
MEET OUR 2026 JUDGES

Julia Bonder-Le Berre
Head of Global Privacy, Iron Mountain
šPortugal
Julia is Head of Global Privacy at Iron Mountain. Julia leads the global privacy program to ensure that Iron Mountain complies with applicable laws and privacy is embedded in our services and operationalized across the organization. Before that, Julia worked on global privacy programs at Hewlett Packard Enterprise and Mastercard and advised multinational organizations on privacy and data protection matters at BakerMcKenzie law firm. Julia served as a member of the IAPP European Advisory Board and she dedicates her pro-bono time to educate students and promote young privacy professionals affiliated with Queen Mary University of London.

Geraldine Scali
Partner, BCLP
šUnited Kingdom
Geraldine is the EMEA lead of data privacy and security, and has a focus on data protection, cybersecurity and Artificial Intelligence, with a specific emphasis on the financial services, life sciences and retail sectors.
She is a dual-qualified lawyer, admitted as a Solicitor in England and Wales, and as a French lawyer admitted to the Paris Bar, which together with her experience gained at US and International law firms over a period of nearly 20 years, makes her uniquely placed to give the best possible service to her global client base in the UK, Europe and the US.
She advises on all aspects of data privacy and security, with an emphasis on advising clients on the emerging laws that impact the development and implementation of AI solutions including the EU AI Act as well as the implementation of global data protection compliance programmes including UK/EU GDPR. cross-border data transfers, preparedness and management of personal data breaches and reporting. She also regularly advises on data protection issues in the context of complex cross-border investigations and litigation, corporate deals, and Inclusion & Diversity Programmes.

Gloria BƩgu
Senior Privacy Manager, Kenvue
šUnited Kingdom
With over 15 yearsā experience in privacy across a range of regulated, consumer-facing and technology led sectors, Gloria is a Senior Privacy Manager at Kenvue. A steering group member of the Black Privacy Professional Network, she has spoken publicly on privacy and AI, helping make complex privacy issues more accessible and relevant to wider audiences. Passionate about demystifying privacy, Gloria is also the founder of Privacy Pulse, an emerging privacy training and educational resources initiative designed to make privacy more practical, accessible and engaging.

Cristina Costache
Global DPO & CISO, Noventiq
šSpain
Cristina is a governance architect operating at the intersection of privacy, cybersecurity, and artificial intelligence ā a combination that remains rare at executive level and rarer still as an integrated discipline.
She serves simultaneously as Global Data Protection Officer, Chief Information Security Officer, and Chair of the AI Council at Noventiq, a global digital transformation and cybersecurity company operating across 60+ markets and 140+ legal entities. In this capacity, she is responsible for building and running the governance infrastructure that translates regulatory obligation into enterprise capability ā across data protection, information security, and responsible AI ā at genuine global scale.
With a 20-year legal background and operational experience spanning more than 60 jurisdictions, Cristina brings a practitioner's perspective to the full spectrum of privacy, security, and AI governance: from regulatory architecture and risk frameworks to board-level accountability and the design of controls that hold under audit. She was recently admitted to the EDPB Support Pool of Experts, recognising her standing in European data protection and her contribution to regulatory development at EU level.

Monica Simoes de Almeida
Vice President - Data Protection Officer, State Street Bank International
šGermany
Monica is a senior privacy and data protection leader who has spent more than 20 years helping organisations make sense of complex privacy regulatory challenges. Her career has taken her across financial services, payments, retail, professional services and technology, with senior roles at Mastercard, John Lewis Partnership, and leading law firms in the UK and Portugal. Monica is now the Data Protection Officer for State Street Bank International GmbH, based in Munich.
Determined on bringing clarity and calm to fast-moving privacy issues, Monica focuses on turning legal and regulatory requirements into practical frameworks that teams can understand and use. She has led global privacy programmes, built accountability and governance models, designed DPIA and risk assessment processes, supported data breach response, and advised on various privacy topics including international data transfers, data sharing initiatives, data protection agreements, e-privacy, AI and automation, outsourcing, third-party risk and privacy by default and by design.
Having been dually-qualified in Portugal and England and Wales, and now based in Munich, Monica brings an international and practical perspective to privacy leadership. She works closely with senior executives, boards, legal teams and business stakeholders, with a particular interest in helping organisations build privacy programmes that are sustainable, proportionate and trusted by the people who use them.
Monica is an experienced speaker, trainer and author, and has contributed to conferences and professional forums including IAPP, TechUK, PDP and the Portuguese Law Society.

Bas van Bentum
Senior Legal Counsel & Advocate / Data Protection Officer, NIBC Bank N.V
šNetherlands
Bas is Senior Legal Counsel and Data Protection Officer at NIBC Bank, bringing more than two decades of experience in privacy, financial services and corporate law. With a career spanning leading organisations including Bird & Bird, AKD and PwC, they combine deep legal expertise with practical experience in data protection, governance and commercial risk management.

Helen Dixon
Consultant, Mason Hayes & Curran
šIreland
Helen is a Consultant at Mason Hayes & Curran, specialising in digital regulation. Her career to-date has spanned senior roles in both private and public sectors. A former Commissioner of both the Data Protection Commission and Commission for Communications Regulation, she offers regulatory insight into the evolving oversight of global digital platforms and technology and data governance.

