First Member State
Co-Chair
eHealth Member State
Expert Group
under MyHealth@EU
I advise European institutions, public authorities, universities, research consortia, international organisations and selected private organisations operating at the intersection of AI, cybersecurity, health data, law and cross-border digital infrastructure.
The objective is to make organisations more fundable, resilient and trusted in environments where law, technology, cybersecurity and institutional responsibility converge.
Selected advisory engagement through VIPCon.
I have authored, led the development of, and substantially contributed to legal and governance instruments used to make European cross-border digital health operational, including Patient Information Notices, Healthcare Professional Information Notices, standardised DPIA frameworks, GDPR implementation guidance, controllership and accountability models, and legal templates for MyHealth@EU / eHDSI cooperation.
This work translated European data-protection law, product-law requirements, cross-border healthcare obligations and institutional responsibilities into practical governance instruments and technical requirements used by public authorities, standards-development organisations, interoperability communities and implementing organisations in real operational settings.
Cyber resilience, AI-related attack surfaces, institutional security governance, NIS2-oriented readiness, security-by-design, incident preparedness, forensic accountability and executive-level cyber risk.
Governance of AI-enabled healthcare, health-data and public-sector data systems where GDPR, EHDS, medical-device considerations, clinical responsibility, patient trust and cross-border implementation must be aligned.
Human oversight, responsibility, explainability, trust, autonomy, institutional judgement, epistemic risk and the ethical boundaries of automation where decisions affect patients, professionals and public institutions.
EHDS, MyHealth@EU, legal interoperability, cross-border health-data exchange, EHR-related requirements, trust frameworks, governance transition and implementation models that make European data exchange operational.
For institutions, research consortia and selected private organisations that need to become fundable, resilient and trusted in complex European digital-health, AI and cybersecurity environments.
Strengthening research proposals, EU-funded project concepts and consortium positioning by building credible governance, ethics, cybersecurity, data-protection, interoperability and implementation architecture into the design.
Preparing organisations for legal and regulatory change across EHDS, GDPR, AI governance, cybersecurity, health-data exchange and European data-space requirements before those changes become operational risk.
Translating cybersecurity, AI-related risk, access control, accountability, incident readiness and supplier exposure into decisions that executives, boards and public institutions can act on.
Converting legal, ethical and technical obligations into governance models, decision structures, operating procedures and evidence of readiness that funders, regulators, partners and implementation teams can trust.
Strategic support for research proposals, EU-funded projects and multi-partner consortia where AI, cybersecurity, health data, EHDS, data protection, ethics, interoperability and governance-by-design must be credible from the start.
Governance, accountability and regulatory-readiness advice for organisations developing, deploying or investing in AI-enabled healthcare, digital-health platforms and health-data infrastructure that must be trusted by partners, patients, regulators or funders.
Senior advisory support for clinics and healthcare groups adopting AI, digital workflows or cross-border services where cyber resilience, data protection, patient trust and EU-facing health-data obligations must be managed together.
Expert review and governance support for health-data, AI, cybersecurity, digital-health and cross-border research initiatives involving sensitive data, European partners, public-interest impact or institutional responsibility.
Strategic advice for private organisations interacting with European legal, data-protection, cybersecurity, AI-governance and health-data frameworks, especially where EU credibility, market access or institutional trust matter.
Governance, legal-operational and implementation-readiness support for digital-health, data-space, interoperability and cybersecurity programmes operating across institutional, sectoral or national borders.
Vanja Pajić is a senior European adviser working at the intersection of artificial intelligence, cybersecurity, health data, law, ethics and cross-border digital infrastructure.
He specialises in regulated environments where legal certainty, cyber resilience, data protection, interoperability and institutional responsibility must be designed together.
His work focuses on health-data infrastructures, EHDS and MyHealth@EU implementation, AI and cybersecurity governance, legal interoperability and public-sector data spaces.
Selected work and engagements span MyHealth@EU / eHDSI, the European Health Data Space, Xt-EHR, XpanDH, X-eHealth, eHealth Action, the Joint Action to Support the eHealth Network, the Patient Registries Initiative Joint Action, WHO digital health and vaccine-certificate work, xShare, TEHDAS, NAPCORE / NAPCORE-X, TISGRADE / TISCORE and related European digital-health, interoperability, cybersecurity and data-space initiatives.
His academic and professional background combines law, cybersecurity, public health, healthcare management, digital health, philosophy, anthropology, business administration and information systems analysis.
Selected academic and professional formation includes PhDs in biomedicine and health sciences, an LL.M., MSc Cyber Security, Global Master of Public Health, MBA, postgraduate public-health and healthcare-management training, advanced study in IT systems analysis and design, PM2 certification and CISO-level cybersecurity training.
Cross-border digital health depends on more than legal permission or technical connectivity. Patient information notices, professional access rules, controllership models, identifiers, audit trails and security controls must operate together as an architecture of trust.
In health-data environments, identity, access management, logging, incident response, continuity planning and supplier governance determine whether institutions can demonstrate responsibility when something goes wrong.
A mapping error in cross-border healthcare is not merely a terminology issue. It can affect clinical interpretation, patient safety, professional liability, auditability and the allocation of responsibility between national systems.
Rights of access, information, transparency and control depend on identifiers, authentication, metadata, logging, user interfaces and institutional explainability. In digital health, rights become real only when systems can execute them.
In high-risk health-data infrastructures, a DPIA should influence access control, minimisation, retention, logging, security, incident response and governance. Otherwise, it merely describes risks that design has already created.
EU research proposals involving AI, health data or cybersecurity are stronger when legal, ethical, technical, interoperability and implementation responsibilities are designed into the consortium from the start.
Selected engagements are considered where legal, cybersecurity, healthcare, ethics and European interoperability expertise must be combined to support senior advisory work, expert review, strategic workshops or governance design.
Engagements are most relevant for organisations working with sensitive data, regulated technologies, AI-enabled systems or cross-border digital infrastructure where credibility, accountability and implementation readiness matter.
Typical outputs include strategic advisory notes, funding-readiness and proposal-architecture input, consortium-positioning advice, governance models, legal-operational mappings, implementation-readiness reviews, risk and accountability analyses, expert-review reports and decision-support papers for senior decision-making.
Selected advisory engagement is considered where the mandate, institutional context, expected output and timeframe are clearly defined.