Vanja Pajić

Senior European Adviser on
AI, Cybersecurity and Health
Data Governance
AI Governance | Cyber Resilience | Health Data Law | Data Protection | Ethics | EHDS | MyHealth@EU | Interoperability

I advise European institutions, public authorities, universities, research consortia, international organisations and selected private organisations operating at the intersection of AI, cybersecurity, health data, law and cross-border digital infrastructure.

The objective is to make organisations more fundable, resilient and trusted in environments where law, technology, cybersecurity and institutional responsibility converge.

Selected advisory engagement through VIPCon.

First Member State
Co-Chair

eHealth Member State
Expert Group
under MyHealth@EU

Chair

Legal Working Group
MyHealth@EU / eHMSEG / eHN

WHO Europe

Senior Consultant
under Emergency
Conditions

European Commission

Expert Evaluator
& Project Reviewer

EU Data Spaces

EHDS, MyHealth@EU governance,
interoperability,
cybersecurity and
data-space initiatives

Signature
Work

I have authored, led the development of, and substantially contributed to legal and governance instruments used to make European cross-border digital health operational, including Patient Information Notices, Healthcare Professional Information Notices, standardised DPIA frameworks, GDPR implementation guidance, controllership and accountability models, and legal templates for MyHealth@EU / eHDSI cooperation.

This work translated European data-protection law, product-law requirements, cross-border healthcare obligations and institutional responsibilities into practical governance instruments and technical requirements used by public authorities, standards-development organisations, interoperability communities and implementing organisations in real operational settings.

Expert Territory

AI × Cybersecurity

Cyber resilience, AI-related attack surfaces, institutional security governance, NIS2-oriented readiness, security-by-design, incident preparedness, forensic accountability and executive-level cyber risk.

AI × Law & Healthcare

Governance of AI-enabled healthcare, health-data and public-sector data systems where GDPR, EHDS, medical-device considerations, clinical responsibility, patient trust and cross-border implementation must be aligned.

AI × Ethics & Accountability

Human oversight, responsibility, explainability, trust, autonomy, institutional judgement, epistemic risk and the ethical boundaries of automation where decisions affect patients, professionals and public institutions.

European Data Governance & Interoperability

EHDS, MyHealth@EU, legal interoperability, cross-border health-data exchange, EHR-related requirements, trust frameworks, governance transition and implementation models that make European data exchange operational.

Strategic Value

For institutions, research consortia and selected private organisations that need to become fundable, resilient and trusted in complex European digital-health, AI and cybersecurity environments.

Funding Readiness

Strengthening research proposals, EU-funded project concepts and consortium positioning by building credible governance, ethics, cybersecurity, data-protection, interoperability and implementation architecture into the design.

Regulatory Resilience

Preparing organisations for legal and regulatory change across EHDS, GDPR, AI governance, cybersecurity, health-data exchange and European data-space requirements before those changes become operational risk.

Cyber and AI Risk Governance

Translating cybersecurity, AI-related risk, access control, accountability, incident readiness and supplier exposure into decisions that executives, boards and public institutions can act on.

Implementation Credibility

Converting legal, ethical and technical obligations into governance models, decision structures, operating procedures and evidence of readiness that funders, regulators, partners and implementation teams can trust.

Where I Advise

Universities and Research Consortia

Strategic support for research proposals, EU-funded projects and multi-partner consortia where AI, cybersecurity, health data, EHDS, data protection, ethics, interoperability and governance-by-design must be credible from the start.

Health-AI and Digital-Health Ventures

Governance, accountability and regulatory-readiness advice for organisations developing, deploying or investing in AI-enabled healthcare, digital-health platforms and health-data infrastructure that must be trusted by partners, patients, regulators or funders.

Private Clinics and Healthcare Groups

Senior advisory support for clinics and healthcare groups adopting AI, digital workflows or cross-border services where cyber resilience, data protection, patient trust and EU-facing health-data obligations must be managed together.

