Skip to content
PodcastsBusinessMasters of Privacy

Masters of Privacy

Sergio Maldonado
Masters of Privacy
Latest episode

174 episodes

  • Masters of Privacy

    Aleksandr Tiulkanov: dissecting transparency requirements in the EU AI Act

    04/10/2026 | 41 mins.
    Aleksandr Tiulkanov has advised businesses on legal and compliance matters since 2003 and has focused on IT law and digital policy since 2015. He has previously been a Special Adviser on Digital Development at the Council of Europe; as well as Senior Manager for Technology, Media and Telecoms at Deloitte Legal.
    Aleksandr is also a Member of the AFNOR CN IA (French Commission on AI Standardisation), as well as a Member of the CEN-CENELEC JTC 21 (Artificial Intelligence), and a PECB Certified ISO/IEC 42001 Lead Implementer.
    He also holds an LL.M. in Innovation, Technology and the Law, University of Edinburgh (2018) and has been listed in “Best Lawyers in Information Technology Law (2020)”
    References:
    Aleksandr Tiulkanov on LinkedIn
    Engagements and training by Aleksandr Tiulkanov
    Preparing for the EU AI Act, a 4-week course by Aleksandr Tiulkanov (code for a 10% discount: MOPPTL2)
    Paragraphs 1-4 of Article 50 of the EU AI Act: Transparency obligations for providers and deployers of certain AI systems
    * Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI systems, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use. This obligation shall not apply to AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences, subject to appropriate safeguards for the rights and freedoms of third parties, unless those systems are available for the public to report a criminal offence.
    * Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI systems are marked in a machine-readable format and detectable as artificially generated or manipulated. Providers shall ensure their technical solutions are effective, interoperable, robust and reliable as far as this is technically feasible, taking into account the specificities and limitations of various types of content, the costs of implementation and the generally acknowledged state of the art, as may be reflected in relevant technical standards. This obligation shall not apply to the extent the AI systems perform an assistive function for standard editing or do not substantially alter the input data provided by the deployer or the semantics thereof, or where authorised by law to detect, prevent, investigate or prosecute criminal offences.
    * Deployers of an emotion recognition system or a biometric categorisation system shall inform the natural persons exposed thereto of the operation of the system, and shall process the personal data in accordance with Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable. This obligation shall not apply to AI systems used for biometric categorisation and emotion recognition, which are permitted by law to detect, prevent or investigate criminal offences, subject to appropriate safeguards for the rights and freedoms of third parties, and in accordance with Union law.
    * Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulated. This obligation shall not apply where the use is authorised by law to detect, prevent, investigate or prosecute criminal offence. Where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work or programme, the transparency obligations set out in this paragraph are limited to disclosure of the existence of such generated or manipulated content in an appropriate manner that does not hamper the display or enjoyment of the work.
    Deployers of an AI system that generates or manipulates text which is published with the purpose of informing the public on matters of public interest shall disclose that the text has been artificially generated or manipulated. This obligation shall not apply where the use is authorised by law to detect, prevent, investigate or prosecute criminal offences or where the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content.


    This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
  • Masters of Privacy

    Dazza Greenwood: from agentic contracts to AI-assisted law firms. Delegation, attribution and judgment

    27/09/2026 | 46 mins.
    Daniel “Dazza” Greenwood is the founder of CIVICS.com, a boutique provider of professional consultancy services for legal technologies, automated transactions, privacy and data management, and technology strategy. Dazza is also a researcher at MIT Media Lab and Lecturer at MIT Connection Science where he has been advancing the field of computational law and generative AI for law as Executive Director of law.MIT.edu.
    Our guest serves as lead on the Data Rights Protocol initiative through Consumer Reports Digital Lab. This protocol provides a common open specification for enabling consumers and companies to process the exercise of individual data rights as a consumer-connected digital service.
    Dazza Greenwood consults to Fortune 100 companies, architecting and building integrated business, legal and technology cross-boundary networks at industry scale. As an attorney, he served as both in-house and special counsel for technology law, representing corporations and governments. He has also testified before the US House, US Senate and other legislatures on electronic transactions law and consults extensively to the public sector.
    References:
    * Dazza Greenwood on LinkedIn
    * Dazza Greenwood’s Substack
    * CIVICS.com
    * Data Rights Protocol: Standardizing consumers’ data rights requests (Consumer Reports)
    * Uniform Electronic Transactions Act (1999)
    * Authority Boundaries for AI (Dazza Greenwood, May 2026)
    * LQAI from LegalQuants on Github (open source platform for law firms)
    * Thirteen Words Shape Legal AI (Dazza Greenwood, September 2026)
    * MIT Computational Law Report - Now part of Stanford Law School
    * HOPE Lab, Hands-On Projects and Experimentation: Learn to work with agents across multiple stages, with clear goals, boundaries, and evidence of what worked.
    * Interlateral (“Bring your own agent”), run by Dazza Greenwood: A space where people and their AI agents meet, coordinate, and build together over the web.
    * Jamie Smith: AI Agents, digital identity, wallets and personal data (Masters of Privacy, December 2024).