Liz Smith
PICCASO Awards 2025 Winner: SME - Outstanding DPO
šUnited Kingdom
Liz is a Senior Consultant at DataGuard and the 2025 PICCASO Privacy Award winner for Data Protection Officer of the Year. A respected data protection professional, DPO and conference speaker, she helps organisations navigate data protection challenges in a practical and people-focused way. Liz believes data protection is ultimately about protecting people, their rights, choices and dignity, and is passionate about helping organisations build cultures where good privacy practices become part of everyday business. For her, itās not just professional, itās personal: āIt isnāt just a work thing, itās a life thing.ā

Rosemary Jay
Senior Attorney, Hunton & Williams LLP
šUnited Kingdom
Rosemary is a senior consultant attorney at Hunton Andrews Kurth. She joined from Pinsent Masons LLP where she was head of the Information Law Practice. Prior to that she was the head of the Legal Office of the Data Protection Registrar (now the Information Commissioner) for 12 years. She has practiced in privacy law for over 30 years and is recognized as one of the top lawyers in the area of data protection in the UK. Her practice covers all areas of information law. She has worked with the Council of Europe and the European Commission on privacy issues in Europe and the Commonwealth Secretariat in West Africa. She has advised non-EU states on the adoption and drafting of privacy laws.
Rosemary is author of Sweet & Maxwellās Data Protection Law & Practice (5th edition 2020), and Guide to the General Data Protection Regulation. She has been a contributing editor to The White Book on data protection and an editor of the Encyclopedia of Data Protection and Privacy and contributed numerous articles to legal journals.
⢠Recognized as a Leader in Risk Advisory: Data Protection, Privacy and Cybersecurity, Legal 500 UK, 2013-2026
⢠Recognized with the PICCASO Privacy Award for Achievement, PICCASO, 2022
⢠Recognized as one of the worldās leading practitioners of Who's Who Legal Thought Leaders: Data 2024, 2013-2024
⢠Leader in the Field, Data Protection, UK-wide, Senior Statesperson, 2016-2026, Star Individual, 2015, Band 1, 2011-2014, Chambers UK
⢠Selected for inclusion in the Best Lawyers in the United Kingdom, Information Technology Law - Data Protection, Privacy & Data Protection Law, 2024
⢠Fellow of the British Computer Society

Emma Butler
Consultant, Creative Elephant
šFrance
Emma has run her own consultancy since 2021 helping organisations with data protection compliance as well as offering plain English editing and training. She started working in data protection in 2005 leading the ICOās international policy team. She was then an in-house DPO at both a multinational and a biometric digital identity SME. She now lives in south-west France helping clients across Europe and the UK.

Paul Dongha
Head of Responsible AI and AI Strategy, Natwest Group
šUnited Kingdom
Paul is the Head of Responsible AI and AI Strategy at one the UKs largest bank, leading a dedicated team of AI practitioners, and pioneering Responsible AI in financial services. Paul also leads the bankās AI Strategy to ensure AI provides not only a highly personalised customer experience but is also deployed ethically to augment colleaguesā day-to-day work.
Paul is also co-author of āGoverning the Machine: How to Navigate the Risks of AI and Unlock its True Potentialā (Bloomsbury Business, 2025), a practical guide to responsible AI which has since been named in the Amazon top 10 bestsellers in two categories and in the FT top 5 Business Books of the Month. Paul's influential work has been published throughout leading articles, including The AI Journal, The Green Business Journal, Business Reporter, Natwest, Evident AI Responsible AI Report, Irish Tech News and CIO Business World Magazine.
Paulās influence extends beyond corporate boardrooms and into the global arena, where he actively participates in international forums, policy discussions and projects aimed at setting global standards for responsible.
Paul has a PhD in Agentic AI and was previously a university researcher and lecturer in Computer science and AI.

Tom Woods
Associate Director - Privacy, Taylor Root
šUnited Kingdom
Tom recruits across the UK, Ireland, and US with a focus on placing digital regulation professionals, both permanent and interim across privacy, cyber security and responsible AI. Typical mandates include Data Protection Officers; AI Governance Leads and Information Security Managers. Tom has recruited across these spaces since 2016 and holds an MSc in Business of Football and a History degree from Cardiff University.

Charlie Gretton
National Account Executive - Dastra
šUnited Kingdom
Charlie is a National Account Executive at Dastra, where he jointly leads the platform's expansion into the UK and Ireland. A former Data Protection Officer, he is a Certified GDPR Practitioner, ISO/IEC 27701 Lead Auditor, and IAPP-certified Artificial Intelligence Governance Professional (AIGP). Having built his career at the intersection of privacy compliance and commercial practice, he brings a pragmatic, practitioner-informed perspective to the judging panel. Charlie is also a keen community-builder, he brings privacy professionals together through informal peer networking sessions, driven by a belief that the profession is strongest as a community.

Niamh Howard
Data Protection Officer and Operations Manager - Dornan
šUnited Kingdom
Charlie is a National Account Executive at Dastra, where he jointly leads the platform's expansion into the UK and Ireland. A former Data Protection Officer, he is a Certified GDPR Practitioner, ISO/IEC 27701 Lead Auditor, and IAPP-certified Artificial Intelligence Governance Professional (AIGP). Having built his career at the intersection of privacy compliance and commercial practice, he brings a pragmatic, practitioner-informed perspective to the judging panel. Charlie is also a keen community-builder, he brings privacy professionals together through informal peer networking sessions, driven by a belief that the profession is strongest as a community.
Brought to you by PICCASO & GRC World Forums.















