Masters of Privacy

Sergio Maldonado

Interviews and updates at the intersection of marketing, data, privacy, and technology. With an eye on a human-centric, demand-led future in which transparency, control, and personal agency play a crucial role. Sergio Maldonado (host) is a triple-qualified lawyer (California, England & Wales, Spain), entrepreneur, investor, guest lecturer at various universities. LL.M in IT & Internet Law, FIP, CIPP/E/US, CIPT. www.mastersofprivacy.com

  1. 2d ago

    Amy Lawrence: Meta settlement, advertising to minors, age assurance and addictive design.

    Amy Lawrence is Chief Privacy Officer and Head of Legal at SuperAwesome, where she leads global privacy strategy for technology and media products designed for young audiences. An expert in youth privacy and digital regulation, Amy advises on building adtech services and responsible advertising in compliance with COPPA, GDPR, state privacy laws, and age-appropriate design codes. Previously, she was with Epic Games helping modernize the global privacy program and regulatory engagement. Amy began her career in private practice, focused on privacy compliance in media and entertainment. She holds CIPP/US and CIPP/E certifications and is admitted to practice in California and New York. References: * Amy Lawrence on LinkedIn * About SuperAwesome * Meta agrees to pay $18 billion to settle US lawsuits over children’s social media addiction (Reuters, August 28th 2026). The company denied wrongdoing and agreed to restrict teenagers’ use of Facebook and Instagram ​to two hours a day and block all usage from midnight to 6 a.m., absent parental consent. * Reddit issued with £14.47m fine for children’s privacy failures (ICO, February 24th 2026) * Yoti: “Thoughts from our CEO: Spanish regulator AEPD fining Yoti” (€950,000, March 27th 2026) * California AB-1043, Age verification signals: software applications and online services. The law enters into force on January 1st 2027, with OS providers (iOS, Android) required to collect a date of birth during the initial device or account setup, subsequently passing age signals to specific apps via API -consisting of age brackets. * AI Sentinel: Future-Proof AI Governance (hosted on TODO.LAW, free) * InScope (North End Law): Which privacy/AI laws apply to your company? This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe

    Amy Lawrence: Meta settlement, advertising to minors, age assurance and addictive design.
  2. Sep 6

    Rosalia Anna D’Agostino: Deep Fakes, algorithmic fairness and the challenges of younger generations

    Rosalia Anna D’Agostino is an Italian Lawyer, Data Privacy and AI Compliance Expert, until recently working at the German law firm Spirit Legal. Fluent in five languages, she graduated in Comparative European and International law from the University of Trento (IT). Rosalia completed a joint programme with the University of Birmingham in the UK and, together with fellow students, founded Legal4Tech, where she leads a podcast on Law and Technology, engaging with top experts in tech governance. Our guest has gone quite deep into the legal analysis of LLMs and their outputs, class action lawsuits in the EU and the UK, social media platform algorithms and more. References: * Rosalia Anna D’Agostino on LinkedIn * Legal4Tech: on Spotify, Apple Podcasts, LinkedIn * Deepfake: Italian Data Protection Authority orders immediate stop to Clothoff, the app that undresses people (Garante, October 2025) * 20M EUR fine for Clearview AI in Italy (Garante, December 2022) * EU Digital Services Act * Russmedia decision (December 2025, CJEU): liability as a data controller for user generated content on a platform, flying over safe harbor provisions for hosting providers (originally in the Ecommerce Directive, now in the DSA) * Rahul Uttamchandani: a legal framework for Deep Fakes (Masters of Privacy ES, March 2023). This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe

    Rosalia Anna D’Agostino: Deep Fakes, algorithmic fairness and the challenges of younger generations
  3. Aug 30

    Carissa Véliz: navigating LLM constraints in the pursuit of AI ethics

    Carissa Véliz is an Associate Professor in Philosophy at the Institute for Ethics in AI, and a Fellow at Hertford College at the University of Oxford. She is the recipient of the 2021 Herbert A. Simon Award for Outstanding Research in Computing and Philosophy. Our guest is the author of Prophecy, now longlisted for the Financial Times business book of the year (2026), as well as the editor of the Oxford Handbook of Digital Ethics. Her previous book, Privacy is Power, was chosen by The Economist as one of the best books of the year in 2020. Carissa advises companies and policymakers around the world on privacy and the ethics of AI, and is a member of UNESCO’s Women 4 Ethical AI. References: * Breakfast Workshop - Santa Monica, CA - September 2, 2026 (free for MoP subscribers) * Prophecy: Prediction, Power, and the Fight for the Future, from Ancient Oracles to AI (Amazon) * Carissa Véliz on Substack (The Antidote) * Gary Marcus: Even more good news for the future of neurosymbolic AI (Substack, April 2026) * Refresher (January 28th special, Masters of Privacy): Data Protection vs. Privacy and Data Privacy (with Carissa Véliz, Gabriela Zanfir-Fortuna, Brendan Quinn, Tim Turner, and Markus Wünschelbaum) * Carissa Véliz: privacy is power (Masters of Privacy ES, Oct 2021 - Spanish) * Install the TODO.LAW suite on your own device (Dealroom, DPO Central, AI Sentinel). Send us your questions, feedback, or report requests (InScope, AuditScan) to: info[@]northend.law. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe

    Carissa Véliz: navigating LLM constraints in the pursuit of AI ethics
  4. Aug 25

    Newsroom: Summer 2026

    We’re back for a new season (#12 across both channels, heading into our 7th year!), and we do it with a Newsroom update. We will cover our usual five blocks: ePrivacy & regulatory updates; MarTech & AdTech; AI, competition and digital markets; Zero-Party Data; and the future of media. This season’s update includes: - Meta’s “addictive design” of services for minors (public nuisance in New Mexico, trial of twenty nine states in California, DSA charge over addictive design in Brussels) - Social media bans for minors in France, the UK and Australia, and the push to move age checks to the operating system - The second largest GDPR fine to date, against Uber, for deactivating drivers by automated decision (Article 22) - Enforcement across Europe (health data warehouses, traveller profiling, loyalty club consent, scraped business contacts, AI companion apps) and in the US (public, private) - AI Act enforcement begins while obligations for high risk systems slip to 2027, plus EDPB guidelines on anonymization, web scraping and generative AI - The end of FTC independence, doubts over the Data Privacy Framework, and a Google fine answered with tariff threats - Advertising inside AI assistants, pixel matching by default, and AI copyright settlements. All references and links (plus some bonus materials) can be found in a separate blog post available to paid Masters of Privacy subscribers on our website’s Newsroom section (Newsroom Notes: Summer 2026). Our usual disclaimer: the voice that joins Sergio today is a text-to-speech output generated with Eleven Labs. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe

    Newsroom: Summer 2026
  5. Jun 21

    Eduardo Ustaran: the status of privacy in 2026, UK-EU divergence on automated decisions

    Where is the privacy-AI convergence taking us in 2026? How different is the UK’s new approach to automated decision making (ADMT)? Is AI pushing young lawyers out of the profession? Eduardo Ustaran is global co-head of the Hogan Lovells Privacy and Cybersecurity practice, widely recognized as one of the world’s leading privacy and data protection lawyers and thought leaders. With over 30 years of experience, our guest advises multinationals and governments around the world on the adoption of privacy and cybersecurity strategies and policies. Eduardo has been involved in the development of the EU data protection framework and was listed by Politico as the most prepared individual in its ‘GDPR power matrix’. Eduardo obtained his JD from Universidad de Navarra and an LLM in European and International Trade Law from the University of Leicester. This is our 40th and last episode in the current (10th) season. We will be back in a few weeks. Have a great summer! References: * Eduardo Ustaran at Hogan Lovells * Eduardo Ustaran on LinkedIn * AI and Automated Decision-Making in the UK (Part I): The new rules and regulatory guidance (Eduardo Ustaran, Katie McMullan, Alina Podolyak) * CCPA Updates, Cybersecurity Audits, Risk Assessments, Automated Decisionmaking Technology (ADMT), and Insurance Regulations * Eduardo Ustaran: (Spanish) Second anniversary of the GDPR (Masters of Privacy ES, May 2020) This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe

    Eduardo Ustaran: the status of privacy in 2026, UK-EU divergence on automated decisions
  6. Jun 14

    Theodore Christakis: chatbot privacy dreams and the health AI agent rush

    “You trust your chatbot with everything. Should you?” is the title of Theodore Christakis’ comprehensive research project on the privacy of our conversations with AI. Part two of this project (“Governments, Courts and the Battle Over Your Chatbot Conversations”) was published on June 8th, and we have taken the opportunity to ask the author for a high-level overview of his findings. On top of this, we have also discussed his separate piece on the rise of AI-powered health assistants against the backdrop of the new European Health Data Space, discussed last week in our Spanish-language channel. (Our previous conversation with Mr. Christakis focused on the use of personal data in LLM training datasets.) Theodore Christakis is Professor of International, European and Digital Law at University Grenoble Alpes (France). He holds, since 2019, the Chair on the Legal and Regulatory Implications of Artificial Intelligence at the Multidisciplinary Institute on AI (AI-Regulation.com). He is Director of Research for Europe at the Cross-Border Data Forum, a member of the Board of Directors of the Future of Privacy Forum, and a former Distinguished Visiting Fellow at the New York University Cybersecurity Centre. His work focuses on the questions at the centre of today’s debates on digital sovereignty: government access to data held by private companies, international data transfers, the security and operational resilience of digital infrastructure, and the regulation of artificial intelligence. He served as an expert for the OECD in the process that led to the adoption, in December 2022, of the OECD Declaration on Government Access to Personal Data Held by Private Sector Entities. He was a member of the International Data Transfers Experts Council of the United Kingdom Government, and an expert for the High-Level Expert Group on Access to Data for Effective Law Enforcement established by the European Commission and the Council of the European Union. He has also served as a member of the French National Digital Council and of the French National Committee on Digital Ethics. He has published or co-edited twelve books and is the author or co-author of more than 120 academic articles and book chapters. He has been invited to lecture and present his work at conferences, workshops and seminars on more than two hundred occasions, in over 38 countries. As an independent expert, he advises governments, international organisations and private companies on questions of international and European law, cybersecurity, artificial intelligence, digital sovereignty and data protection. References: * Theodore Christakis’ SSRN Author Page * Theodore Christakis on LinkedIn * You Trust Your Chatbot With Everything. Should You? Part I: How The Controller Uses Your Chat Data (March 3, 2026) * You Trust Your Chatbot With Everything. Should You? Part II: Governments, Courts and the Battle Over Your Chatbot Conversations (June 8th, 2026) * The Health AI Agent Rush: Five Companies, Your Health Data, and the Governance Questions Nobody Is Asking (March 25th, 2026) * Mikel Recuero: a deep dive into the European Health Data Space (ES, Masters of Privacy, June 2026) * Multidisciplinary Institute on AI * Université Grenoble Alpes: Centre d’études sur la sécurité internationale et les coopérations européennes. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe

    Theodore Christakis: chatbot privacy dreams and the health AI agent rush
  7. Jun 9

    Malcolm Bain: copyright protection of AI-generated works and protection of copyrighted works from AI training

    We are revisiting the AI-copyright interplay for the first time in nearly three years. Copyright remains very relevant to our sphere of interest, not least because the EU AI Act specifically points at EU copyright law with regards to training data and transparency requirements for AI models. Malcolm Bain is an English solicitor and Spanish abogado. He has worked as an Information Technology and Intellectual Property lawyer over the last 20 years, with a specialisation in technology licensing, open source software and content, technology transfer and privacy. In 2006, together with his partner Manuel Martínez, he founded his own firm “id-law partners” as a boutique specialized in IP and ICT. In May 2018, both incorporated this firm into Across Legal. In addition to his professional activity advising entrepreneurs, private companies, public administrations and open source projects, Malcolm is a member of the Free Software Foundation Europe and ASTP, associate professor of law at the University of Barcelona, ​​mentor in Tecniospring Industry and other programs for entrepreneurs and frequent speaker at conferences and seminars in the field of ICTs and entrepreneurship in the digital world. References: * Malcolm Bain at Across Legal * Malcolm Bain on LinkedIn * Monkey selfie copyright dispute (Wikipedia) * Directive (EU) 2019/790 of the European Parliament and of the Council of 17 April 2019 on copyright and related rights in the Digital Single Market and amending Directives 96/9/EC and 2001/29/EC * Report on Copyright and Artificial Intelligence (UK Intellectual Property Office) * Stability AI largely wins UK court battle against Getty Images over copyright and trademark (AP News, November 2025) * US Copyright Office: Copyright Registration Guidance: Works Containing Material Generated by Artificial Intelligence (2023) * German Court Rules OpenAI Infringed Song Lyrics in Europe’s First Major AI Music Ruling (November 2025) * Jakob Plesner: Copyright Exceptions for Generative AI (Masters of Privacy, October 2023). * (NOTE: The second part of this conversation was recorded in Spanish and is available in our separate Masters of Privacy ES channel.) This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe

    Malcolm Bain: copyright protection of AI-generated works and protection of copyrighted works from AI training

Ratings & Reviews

5
out of 5
8 Ratings

About

Interviews and updates at the intersection of marketing, data, privacy, and technology. With an eye on a human-centric, demand-led future in which transparency, control, and personal agency play a crucial role. Sergio Maldonado (host) is a triple-qualified lawyer (California, England & Wales, Spain), entrepreneur, investor, guest lecturer at various universities. LL.M in IT & Internet Law, FIP, CIPP/E/US, CIPT. www.mastersofprivacy.com

You Might Also Like