<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Masters of Privacy]]></title><description><![CDATA[Interviews and updates at the intersection of marketing, data, privacy, and technology. With an eye on a human-centric, demand-led future in which transparency, control, and personal agency play a crucial role.  ]]></description><link>https://www.mastersofprivacy.com</link><image><url>https://substackcdn.com/image/fetch/$s_!RHtP!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F706b5062-0f94-4068-91bb-755193e2d703_500x500.png</url><title>Masters of Privacy</title><link>https://www.mastersofprivacy.com</link></image><generator>Substack</generator><lastBuildDate>Sat, 23 May 2026 08:06:25 GMT</lastBuildDate><atom:link href="https://www.mastersofprivacy.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Sergio Maldonado]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[smaldonado@privacycloud.com]]></webMaster><itunes:owner><itunes:email><![CDATA[smaldonado@privacycloud.com]]></itunes:email><itunes:name><![CDATA[Sergio Maldonado]]></itunes:name></itunes:owner><itunes:author><![CDATA[Sergio Maldonado]]></itunes:author><googleplay:owner><![CDATA[smaldonado@privacycloud.com]]></googleplay:owner><googleplay:email><![CDATA[smaldonado@privacycloud.com]]></googleplay:email><googleplay:author><![CDATA[Sergio Maldonado]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Newsroom (referencias) de primavera de 2026]]></title><description><![CDATA[Resumen de noticias en el segundo trimestre de 2026 (complementando al episodio grabado)]]></description><link>https://www.mastersofprivacy.com/p/newsroom-referencias-de-primavera26</link><guid isPermaLink="false">https://www.mastersofprivacy.com/p/newsroom-referencias-de-primavera26</guid><dc:creator><![CDATA[Sergio Maldonado]]></dc:creator><pubDate>Mon, 18 May 2026 20:04:48 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/a3381392-a10a-44e2-83c1-f2629967bb94_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Vamos a por otro resumen trimestral, en cuatro de las secciones de siempre (ePrivacy y marco regulatorio; MarTech &amp; AdTech; IA, competencia y mercados digitales; y futuro de los medios).</p><p>Pod&#233;is escuchar la versi&#243;n audio con la mayor parte de estas noticias comentadas, <a href="https://www.mastersofprivacy.com/p/newsroom-de-primavera-de-2026">aqu&#237;</a>.</p><h3>ePrivacy y marco regulatorio</h3><h4>Multas y sanciones</h4><h5>UE y RU</h5><p>El 6 de mayo, la <strong>AEPD</strong> <a href="https://www.aepd.es/prensa-y-comunicacion/notas-de-prensa/la-agencia-recibio-mas-de-30.000-reclamaciones-en-2025-un-64-mas">public&#243; su </a><em><a href="https://www.aepd.es/prensa-y-comunicacion/notas-de-prensa/la-agencia-recibio-mas-de-30.000-reclamaciones-en-2025-un-64-mas">Memoria de actuaci&#243;n correspondiente a 2025</a></em>. La Agencia recibi&#243; <strong>30.931 reclamaciones</strong> a lo largo del a&#241;o, la cifra m&#225;s alta de su historia, lo que supone un incremento del 64 por ciento respecto al ejercicio anterior. Las sanciones impuestas en 2025 alcanzaron los <strong>48,1 millones de euros</strong>. La Memoria recoge tambi&#233;n el inicio de una nueva presidencia y la publicaci&#243;n del <em>Plan Estrat&#233;gico 2025-2030</em>, que orienta la actuaci&#243;n de la autoridad hacia el fomento de la innovaci&#243;n responsable y la defensa de la dignidad en la era digital.</p><p>El 19 de marzo, <strong>Ofcom</strong> <a href="https://dig.watch/updates/ofcom-4chan-decision-online-safety-act">sancion&#243; a </a><strong><a href="https://dig.watch/updates/ofcom-4chan-decision-online-safety-act">4chan</a></strong><a href="https://dig.watch/updates/ofcom-4chan-decision-online-safety-act"> con un total de 520.000 libras al amparo de la </a><em><a href="https://dig.watch/updates/ofcom-4chan-decision-online-safety-act">UK Online Safety Act</a></em>: 450.000 por no implantar un control de edad para contenidos pornogr&#225;ficos, 50.000 por una evaluaci&#243;n de riesgos de contenidos ilegales inadecuada, y 20.000 por incumplimientos en sus condiciones del servicio. Se establecieron sanciones diarias adicionales de 200 libras en caso de no presentarse una evaluaci&#243;n de riesgos suficiente.</p><p>Una semana m&#225;s tarde, la propia <strong>AEPD</strong> <a href="https://ppc.land/spain-fines-yoti-eu950-000-over-biometric-data-and-consent-failures/">sancion&#243; a </a><strong><a href="https://ppc.land/spain-fines-yoti-eu950-000-over-biometric-data-and-consent-failures/">Yoti</a></strong><a href="https://ppc.land/spain-fines-yoti-eu950-000-over-biometric-data-and-consent-failures/">, una empresa brit&#225;nica de identidad digital y verificaci&#243;n de edad, con </a><strong><a href="https://ppc.land/spain-fines-yoti-eu950-000-over-biometric-data-and-consent-failures/">950.000 euros</a></strong> por tres infracciones del RGPD relacionadas con su aplicaci&#243;n Digital ID operada en Espa&#241;a. La AEPD impuso 500.000 euros por el tratamiento de datos biom&#233;tricos de categor&#237;a especial &#8212;en concreto, plantillas faciales&#8212; sin base jur&#237;dica adecuada conforme al art&#237;culo 9; 200.000 euros por obtener un consentimiento inv&#225;lido a trav&#233;s de casillas premarcadas para la investigaci&#243;n con datos biom&#233;tricos; y 250.000 euros por retener datos personales, incluidos registros de geolocalizaci&#243;n durante cinco a&#241;os y grabaciones de detecci&#243;n de vida durante 30 d&#237;as, m&#225;s all&#225; de lo necesario para los fines del tratamiento.</p><p>El 20 de abril, el <strong>Garante italiano</strong> <a href="https://en.ilsole24ore.com/art/privacy-fine-125-million-italian-postal-regulator-AIP0pXbC">sancion&#243; a </a><strong><a href="https://en.ilsole24ore.com/art/privacy-fine-125-million-italian-postal-regulator-AIP0pXbC">Poste Italiane</a></strong><a href="https://en.ilsole24ore.com/art/privacy-fine-125-million-italian-postal-regulator-AIP0pXbC"> con 6,6 millones de euros y a su filial </a><strong><a href="https://en.ilsole24ore.com/art/privacy-fine-125-million-italian-postal-regulator-AIP0pXbC">Postepay</a></strong><a href="https://en.ilsole24ore.com/art/privacy-fine-125-million-italian-postal-regulator-AIP0pXbC"> con 5,9 millones &#8212;un total de 12,5 millones&#8212;</a> por las aplicaciones m&#243;viles BancoPosta y Postepay. La autoridad concluy&#243; que la monitorizaci&#243;n por parte de las aplicaciones de qu&#233; otras aplicaciones ten&#237;an instaladas y en ejecuci&#243;n los usuarios en sus dispositivos no era estrictamente necesaria para la prevenci&#243;n del fraude, e identific&#243; deficiencias adicionales en transparencia, evaluaci&#243;n de impacto, conservaci&#243;n y designaci&#243;n del encargado del tratamiento.