
Sign up to save your podcasts
Or


Aleksandr Tiulkanov has advised businesses on legal and compliance matters since 2003 and has focused on IT law and digital policy since 2015. He has previously been a Special Adviser on Digital Development at the Council of Europe; as well as Senior Manager for Technology, Media and Telecoms at Deloitte Legal.
Aleksandr is also a Member of the AFNOR CN IA (French Commission on AI Standardisation), as well as a Member of the CEN-CENELEC JTC 21 (Artificial Intelligence), and a PECB Certified ISO/IEC 42001 Lead Implementer.
He also holds an LL.M. in Innovation, Technology and the Law, University of Edinburgh (2018) and has been listed in “Best Lawyers in Information Technology Law (2020)”
References:
Aleksandr Tiulkanov on LinkedIn
Engagements and training by Aleksandr Tiulkanov
Preparing for the EU AI Act, a 4-week course by Aleksandr Tiulkanov (code for a 10% discount: MOPPTL2)
Paragraphs 1-4 of Article 50 of the EU AI Act: Transparency obligations for providers and deployers of certain AI systems
* Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI systems, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use. This obligation shall not apply to AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences, subject to appropriate safeguards for the rights and freedoms of third parties, unless those systems are available for the public to report a criminal offence.
* Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI systems are marked in a machine-readable format and detectable as artificially generated or manipulated. Providers shall ensure their technical solutions are effective, interoperable, robust and reliable as far as this is technically feasible, taking into account the specificities and limitations of various types of content, the costs of implementation and the generally acknowledged state of the art, as may be reflected in relevant technical standards. This obligation shall not apply to the extent the AI systems perform an assistive function for standard editing or do not substantially alter the input data provided by the deployer or the semantics thereof, or where authorised by law to detect, prevent, investigate or prosecute criminal offences.
* Deployers of an emotion recognition system or a biometric categorisation system shall inform the natural persons exposed thereto of the operation of the system, and shall process the personal data in accordance with Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable. This obligation shall not apply to AI systems used for biometric categorisation and emotion recognition, which are permitted by law to detect, prevent or investigate criminal offences, subject to appropriate safeguards for the rights and freedoms of third parties, and in accordance with Union law.
* Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulated. This obligation shall not apply where the use is authorised by law to detect, prevent, investigate or prosecute criminal offence. Where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work or programme, the transparency obligations set out in this paragraph are limited to disclosure of the existence of such generated or manipulated content in an appropriate manner that does not hamper the display or enjoyment of the work.
Deployers of an AI system that generates or manipulates text which is published with the purpose of informing the public on matters of public interest shall disclose that the text has been artificially generated or manipulated. This obligation shall not apply where the use is authorised by law to detect, prevent, investigate or prosecute criminal offences or where the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content.
Daniel “Dazza” Greenwood is the founder of CIVICS.com, a boutique provider of professional consultancy services for legal technologies, automated transactions, privacy and data management, and technology strategy. Dazza is also a researcher at MIT Media Lab and Lecturer at MIT Connection Science where he has been advancing the field of computational law and generative AI for law as Executive Director of law.MIT.edu.
Our guest serves as lead on the Data Rights Protocol initiative through Consumer Reports Digital Lab. This protocol provides a common open specification for enabling consumers and companies to process the exercise of individual data rights as a consumer-connected digital service.
Dazza Greenwood consults to Fortune 100 companies, architecting and building integrated business, legal and technology cross-boundary networks at industry scale. As an attorney, he served as both in-house and special counsel for technology law, representing corporations and governments. He has also testified before the US House, US Senate and other legislatures on electronic transactions law and consults extensively to the public sector.
References:
* Dazza Greenwood on LinkedIn
* Dazza Greenwood’s Substack
* CIVICS.com
* Data Rights Protocol: Standardizing consumers’ data rights requests (Consumer Reports)
* Uniform Electronic Transactions Act (1999)
* Authority Boundaries for AI (Dazza Greenwood, May 2026)
* LQAI from LegalQuants on Github (open source platform for law firms)
* Thirteen Words Shape Legal AI (Dazza Greenwood, September 2026)
* MIT Computational Law Report - Now part of Stanford Law School
* HOPE Lab, Hands-On Projects and Experimentation: Learn to work with agents across multiple stages, with clear goals, boundaries, and evidence of what worked.
* Interlateral (“Bring your own agent”), run by Dazza Greenwood: A space where people and their AI agents meet, coordinate, and build together over the web.
* Jamie Smith: AI Agents, digital identity, wallets and personal data (Masters of Privacy, December 2024).
Shannon Yavorsky is a Global Co-Chair of Orrick’s Cyber, Privacy & Data Innovation group and co-head of its AI practice. She advises leading companies on privacy, cybersecurity and AI regulation, governance, transactions and strategic risk management, helping clients translate fast-moving legal requirements into practical, business-focused solutions.
References:
* Shannon Yavorsky on LinkedIn
* Shannon Yavorsky at Orrick
* AI governance frameworks, comparison and overlaps (AI Sentinel docs): Thirteen widely used AI governance frameworks, including AIUC-1, AI Act, NIST, ISO, California ADMT, and more. Compared across fourteen dimensions.
How should we approach a Data Protection Impact Assessment or Privacy Impact Assessment in this new world? Are we recycling “mitigation measures” shamelessly? Are we drowning in futile DPIAs that were never really required?
Julian Gage is a fractional DPO and the founder of Engage Compliance. He has acted as an external DPO and EU representative for over 100 companies including Coinbase and Robinhood, as well as plenty of startups.
References:
* DPO Central: build a DPIA
* TODO.LAW: Run it your way
* Julian Gage on LinkedIn
* Engage Compliance
* EDPB: Template for a Data Protection Impact Assessment
* Nick Baskett: Mastering DPIAs (Masters of Privacy, July 2023)
Amy Lawrence is Chief Privacy Officer and Head of Legal at SuperAwesome, where she leads global privacy strategy for technology and media products designed for young audiences. An expert in youth privacy and digital regulation, Amy advises on building adtech services and responsible advertising in compliance with COPPA, GDPR, state privacy laws, and age-appropriate design codes. Previously, she was with Epic Games helping modernize the global privacy program and regulatory engagement.
Amy began her career in private practice, focused on privacy compliance in media and entertainment. She holds CIPP/US and CIPP/E certifications and is admitted to practice in California and New York.
References:
* Amy Lawrence on LinkedIn
* About SuperAwesome
* Meta agrees to pay $18 billion to settle US lawsuits over children’s social media addiction (Reuters, August 28th 2026). The company denied wrongdoing and agreed to restrict teenagers’ use of Facebook and Instagram to two hours a day and block all usage from midnight to 6 a.m., absent parental consent.
* Reddit issued with £14.47m fine for children’s privacy failures (ICO, February 24th 2026)
* Yoti: “Thoughts from our CEO: Spanish regulator AEPD fining Yoti” (€950,000, March 27th 2026)
* California AB-1043, Age verification signals: software applications and online services. The law enters into force on January 1st 2027, with OS providers (iOS, Android) required to collect a date of birth during the initial device or account setup, subsequently passing age signals to specific apps via API -consisting of age brackets.
* AI Sentinel: Future-Proof AI Governance (hosted on TODO.LAW, free)
* InScope (North End Law): Which privacy/AI laws apply to your company?
Rosalia Anna D’Agostino is an Italian Lawyer, Data Privacy and AI Compliance Expert, until recently working at the German law firm Spirit Legal. Fluent in five languages, she graduated in Comparative European and International law from the University of Trento (IT).
Rosalia completed a joint programme with the University of Birmingham in the UK and, together with fellow students, founded Legal4Tech, where she leads a podcast on Law and Technology, engaging with top experts in tech governance.
Our guest has gone quite deep into the legal analysis of LLMs and their outputs, class action lawsuits in the EU and the UK, social media platform algorithms and more.
References:
* Rosalia Anna D’Agostino on LinkedIn
* Legal4Tech: on Spotify, Apple Podcasts, LinkedIn
* Deepfake: Italian Data Protection Authority orders immediate stop to Clothoff, the app that undresses people (Garante, October 2025)
* 20M EUR fine for Clearview AI in Italy (Garante, December 2022)
* EU Digital Services Act
* Russmedia decision (December 2025, CJEU): liability as a data controller for user generated content on a platform, flying over safe harbor provisions for hosting providers (originally in the Ecommerce Directive, now in the DSA)
* Rahul Uttamchandani: a legal framework for Deep Fakes (Masters of Privacy ES, March 2023).
Carissa Véliz is an Associate Professor in Philosophy at the Institute for Ethics in AI, and a Fellow at Hertford College at the University of Oxford. She is the recipient of the 2021 Herbert A. Simon Award for Outstanding Research in Computing and Philosophy.
Our guest is the author of Prophecy, now longlisted for the Financial Times business book of the year (2026), as well as the editor of the Oxford Handbook of Digital Ethics. Her previous book, Privacy is Power, was chosen by The Economist as one of the best books of the year in 2020.
Carissa advises companies and policymakers around the world on privacy and the ethics of AI, and is a member of UNESCO’s Women 4 Ethical AI.
References:
* Breakfast Workshop - Santa Monica, CA - September 2, 2026 (free for MoP subscribers)
* Prophecy: Prediction, Power, and the Fight for the Future, from Ancient Oracles to AI (Amazon)
* Carissa Véliz on Substack (The Antidote)
* Gary Marcus: Even more good news for the future of neurosymbolic AI (Substack, April 2026)
* Refresher (January 28th special, Masters of Privacy): Data Protection vs. Privacy and Data Privacy (with Carissa Véliz, Gabriela Zanfir-Fortuna, Brendan Quinn, Tim Turner, and Markus Wünschelbaum)
* Carissa Véliz: privacy is power (Masters of Privacy ES, Oct 2021 - Spanish)
* Install the TODO.LAW suite on your own device (Dealroom, DPO Central, AI Sentinel).
Send us your questions, feedback, or report requests (InScope, AuditScan) to: info[@]northend.law.
Professor Solove returns to discuss the fundamental flaws of “informed consent” and explore viable alternatives in the quest for true individual privacy.
Daniel J. Solove is the Bernard Professor of Intellectual Property and Technology Law at the George Washington University Law School. He is the co-director of the GW Center for Law & Technology. One of the world’s leading experts in privacy law, Solove is the author of 10+ books, 100+ articles, and a children’s fiction book about privacy. His latest book is “On Privacy and Technology”.
References:
* Daniel J. Solove on Substack
* Daniel J. Solove on LinkedIn
* Daniel J. Solove on Bluesky
* Daniel J. Solove’s personal page
* On Privacy and Technology: Oxford University Press, Amazon
* Murky Consent: An Approach to the Fictions of Consent in Privacy Law, (Daniel J. Solove, August 2023)
* Orwell vs. Huxley: Which Dystopia Was More Prescient? (Daniel J. Solove, June 2026)
* How to Maintain Our Privacy in the AI Age (Daniel J. Solove, June 2026).
We’re back for a new season (#12 across both channels, heading into our 7th year!), and we do it with a Newsroom update. We will cover our usual five blocks: ePrivacy & regulatory updates; MarTech & AdTech; AI, competition and digital markets; Zero-Party Data; and the future of media.
This season’s update includes:
- Meta’s “addictive design” of services for minors (public nuisance in New Mexico, trial of twenty nine states in California, DSA charge over addictive design in Brussels)
- Social media bans for minors in France, the UK and Australia, and the push to move age checks to the operating system
- The second largest GDPR fine to date, against Uber, for deactivating drivers by automated decision (Article 22)
- Enforcement across Europe (health data warehouses, traveller profiling, loyalty club consent, scraped business contacts, AI companion apps) and in the US (public, private)
- AI Act enforcement begins while obligations for high risk systems slip to 2027, plus EDPB guidelines on anonymization, web scraping and generative AI
- The end of FTC independence, doubts over the Data Privacy Framework, and a Google fine answered with tariff threats
- Advertising inside AI assistants, pixel matching by default, and AI copyright settlements.
All references and links (plus some bonus materials) can be found in a separate blog post available to paid Masters of Privacy subscribers on our website’s Newsroom section (Newsroom Notes: Summer 2026).
Our usual disclaimer: the voice that joins Sergio today is a text-to-speech output generated with Eleven Labs.
Where is the privacy-AI convergence taking us in 2026? How different is the UK’s new approach to automated decision making (ADMT)? Is AI pushing young lawyers out of the profession?
Eduardo Ustaran is global co-head of the Hogan Lovells Privacy and Cybersecurity practice, widely recognized as one of the world’s leading privacy and data protection lawyers and thought leaders. With over 30 years of experience, our guest advises multinationals and governments around the world on the adoption of privacy and cybersecurity strategies and policies. Eduardo has been involved in the development of the EU data protection framework and was listed by Politico as the most prepared individual in its ‘GDPR power matrix’.
Eduardo obtained his JD from Universidad de Navarra and an LLM in European and International Trade Law from the University of Leicester.
This is our 40th and last episode in the current (10th) season. We will be back in a few weeks. Have a great summer!
References:
* Eduardo Ustaran at Hogan Lovells
* Eduardo Ustaran on LinkedIn
* AI and Automated Decision-Making in the UK (Part I): The new rules and regulatory guidance (Eduardo Ustaran, Katie McMullan, Alina Podolyak)
* CCPA Updates, Cybersecurity Audits, Risk Assessments, Automated Decisionmaking Technology (ADMT), and Insurance Regulations
* Eduardo Ustaran: (Spanish) Second anniversary of the GDPR (Masters of Privacy ES, May 2020)
From the publisher's feed

30,692 Listeners

38,688 Listeners

14,503 Listeners

9,613 Listeners

67 Listeners

111,779 Listeners

56,445 Listeners

9,544 Listeners

9,708 Listeners

22 Listeners

29 Listeners

5,559 Listeners

3,021 Listeners

2,273 Listeners

1,451 Listeners