DiscoverMasters of Privacy
Masters of Privacy
Claim Ownership

Masters of Privacy

Author: Sergio Maldonado

Subscribed: 28Played: 297
Share

Description

Interviews and updates at the intersection of marketing, data, privacy, and technology. With an eye on a human-centric, demand-led future in which transparency, control, and personal agency play a crucial role.

Sergio Maldonado (host) is a dual-qualified lawyer, entrepreneur, investor, guest lecturer at various universities. LL.M in IT & Internet Law, FIP, CIPP/E/US, CIPT.

www.mastersofprivacy.com
131 Episodes
Reverse
Robert Bateman is a Senior Partner at Privacy Partnership, which provides consultancy and training on data protection and AI regulation, as well as legal advice via its associated law firm, Privacy Partnership Law. He also hosts The Privacy Partnership Podcast.This is Robert’s third appearance on the show. We have covered three hot topics:* How far do we take watermarking of AI-generated content under article 50 of the AI Act?* How do pre-defined legitimate interest scenarios work under the UK Data (Use and Access) Act?* What is the tension between the Online Safety Act and the new data protection framework in the UK?References:SIGN UP NOW for the Masters of Privacy NYC LIVE recording and networking event on Nov 6 (if you happen to be in town)* Robert Bateman on LinkedIn* Robert Bateman on Bluesky* The Privacy Partnership Podcast* AI Act (EU Commission’s resources)* Data (Use and Access) Act 2025: data protection and privacy changes* The EU approach to age verification (EU Commission)* EU follows UK with age verification in 2026 (PPC Land)* Wikipedia loses challenge against Online Safety Act verification rules (BBC)* Robert Bateman: the EDPB’s Opinion on auditing subprocessors and the future of Meta’s unskippable ads (Masters of Privacy, Nov 2024)* Robert Bateman: Consent or Pay (Masters of Privacy, Oct 2023) This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
Newsroom: Summer 2025