    This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
  • Masters of Privacy

    Shannon Yavorsky: legal implications of AI-driven recruitment

    23/09/2026 | 26 mins.
    Shannon Yavorsky is a Global Co-Chair of Orrick’s Cyber, Privacy & Data Innovation group and co-head of its AI practice. She advises leading companies on privacy, cybersecurity and AI regulation, governance, transactions and strategic risk management, helping clients translate fast-moving legal requirements into practical, business-focused solutions.
    References:
    * Shannon Yavorsky on LinkedIn
    * Shannon Yavorsky at Orrick
    * AI governance frameworks, comparison and overlaps (AI Sentinel docs): Thirteen widely used AI governance frameworks, including AIUC-1, AI Act, NIST, ISO, California ADMT, and more. Compared across fourteen dimensions.


    This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
  • Masters of Privacy

    Julian Gage: the evolving shape and role of DPIAs

    20/09/2026 | 31 mins.
    How should we approach a Data Protection Impact Assessment or Privacy Impact Assessment in this new world? Are we recycling “mitigation measures” shamelessly? Are we drowning in futile DPIAs that were never really required?
    Julian Gage is a fractional DPO and the founder of Engage Compliance. He has acted as an external DPO and EU representative for over 100 companies including Coinbase and Robinhood, as well as plenty of startups.
    References:
    * DPO Central: build a DPIA
    * TODO.LAW: Run it your way
    * Julian Gage on LinkedIn
    * Engage Compliance
    * EDPB: Template for a Data Protection Impact Assessment
    * Nick Baskett: Mastering DPIAs (Masters of Privacy, July 2023)


    This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
  • Masters of Privacy

    Amy Lawrence: Meta settlement, advertising to minors, age assurance and addictive design.

    13/09/2026 | 29 mins.
    Amy Lawrence is Chief Privacy Officer and Head of Legal at SuperAwesome, where she leads global privacy strategy for technology and media products designed for young audiences. An expert in youth privacy and digital regulation, Amy advises on building adtech services and responsible advertising in compliance with COPPA, GDPR, state privacy laws, and age-appropriate design codes. Previously, she was with Epic Games helping modernize the global privacy program and regulatory engagement.
    Amy began her career in private practice, focused on privacy compliance in media and entertainment. She holds CIPP/US and CIPP/E certifications and is admitted to practice in California and New York.
    References:
    * Amy Lawrence on LinkedIn
    * About SuperAwesome
    * Meta agrees to pay $18 billion to settle US lawsuits over children’s social media addiction (Reuters, August 28th 2026). The company denied wrongdoing and agreed to restrict teenagers’ use of Facebook and Instagram ​to two hours a day and block all usage from midnight to 6 a.m., absent parental consent.
    * Reddit issued with £14.47m fine for children’s privacy failures (ICO, February 24th 2026)
    * Yoti: “Thoughts from our CEO: Spanish regulator AEPD fining Yoti” (€950,000, March 27th 2026)
    * California AB-1043, Age verification signals: software applications and online services. The law enters into force on January 1st 2027, with OS providers (iOS, Android) required to collect a date of birth during the initial device or account setup, subsequently passing age signals to specific apps via API -consisting of age brackets.
    * AI Sentinel: Future-Proof AI Governance (hosted on TODO.LAW, free)
    * InScope (North End Law): Which privacy/AI laws apply to your company?


    This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.mastersofprivacy.com/subscribe
More Business podcasts
About Masters of Privacy
Interviews and updates at the intersection of marketing, data, privacy, and technology. With an eye on a human-centric, demand-led future in which transparency, control, and personal agency play a crucial role. Sergio Maldonado (host) is a triple-qualified lawyer (California, England & Wales, Spain), entrepreneur, investor, guest lecturer at various universities. LL.M in IT & Internet Law, FIP, CIPP/E/US, CIPT. www.mastersofprivacy.com
Podcast website

Listen to Masters of Privacy, Great Business Stories and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features
Masters of Privacy: Podcasts in Family