</p><h5>Estados Unidos</h5><p>El 30 de marzo, la <strong>FTC</strong> <a href="https://www.ftc.gov/news-events/news/press-releases/2026/03/ftc-takes-action-against-match-okcupid-deceiving-users-sharing-personal-data-third-party">alcanz&#243; un acuerdo con </a><strong><a href="https://www.ftc.gov/news-events/news/press-releases/2026/03/ftc-takes-action-against-match-okcupid-deceiving-users-sharing-personal-data-third-party">Match Group</a></strong><a href="https://www.ftc.gov/news-events/news/press-releases/2026/03/ftc-takes-action-against-match-okcupid-deceiving-users-sharing-personal-data-third-party"> y </a><strong><a href="https://www.ftc.gov/news-events/news/press-releases/2026/03/ftc-takes-action-against-match-okcupid-deceiving-users-sharing-personal-data-third-party">OkCupid</a></strong><a href="https://www.ftc.gov/news-events/news/press-releases/2026/03/ftc-takes-action-against-match-okcupid-deceiving-users-sharing-personal-data-third-party"> por la cesi&#243;n no divulgada de datos a la empresa de IA </a><strong><a href="https://www.ftc.gov/news-events/news/press-releases/2026/03/ftc-takes-action-against-match-okcupid-deceiving-users-sharing-personal-data-third-party">Clarifai</a></strong>. La denuncia alegaba que OkCupid hab&#237;a proporcionado a Clarifai acceso sin restricciones a aproximadamente 3 millones de fotos de usuarios, junto con datos demogr&#225;ficos y de localizaci&#243;n, en contradicci&#243;n con la pol&#237;tica de privacidad de la plataforma. La orden propuesta, de 20 a&#241;os de duraci&#243;n, proh&#237;be declaraciones enga&#241;osas sobre pr&#225;cticas de tratamiento de datos, pero no impone sanci&#243;n econ&#243;mica.</p><p>El 8 de mayo, el fiscal general de California, <strong>Rob Bonta</strong>, junto con la <strong>Agencia de Protecci&#243;n de la Privacidad de California</strong> y varios fiscales de distrito locales, <a href="https://oag.ca.gov/news/press-releases/when-it-comes-data-privacy-consumers-must-be-driver%E2%80%99s-seat-attorney-general">anunci&#243; un acuerdo de </a><strong><a href="https://oag.ca.gov/news/press-releases/when-it-comes-data-privacy-consumers-must-be-driver%E2%80%99s-seat-attorney-general">12,75 millones de d&#243;lares</a></strong><a href="https://oag.ca.gov/news/press-releases/when-it-comes-data-privacy-consumers-must-be-driver%E2%80%99s-seat-attorney-general"> con </a><strong><a href="https://oag.ca.gov/news/press-releases/when-it-comes-data-privacy-consumers-must-be-driver%E2%80%99s-seat-attorney-general">General Motors</a></strong><a href="https://oag.ca.gov/news/press-releases/when-it-comes-data-privacy-consumers-must-be-driver%E2%80%99s-seat-attorney-general"> al amparo de la </a><em><a href="https://oag.ca.gov/news/press-releases/when-it-comes-data-privacy-consumers-must-be-driver%E2%80%99s-seat-attorney-general">California Consumer Privacy Act</a></em>: el mayor acuerdo sancionador del CCPA hasta la fecha. GM hab&#237;a vendido los nombres, datos de contacto, datos de geolocalizaci&#243;n precisa y datos de comportamiento al volante de cientos de miles de suscriptores californianos de OnStar a las intermediarias de datos <strong>Verisk Analytics</strong> y <strong>LexisNexis Risk Solutions</strong> entre 2020 y 2024. El acuerdo es tambi&#233;n la <a href="https://privacy.ca.gov/2026/05/when-it-comes-to-data-privacy-consumers-must-be-in-the-drivers-seat-attorney-general-bonta-partners-secure-12-75-million-general-motors-privacy-settlement/">primera acci&#243;n sancionadora basada en los requisitos de minimizaci&#243;n de datos del CCPA</a>. Adem&#225;s de las sanciones econ&#243;micas, exige a GM cesar la venta de datos de conducci&#243;n a agencias de informes de consumidores durante cinco a&#241;os, desarrollar un programa robusto de privacidad, y eliminar los datos de conducci&#243;n retenidos en un plazo de 180 d&#237;as, salvo consentimiento expreso afirmativo. La acci&#243;n complementa la orden de consentimiento de 20 a&#241;os que la FTC alcanz&#243; con las mismas empresas en enero.</p><p>El 24 de marzo, un <a href="https://nmdoj.gov/press-release/new-mexico-department-of-justice-wins-landmark-verdict-against-meta/">jurado de un tribunal estatal de Nuevo M&#233;xico conden&#243; a </a><strong><a href="https://nmdoj.gov/press-release/new-mexico-department-of-justice-wins-landmark-verdict-against-meta/">Meta</a></strong><a href="https://nmdoj.gov/press-release/new-mexico-department-of-justice-wins-landmark-verdict-against-meta/"> a pagar </a><strong><a href="https://nmdoj.gov/press-release/new-mexico-department-of-justice-wins-landmark-verdict-against-meta/">375 millones de d&#243;lares</a></strong><a href="https://nmdoj.gov/press-release/new-mexico-department-of-justice-wins-landmark-verdict-against-meta/"> en concepto de da&#241;os civiles</a>, al considerar a la compa&#241;&#237;a responsable de haber enga&#241;ado a los usuarios sobre la seguridad de sus plataformas y de haber facilitado la explotaci&#243;n sexual infantil en Facebook e Instagram. El caso, presentado por la fiscal&#237;a general del estado, tuvo origen en una operaci&#243;n encubierta de 2023 en la que investigadores crearon cuentas haci&#233;ndose pasar por usuarios menores de 14 a&#241;os y fueron contactados por adultos que solicitaban material sexual expl&#237;cito. Es la primera vez que un estado vence en juicio a una gran tecnol&#243;gica por reclamaciones de que sus plataformas perjudican a menores. Un juicio sin jurado separado, sobre la reclamaci&#243;n de da&#241;o p&#250;blico planteada por el estado y en el que se solicita la imposici&#243;n de medidas cautelares, estaba previsto a continuaci&#243;n para el 4 de mayo. Meta ha anunciado que recurrir&#225;.