Dr. Robin Schoss
Tech-savvy lawyer with entrepreneurial spirit, working in the space between innovation and regulation. Speaker & Advisor.
AIGP · CIPM · CIPP/E
Hamburg, Germany — available remote & travelling
I help organizations use AI without breaking the law, losing trust, or annoying their regulators — working in-house at Olympus, speaking at conferences, and advising independently.
About
Technology is fun and moves fast, as it should. Regulation tries to keep up. As a tech-savvy lawyer with entrepreneurial and enterprise experience who enjoys speaking and teaching, I work in the space between.
I moved in-house early because I wanted to be closer to and actually help make the decisions that shape how organizations use technology, not just review them after the fact (and add "CYA" disclaimers to everything). Today that means building AI and data governance, privacy, and cybersecurity programs at global MedTech leader Olympus, but the purpose has always been the same: making complex regulation workable for the people who build and ship products.
Right now, the most interesting problems in my field sit at the collision of AI regulation, data privacy, and cybersecurity, the EU AI Act, GDPR, NIS2, MDR, and the tensions between them. That's where I spend most of my time, both at Olympus and as a trainer, speaker, and independent advisor to organizations figuring this out for the first time (or second, or third...).
I've always believed that "a true thing, poorly expressed, is a lie", which is why I care as much about communication and presentation as I do about the substance. I enjoy speaking at conferences, running workshops, and training teams across functions, because regulation only works when the people it affects actually understand it.
Speaking other people's language is my strongest soft skill: When I work with engineering teams, they appreciate that when we talk about 'calling the API', I'm not reaching for a phone. When I sit with board members, they appreciate that when we talk about 'risk appetite', I'm not ordering lunch.
If you're looking for someone who can make regulatory complexity accessible to a room full of engineers, product managers, or board members, not just lawyers, let's talk.
Let's talk.
For speaking engagements or advisory work, reach me on LinkedIn or by email.
What I Offer
Keynotes · Workshops · Advisory
AI Governance
I help organizations build AI governance programs from the ground up — risk frameworks, AI inventories, policy architecture, and cross-functional rollout. Available as an advisory mandate or keynote.
EU AI Act
Practical implementation of the EU AI Act: high-risk classification, Article 4 literacy obligations, conformity assessments. I run workshops and advisory sessions for teams working through this for the first time — or the third.
Data Privacy & GDPR
From the GDPR/AI Act overlap to anonymization, automated decision-making, and privacy-by-design for AI products — I advise and speak for legal, technical, and mixed audiences.
Cybersecurity & NIS2
NIS2 implementation, management body accountability, and the convergence of AI and cyber risk. I advise on governance frameworks and deliver keynotes and tabletop exercises for security teams and boards.
MedTech & Healthcare AI
The MDR/AI Act intersection is where most MedTech companies are stuck. I advise on software-as-medical-device classification, post-market surveillance, and patient safety in AI-enabled healthcare.
Workshops & Training
I design and run workshops that make regulation actually click for non-lawyers — for engineering teams, product managers, procurement, and board members. In-person, hybrid, or fully remote.
“A good plan, violently executed now, is better than a perfect plan executed next week.”
— George S. Patton
“A true thing, badly expressed, becomes a lie.”
— Stephen Fry
Speaking & Training
Keynotes · Talks · Workshops · Podcasts
KI im Gesundheitswesen — Legal Deep Dive
MÖHRLE HAPP LUTHER
Hamburg
Tabletop Exercises for IT Security Incidents — How Prepared Are We Really?
CISO Executive Circle · Network Circle
Hamburg
What Legal Teams Get Wrong About AI Risk — and How to Fix It
IAPP AI Governance Global Europe 2025
Brussels
Global Digital Academy Series on AI Governance
Olympus Global Digital Academy
Panel
Coming Up 2026
Responsible AI Summit
AI & Data Analytics Network
London
Keynote on AI Governance, Privacy and Cybersecurity management systems
CV
Download PDFOlympus
Global Privacy, AI Governance & Data Compliance Manager
Reporting to the Global CPO · Leading the global EU AI Act Readiness project · Leading the global EU Data Act Readiness project
Head of Information Security EMEA
Reporting to the Global CISO · Regional incident crisis management, training and policies · NIS2 implementation project
Data Protection Manager (In-house lawyer)
Attorney-at-Law / Associate
PLANIT // LEGAL
Advised international clients on data protection and IT law · Civil and administrative proceedings in data protection and IT law
Legal Clerkship (Referendariat)
Higher Regional Court of Hamburg
Positions at Freshfields Bruckhaus Deringer, NEUWERK Rechtsanwälte, Google Germany GmbH
CEO & Founder
mymun GmbH
SaaS event management platform and social network for international student conferences (>100,000 users) · Full-stack development (JS, Python, HTML/CSS) · Commercial management from foundation to exit
Dr. iur. (Law)
University of Hamburg
First & Second State Examination, Law
University of Hamburg · Higher Regional Court of Hamburg
Graduated "With Distinction" (Prädikatsexamen)
Publications
Legality of the Use of Artificial Intelligence in Commercial Enterprises
ZD 2024, 354
Commentary on Hamburg Labor Court judgment
Commentary on Articles 86, 87, 90, 96–99 GDPR
Practical Commentary on the GDPR (dfv)
Staatliches Informationshandeln in sozialen Medien
Dr. iur. Dissertation · Verlag Dr. Koväč, Hamburg · ISBN 978-3-339-13588-9
Governmental use of social media — legitimacy, fundamental rights, and legal regulation of state information action · 232 pp.
Let's talk.
For speaking engagements or advisory work, reach me on LinkedIn or by email.