Foundations and Research Organisations

Expert review and governance support for health-data, AI, cybersecurity, digital-health and cross-border research initiatives involving sensitive data, European partners, public-interest impact or institutional responsibility.

EU-Facing Private Organisations

Strategic advice for private organisations interacting with European legal, data-protection, cybersecurity, AI-governance and health-data frameworks, especially where EU credibility, market access or institutional trust matter.

Public Authorities and European Programmes

Governance, legal-operational and implementation-readiness support for digital-health, data-space, interoperability and cybersecurity programmes operating across institutional, sectoral or national borders.

Profile

Vanja Pajić is a senior European adviser working at the intersection of artificial intelligence, cybersecurity, health data, law, ethics and cross-border digital infrastructure.

He specialises in regulated environments where legal certainty, cyber resilience, data protection, interoperability and institutional responsibility must be designed together.

His work focuses on health-data infrastructures, EHDS and MyHealth@EU implementation, AI and cybersecurity governance, legal interoperability and public-sector data spaces.

Selected European and International Experience

Selected work and engagements span MyHealth@EU / eHDSI, the European Health Data Space, Xt-EHR, XpanDH, X-eHealth, eHealth Action, the Joint Action to Support the eHealth Network, the Patient Registries Initiative Joint Action, WHO digital health and vaccine-certificate work, xShare, TEHDAS, NAPCORE / NAPCORE-X, TISGRADE / TISCORE and related European digital-health, interoperability, cybersecurity and data-space initiatives.

Academic and Professional Background

His academic and professional background combines law, cybersecurity, public health, healthcare management, digital health, philosophy, anthropology, business administration and information systems analysis.

Selected academic and professional formation includes PhDs in biomedicine and health sciences, an LL.M., MSc Cyber Security, Global Master of Public Health, MBA, postgraduate public-health and healthcare-management training, advanced study in IT systems analysis and design, PM2 certification and CISO-level cybersecurity training.

Pressure Points

Legal Trust Must Become System Design

Cross-border digital health depends on more than legal permission or technical connectivity. Patient information notices, professional access rules, controllership models, identifiers, audit trails and security controls must operate together as an architecture of trust.

Cybersecurity Is Now Part of Legal Accountability

In health-data environments, identity, access management, logging, incident response, continuity planning and supplier governance determine whether institutions can demonstrate responsibility when something goes wrong.

Semantic Mapping Can Become Clinical Risk

A mapping error in cross-border healthcare is not merely a terminology issue. It can affect clinical interpretation, patient safety, professional liability, auditability and the allocation of responsibility between national systems.

Patient Rights Depend on Architecture

Rights of access, information, transparency and control depend on identifiers, authentication, metadata, logging, user interfaces and institutional explainability. In digital health, rights become real only when systems can execute them.

DPIAs Should Shape the System

In high-risk health-data infrastructures, a DPIA should influence access control, minimisation, retention, logging, security, incident response and governance. Otherwise, it merely describes risks that design has already created.

Research Consortia Need Governance-by-Design

EU research proposals involving AI, health data or cybersecurity are stronger when legal, ethical, technical, interoperability and implementation responsibilities are designed into the consortium from the start.

Selected Advisory Engagement

Selected engagements are considered where legal, cybersecurity, healthcare, ethics and European interoperability expertise must be combined to support senior advisory work, expert review, strategic workshops or governance design.

Engagements are most relevant for organisations working with sensitive data, regulated technologies, AI-enabled systems or cross-border digital infrastructure where credibility, accountability and implementation readiness matter.

Typical outputs include strategic advisory notes, funding-readiness and proposal-architecture input, consortium-positioning advice, governance models, legal-operational mappings, implementation-readiness reviews, risk and accountability analyses, expert-review reports and decision-support papers for senior decision-making.

Request
Consideration

Engagement Consideration

Selected advisory engagement is considered where the mandate, institutional context, expected output and timeframe are clearly defined.