Privacy Policy

Privacy Policy – Next IT Security

Last updated: 4 September 2026

1. Who we are

This website is operated by Grand IT Security AB, registered at Regeringsgatan 93, 111 93 Stockholm, Sweden, company registration number 559522-2802 (“we”, “us”).

We are the controller of the personal data described in this policy. For any question about it, write to [email protected].

2. What this policy covers

It covers personal data we collect through this website, through our events, and through correspondence with attendees, speakers, partners and sponsors. It does not cover websites we link to, which have policies of their own.

3. What we collect, why, and on what basis

WhatDataWhyBasisKept for
Enquiry and partnership formsName, company, job title, email, LinkedIn profileTo answer the enquiry and discuss participation or sponsorship.Steps taken at your request before entering a contract; legitimate interest in responding to business enquiries.5 years after last contact
Registration and admissionName, company, job title, email, phone, dietary and access requirementsTo assess the application, admit you to the event, produce your badge, and organise catering and access.Performance of a contract. Dietary/access requirements on the basis of explicit consent.5 years after the event
Ticket purchaseBilling details, transaction referenceTo process the purchase and issue an invoice.Performance of a contract, and legal obligation to keep accounting records.As required by accounting law
Newsletter and event announcementsEmail addressTo send invitations, agendas and announcements.Consent, which you may withdraw at any time.Until you unsubscribe
Website usagePages viewed, approximate location, device, referring sourceTo understand how the site is used and to measure our advertising.Consent, given through the cookie banner.2 years
Photography and filming at eventsTo document the event and to promote future editions.Legitimate interest in documenting our own events, subject to your right to object — see section 9.5 years

We do not knowingly collect data from anyone under 18, and our events are not directed at them.

4. Who we share it with

We use the following service providers, who process data on our instructions and are bound to protect it:

  • Google — business email, and website analytics
  • Cloudflare — website delivery and security
  • Mailjet and Mailchimp — sending email
  • LinkedIn — advertising measurement
  • Our web hosting provider — unlimited.rs
  • The ticketing platform — effinity.rs, which handles ticket purchases
  • Venues and on-site suppliers — only the details needed to admit you and cater for you

We also disclose data where the law requires it, and to our professional advisers where necessary.

5. Sponsors and partners

In the lead-up to an event, we share your job title and organisation with our sponsors and partners, so they are aware of who is attending and can prepare for any discussions that may follow. Sponsors and partners receive only your job title and organisation — not your name, email, phone number, or any other contact detail — and they act as an independent controller in relation to that information.

6. Where your data goes

Our events take place across Europe and some of our providers are based outside the EEA. Where data is transferred outside the European Economic Area, we rely on the European Commission’s standard contractual clauses or an adequacy decision. You may ask us for details of the safeguards that apply.

7. How long we keep it

We keep personal data for the periods set out in section 3, and then delete it or anonymise it. Where the law requires a longer period — accounting records in particular — that period applies instead.

8. Your rights

You may ask us to:

  • give you a copy of the data we hold about you
  • correct it if it is wrong
  • delete it
  • restrict how we use it
  • send it to you or to someone else in a portable form

You may object to processing we carry out on the basis of legitimate interests, including photography at our events. You may withdraw consent at any time, which does not affect anything done before you withdrew it.

Write to [email protected]. We respond within one month. If you are not satisfied, you may complain to the data protection authority in your country, or to Sweden’s Integritetsskyddsmyndigheten (IMY).

9. Photography and filming

We photograph and film our events. If you would prefer not to appear, tell us at registration or at the welcome desk and we will mark it on your badge and instruct the photographer. If you find yourself in a published image and want it removed, write to us and we will remove it.

10. Cookies

The site uses cookies that are necessary for it to work, and — only with your consent — cookies that measure how the site is used and how our advertising performs. You can change your choice at any time through the cookie settings link in the footer.

11. Security

We hold personal data on services protected by access control, encryption in transit, and restricted administrative access. No system is perfect; if a breach affects your data and is likely to present a risk to you, we will tell you and the relevant authority within the periods the law requires.

12. Changes

We update this policy when what we do changes. The date at the top shows the current version. Where a change materially affects you, we will say so directly rather than rely on you noticing.

Get your pass

The most exclusive Cyber Security EVENTS in the world.

Exclusive C-level cybersecurity gatherings across Europe. Limited seats, maximum impact.

Session reserved
05:00
Your registration session is active. Complete your application within the reserved time.
Next IT Security · East Central
Main Conference Ticket
€495
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. September 30, Belgrade.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
Workshops — Sold Separately
Workshop 1 Chapter 1 · Compliance & Regulation
From Regulation to Reality: Making NIS2 & DORA Work in Practice
A working session for security leaders who need to translate regulatory requirements into operational plans. Participants work through actual compliance gaps, build a self-assessment framework, and leave with a prioritised action list — without dedicated compliance teams or enterprise-level budgets.
Time
09:00 – 11:00
Format
Masterclass + working groups
Duration
2 hours
Capacity
Limited seats
Workshop 2 Chapter 2 · AI & Emerging Threats
Shadow AI: How to Find It, Govern It, and Not Kill Innovation Doing It
A practical masterclass for security leaders dealing with AI tools that were never approved, deployed without oversight, and are already inside the environment. Participants map their own shadow AI exposure and build a proportionate governance framework.
Time
11:15 – 13:15
Format
Masterclass + case analysis
Duration
2 hours
Capacity
Limited seats
Workshop 3 Chapter 3 · Vendor Dependency & Sovereignty
Managing Vendor Risk Without Rebuilding Your Stack
A strategic working session on third-party risk, technology dependency, and realistic options for East Central organisations. Participants conduct a structured dependency audit, evaluate viable European alternatives, and leave with a vendor risk strategy that is operationally grounded.
Time
13:15 – 15:15
Format
Masterclass + structured audit
Duration
2 hours
Capacity
Limited seats
Workshop 4 Chapter 4 · Cybercrime in a Borderless Threat Landscape
Cross-Border Cybercrime: What Private Sector Security Leaders Need to Know
A practitioner-led masterclass bridging private sector incident response and the realities of cross-jurisdictional law enforcement. Participants learn how cybercrime investigations unfold across borders and how to build an incident posture that works with — not against — public sector constraints.
Time
15:30 – 17:30
Format
Masterclass + Q&A
Duration
2 hours
Capacity
Limited seats
By submitting this form, you acknowledge that you have read and agree to our Privacy Policy .
Next IT Security · Nordics
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. October 22, Stockholm.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
By submitting this form, you acknowledge that you have read and agree to our Privacy Policy .
Next IT Security · Benelux
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. November 12, Amsterdam.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
By submitting this form, you acknowledge that you have read and agree to our Privacy Policy .
Next IT Security · DACH
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. November 26, Frankfurt.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
By submitting this form, you acknowledge that you have read and agree to our Privacy Policy .
Next IT Security · Nordics
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. March 11, Stockholm.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
By submitting this form, you acknowledge that you have read and agree to our Privacy Policy .
Next IT Security · Benelux
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. April 15, Amsterdam.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials