Masters of Privacy

Sergio Maldonado

Interviews and updates at the intersection of marketing, data, privacy, and technology. With an eye on a human-centric, demand-led future in which transparency, control, and personal agency play a crucial role. Sergio Maldonado (host) is a triple-qualified lawyer (California, England & Wales, Spain), entrepreneur, investor, guest lecturer at various universities. LL.M in IT & Internet Law, FIP, CIPP/E/US, CIPT. www.mastersofprivacy.com

  1. 6d ago

    Aleksandr Tiulkanov: dissecting transparency requirements in the EU AI Act

    Aleksandr Tiulkanov has advised businesses on legal and compliance matters since 2003 and has focused on IT law and digital policy since 2015. He has previously been a Special Adviser on Digital Development at the Council of Europe; as well as Senior Manager for Technology, Media and Telecoms at Deloitte Legal. Aleksandr is also a Member of the AFNOR CN IA (French Commission on AI Standardisation), as well as a Member of the CEN-CENELEC JTC 21 (Artificial Intelligence), and a PECB Certified ISO/IEC 42001 Lead Implementer. He also holds an LL.M. in Innovation, Technology and the Law, University of Edinburgh (2018) and has been listed in “Best Lawyers in Information Technology Law (2020)” References: Aleksandr Tiulkanov on LinkedIn Engagements and training by Aleksandr Tiulkanov Preparing for the EU AI Act, a 4-week course by Aleksandr Tiulkanov (code for a 10% discount: MOPPTL2) Paragraphs 1-4 of Article 50 of the EU AI Act: Transparency obligations for providers and deployers of certain AI systems * Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI systems, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use. This obligation shall not apply to AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences, subject to appropriate safeguards for the rights and freedoms of third parties, unless those systems are available for the public to report a criminal offence. * Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI systems are marked in a machine-readable format and detectable as artificially generated or manipulated. Providers shall ensure their technical solutions are effective, interoperable, robust and reliable as far as this is technically feasible, taking into account the specificities and limitations of various types of content, the costs of implementation and the generally acknowledged state of the art, as may be reflected in relevant technical standards. This obligation shall not apply to the extent the AI systems perform an assistive function for standard editing or do not substantially alter the input data provided by the deployer or the semantics thereof, or where authorised by law to detect, prevent, investigate or prosecute criminal offences. * Deployers of an emotion recognition system or a biometric categorisation system shall inform the natural persons exposed thereto of the operation of the system, and shall process the personal data in accordance with Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable. This obligation shall not apply to AI systems used for biometric categorisation and emotion recognition, which are permitted by law to detect, prevent or investigate criminal offences, subject to appropriate safeguards for the rights and freedoms of third parties, and in accordance with Union law. * Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulated. This obligation shall not apply where the use is authorised by law to detect, prevent, investigate or prosecute criminal offence. Where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work or programme, the transparency obligations set out in this paragraph are limited to disclosure of the existence of such generated or manipulated content in an appropriate manner that does not hamper the display or enjoyment of the work. Deployers of an AI system that generates or manipulates text which is published with the purpose of informing the public on matters of public interest shall disclose that the text has been artificially generated or manipulated. This obligation shall not apply where the use is authorised by law to detect, prevent, investigate or prosecute criminal offences or where the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe

    Aleksandr Tiulkanov: dissecting transparency requirements in the EU AI Act
  2. Sep 27

    Dazza Greenwood: from agentic contracts to AI-assisted law firms. Delegation, attribution and judgment

    Daniel “Dazza” Greenwood is the founder of CIVICS.com, a boutique provider of professional consultancy services for legal technologies, automated transactions, privacy and data management, and technology strategy. Dazza is also a researcher at MIT Media Lab and Lecturer at MIT Connection Science where he has been advancing the field of computational law and generative AI for law as Executive Director of law.MIT.edu. Our guest serves as lead on the Data Rights Protocol initiative through Consumer Reports Digital Lab. This protocol provides a common open specification for enabling consumers and companies to process the exercise of individual data rights as a consumer-connected digital service. Dazza Greenwood consults to Fortune 100 companies, architecting and building integrated business, legal and technology cross-boundary networks at industry scale. As an attorney, he served as both in-house and special counsel for technology law, representing corporations and governments. He has also testified before the US House, US Senate and other legislatures on electronic transactions law and consults extensively to the public sector. References: * Dazza Greenwood on LinkedIn * Dazza Greenwood’s Substack * CIVICS.com * Data Rights Protocol: Standardizing consumers’ data rights requests (Consumer Reports) * Uniform Electronic Transactions Act (1999) * Authority Boundaries for AI (Dazza Greenwood, May 2026) * LQAI from LegalQuants on Github (open source platform for law firms) * Thirteen Words Shape Legal AI (Dazza Greenwood, September 2026) * MIT Computational Law Report - Now part of Stanford Law School * HOPE Lab, Hands-On Projects and Experimentation: Learn to work with agents across multiple stages, with clear goals, boundaries, and evidence of what worked. * Interlateral (“Bring your own agent”), run by Dazza Greenwood: A space where people and their AI agents meet, coordinate, and build together over the web. * Jamie Smith: AI Agents, digital identity, wallets and personal data (Masters of Privacy, December 2024). This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe

    Dazza Greenwood: from agentic contracts to AI-assisted law firms. Delegation, attribution and judgment
  3. Sep 13

    Amy Lawrence: Meta settlement, advertising to minors, age assurance and addictive design.

    Amy Lawrence is Chief Privacy Officer and Head of Legal at SuperAwesome, where she leads global privacy strategy for technology and media products designed for young audiences. An expert in youth privacy and digital regulation, Amy advises on building adtech services and responsible advertising in compliance with COPPA, GDPR, state privacy laws, and age-appropriate design codes. Previously, she was with Epic Games helping modernize the global privacy program and regulatory engagement. Amy began her career in private practice, focused on privacy compliance in media and entertainment. She holds CIPP/US and CIPP/E certifications and is admitted to practice in California and New York. References: * Amy Lawrence on LinkedIn * About SuperAwesome * Meta agrees to pay $18 billion to settle US lawsuits over children’s social media addiction (Reuters, August 28th 2026). The company denied wrongdoing and agreed to restrict teenagers’ use of Facebook and Instagram ​to two hours a day and block all usage from midnight to 6 a.m., absent parental consent. * Reddit issued with £14.47m fine for children’s privacy failures (ICO, February 24th 2026) * Yoti: “Thoughts from our CEO: Spanish regulator AEPD fining Yoti” (€950,000, March 27th 2026) * California AB-1043, Age verification signals: software applications and online services. The law enters into force on January 1st 2027, with OS providers (iOS, Android) required to collect a date of birth during the initial device or account setup, subsequently passing age signals to specific apps via API -consisting of age brackets. * AI Sentinel: Future-Proof AI Governance (hosted on TODO.LAW, free) * InScope (North End Law): Which privacy/AI laws apply to your company? This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe

    Amy Lawrence: Meta settlement, advertising to minors, age assurance and addictive design.
  4. Sep 6

    Rosalia Anna D’Agostino: Deep Fakes, algorithmic fairness and the challenges of younger generations

    Rosalia Anna D’Agostino is an Italian Lawyer, Data Privacy and AI Compliance Expert, until recently working at the German law firm Spirit Legal. Fluent in five languages, she graduated in Comparative European and International law from the University of Trento (IT). Rosalia completed a joint programme with the University of Birmingham in the UK and, together with fellow students, founded Legal4Tech, where she leads a podcast on Law and Technology, engaging with top experts in tech governance. Our guest has gone quite deep into the legal analysis of LLMs and their outputs, class action lawsuits in the EU and the UK, social media platform algorithms and more. References: * Rosalia Anna D’Agostino on LinkedIn * Legal4Tech: on Spotify, Apple Podcasts, LinkedIn * Deepfake: Italian Data Protection Authority orders immediate stop to Clothoff, the app that undresses people (Garante, October 2025) * 20M EUR fine for Clearview AI in Italy (Garante, December 2022) * EU Digital Services Act * Russmedia decision (December 2025, CJEU): liability as a data controller for user generated content on a platform, flying over safe harbor provisions for hosting providers (originally in the Ecommerce Directive, now in the DSA) * Rahul Uttamchandani: a legal framework for Deep Fakes (Masters of Privacy ES, March 2023). This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe

    Rosalia Anna D’Agostino: Deep Fakes, algorithmic fairness and the challenges of younger generations
  5. Aug 30

    Carissa Véliz: navigating LLM constraints in the pursuit of AI ethics

    Carissa Véliz is an Associate Professor in Philosophy at the Institute for Ethics in AI, and a Fellow at Hertford College at the University of Oxford. She is the recipient of the 2021 Herbert A. Simon Award for Outstanding Research in Computing and Philosophy. Our guest is the author of Prophecy, now longlisted for the Financial Times business book of the year (2026), as well as the editor of the Oxford Handbook of Digital Ethics. Her previous book, Privacy is Power, was chosen by The Economist as one of the best books of the year in 2020. Carissa advises companies and policymakers around the world on privacy and the ethics of AI, and is a member of UNESCO’s Women 4 Ethical AI. References: * Breakfast Workshop - Santa Monica, CA - September 2, 2026 (free for MoP subscribers) * Prophecy: Prediction, Power, and the Fight for the Future, from Ancient Oracles to AI (Amazon) * Carissa Véliz on Substack (The Antidote) * Gary Marcus: Even more good news for the future of neurosymbolic AI (Substack, April 2026) * Refresher (January 28th special, Masters of Privacy): Data Protection vs. Privacy and Data Privacy (with Carissa Véliz, Gabriela Zanfir-Fortuna, Brendan Quinn, Tim Turner, and Markus Wünschelbaum) * Carissa Véliz: privacy is power (Masters of Privacy ES, Oct 2021 - Spanish) * Install the TODO.LAW suite on your own device (Dealroom, DPO Central, AI Sentinel). Send us your questions, feedback, or report requests (InScope, AuditScan) to: info[@]northend.law. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe

    Carissa Véliz: navigating LLM constraints in the pursuit of AI ethics

Ratings & Reviews

5
out of 5
8 Ratings

About

Interviews and updates at the intersection of marketing, data, privacy, and technology. With an eye on a human-centric, demand-led future in which transparency, control, and personal agency play a crucial role. Sergio Maldonado (host) is a triple-qualified lawyer (California, England & Wales, Spain), entrepreneur, investor, guest lecturer at various universities. LL.M in IT & Internet Law, FIP, CIPP/E/US, CIPT. www.mastersofprivacy.com

You Might Also Like