</p><p>Al d&#237;a siguiente, el 25 de marzo, un <a href="https://www.npr.org/2026/03/25/nx-s1-5746125/meta-youtube-social-media-trial-verdict">jurado de Los &#193;ngeles concluy&#243; que </a><strong><a href="https://www.npr.org/2026/03/25/nx-s1-5746125/meta-youtube-social-media-trial-verdict">Meta</a></strong><a href="https://www.npr.org/2026/03/25/nx-s1-5746125/meta-youtube-social-media-trial-verdict"> y </a><strong><a href="https://www.npr.org/2026/03/25/nx-s1-5746125/meta-youtube-social-media-trial-verdict">Google</a></strong><a href="https://www.npr.org/2026/03/25/nx-s1-5746125/meta-youtube-social-media-trial-verdict"> hab&#237;an dise&#241;ado negligentemente sus productos para que resultaran adictivos para los menores</a>, y conden&#243; a ambas compa&#241;&#237;as al pago de <strong>6 millones de d&#243;lares</strong> en concepto de da&#241;os y perjuicios &#8212;3 millones en da&#241;os compensatorios y 3 millones en da&#241;os punitivos&#8212;, asumiendo Meta el 70 por ciento de la cuant&#237;a. La demandante, identificada como Kaley, una mujer californiana de 20 a&#241;os, aleg&#243; que su adicci&#243;n a Instagram y YouTube siendo menor de edad le hab&#237;a provocado depresi&#243;n grave, ansiedad e ideaci&#243;n suicida. Es la <a href="https://www.crowell.com/en/insights/client-alerts/landmark-verdicts-against-meta-and-youtube-signal-new-era-of-social-media-platform-liability">primera vez que un jurado considera que las aplicaciones de redes sociales deben tratarse como productos defectuosos</a> por estar dise&#241;adas para explotar el cerebro en desarrollo de ni&#241;os y adolescentes. El veredicto podr&#237;a influir en el resultado de m&#225;s de 2.000 demandas similares pendientes en Estados Unidos. Tanto Meta como Google anunciaron que recurrir&#225;n.</p><h4>Novedades legislativas, directrices, jurisprudencia</h4><h5>UE y RU</h5><p>El 19 de marzo, el <strong>Tribunal de Justicia de la UE</strong> <a href="https://www.gtlaw.com/en/insights/2026/3/cjeu-first-request-for-access-may-be-rejected-as-abusive-under-gdpr">dict&#243; sentencia en el caso </a><em><a href="https://www.gtlaw.com/en/insights/2026/3/cjeu-first-request-for-access-may-be-rejected-as-abusive-under-gdpr">Brillen Rottler</a></em><a href="https://www.gtlaw.com/en/insights/2026/3/cjeu-first-request-for-access-may-be-rejected-as-abusive-under-gdpr"> (asunto C-526/24), estableciendo que incluso una primera solicitud de acceso conforme al art&#237;culo 15 del RGPD puede ser rechazada por excesiva</a>, cuando el responsable del tratamiento pueda acreditar que el interesado actu&#243; con intenci&#243;n abusiva &#8212;por ejemplo, para fabricar una reclamaci&#243;n de indemnizaci&#243;n&#8212;. El umbral de prueba es alto, pero la sentencia abre una nueva v&#237;a defensiva para los responsables.</p><p>El 1 de abril, el <strong><a href="https://www.euronews.com/next/2026/04/01/france-moves-closer-to-social-media-ban-for-children-under-15-but-houses-divided-on-detail">Senado franc&#233;s</a></strong><a href="https://www.euronews.com/next/2026/04/01/france-moves-closer-to-social-media-ban-for-children-under-15-but-houses-divided-on-detail"> aprob&#243; su versi&#243;n de la prohibici&#243;n de redes sociales para menores de 15 a&#241;os</a>, sum&#225;ndose a la <em>Assembl&#233;e Nationale</em>, que hab&#237;a aprobado la legislaci&#243;n en enero. Las dos c&#225;maras deber&#225;n ahora conciliar textos divergentes: la versi&#243;n de la Asamblea exige a las plataformas eliminar todas las cuentas de menores de 15 a&#241;os y rechazar nuevas, mientras que el Senado prefiere una categorizaci&#243;n en dos niveles. La aplicaci&#243;n est&#225; prevista para el inicio del curso escolar en septiembre de 2026, con las plataformas obligadas a desactivar las cuentas no conformes antes del 31 de diciembre.</p><p>El 18 de abril, el presidente del Gobierno espa&#241;ol, <strong>Pedro S&#225;nchez</strong>, <a href="https://time.com/7368633/spain-social-media-ban-under-16-sanchez-australia-france/">llev&#243; la campa&#241;a un paso m&#225;s all&#225; al impulsar una prohibici&#243;n a escala de toda la Uni&#243;n Europea de las redes sociales para menores de 16 a&#241;os</a>, enmarcando el debate en t&#233;rminos de protecci&#243;n frente a la adicci&#243;n algor&#237;tmica, la exposici&#243;n a contenidos nocivos y el da&#241;o psicol&#243;gico a los menores. La <em>Ley para la Protecci&#243;n de los Menores en el Entorno Digital</em> del propio Gobierno espa&#241;ol contin&#250;a su tramitaci&#243;n parlamentaria, con el apoyo del centroderechista Partido Popular.</p><p>A finales de marzo, la ministra australiana de comunicaciones, <strong>Anika Wells</strong>, <a href="https://fortune.com/2026/04/25/australia-social-media-ban-isnt-working-teens-sidestepping-restrictions/">confirm&#243; que el gobierno investigar&#237;a a </a><strong><a href="https://fortune.com/2026/04/25/australia-social-media-ban-isnt-working-teens-sidestepping-restrictions/">Meta</a></strong><a href="https://fortune.com/2026/04/25/australia-social-media-ban-isnt-working-teens-sidestepping-restrictions/">, </a><strong><a href="https://fortune.com/2026/04/25/australia-social-media-ban-isnt-working-teens-sidestepping-restrictions/">Snap</a></strong><a href="https://fortune.com/2026/04/25/australia-social-media-ban-isnt-working-teens-sidestepping-restrictions/">, </a><strong><a href="https://fortune.com/2026/04/25/australia-social-media-ban-isnt-working-teens-sidestepping-restrictions/">TikTok</a></strong><a href="https://fortune.com/2026/04/25/australia-social-media-ban-isnt-working-teens-sidestepping-restrictions/"> y </a><strong><a href="https://fortune.com/2026/04/25/australia-social-media-ban-isnt-working-teens-sidestepping-restrictions/">YouTube</a></strong> por posibles incumplimientos de la prohibici&#243;n de redes sociales para menores de 16 a&#241;os, con multas potenciales de hasta 49,5 millones de d&#243;lares australianos. Los primeros datos indican que entre el 60 y el 64 por ciento de los usuarios menores de edad mantuvieron sus cuentas y aproximadamente una cuarta parte eludi&#243; los controles de edad.</p><p>Y el 27 de abril, el <strong>Becker Friedman Institute</strong> de la Universidad de Chicago <a href="https://bfi.uchicago.edu/working-papers/why-bans-fail-tipping-points-and-australias-social-media-ban/">public&#243; un </a><em><a href="https://bfi.uchicago.edu/working-papers/why-bans-fail-tipping-points-and-australias-social-media-ban/">working paper</a></em><a href="https://bfi.uchicago.edu/working-papers/why-bans-fail-tipping-points-and-australias-social-media-ban/"> firmado por Leonardo Bursztyn, Cass Sunstein y otros autores, bajo el t&#237;tulo </a><em><a href="https://bfi.uchicago.edu/working-papers/why-bans-fail-tipping-points-and-australias-social-media-ban/">Why Bans Fail: Tipping Points and Australia&#8217;s Social Media Ban</a></em>. El estudio concluye que la prohibici&#243;n australiana est&#225; fracasando porque no consigue alcanzar el umbral cr&#237;tico de cumplimiento entre pares necesario para autorreforzarse. Solo aproximadamente el <strong>25 por ciento</strong> de los encuestados de 14 y 15 a&#241;os cumple con la prohibici&#243;n; el modelo sugiere que <strong>cerca de dos tercios</strong> de los pares tendr&#237;an que dejar de usar las redes sociales antes de que los adolescentes individualmente decidieran hacerlo. La din&#225;mica es adem&#225;s perversa: los adolescentes perciben a quienes cumplen como menos populares que quienes no cumplen, lo que implica que son precisamente los pares m&#225;s influyentes los que tienden a permanecer en las plataformas. Los autores concluyen que las prohibiciones por s&#237; solas resultan insuficientes y que su efectividad exige medidas complementarias que reconfiguren las normas sociales y los incentivos individuales, no &#250;nicamente restringir el acceso.</p><p>(Gracias a Jorge Garc&#237;a Herrero por sacar a la luz est&#233; papel en <a href="https://zerpartydata.es">su newsletter</a>.)</p><p>El 29 de abril, la <strong>Comisi&#243;n Europea</strong> <a href="https://commission.europa.eu/news-and-media/news/commission-urges-fast-rollout-age-verification-app-2026-04-29_en">adopt&#243; una recomendaci&#243;n instando a los Estados miembros de la UE a hacer disponible para todos los ciudadanos, antes del </a><strong><a href="https://commission.europa.eu/news-and-media/news/commission-urges-fast-rollout-age-verification-app-2026-04-29_en">31 de diciembre de 2026</a></strong><a href="https://commission.europa.eu/news-and-media/news/commission-urges-fast-rollout-age-verification-app-2026-04-29_en">, una verificaci&#243;n de edad robusta y respetuosa con la privacidad</a>. El <a href="https://digital-strategy.ec.europa.eu/en/policies/eu-age-verification">Blueprint de Verificaci&#243;n de Edad de la UE</a>, que alcanz&#243; su versi&#243;n funcional el 15 de abril, permite a los usuarios demostrar que son mayores de 18 a&#241;os sin compartir ninguna otra informaci&#243;n personal, y est&#225; dise&#241;ado para ser interoperable con las <strong>Carteras de Identidad Digital de la UE</strong> que los Estados miembros deber&#225;n ofrecer de forma gratuita en el mismo plazo de finales de 2026. Francia, Dinamarca, Grecia, Italia, Espa&#241;a, Chipre e Irlanda son los Estados miembros pioneros que est&#225;n pilotando la integraci&#243;n con sus carteras nacionales EUDI.</p><p>El 14 de abril, la <strong>CNIL</strong> francesa <a href="https://www.insideprivacy.com/data-privacy/cnil-publishes-recommendation-on-email-tracking-pixels/">public&#243; una recomendaci&#243;n que exige consentimiento previo para el uso de p&#237;xeles de seguimiento en correos electr&#243;nicos</a>, salvo cuando resulten estrictamente necesarios para la entrega del correo o para la prestaci&#243;n de un servicio solicitado por el destinatario. La recomendaci&#243;n, adoptada en marzo, considera que el uso de p&#237;xeles para medir tasas de apertura, elaborar perfiles u optimizar campa&#241;as publicitarias requiere consentimiento <em>opt-in</em>, mientras que la autenticaci&#243;n de seguridad y las operaciones de depuraci&#243;n de bases de datos quedan exentas. Las organizaciones tienen hasta el <strong>14 de julio</strong> para informar a los destinatarios existentes sobre el uso de p&#237;xeles y ofrecerles la posibilidad de oponerse.</p><p>Casi al mismo tiempo, el Garante public&#243; <a href="https://www.consentmo.com/blog-posts/12-5m-fine-and-new-email-rules-what-italys-april-2026-gdpr-decisions-mean-for-your-business">directrices que tratan los p&#237;xeles de seguimiento en correos electr&#243;nicos como un acceso al dispositivo terminal del usuario</a>, sujetos al mismo r&#233;gimen de consentimiento que las cookies. Los remitentes de correos electr&#243;nicos necesitan ahora, en la mayor&#237;a de los contextos, un consentimiento previo, libre, espec&#237;fico e informado antes de incorporar dichos p&#237;xeles. Con Francia e Italia ampliamente alineadas en el r&#233;gimen estricto de consentimiento para los p&#237;xeles de correo, los anunciantes y editores se enfrentan a una base europea cada vez m&#225;s convergente.</p><p>El 15 de abril, el <strong>Comit&#233; Europeo de Protecci&#243;n de Datos</strong> <a href="https://www.edpb.europa.eu/news/news/2026/edpb-brings-clarity-data-processing-scientific-research-speeds-finalisation_en">adopt&#243; las Directrices 1/2026 sobre el tratamiento de datos personales con fines de investigaci&#243;n cient&#237;fica</a>, abiertas a consulta p&#250;blica hasta el 25 de junio. El plenario tambi&#233;n form&#243; un equipo de trabajo acelerado para finalizar este verano las directrices pendientes sobre anonimizaci&#243;n, y aprob&#243; los primeros criterios de Europrivacy como Sello Europeo de Protecci&#243;n de Datos, v&#225;lido tambi&#233;n para transferencias internacionales.</p><p>El 24 de abril, el <strong>Tribunal de Apelaci&#243;n del Reino Unido</strong> dict&#243; sentencia en el caso <em><a href="https://www.mishcon.com/news/rtm-v-bonne-terre-court-of-appeal-confirms-that-consent-under-uk-gdpr-and-pecr-is-an-objective-test">RTM contra Bonne Terre Ltd &amp; Anor</a></em><a href="https://www.mishcon.com/news/rtm-v-bonne-terre-court-of-appeal-confirms-that-consent-under-uk-gdpr-and-pecr-is-an-objective-test"> [2026] EWCA Civ 488, estableciendo que la validez del consentimiento bajo el UK GDPR y la PECR es una prueba objetiva</a>. El caso hab&#237;a sido presentado por un jugador compulsivo contra Bonne Terre, que opera como <strong>Sky Betting and Gaming</strong>, quien alegaba que la compa&#241;&#237;a hab&#237;a utilizado il&#237;citamente sus datos personales para publicidad dirigida que explotaba su adicci&#243;n, pese a que &#233;l hab&#237;a prestado consentimiento formalmente. La High Court le hab&#237;a dado la raz&#243;n, concluyendo que su capacidad aut&#243;noma para consentir hab&#237;a quedado lo suficientemente mermada por su trastorno de juego como para que el consentimiento no pudiera considerarse libremente otorgado. El Tribunal de Apelaci&#243;n revoc&#243; esa sentencia, sosteniendo que los responsables del tratamiento solo deben acreditar que el consentimiento aparece objetivamente a partir de las declaraciones o acciones claras del interesado &#8212;como marcar una casilla de consentimiento&#8212; y que no tienen que probar qu&#233; pensaba realmente el interesado en el momento. Las vulnerabilidades personales desconocidas para el responsable no invalidan un consentimiento que sea objetivamente v&#225;lido. La sentencia restablece la certeza jur&#237;dica y pr&#225;ctica para las organizaciones que se basan en el consentimiento para marketing directo o cookies, salvo que el Tribunal Supremo del Reino Unido conceda permiso para un recurso adicional.</p><p>Ese mismo d&#237;a, la <strong>Oficina del Comisionado de Informaci&#243;n del Reino Unido (ICO)</strong> <a href="https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/04/final-storage-and-access-technologies-guidance-published/">finaliz&#243; su esperada gu&#237;a sobre el uso de </a><em><a href="https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/04/final-storage-and-access-technologies-guidance-published/">tecnolog&#237;as de almacenamiento y acceso</a></em>, su reformulaci&#243;n de lo que la industria sigue llamando cookies. La gu&#237;a refleja la introducci&#243;n, por parte de la Ley de Uso y Acceso a los Datos, de <a href="https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guidance-on-the-use-of-storage-and-access-technologies/what-are-the-exceptions/">cinco nuevas categor&#237;as de excepciones en las que no se requiere consentimiento</a>: las tecnolog&#237;as utilizadas para la transmisi&#243;n de una comunicaci&#243;n; la prestaci&#243;n de un servicio solicitado por el usuario; las anal&#237;ticas de primera parte; las mejoras del servicio basadas en preferencias del usuario; y la identificaci&#243;n de usuarios que requieren asistencia de emergencia. La ICO deja claro que una excepci&#243;n solo se aplica cuando la tecnolog&#237;a se utiliza exclusivamente para ese fin; el uso para m&#250;ltiples prop&#243;sitos hace que la actividad vuelva al r&#233;gimen general de consentimiento. Las sanciones m&#225;ximas de la PECR, alineadas con los niveles del RGPD del Reino Unido desde el 5 de febrero, ascienden ahora a <strong>17,5 millones de libras</strong> o el 4 por ciento de la facturaci&#243;n global.</p><h3>MarTech &amp; AdTech</h3><p>El 21 de abril, <strong>OpenAI</strong> <a href="https://digiday.com/marketing/openai-turns-on-cost-per-click-ads-inside-chatgpt/">activ&#243; la puja por coste por clic dentro de ChatGPT</a>, junto al modelo CPM original. Las pujas por clic se situaron entre 3 y 5 d&#243;lares, y el compromiso m&#237;nimo se redujo de 250.000 a 50.000 d&#243;lares. Los CPM de lanzamiento, en torno a los 60 d&#243;lares, ya hab&#237;an ca&#237;do hasta unos 25 d&#243;lares.</p><p>El mismo d&#237;a, <strong>The Trade Desk</strong> <a href="https://adtechradar.com/2026/04/21/the-trade-desk-koa-agents-agentic-media-buying/">lanz&#243; </a><strong><a href="https://adtechradar.com/2026/04/21/the-trade-desk-koa-agents-agentic-media-buying/">Koa Agents</a></strong>, un conjunto de herramientas de IA ag&#233;ntica que permiten al comprador describir los objetivos de la campa&#241;a en lenguaje natural y dejar que el agente ejecute y optimice. Por las mismas fechas, se inform&#243; de que <strong>Omnicom</strong> hab&#237;a <a href="https://digiday.com/media-buying/that-is-an-objective-omnicom-tests-ai-agents-to-cut-out-the-ad-tech-middlemen/">ejecutado compras de medios entre agentes en directo, prescindiendo de los intermediarios tradicionales</a> de la cadena publicitaria. Se trata del primer despliegue real de compra de medios ag&#233;ntica por parte de un gran holding.</p><p>El 30 de abril, OpenAI <a href="https://www.technewshub.co.uk/post/openai-quietly-enables-marketing-cookies-by-default-for-free-chatgpt-users-in-pivot-to-ad-revenue">actualiz&#243; su pol&#237;tica para compartir datos de seguimiento limitados con socios publicitarios</a>, incluidos Meta y Google. La finalidad declarada es promocionar los propios productos de OpenAI en plataformas de terceros, pero acerca a la empresa un paso m&#225;s a una infraestructura publicitaria de resultados completa.</p><p>Ese paso lleg&#243; el 5 de mayo, cuando OpenAI <a href="https://digiday.com/marketing/openai-opens-up-chatgpt-ads-manager-to-the-u-s-while-promising-third-party-measurement-cpa-bidding/">lanz&#243; el p&#237;xel de medici&#243;n de ChatGPT Ads y una API de Conversiones del lado del servidor</a>, que admite eventos de <em>lead</em>, pedido, vista de p&#225;gina, suscripci&#243;n y prueba. El mismo d&#237;a, la empresa <a href="https://developers.openai.com/ads/conversions-api">abri&#243; Ads Manager a todos los anunciantes estadounidenses</a> sin compromiso m&#237;nimo de inversi&#243;n. La infraestructura publicitaria de resultados completa dentro de ChatGPT est&#225; ya operativa.</p><h3>AI, Competition, and Digital Markets</h3><p>Arrancamos con el <a href="https://leakylm.github.io/">informe de IMDEA</a> (v&#237;a Jorge Garc&#237;a Herrero) que expone c&#243;mo env&#237;an datos de conversaciones (URLs) a terceros las principales plataformas de IA. Nada mejor que asomarse al propio detalle.</p><p>En marzo, <strong>OpenAI</strong> <a href="https://deadline.com/2026/03/sora-shut-down-disney-investment-1236764689/">confirm&#243; el cierre de su aplicaci&#243;n de v&#237;deo </a><strong><a href="https://deadline.com/2026/03/sora-shut-down-disney-investment-1236764689/">Sora</a></strong><a href="https://deadline.com/2026/03/sora-shut-down-disney-investment-1236764689/"> dirigida al consumidor</a>, alegando los altos costes de c&#243;mputo y la d&#233;bil adopci&#243;n, con un n&#250;mero de usuarios activos que hab&#237;a ca&#237;do por debajo de 500.000. Como consecuencia, la licencia de propiedad intelectual a tres a&#241;os con Disney y la inversi&#243;n de capital de 1.000 millones de d&#243;lares anunciadas en diciembre se desmoronaron antes de que el dinero cambiara de manos.</p><p>El 7 de abril, <strong>Anthropic</strong> <a href="https://en.wikipedia.org/wiki/Claude_(language_model)">abri&#243; una versi&#243;n preliminar de </a><strong><a href="https://en.wikipedia.org/wiki/Claude_(language_model)">Claude Mythos</a></strong>, conocida internamente como <em>Project Glasswing</em>, a 11 organizaciones colaboradoras para el descubrimiento ofensivo de vulnerabilidades de ciberseguridad.</p><p>El 23 de abril, <strong>OpenAI</strong> <a href="https://techcrunch.com/2026/04/23/openai-chatgpt-gpt-5-5-ai-model-superapp/">lanz&#243; </a><strong><a href="https://techcrunch.com/2026/04/23/openai-chatgpt-gpt-5-5-ai-model-superapp/">GPT-5.5</a></strong><a href="https://techcrunch.com/2026/04/23/openai-chatgpt-gpt-5-5-ai-model-superapp/"> y </a><strong><a href="https://techcrunch.com/2026/04/23/openai-chatgpt-gpt-5-5-ai-model-superapp/">GPT-5.5 Pro</a></strong>, descritos por la empresa como su modelo m&#225;s inteligente e intuitivo, desplegados en los niveles de consumo y empresariales de ChatGPT y Codex. Cabe destacar que OpenAI opt&#243; por no etiquetar el lanzamiento como GPT-6.</p><p>Casi al mismo tiempo, <strong>DeepSeek</strong> <a href="https://www.cnbc.com/2026/04/24/deepseek-v4-llm-preview-open-source-ai-competition-china.html">lanz&#243; su versi&#243;n preliminar </a><strong><a href="https://www.cnbc.com/2026/04/24/deepseek-v4-llm-preview-open-source-ai-competition-china.html">V4</a></strong><a href="https://www.cnbc.com/2026/04/24/deepseek-v4-llm-preview-open-source-ai-competition-china.html"> en variantes Pro y Flash</a>. El modelo, de c&#243;digo abierto, est&#225; optimizado para inferencia en los chips Huawei Ascend 950 en lugar de los de Nvidia, supuestamente por indicaci&#243;n de Pek&#237;n. Su precio es agresivo, aunque el modelo a&#250;n no se sit&#250;a al nivel de las propuestas estadounidenses de frontera.</p><p>El 24 de abril, la canadiense <strong>Cohere</strong> y la alemana <strong>Aleph Alpha</strong> <a href="https://techcrunch.com/2026/04/24/cohere-acquires-merges-with-german-based-startup-to-create-a-transatlantic-ai-powerhouse/">anunciaron una fusi&#243;n con una valoraci&#243;n combinada de 20.000 millones de d&#243;lares</a>, presentada como una alternativa transatl&#225;ntica soberana frente a los hiperescaladores estadounidenses. Los accionistas de Cohere se quedan con aproximadamente el 90 por ciento. El alem&#225;n Grupo Schwarz comprometi&#243; 600 millones de d&#243;lares para una Serie E. La operaci&#243;n cont&#243; con el respaldo de ambos gobiernos.</p><p>El 27 de abril, <a href="https://www.cnbc.com/2026/04/27/meta-manus-china-blocks-acquisition-ai-startup.html">el regulador del mercado de China bloque&#243; la adquisici&#243;n de </a><strong><a href="https://www.cnbc.com/2026/04/27/meta-manus-china-blocks-acquisition-ai-startup.html">Manus</a></strong><a href="https://www.cnbc.com/2026/04/27/meta-manus-china-blocks-acquisition-ai-startup.html"> por parte de </a><strong><a href="https://www.cnbc.com/2026/04/27/meta-manus-china-blocks-acquisition-ai-startup.html">Meta</a></strong><a href="https://www.cnbc.com/2026/04/27/meta-manus-china-blocks-acquisition-ai-startup.html">, una operaci&#243;n de 2.000 millones de d&#243;lares</a> sobre la startup china de IA ag&#233;ntica, alegando motivos de seguridad nacional. La decisi&#243;n deshace formalmente la operaci&#243;n que se hab&#237;a cerrado a finales de diciembre de 2025.</p><p>Y el 6 de mayo, <strong>Anthropic</strong> <a href="https://www.aljazeera.com/economy/2026/5/6/spacex-backs-anthropic-with-data-centre-deal-amidst-musks-openai-lawsuit">asegur&#243; 300 megavatios de nueva capacidad de c&#243;mputo mediante un acuerdo con la instalaci&#243;n </a><strong><a href="https://www.aljazeera.com/economy/2026/5/6/spacex-backs-anthropic-with-data-centre-deal-amidst-musks-openai-lawsuit">Colossus 1</a></strong><a href="https://www.aljazeera.com/economy/2026/5/6/spacex-backs-anthropic-with-data-centre-deal-amidst-musks-openai-lawsuit"> de SpaceX</a> en Memphis, dotada de aproximadamente 220.000 GPUs de Nvidia. El acuerdo resulta llamativo dada la demanda paralela de Musk contra OpenAI.</p><h3>Futuro de los medios</h3><p>El 30 de abril, el <strong>Datatilsynet</strong> de Noruega <a href="https://ppc.land/schibsteds-ad-opt-out-fee-alarms-norway-dpa-over-privacy-as-a-luxury/">emiti&#243; una declaraci&#243;n p&#250;blica cr&#237;tica con el modelo de consentir o pagar de </a><strong><a href="https://ppc.land/schibsteds-ad-opt-out-fee-alarms-norway-dpa-over-privacy-as-a-luxury/">Schibsted</a></strong>. Schibsted cobra 39 coronas noruegas al mes a los usuarios que desean excluirse de la publicidad personalizada en <em>Aftenposten</em>, <em>VG</em> y <em>Bergens Tidende</em>. La autoridad advirti&#243; de que monetizar el consentimiento de esta forma corre el riesgo de invalidarlo, por considerar que no se otorga libremente conforme al art&#237;culo 7 del RGPD. Se trata de una declaraci&#243;n, no de una sanci&#243;n formal.</p><p>Y el 12 de mayo, el <strong>Tribunal de Justicia de la UE</strong> <a href="https://www.reuters.com/legal/litigation/meta-loses-court-fight-over-compensation-italian-publishers-2026-05-12/">dio la raz&#243;n a la autoridad italiana de comunicaciones </a><strong><a href="https://www.reuters.com/legal/litigation/meta-loses-court-fight-over-compensation-italian-publishers-2026-05-12/">AGCOM</a></strong><a href="https://www.reuters.com/legal/litigation/meta-loses-court-fight-over-compensation-italian-publishers-2026-05-12/"> en el caso </a><em><a href="https://www.reuters.com/legal/litigation/meta-loses-court-fight-over-compensation-italian-publishers-2026-05-12/">C-797/23 Meta Platforms Ireland (Fair compensation)</a></em>, dictaminando que el derecho de los editores de prensa a recibir una compensaci&#243;n justa de las grandes plataformas en l&#237;nea es compatible con el Derecho de la UE, siempre que el pago constituya una contrapartida por autorizar el uso de sus contenidos. Italia hab&#237;a transpuesto la Directiva de Derechos de Autor de la UE en 2021 y otorg&#243; a AGCOM en 2023 la facultad de solicitar a las plataformas datos de tr&#225;fico y publicidad, intervenir en las negociaciones entre editores y plataformas, y sancionar a las plataformas que no cumplieran. El Tribunal respald&#243; la potestad de AGCOM para exigir que las plataformas compartan los datos necesarios para calcular la compensaci&#243;n justa. La sentencia, articulada en torno al <a href="https://www.niemanlab.org/2026/05/the-eu-backs-italys-right-to-make-meta-pay-for-news/">art&#237;culo 15 de la Directiva de Derechos de Autor de la UE &#8212; la disposici&#243;n sobre derechos conexos</a> &#8212; refuerza la posici&#243;n de los editores de toda Europa que reclaman pagos por licencias a las grandes tecnol&#243;gicas y empresas de IA que utilizan material protegido a gran escala.</p><p>Y esto es todo por hoy (y por la primavera que llevamos consumida). Feliz semana :)</p>]]></content:encoded></item><item><title><![CDATA[Newsroom de primavera de 2026]]></title><description><![CDATA[Listen now | Verificaci&#243;n de edad hasta en la sopa, p&#237;xeles en los emails, AEPD, CEPD, CAPIs, multas y juicios]]></description><link>https://www.mastersofprivacy.com/p/newsroom-de-primavera-de-2026</link><guid isPermaLink="false">https://www.mastersofprivacy.com/p/newsroom-de-primavera-de-2026</guid><dc:creator><![CDATA[Sergio Maldonado]]></dc:creator><pubDate>Mon, 18 May 2026 19:58:59 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/198312121/a17183e7ce1d560a26ee7d96852dacb5.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Muy bien, vamos a por otro resumen trimestral, en cuatro de las secciones habituales (ePrivacy y marco regulatorio; MarTech &amp; AdTech; IA, competencia y mercados digitales; y futuro de los medios).</p><p>Entre otras cosas, hoy tratamos:</p><ul><li><p>Verificaci&#243;n de edad en sus m&#250;ltiples variantes y la evoluci&#243;n de la prohibici&#243;n de medios sociales para menores</p></li><li><p>Memoria de actividad de la AEPD</p></li><li><p>Directrices varias del EDPB</p></li><li><p>Campa&#241;as en ChatGPT, p&#237;xeles y APIs de conversi&#243;n</p></li><li><p>P&#237;xeles de apertura en correos electr&#243;nicos (Francia, Italia)</p></li><li><p>Nuevas directrices ICO para ePrivacy (analytics, A/B testing, etc.)</p></li><li><p>Multas y juicios en California (Meta, General Motors).</p></li></ul><p>Hemos incluido las notas detalladas del episodio y todos los links o referencias en un post espec&#237;fico, como siempre, <a href="https://www.mastersofprivacy.com/p/newsroom-referencias-de-primavera26">aqu&#237; disponible</a>.</p>]]></content:encoded></item><item><title><![CDATA[Newsroom Notes: Spring 2026]]></title><description><![CDATA[Further information and references.]]></description><link>https://www.mastersofprivacy.com/p/newsroom-notes-spring-2026</link><guid isPermaLink="false">https://www.mastersofprivacy.com/p/newsroom-notes-spring-2026</guid><dc:creator><![CDATA[Sergio Maldonado]]></dc:creator><pubDate>Sun, 17 May 2026 23:00:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!1DEG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d7f3cf4-9933-4ed7-a253-8408e6db1450_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1DEG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d7f3cf4-9933-4ed7-a253-8408e6db1450_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1DEG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d7f3cf4-9933-4ed7-a253-8408e6db1450_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!1DEG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d7f3cf4-9933-4ed7-a253-8408e6db1450_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!1DEG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d7f3cf4-9933-4ed7-a253-8408e6db1450_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!1DEG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d7f3cf4-9933-4ed7-a253-8408e6db1450_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1DEG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d7f3cf4-9933-4ed7-a253-8408e6db1450_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9d7f3cf4-9933-4ed7-a253-8408e6db1450_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:869354,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.mastersofprivacy.com/i/198184311?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d7f3cf4-9933-4ed7-a253-8408e6db1450_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1DEG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d7f3cf4-9933-4ed7-a253-8408e6db1450_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!1DEG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d7f3cf4-9933-4ed7-a253-8408e6db1450_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!1DEG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d7f3cf4-9933-4ed7-a253-8408e6db1450_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!1DEG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d7f3cf4-9933-4ed7-a253-8408e6db1450_1200x630.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Please find below references and notes for the latest edition of the Masters of Privacy Newsroom. Grouped in four of our usual five blocks: ePrivacy &amp; regulatory updates; MarTech &amp; AdTech; AI, Competition and Digital Markets; Future of Media.</p><p>This content is for paid Masters of Privacy subscribers only. You will find a <a href="https://www.mastersofprivacy.com/p/newsroom-spring-2026">free audio version</a> of this content on the main podcast feed.</p>
      <p>