Newsroom: Summer 2025

2025-09-2121:23

It is time for a seasonal update at the intersection of Marketing, Data, Privacy and Technology. We will stick to our usual five blocks: ePrivacy & regulatory updates; MarTech & AdTech; AI, Competition and Digital Markets; PETs and Zero-Party Data; Future of Media.This includes:* CJEU decisions on Latombe (EU-US data transfers have survived, for now) and SRB (relative nature of personal data) * UK legal updates and ICO consultations on ePrivacy-related topics* Record public fines and enforcement actions in California* Ongoing explosion of pixel and cookie-related lawsuits across the US* Important fines in the EU, with CNIL’s unwavering passion for large-scale ePrivacy enforcement* Agentic AI milestones for AdTech and customer centricity/empowerment* Key initiatives to protect copyright holders from large AI labs (together with Anthropic’s settlement)All references and links can be found in a separate blog post available to Masters of Privacy Connect subscribers on our website’s Newsroom section.Our usual disclaimer: the voice that joins me today is a text-to-speech output generated with Eleven Labs. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
How can we apply differential privacy to real-world scenarios? How do you go about algorithmic design? Is there a conflict between data minimization and differential privacy? Can you solve for personal data finding its way into machine learning models? Where can a young professional find resources to dive deeper?References:* Daniel Simmons-Marengo on LinkedIn* OpenDP* Some takeaways from PEPR’24 (USENIX Conference on Privacy Engineering Practice and Respect 2024)* Damien Desfontaines: Differential Privacy in Data Clean Rooms (Masters of Privacy, January 2024)* NIST Guidelines for Evaluating Differential Privacy Guarantees (March 2025)* Peter Craddock: EDPS v SRB, the relative nature of personal data, processors, transparency, impact on MarTech and AdTech (Masters of Privacy, September 2025)* Katharine Jarmul: Demystifying Privacy Enhancing Technologies (Masters of Privacy, October 2023)* Sunny Kang: Machine Learning meets Privacy Enhancing Technologies (Masters of Privacy, February 2023)* How GDPR changes the rules for research (Gabe Maldoff, IAPP blog, 2016) This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
Peter Craddock joins us once again to discuss the recent EDPS v Single Resolution Board decision by the Court of Justice of the EU. Although it builds on the previous Scania and Breyer cases to settle on the “relative” nature of personal data, its practical implications on everything we do in the Marketing Technology and digital advertising spaces cannot be overstated.Peter is a lawyer as well as a software developer. He is based in Brussels, heads the EU Data/Cyber/Tech Law team at Keller & Heckman, and helps international companies with their global data strategy and with EU data litigation.References:* Peter Craddock on LinkedIn* When is data no longer personal? And what are the implications? (Peter Craddock)* EDPS v. SRB (full text of the decision)* Peter Craddock: ePrivacy exceptions, advertising, analytics, the limits of consent and server-side processing (Masters of Privacy, 2024) This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
Meaghan Henderson started off as a litigation attorney in Los Angeles, subsequently joining Snap Inc.’s Trust and Safety operations. She is now Global Head of Privacy at iRobot (makers of the ubiquitous Roomba, a robotic vacuum cleaner).We have gone over the many tasks that Meaghan has managed (and regularly manages) to accomplish as a one-person team: rolling out a full privacy program, raising internal awareness, coordinating with security teams, complying across multiple jurisdictions, and being part of the AI governance committee.References:* Meaghan Henderson on LinkedIn* Generally Accepted Privacy Principles (GAPP)* ISO/IEC 27701 (program maturity over time)* Fair Information Practice Principles (FIPPs)* NIST Privacy Framework* OECD Privacy guidelines* Amazon and iRobot agree to terminate pending acquisition This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
We revisit the topics of individual agency, consumer perceptions of privacy, and self-sovereign identity through the lens of a “personal AI”.Copenhagen-based Yngvi Karlson is the Co-founder of Kin, a personal AI built on privacy and trust. After two successful exits and a career in venture capital, he set out to answer a bigger question: can AI empower us without owning us? For him, Kin is more than technology. It’s a movement to put people back in control of their data, their conversations, and their future.References:* Download Kin* Yngvi Karlson on LinkedIn* My data, my rules? Not so fast. (Sergio Maldonado, 2021)* Dan Stone: how to own our identity, protect personal data, and escape LinkedIn (Masters of Privacy)* Jamie Smith: AI Agents, digital identity, wallets and personal data (Masters of Privacy)* Adrian Doerk: digital identity, digital wallets and data protection (Masters of Privacy)* Sille Sepp: MyData Global and the fight for Human Centricity (Masters of Privacy)* An emotional attachment to GPT 4o results in OpenAI reversing course on GPT 5 (Wired) This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
Jennifer Oliver is an experienced commercial litigator who has defended consumer class actions and multidistrict litigation, including those arising from data breaches and antitrust. She has worked in several high-profile jury trials, serving as lead counsel in complex mediations. She also counsels clients on matters related to privacy compliance and use of ad tech and similar technologies.Jennifer is a shareholder at Buchanan, Ingersoll & Rooney and has a long list of relevant affiliations and certifications including being an Executive Committee Member of the Privacy Section at the California Lawyers Association.With Jennifer we have dived deeper into AdTech or pixel-related litigation in California, both in court and through arbitration.References:* Jennifer Oliver on LinkedIn* Jennifer Oliver’s profile at Buchanan* John Pavolotsky: How successful can US privacy laws be at regulating AI models and systems? (Masters of Privacy)* California SB 690 Passes California’s Senate, Signaling a Major Step in Redefining Privacy Law and Limiting CIPA Litigation for Online Businesses This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
Are privacy compliance and AI governance poised to remain stand-alone practices within the large enterprise? What is their interplay with an all-encompassing compliance effort? How will we deal with consent in the world of AI Agents? Erica Irvin is SVP, Commercial and Innovation Law, and Chief Privacy Counsel at Lowe’s Companies, Inc., where she leads legal strategy for commercial operations, privacy, and innovation. With nearly 30 years of in-house experience across retail, tech, and education, she is known for building agile legal teams and shaping ethical approaches to Privacy by Design, AI and digital transformation. Erica is also a frequent speaker and advisor on privacy, data governance, and legal innovation. References: Erica Irvin on LinkedIn Linsey Krolik: the growing role of the Product Counsel in privacy and AI compliance (Masters of Privacy, May 2025) Gam Dias: Agents Unleashed, understanding the Agentic AI stack (Masters of Privacy, April 2025) This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
Gam Dias is a seasoned technologist and entrepreneur with a rich background in software engineering, AI, and product innovation. As a consultant, he has helped write the data strategy for Fortune Global 500 companies, innovative startups, and ambitious non-profits. He has a degree in Computer Science from the University of Liverpool and an MBA from Warwick Business School. Gam has lived in London, Leeds, Salt Lake City, Santa Cruz, San Francisco, and he currently lives in and works from Madrid, Spain. Gam’s latest work, Agents Unleashed, distills years of experience into a compelling look at the rise of autonomous AI agents and their growing role in marketing, sales, and beyond.  References: Gam Dias on LinkedIn Agents Unleashed (Amazon) Agentforce (Salesforce) Gam Dias: on privacy, agency, convenience, and freedom (Masters of Privacy, 2021)  Hubbl Process Analytics Diana Stern and Dazza Greenwood, From Fine Print to Machine Code: How AI Agents are Rewriting the Rules of Engagement (Stanford Law School)   This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
What is “manipulative design”? How does this concept differ from “dark patterns”? How could we expand website and mobile app monitoring to a company’s ad stack?  Boltive’s Christine Desrosiers has joined us for another Privacy Tech interview. She is an operations and product professional with 20 years of experience building best-in-class publisher ad stacks and ops teams, and integrating ad and site stacks with Privacy Tech. She is involved in a number of industry working groups and advisory boards, working to raise the bar on privacy, security and transparency.  References: Christine Desrosiers on LinkedIn Boltive: monitor security and privacy compliance across the consumer front end (including publishing and AdTech) Jessica B. Lee, Chair of Loeb & Loeb LLP’s Privacy, Security & Data Innovations practice Global Privacy Enforcement Network: 2024 “sweep” on deceptive design patterns FTC, ICPEN, GPEN Announce Results of Review of Use of Dark Patterns Affecting Subscription Services, Privacy (FTC, July 2024) Bringing Dark Patterns to Light (FTC, September 2022) Daniel Solove, A Taxonomy of Privacy (UPenn Law Review, January 2006) - see “decisional interference” Website Privacy Controls (New York State Attorney General) FTC study finds ‘dark patterns’ used by a majority of subscription apps and websites (TechCrunch, July 2024) FTC vs. Amazon (“Roach Motel” pattern through the internally called “Illiad” process for consumers to cancel their Amazon Prime membership) California SB 690: A new hope for CIPA litigation overload? (Norton Rose Fulbright) Daniel Solove: On Privacy and Technology (Masters of Privacy, March 2025) Max Anderson (Ketch): Privacy Tech spotlight I – the future of CMPs, value vs. hype in privacy compliance SaaS (Masters of Privacy, April 2025) Daniel Barber (DataGrail): Privacy Tech spotlight II – widespread non-compliance, opt-out challenges, and shadow AI (Masters of Privacy, May 2025) Cillian Kieran (Ethyca): Privacy Tech spotlight III – compliance as an engineering challenge (Masters of Privacy, June 2025) Vaibhav Antil (Privado): Privacy Tech spotlight IV - from trust to evidence (Masters of Privacy, July 2025) This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
Could transparency and control requirements be seamlessly integrated within delightful customer journeys? How has a famously design-led company (Airbnb) mastered Privacy User Experience? Ansuman Acharya serves as a Principal Product Manager at Airbnb, where he leads the design and development of cutting-edge privacy experiences that safeguard the trust of millions across the globe. With a foundation in privacy technology and user-centric design, he artfully bridges engineering depth with ethical product leadership. His 11-year journey at Microsoft, spanning Hyderabad, India and Bellevue, WA shaped his multidisciplinary expertise across enterprise and consumer domains spanning commerce, collaboration/productivity and healthcare tech. Ansuman holds a Master’s from the University of Washington’s Foster School in Information Systems and a Bachelors degree in Computer Science Engineering from NIT Rourkela in India. References: Ansuman Acharya on LinkedIn Airbnb: privacy choices USENIX Conference on Privacy Engineering Practice and Respect Defining Privacy UX (UserTesting) This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
Will EU cybersecurity laws result in new global standards? Should companies handle NIS2 compliance in concert with GDPR, AI Act, or Data Act requirements? Does it make sense to take data localization to its ultimate consequences? Nathalie Barrera serves as the Director for Privacy for the EMEA region at Palo Alto Networks, which is a leading provider of cybersecurity solutions. Her expertise involves the company’s compliance with NIS2, the AI Act, the GDPR, and DORA. She also assists customers in navigating their own complex regulatory requirements. She has previously spent seven years at Cisco Systems working as commercial counsel and Privacy and Security Counsel.  She studied law and completed her LLM at the University of Navarra.  References: Nathalie Barrera on LinkedIn EU Network and Information Services Directive II EU Data Act EU Digital Operational Resilience Act (DORA)   This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
How do we move from mere words to actual baked-in privacy? Can built-in alerts, code scanning tools, or server-side auditing make life much easier for DPOs and legal teams?  We are joined by Vaibhav Antil in a new installment of our Privacy Tech series. Vaibhav is founder & CEO of Privado.ai. Before starting Privado.ai, Vaibhav led product management at a tech company and worked with the legal team on GDPR compliance. Vaibhav started Privado.ai to solve the language gap between legal, privacy, and product engineering teams. References: Vaibhav Antil on LinkedIn Privado: Evidence-based Privacy Bridge: Technical Privacy Summit (by Privado) CNIL: Use analytics on your websites and applications (how analytical cookies can be exempt from consent) Max Anderson (Ketch): Privacy Tech spotlight I – the future of CMPs, value vs. hype in privacy compliance SaaS (Masters of Privacy, April 2025) Daniel Barber (DataGrail): Privacy Tech spotlight II – widespread non-compliance, opt-out challenges, and shadow AI (Masters of Privacy, May 2025) Cillian Kieran (Ethyca): Privacy Tech spotlight III – compliance as an engineering challenge (Masters of Privacy, June 2025) This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
John Pavolotsky is a partner at Stoel Rives in San Francisco. He is co-chair of the firm's AI, Privacy & Cybersecurity group and focuses his practice on data privacy, information security, and complex technology transactions. He has also been chair of the Intellectual Property Section of the California Lawyers Association.  John has taught Technology Transactions Law at the UC Davis School of Law and Comparative Privacy Law at the Santa Clara University School of Law. John has also guest lectured on technology and privacy law topics at the University of California, Berkeley, Haas School of Business; the University of San Francisco School of Management; and Stanford University. References: John Pavolotsky on LinkedIn John Pavolotksy at Stoel Rives Timeline of discussions (House, Senate) leading to a final decision on a 10-year moratorium on state-level AI laws (final deadline: July 4, 2025), Techcrunch Texas Legislature Passes House Bill 149 to Regulate AI Use (Nelson Mullins) Colorado AI Act California Privacy Protection Agency: Draft Automated Decision-making Technology Regulations California Gov. Newsom vetoes AI safety bill that divided Silicon Valley (September 2024), NPR Poland puts pausing enforcement of the AI Act on EU ministers' table (June 2025, MLex - paywalled) A Brief Overview of the Federal Trade Commission's Investigative, Law Enforcement, and Rulemaking Authority (FTC) This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
Who can really claim to be a privacy engineer? Does this change in the digital marketing arena? What is the winning formula to integrate this role within the company’s privacy practice? Thomas Ghys has worked as a management consultant, data scientist, and data strategist, including a 5-year stint at McKinsey, prior to setting up his own privacy engineering practice. He has deep expertise in MarTech and AdTech, auditing traditional machine learning models and data flows. He is also the founder and CEO of Webclew, a tool that helps with the auditing of websites and mobile apps. References: Thomas Ghys on LinkedIn Webclew: scanning websites and apps for privacy risks CNIL: a focus on mobile SDKs, announcing enforcement actions in 2025 Thomas Ghys: BAPD expectations for cookie compliancy unattainable for most publishers Dr. Augustine Fou: dismantling marketing attribution, ad fraud controls, and the business case for third-party cookies (Masters of Privacy, February 2024) This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
Can we shift the focus from documentation to technical implementation? How can we bridge the cultural differences between legal teams and engineers? What do we mean with open-source data classification? We are joined by Cillian Kieran, Ethyca’s CEO and founder, in a new installment of our Privacy Tech series. Cillian is a serial entrepreneur and seasoned privacy engineer with two decades of experience leading data-intensive businesses. He combines deep technical expertise with a track record of building and scaling companies, including a global digital agency serving Fortune 500 clients.  References: Fides: the open source language for data privacy Cillian Kieran on LinkedIn Ethyca Max Anderson (Ketch): Privacy Tech spotlight I – the future of CMPs, value vs. hype in privacy compliance SaaS (Masters of Privacy, April 2025) Daniel Barber (DataGrail): Privacy Tech spotlight II – widespread non-compliance, opt-out challenges, and shadow AI (Masters of Privacy, May 2025) This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
It is time for a seasonal update at the intersection of Marketing, Data, Privacy and Technology. We are today covering the first four of our usual five blocks: ePrivacy & regulatory updates; MarTech & AdTech; AI, Competition and Digital Markets; PETs and Zero-Party Data.  All references and links can be found in this episode’s blog post: Masters of Privacy. Allow us to thank two people in advance for their routine work in breaking down the news across some of the topics and jurisdictions covered here: Robert Bateman and his Privacy Corner and Federico Marengo with his Privacy and AI newsletter. Also, an important disclaimer: the voice that joins me today is a text-to-speech output generated with Eleven Labs. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
What do we refer to with “privacy metrics”? Are privacy professionals delusional regarding the impact of the discipline in the overall business context? Lauren Reid is founder of The Privacy Pro, a boutique firm that provides essential training, tools, and support for privacy professionals to turn knowledge into action. In addition to leading The Privacy Pro, Lauren works with executives, boards, and product teams to build privacy data governance strategies that support responsible innovation and prepare companies for investor and regulatory scrutiny. She has a 20-year track record in this space. References: Lauren Reid on LinkedIn The Privacy Pro Lauren Reid: Rethinking Privacy Metrics: Aligning with Business Strategy This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
Can telco-powered identifiers overcome their own privacy challenges in their attempt to replace third-party cookies or email-based alternatives? Pascale is the Data Protection Officer at Utiq, a European based AdTech company. She has been working in privacy and data protection ever since completing her degree in Law, including roles at fashion group Arcadia and Vodafone Group. Pascale’s main goal is always to put privacy at the heart of the business. Utiq’s mission is to enable more responsible digital marketing by offering a telco powered privacy-first technology to Brands, Publishers and Tech Vendors operating in the adtech ecosystem. The Utiq technology consists of online identifiers which can be used to support and optimize digital marketing, advertising and analytics activities, whilst offering individuals enhanced choice, control and transparency, including via the application of privacy-centric controls and a dedicated privacy portal for end users, known as consenthub. Launched in 2023, Utiq was originally backed by Deutsche Telekom AG, Orange SA, Telefónica S.A., and Vodafone Group plc. It has continued to gain support from numerous other leading telecom operators across Germany, France, Spain, Austria and soon expanding to the UK and Italy. References: Pascale Arguinarena on LinkedIn FCC fines Verizon $1.35 million over ‘supercookie’ tracking (The Verge, May 2016) Utiq’s consenthub   This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
Are Product Counsels in the best position to anticipate and solve privacy and AI compliance problems before we release new products to the public at large - all of it while avoiding costly delays in fast-moving projects? Linsey Krolik is Assistant Clinical Professor at Santa Clara University School of Law, where she runs the Privacy Law Certificate and teaches Privacy Law. She is Director of the Entrepreneurs’ Law Clinic, where students work with real startups on transactional law projects, and Director of the TechEdge JD, a skills based certificate program for students interested in working in technology law. She also teaches a class called Law and Technology of Silicon Valley, with students playing the role of product or privacy counsel for a day.  Prior to joining academia, Linsey held senior in-house roles as a product, privacy, and commercial lawyer at global companies including PayPal, ARM, and Palm. Also, she continues to consult on privacy and AI governance in her solo law practice. References: Linsey Krolik on LinkedIn Santa Clara University School of Law TechEdge JD Entrepreneurs' Law Clinic Privacy Law Certificate Navigating AI and Data Ethics: The Essential Role of Product Lawyers and the Product Counsel Framework (Linsey Krolik, Adrienne Go, Olga Mack) Gam Dias: Agents Unleashed, understanding the Agentic AI stack (Masters of Privacy) This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
loading
Comments