Once AI starts combining and repurposing enterprise data in ways nobody imagined when it was collected, those decisions can no longer be made in separate rooms.

This panel brings privacy and security leaders together to compare how they divide the work, where responsibilities overlap, and what happens when the two functions reach different conclusions.

We’ll discuss:

  • How privacy and security divide ownership of minimization, retention, and deletion
  • Preparing for new state privacy and AI rules without rebuilding controls market by market
  • Telling one defensible story about your data practices to regulators, boards, and customers
No items found.
12:40 pm
Roundtable Discussions
No items found.
1:30 pm
Lunch & Networking
No items found.
2:20 pm
QuickFire Quiz: Test Your Knowledge Against Your Peers

Put your knowledge to the test in this fast-paced quiz covering real-world trivia, key concepts, and emerging trends. Compete for bragging rights—and a travel voucher—as the top scorer takes the crown.

No items found.
2:35 pm
Afternoon Keynote: You Found the Risk. What Gets Fixed First?

Better discovery creates a new problem:too many findings.

Large organizations can surface millionsof sensitive records, thousands of exposed data stores, and years of redundantcopies. The real work is deciding which findings create meaningful businessrisk, which can be accepted, and which need an immediate control around them.

This keynote gets into how teams movefrom classifying everything to prioritizing what deserves action, then matchingthe response to the risk. Fix it, restrict it, encrypt it, tokenize it, ordelete it.

We’ll cover:

  • Deciding what to fix, restrict,encrypt, or delete first across cloud, AI, and legacy systems
  • Separating exposures that createreal business risk from lower-priority findings
  • Where encryption, tokenization,and masking earn their place, and where they are the wrong tool
No items found.
2:55 pm
Afternoon Keynote: Your Vendor Has Your Data. You Still Own the Risk

Sending data to a vendor does not send the accountability with it.

Cloud platforms, AI providers, and specialist SaaS tools now process some of the organization’s most sensitive information. The challenge is proving where that data goes, who can access it, whether it is being used to train models, and whether retention and deletion commitments are happening outside the contract.

This keynote gets into what actually holds vendors accountable, from diligence and contractual controls to technical verification and ongoing monitoring. It also looks at how teams keep pace with NYDFS, SEC, state privacy, and global requirements without turning every new vendor into a six-month approval process.

We’ll cover:

  • Verifying where vendors keep your data, who can access it, and whether it can be used to train models
  • Staying accountable after the data leaves the building through diligence, contracts, and continuous monitoring
  • Meeting US and global requirements as they change without stalling the business
No items found.
3:10 pm
Think Tank: The Breach Involves AI. What Was Actually Exposed?

Most incident response plans assume you can trace what data was involved. AI breaks that assumption.

Sensitive information may now sit in prompt histories, vector stores, evaluation sets, temporary caches, and third-party AI services that were never included in the original data map. When an incident happens, the first and hardest question becomes what was actually exposed.

This think tank brings security, privacy, legal, and data protection engineering leaders together to work through how breach response changes when AI is involved. In New York, that can mean reconciling the SHIELD Act with NYDFS and SEC requirements, while determining whether encryption held and whether the keys were also compromised.

We’ll discuss:

  • Scoping what was exposed when data has been copied far beyond production systems
  • Making disclosure calls across NYDFS’s 72-hour requirement, the SEC’s four-business-day deadline once a public company determines an incident is material, the SHIELD Act, and other state regimes
  • How encryption, tokenization, and masking change the real exposure, and how to prove those controls held after an incident
No items found.
3:40 pm
Networking Drinks Hour

Unwind with your peers for a couple of drinks on us.

No items found.
4:30 pm
Event Closed

Unwind with your peers for a couple of drinks on us!

No items found.

Our event sponsors

For sponsorship opportunities, please get in touch with Danny Perry, danny@clutchgroup.co

Past Speaker Highlights

Devon Bryan

SVP Global Chief Security Officer, Booking Holdings

Patty Voight

Executive Managing Director; CISO and Tech Risk Management, Webster Bank

Patrick Burke

Chief Data & Privacy Officer, Havas

Jo Ann Davaris

Chief Privacy Officer, Global Privacy, Booking Holdings

John Albus

Vice President Data Risk and Privacy, Natixis Corporate & Investment Banking

Anand Pallapalayam

Vice President, Enterprise Data Protection Leader, LPL Financial

Past Sponsors

Event Location

Conrad Hotel New York Downtown

102 N End Ave, New York, NY 10282, United States
New York Data Protection & Security Summit 2026

About Clutch

Hyper-Niche Content

Our conferences are specific to niche sub-sets of the technology industry, drilling down into the biggest issues, challenges and market trends facing tomorrow's leaders.

Collaboration first

Enjoy ample networking opportunities, roundtable discussions, interactive group sessions and real-world case-studies that arm attendees with actionable insights.

Dynamic & Bite-Size formats

No more death-by-PowerPoint. Our events are short, sharp and collaborative with a variety of session formats and a 3/4 day commitment to ensure returns on your time investment.

Get In Touch

Contact our event team for any enquiry

Danny Perry

Director of Sales
For sponsorship opportunities.
danny@clutchgroup.co

Lili Munar

Director of Client Relations
For guest and attendee enquiries.
lilibeth@clutchgroup.co

Steph Tolmie

Director of Conference Production
For speaking opportunities & content enquiries.
stephanie@clutchevents.co

Taylor Stanyon

Director of Operations
For event-related enquiries.
taylor@clutchgroup.co