Masters of Privacy

Sergio Maldonado
undefined
Oct 19, 2025 • 37min

John Pavolotsky: California's privacy and AI legislative spree (October 2025)

California has enacted a sweeping wave of new privacy and AI laws in the past few days. From browsers finally reading opt-out signals to age verification, chatbot companions, data brokers and AI transparency, some of these laws will have a serious impact on the areas we mostly focus on (marketing, advertising, ecommerce, media).We have discussed AB 566, SB 361, SB 53, AB 1043, AB 656, AB 853, and SB 243 with John Pavolosky, joining us for a second time.Our guest is a partner at Stoel Rives in San Francisco. He is co-lead of the firm’s Technology Industry Group. He has also been chair of the Intellectual Property Section of the California Lawyers Association.John has taught Technology Transactions Law at the UC Davis School of Law and Comparative Privacy Law at the Santa Clara University School of Law. John has also guest lectured on technology and privacy law topics at the University of California, Berkeley, Haas School of Business; the University of San Francisco School of Management; and Stanford University.References:* John Pavolotsky on LinkedIn* John Pavolotsky at Stoel Rives* John Pavolotsky: How successful can US privacy laws be at regulating AI models and systems? (Masters of Privacy, June 2025)* AB 566 (Opt-Out Preference Signal, October 8)* AB 1043 (Digital Age Assurance Act, October 13)* SB690, the law that could have done away with most CIPA lawsuits* SB 361 (Expanded Data Broker Transparency Requirements, October 8)* AB 56 (Social Media Warning Law, October 13)* AB 656 (Social Media Account “Delete” Button, October 8)* SB 243 (Companion Chatbots, October 13)* Her, a Spike Jonze movie (2013)* AB 853 (Amendment to the California AI Transparency Act, October 13)* SB 53 (Transparency in Frontier AI Act, September 29). This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
undefined
Oct 12, 2025 • 30min

Pádraig O’Leary (TrustWorks): the role of context, built-in know-how, and AI in Privacy Tech

Can we ever escape never-ending assessments as a core activity of a privacy management program? How does Privacy Tech extend to AI governance? Does built-in know-how become the most crucial moat?We are joined by Pádraig O’Leary, co-founder and CEO of TrustWorks, in a new installment of our Privacy Tech series (our sixth). Pádraig (Ph.D.) is a former academic in computer science.TrustWorks works with Fortune 500 and high-growth clients, helping them discover what AI and data they’re really using, understand the context of regulations and implications, and embed governance into everyday operations.References:* Pádraig O’Leary Ph.D. on LinkedIn* TrustWorks, recipients of the PICASSO most Impactful Privacy Product Award* Christine Desrosiers (Boltive): Privacy Tech spotlight V - understanding Manipulative Design and rolling out comprehensive client-side monitoring (Masters of Privacy, July 2025)* Vaibhav Antil (Privado): Privacy Tech spotlight IV - from trust to evidence (Masters of Privacy, July 2025)* Cillian Kieran (Ethyca): Privacy Tech spotlight III – compliance as an engineering challenge (Masters of Privacy, June 2025)* Daniel Barber (DataGrail): Privacy Tech spotlight II – widespread non-compliance, opt-out challenges, and shadow AI (Masters of Privacy, May 2025)* Max Anderson (Ketch): Privacy Tech spotlight I – the future of CMPs, value vs. hype in privacy compliance SaaS (Masters of Privacy, April 2025). This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
undefined
Oct 5, 2025 • 34min

Alexandria Lutz: protecting the elder from a new generation of privacy threats

Alexandria (Lexi) Andresen Lutz is founder of the nonprofit Opt-Inspire, Inc., which is focused on empowering seniors, children, other vulnerable populations, and their caregivers to reduce scams and close the digital divide between generations.In her day job, Lexi serves as Senior Corporate Counsel at a Fortune 500 retail company, where she advises on privacy, cybersecurity, and AI. She currently serves in leadership roles in the American Bar Association and is Chair of the IAPP Boston chapter.References:* SIGN UP NOW for the Masters of Privacy NYC LIVE recording and networking event on Nov 6* Alexandria (Lexi) Lutz on LinkedIn* Opt Inspire* FBI: Internet Crime Report 2024* John Cavanaugh: Privacy as a grassroots movement (Masters of Privacy, June 2024)* Jeff Jockisch: AI-powered phishing attacks in the age of the Delete Act (Masters of Privacy, October 2023). This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
undefined
Sep 28, 2025 • 30min

Robert Bateman: AI watermarking, recognized legitimate interests and age verification in the UK

Robert Bateman is a Senior Partner at Privacy Partnership, which provides consultancy and training on data protection and AI regulation, as well as legal advice via its associated law firm, Privacy Partnership Law. He also hosts The Privacy Partnership Podcast.This is Robert’s third appearance on the show. We have covered three hot topics:* How far do we take watermarking of AI-generated content under article 50 of the AI Act?* How do pre-defined legitimate interest scenarios work under the UK Data (Use and Access) Act?* What is the tension between the Online Safety Act and the new data protection framework in the UK?References:SIGN UP NOW for the Masters of Privacy NYC LIVE recording and networking event on Nov 6 (if you happen to be in town)* Robert Bateman on LinkedIn* Robert Bateman on Bluesky* The Privacy Partnership Podcast* AI Act (EU Commission’s resources)* Data (Use and Access) Act 2025: data protection and privacy changes* The EU approach to age verification (EU Commission)* EU follows UK with age verification in 2026 (PPC Land)* Wikipedia loses challenge against Online Safety Act verification rules (BBC)* Robert Bateman: the EDPB’s Opinion on auditing subprocessors and the future of Meta’s unskippable ads (Masters of Privacy, Nov 2024)* Robert Bateman: Consent or Pay (Masters of Privacy, Oct 2023) This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
undefined
Sep 21, 2025 • 21min

Newsroom: Summer 2025

It is time for a seasonal update at the intersection of Marketing, Data, Privacy and Technology. We will stick to our usual five blocks: ePrivacy & regulatory updates; MarTech & AdTech; AI, Competition and Digital Markets; PETs and Zero-Party Data; Future of Media.This includes:* CJEU decisions on Latombe (EU-US data transfers have survived, for now) and SRB (relative nature of personal data) * UK legal updates and ICO consultations on ePrivacy-related topics* Record public fines and enforcement actions in California* Ongoing explosion of pixel and cookie-related lawsuits across the US* Important fines in the EU, with CNIL’s unwavering passion for large-scale ePrivacy enforcement* Agentic AI milestones for AdTech and customer centricity/empowerment* Key initiatives to protect copyright holders from large AI labs (together with Anthropic’s settlement)All references and links can be found in a separate blog post available to Masters of Privacy Connect subscribers on our website’s Newsroom section.Our usual disclaimer: the voice that joins me today is a text-to-speech output generated with Eleven Labs. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
undefined
Sep 14, 2025 • 34min

Daniel Simmons-Marengo: Differential Privacy in practice

How can we apply differential privacy to real-world scenarios? How do you go about algorithmic design? Is there a conflict between data minimization and differential privacy? Can you solve for personal data finding its way into machine learning models? Where can a young professional find resources to dive deeper?References:* Daniel Simmons-Marengo on LinkedIn* OpenDP* Some takeaways from PEPR’24 (USENIX Conference on Privacy Engineering Practice and Respect 2024)* Damien Desfontaines: Differential Privacy in Data Clean Rooms (Masters of Privacy, January 2024)* NIST Guidelines for Evaluating Differential Privacy Guarantees (March 2025)* Peter Craddock: EDPS v SRB, the relative nature of personal data, processors, transparency, impact on MarTech and AdTech (Masters of Privacy, September 2025)* Katharine Jarmul: Demystifying Privacy Enhancing Technologies (Masters of Privacy, October 2023)* Sunny Kang: Machine Learning meets Privacy Enhancing Technologies (Masters of Privacy, February 2023)* How GDPR changes the rules for research (Gabe Maldoff, IAPP blog, 2016) This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
undefined
Sep 9, 2025 • 50min

Peter Craddock: EDPS v SRB, the relative nature of personal data, processors, transparency, impact on MarTech and AdTech

Peter Craddock joins us once again to discuss the recent EDPS v Single Resolution Board decision by the Court of Justice of the EU. Although it builds on the previous Scania and Breyer cases to settle on the “relative” nature of personal data, its practical implications on everything we do in the Marketing Technology and digital advertising spaces cannot be overstated.Peter is a lawyer as well as a software developer. He is based in Brussels, heads the EU Data/Cyber/Tech Law team at Keller & Heckman, and helps international companies with their global data strategy and with EU data litigation.References:* Peter Craddock on LinkedIn* When is data no longer personal? And what are the implications? (Peter Craddock)* EDPS v. SRB (full text of the decision)* Peter Craddock: ePrivacy exceptions, advertising, analytics, the limits of consent and server-side processing (Masters of Privacy, 2024) This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
undefined
Sep 7, 2025 • 23min

Meaghan Henderson (iRobot): the privacy department as a one-woman show

Meaghan Henderson started off as a litigation attorney in Los Angeles, subsequently joining Snap Inc.’s Trust and Safety operations. She is now Global Head of Privacy at iRobot (makers of the ubiquitous Roomba, a robotic vacuum cleaner).We have gone over the many tasks that Meaghan has managed (and regularly manages) to accomplish as a one-person team: rolling out a full privacy program, raising internal awareness, coordinating with security teams, complying across multiple jurisdictions, and being part of the AI governance committee.References:* Meaghan Henderson on LinkedIn* Generally Accepted Privacy Principles (GAPP)* ISO/IEC 27701 (program maturity over time)* Fair Information Practice Principles (FIPPs)* NIST Privacy Framework* OECD Privacy guidelines* Amazon and iRobot agree to terminate pending acquisition This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
undefined
Aug 29, 2025 • 39min

Yngvi Karlson (Kin): the rise of the Personal AI Assistant

We revisit the topics of individual agency, consumer perceptions of privacy, and self-sovereign identity through the lens of a “personal AI”.Copenhagen-based Yngvi Karlson is the Co-founder of Kin, a personal AI built on privacy and trust. After two successful exits and a career in venture capital, he set out to answer a bigger question: can AI empower us without owning us? For him, Kin is more than technology. It’s a movement to put people back in control of their data, their conversations, and their future.References:* Download Kin* Yngvi Karlson on LinkedIn* My data, my rules? Not so fast. (Sergio Maldonado, 2021)* Dan Stone: how to own our identity, protect personal data, and escape LinkedIn (Masters of Privacy)* Jamie Smith: AI Agents, digital identity, wallets and personal data (Masters of Privacy)* Adrian Doerk: digital identity, digital wallets and data protection (Masters of Privacy)* Sille Sepp: MyData Global and the fight for Human Centricity (Masters of Privacy)* An emotional attachment to GPT 4o results in OpenAI reversing course on GPT 5 (Wired) This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
undefined
Aug 23, 2025 • 25min

Jennifer Oliver: privacy litigation over pixels, trackers, and cookies

Jennifer Oliver is an experienced commercial litigator who has defended consumer class actions and multidistrict litigation, including those arising from data breaches and antitrust. She has worked in several high-profile jury trials, serving as lead counsel in complex mediations. She also counsels clients on matters related to privacy compliance and use of ad tech and similar technologies.Jennifer is a shareholder at Buchanan, Ingersoll & Rooney and has a long list of relevant affiliations and certifications including being an Executive Committee Member of the Privacy Section at the California Lawyers Association.With Jennifer we have dived deeper into AdTech or pixel-related litigation in California, both in court and through arbitration.References:* Jennifer Oliver on LinkedIn* Jennifer Oliver’s profile at Buchanan* John Pavolotsky: How successful can US privacy laws be at regulating AI models and systems? (Masters of Privacy)* California SB 690 Passes California’s Senate, Signaling a Major Step in Redefining Privacy Law and Limiting CIPA Litigation for Online Businesses This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app