Creating safe open source packages in a hostile domain
Talk presented by: Charles de Leau
During PyCon NL 2026, at 10:45 in Polars

My story is about how my career began to revolve around an open source package, that was finally published on August 18, 2026.

Two years ago, an email from a casino made me quit my super fun job at bol. There, I had spent five years working as a Staff (craft lead) member and Engineering manager, creating tools in hackathons (the most profitable tool I’ve started working on made a profit of 100 Mln yearly).

I was climbing the corp ladder, when an unexpected email from a person that presumably was terminated directly after that. It pointed me to an unusual Dutch law, that exists nowhere else but in the Netherlands. It legally requires casinos to give their customer data to a researcher.

At first, I could not believe it; this would help any researcher to stay independent, while collecting a huge dataset for gambling harm prevention and get the model published without contracts that would limit the openness of the software!

But it was true. And even though this legal option already existed for five years, it turned out no one had ever used it. I started creating the software from scratch, using the Dutch supercomputer SNELLIUS to process the huge amounts of data that I gathered, and I loved every minute of it. The Bol.com school of ‘YBIYRIYLI’ really helped out with that.

Publishing it turned out to be a very different problem from building it. This is a very privacy sensitive domain where “just serialise the model” may accidentally leak stuff. For instance, there are laws that prohibit the disclosure of ‘market information’, but how do standard packages fit in with these legal requirements? I want to talk about these challenges, and what I’ve tried to combat them.

Practical information
When: October 15th 2026
A map showing where the Jaarbeurs Utrecht is located
Where: Jaarbeurs Utrecht
Jaarbeursplein 6
3521 AL Utrecht
The Netherlands
More info
Follow us: