Masters of Privacy cover image

Masters of Privacy

Latest episodes

undefined
Jul 13, 2025 • 31min

Nathalie Barrera: NIS2 (EU) and the interplay between cybersecurity, privacy, AI, and IoT data laws

Will EU cybersecurity laws result in new global standards? Should companies handle NIS2 compliance in concert with GDPR, AI Act, or Data Act requirements? Does it make sense to take data localization to its ultimate consequences? Nathalie Barrera serves as the Director for Privacy for the EMEA region at Palo Alto Networks, which is a leading provider of cybersecurity solutions. Her expertise involves the company’s compliance with NIS2, the AI Act, the GDPR, and DORA. She also assists customers in navigating their own complex regulatory requirements. She has previously spent seven years at Cisco Systems working as commercial counsel and Privacy and Security Counsel.  She studied law and completed her LLM at the University of Navarra.  References: Nathalie Barrera on LinkedIn EU Network and Information Services Directive II EU Data Act EU Digital Operational Resilience Act (DORA)  
undefined
Jul 7, 2025 • 28min

Vaibhav Antil (Privado): Privacy Tech spotlight IV - from trust to evidence

How do we move from mere words to actual baked-in privacy? Can built-in alerts, code scanning tools, or server-side auditing make life much easier for DPOs and legal teams?  We are joined by Vaibhav Antil in a new installment of our Privacy Tech series. Vaibhav is founder & CEO of Privado.ai. Before starting Privado.ai, Vaibhav led product management at a tech company and worked with the legal team on GDPR compliance. Vaibhav started Privado.ai to solve the language gap between legal, privacy, and product engineering teams. References: Vaibhav Antil on LinkedIn Privado: Evidence-based Privacy Bridge: Technical Privacy Summit (by Privado) CNIL: Use analytics on your websites and applications (how analytical cookies can be exempt from consent) Max Anderson (Ketch): Privacy Tech spotlight I – the future of CMPs, value vs. hype in privacy compliance SaaS (Masters of Privacy, April 2025) Daniel Barber (DataGrail): Privacy Tech spotlight II – widespread non-compliance, opt-out challenges, and shadow AI (Masters of Privacy, May 2025) Cillian Kieran (Ethyca): Privacy Tech spotlight III – compliance as an engineering challenge (Masters of Privacy, June 2025)
undefined
Jun 30, 2025 • 28min

John Pavolotsky: How successful can US privacy laws be at regulating AI models and systems?

John Pavolotsky is a partner at Stoel Rives in San Francisco. He is co-chair of the firm's AI, Privacy & Cybersecurity group and focuses his practice on data privacy, information security, and complex technology transactions. He has also been chair of the Intellectual Property Section of the California Lawyers Association.  John has taught Technology Transactions Law at the UC Davis School of Law and Comparative Privacy Law at the Santa Clara University School of Law. John has also guest lectured on technology and privacy law topics at the University of California, Berkeley, Haas School of Business; the University of San Francisco School of Management; and Stanford University. References: John Pavolotsky on LinkedIn John Pavolotksy at Stoel Rives Timeline of discussions (House, Senate) leading to a final decision on a 10-year moratorium on state-level AI laws (final deadline: July 4, 2025), Techcrunch Texas Legislature Passes House Bill 149 to Regulate AI Use (Nelson Mullins) Colorado AI Act California Privacy Protection Agency: Draft Automated Decision-making Technology Regulations California Gov. Newsom vetoes AI safety bill that divided Silicon Valley (September 2024), NPR Poland puts pausing enforcement of the AI Act on EU ministers' table (June 2025, MLex - paywalled) A Brief Overview of the Federal Trade Commission's Investigative, Law Enforcement, and Rulemaking Authority (FTC)
undefined
Jun 21, 2025 • 28min

Thomas Ghys: The privacy engineer as a translator, an auditor, and a programmer

Who can really claim to be a privacy engineer? Does this change in the digital marketing arena? What is the winning formula to integrate this role within the company’s privacy practice? Thomas Ghys has worked as a management consultant, data scientist, and data strategist, including a 5-year stint at McKinsey, prior to setting up his own privacy engineering practice. He has deep expertise in MarTech and AdTech, auditing traditional machine learning models and data flows. He is also the founder and CEO of Webclew, a tool that helps with the auditing of websites and mobile apps. References: Thomas Ghys on LinkedIn Webclew: scanning websites and apps for privacy risks CNIL: a focus on mobile SDKs, announcing enforcement actions in 2025 Thomas Ghys: BAPD expectations for cookie compliancy unattainable for most publishers Dr. Augustine Fou: dismantling marketing attribution, ad fraud controls, and the business case for third-party cookies (Masters of Privacy, February 2024)
undefined
Jun 14, 2025 • 27min

Cillian Kieran (Ethyca): Privacy Tech spotlight III - compliance as an engineering challenge

Can we shift the focus from documentation to technical implementation? How can we bridge the cultural differences between legal teams and engineers? What do we mean with open-source data classification? We are joined by Cillian Kieran, Ethyca’s CEO and founder, in a new installment of our Privacy Tech series. Cillian is a serial entrepreneur and seasoned privacy engineer with two decades of experience leading data-intensive businesses. He combines deep technical expertise with a track record of building and scaling companies, including a global digital agency serving Fortune 500 clients.  References: Fides: the open source language for data privacy Cillian Kieran on LinkedIn Ethyca Max Anderson (Ketch): Privacy Tech spotlight I – the future of CMPs, value vs. hype in privacy compliance SaaS (Masters of Privacy, April 2025) Daniel Barber (DataGrail): Privacy Tech spotlight II – widespread non-compliance, opt-out challenges, and shadow AI (Masters of Privacy, May 2025)
undefined
Jun 9, 2025 • 29min

Newsroom: Spring 2025. AI fines, fingerprinting on steroids, UOOM momentum, and the ad automation tsunami

It is time for a seasonal update at the intersection of Marketing, Data, Privacy and Technology. We are today covering the first four of our usual five blocks: ePrivacy & regulatory updates; MarTech & AdTech; AI, Competition and Digital Markets; PETs and Zero-Party Data.  All references and links can be found in this episode’s blog post: Masters of Privacy. Allow us to thank two people in advance for their routine work in breaking down the news across some of the topics and jurisdictions covered here: Robert Bateman and his Privacy Corner and Federico Marengo with his Privacy and AI newsletter. Also, an important disclaimer: the voice that joins me today is a text-to-speech output generated with Eleven Labs.
undefined
Jun 1, 2025 • 36min

Lauren Reid: privacy metrics and the unbearable insignificance of the privacy professional

What do we refer to with “privacy metrics”? Are privacy professionals delusional regarding the impact of the discipline in the overall business context? Lauren Reid is founder of The Privacy Pro, a boutique firm that provides essential training, tools, and support for privacy professionals to turn knowledge into action. In addition to leading The Privacy Pro, Lauren works with executives, boards, and product teams to build privacy data governance strategies that support responsible innovation and prepare companies for investor and regulatory scrutiny. She has a 20-year track record in this space. References: Lauren Reid on LinkedIn The Privacy Pro Lauren Reid: Rethinking Privacy Metrics: Aligning with Business Strategy
undefined
May 26, 2025 • 34min

Pascale Arguinarena (Utiq): cross-device addressability in digital advertising through telco-powered identifiers

Can telco-powered identifiers overcome their own privacy challenges in their attempt to replace third-party cookies or email-based alternatives? Pascale is the Data Protection Officer at Utiq, a European based AdTech company. She has been working in privacy and data protection ever since completing her degree in Law, including roles at fashion group Arcadia and Vodafone Group. Pascale’s main goal is always to put privacy at the heart of the business. Utiq’s mission is to enable more responsible digital marketing by offering a telco powered privacy-first technology to Brands, Publishers and Tech Vendors operating in the adtech ecosystem. The Utiq technology consists of online identifiers which can be used to support and optimize digital marketing, advertising and analytics activities, whilst offering individuals enhanced choice, control and transparency, including via the application of privacy-centric controls and a dedicated privacy portal for end users, known as consenthub. Launched in 2023, Utiq was originally backed by Deutsche Telekom AG, Orange SA, Telefónica S.A., and Vodafone Group plc. It has continued to gain support from numerous other leading telecom operators across Germany, France, Spain, Austria and soon expanding to the UK and Italy. References: Pascale Arguinarena on LinkedIn FCC fines Verizon $1.35 million over ‘supercookie’ tracking (The Verge, May 2016) Utiq’s consenthub  
undefined
May 18, 2025 • 29min

Linsey Krolik: the growing role of the Product Counsel in privacy and AI compliance

Are Product Counsels in the best position to anticipate and solve privacy and AI compliance problems before we release new products to the public at large - all of it while avoiding costly delays in fast-moving projects? Linsey Krolik is Assistant Clinical Professor at Santa Clara University School of Law, where she runs the Privacy Law Certificate and teaches Privacy Law. She is Director of the Entrepreneurs’ Law Clinic, where students work with real startups on transactional law projects, and Director of the TechEdge JD, a skills based certificate program for students interested in working in technology law. She also teaches a class called Law and Technology of Silicon Valley, with students playing the role of product or privacy counsel for a day.  Prior to joining academia, Linsey held senior in-house roles as a product, privacy, and commercial lawyer at global companies including PayPal, ARM, and Palm. Also, she continues to consult on privacy and AI governance in her solo law practice. References: Linsey Krolik on LinkedIn Santa Clara University School of Law TechEdge JD Entrepreneurs' Law Clinic Privacy Law Certificate Navigating AI and Data Ethics: The Essential Role of Product Lawyers and the Product Counsel Framework (Linsey Krolik, Adrienne Go, Olga Mack) Gam Dias: Agents Unleashed, understanding the Agentic AI stack (Masters of Privacy)
undefined
May 11, 2025 • 36min

Daniel Barber (DataGrail): Privacy Tech spotlight II - widespread non-compliance, opt-out challenges, and shadow AI

Is it possible that a whole generation of consent-management solutions built for the EU-driven opt-in world are unsuitable for the opt-out scenario predominant in the US? How are DPOs and AI Governance professionals to deal with “shadow AI” and “shadow IT”?  Daniel Barber is DataGrail’s CEO and co-founder. Prior to DataGrail Daniel led revenue teams at DocuSign, Datanyze (acquired by ZoomInfo), ToutApp (acquired by Marketo) and Responsys (acquired by Oracle). He also advises several high-growth startups. References: Daniel Barber on LinkedIn Unveiling DataGrail’s 2024 Data Privacy Trends Report: The Time Data Subject Requests Surged 246% in Two Years DataGrail Privacy Inspector (Chrome Web Store) Max Anderson (Ketch): Privacy Tech spotlight I – the future of CMPs, value vs. hype in privacy compliance SaaS (Masters of Privacy, April 2025)

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app