Dr. Kavita Sharma
PhD, CIPP/E

Bridges law, policy, and technology, specialising in privacy, data protection, and the regulatory landscape.
Dr. Kavita Sharma is a Professor of Cyber Law, Policy, and Privacy at GICCT, where she teaches the legal and regulatory dimensions of security that technical training so often neglects. As privacy law and cyber regulation reshape how organisations must operate, she helps students understand that security is not only a technical challenge but a legal and ethical one.
Background and career
Dr. Sharma trained in law before specialising in the rapidly growing field of technology and privacy regulation. That legal foundation, combined with a deep engagement with technology, lets her bridge two worlds that often struggle to understand each other: the technical teams who build systems and the legal and compliance functions who must answer for them. She has spent her career translating between these worlds, helping each understand what the other needs.
She has advised organisations across Greece and the wider European Union on privacy compliance, data protection strategy, and the legal implications of security incidents. She has served as an external Data Protection Officer for clients in regulated sectors and has guided organisations through the practical realities of the GDPR and the Greek implementing legislation. She holds the CIPP/E certification, a leading credential in European data protection.
Areas of expertise
Dr. Sharma’s expertise covers data protection law including the GDPR and Greek Law 4624/2019, the role and responsibilities of the Data Protection Officer, cyber policy, and the legal dimensions of incident response — particularly the breach notification obligations that now impose strict timelines on organisations. She has particular depth in privacy by design, the principle that data protection must be built into systems from the outset rather than added afterward.
She also brings strong knowledge of the broader regulatory landscape affecting security, from the NIS2 directive to the emerging body of law governing artificial intelligence. She helps students see how these overlapping regimes fit together and what they collectively demand of organisations operating in Europe.
Teaching philosophy
Dr. Sharma makes a subject that intimidates many technical professionals genuinely accessible. She teaches law not as a forbidding body of rules to be feared but as a logical framework that, once understood, becomes a practical tool. Her courses work from real cases, real regulatory decisions, and real compliance documentation, so students learn to apply the law rather than merely recite it.
She is a firm believer that every security professional needs a working grasp of the legal landscape, regardless of their technical specialism. A forensic investigator must understand evidence law; a developer must understand privacy by design; an incident responder must understand notification obligations. She weaves this conviction through her teaching, helping students see law as part of their professional toolkit rather than someone else’s problem.
A practitioner’s perspective
Dr. Sharma’s teaching is grounded in the reality of advising organisations through genuine compliance challenges and actual breaches, where the clean lines of the law meet the messy facts of a real situation. She shares the practical judgement this requires — how to assess whether a breach is notifiable, how to balance legal caution against operational urgency, and how to document decisions defensibly.
She keeps close to a fast-evolving regulatory landscape, where new laws, court decisions, and regulatory guidance continually shift what organisations must do. She helps students understand not just the current state of the law but the direction it is travelling, so they are prepared for the obligations coming rather than only those already here.
At GICCT
At the institute, Dr. Sharma leads the curriculum on cyber law, policy, and privacy, and contributes the legal and regulatory dimension to programs across the institute, from GDPR and data protection to incident response. She is a strong advocate for the view that technical and legal competence must go together, regularly reminding students that an organisation’s security is only as strong as its weakest link — and that link is often a legal or procedural one. For professionals seeking to work at the intersection of security, law, and policy, her courses offer a distinctive and increasingly valuable foundation.