          <a href="https://www.mastersofprivacy.com/p/newsroom-notes-spring-2026">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Newsroom: Spring 2026]]></title><description><![CDATA[Listen now | Age verification conquers the world, email tracking pixels, ChatGPT&#8217;s CAPI, no consent required for analytics and A/B testing in the UK]]></description><link>https://www.mastersofprivacy.com/p/newsroom-spring-2026</link><guid isPermaLink="false">https://www.mastersofprivacy.com/p/newsroom-spring-2026</guid><dc:creator><![CDATA[Sergio Maldonado]]></dc:creator><pubDate>Sun, 17 May 2026 22:50:04 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/198182769/2d459176e33cacb4fcfda3143d269ba8.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>We&#8217;re back with a Newsroom update. We will cover four of our usual five blocks: ePrivacy &amp; regulatory updates; MarTech &amp; AdTech; AI, competition and digital markets; and the future of media.</p><p>This season&#8217;s update includes:</p><ul><li><p>Age-verification fines (insufficient controls, too much data collection) in the UK and Spain, EDPB age-verification guidelines, California&#8217;s upcoming age-verification requirements</p></li><li><p>Enforcement actions in the US (public, private)</p></li><li><p>Guidelines for email tracking pixels in France and Italy</p></li><li><p>New ICO guidelines for storage and access technologies (exceptions for analytics, A/B testing, etc.)</p></li><li><p>Social Media bans across the world and what is failing</p></li><li><p>Data collection in the context of new media networks and AI labs.</p></li></ul><p>As announced - <a href="http://firmas.io">Firmas.io</a>: a mobile application to complement the TODO.LAW ecosystem (contract management, signatures, credentials).</p><p>All references and links (plus some bonus materials) can be found in a <a href="https://www.mastersofprivacy.com/p/newsroom-notes-spring-2026">separate blog post</a> available to paid Masters of Privacy subscribers on our website&#8217;s Newsroom section (Newsroom Notes: Spring 2026).</p><p>Our usual disclaimer: the voice that joins Sergio today is a text-to-speech output generated with Eleven Labs.</p>]]></content:encoded></item><item><title><![CDATA[RoPA exports with DPO Central]]></title><description><![CDATA[A few easy steps]]></description><link>https://www.mastersofprivacy.com/p/ropa-exports-with-dpo-central</link><guid isPermaLink="false">https://www.mastersofprivacy.com/p/ropa-exports-with-dpo-central</guid><dc:creator><![CDATA[Sergio Maldonado]]></dc:creator><pubDate>Sat, 16 May 2026 21:11:00 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/3ca74649-79bf-4129-9491-ce01b69a0235_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;3fbf9e5c-2a66-47e7-8def-a4ebab9c4eff&quot;,&quot;duration&quot;:null}"></div><p>Generating a ROPA (Records of Processing Activities) export out of your DPO Central inventory is an easy first step towards internal awareness and accountability. </p><p>This video may not be the most illustrative, but it is a good summary.</p>]]></content:encoded></item><item><title><![CDATA[Tom Kemp (CalPrivacy): on the SECURE Data Act, CCPA whistleblowers, DROP, and AB 566]]></title><description><![CDATA[Listen now | Data brokers, browser signals, whistleblowers, and the challenges of a new federal initiative]]></description><link>https://www.mastersofprivacy.com/p/tom-kemp-calprivacy-ccpa-drop-gpc</link><guid isPermaLink="false">https://www.mastersofprivacy.com/p/tom-kemp-calprivacy-ccpa-drop-gpc</guid><dc:creator><![CDATA[Sergio Maldonado]]></dc:creator><pubDate>Sun, 10 May 2026 13:52:53 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/197104483/e2eac1b3d9e469f4fb911733d6bd6dd9.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>As Executive Director of CalPrivacy (California Privacy Protection Agency), Tom Kemp oversees the CPPA&#8217;s mission to enforce and implement California&#8217;s comprehensive privacy laws and ensure the public has a strong understanding of their rights. Tom has a deep understanding of privacy and cybersecurity, combined with his track record as an executive in the tech industry.</p><p>References:</p><ul><li><p><a href="https://www.eventbrite.com/e/breakfast-workshop-santa-monica-may-2026-tickets-1988630859433">Breakfast Workshop: Santa Monica - Registration</a></p></li><li><p><a href="https://www.linkedin.com/in/tomkemp/">Tom Kemp on LinkedIn</a></p></li><li><p><a href="https://www.mastersofprivacy.com/p/daniel-solove-on-privacy-and-technology">Daniel Solove: On Privacy and Technology</a> (Masters of Privacy, March 2025)</p></li><li><p><a href="https://privacy.ca.gov/">CalPrivacy</a></p></li><li><p><a href="https://privacy.ca.gov/drop/">DROP System</a></p></li><li><p><a href="https://cppa.ca.gov/data_broker_registry/">Data Broker Registry</a></p></li><li><p><a href="https://www.hunton.com/privacy-and-cybersecurity-law-blog/california-expands-data-broker-registration-requirements">California expands data broker registration requirements, SP 361</a> (Hunton Privacy Blog, October 2025)</p></li><li><p><a href="https://legiscan.com/CA/text/SB923/2025">Expanding Privacy Rights Act</a> (SB 923, introduced on January 28, 2026)</p></li><li><p><a href="https://www.hunton.com/privacy-and-cybersecurity-law-blog/california-enacts-first-in-nation-law-requiring-web-browser-opt-out-preference-signal">California enacts first-in-nation law requiring web browser opt-out preference signal, AB 566</a> (Hunton Privacy Blog)</p></li><li><p><a href="https://ballotpedia.org/California_Proposition_24,_Consumer_Personal_Information_Law_and_Agency_Initiative_(2020)">California Proposition 24, Consumer Personal Information Law and Agency Initiative</a> (2020)</p></li><li><p><a href="https://www.cognism.com/blog/api-enrichment">Data broker-provided customer properties in action - enriching first-party data sets for Conversion API uploads</a> (Cognism)</p></li><li><p><a href="https://privacy.ca.gov/2026/04/california-privacy-protection-agency-releases-letter-opposing-the-secure-data-act/">California Privacy Protection Agency releases letter opposing the SECURE Data Act</a></p></li><li><p><a href="https://www.congress.gov/bill/119th-congress/house-bill/8413">SECURE Data Act</a> (H.R. 8413, Introduced 04/21/2026)</p></li><li><p><a href="https://privacy.ca.gov/2026/02/calprivacy-sponsors-whistleblower-protection-bill/">Whistleblower Protection and Privacy Act (AB 2021)</a>, linking the California Whistleblower Protection Act&#8217;s principles to the California Consumer Privacy Act (CCPA) to expose privacy violations hidden within corporate &#8220;black boxes&#8221;.</p></li></ul>]]></content:encoded></item><item><title><![CDATA[Breakfast workshop: Santa Monica May 2026]]></title><description><![CDATA[An informal chat about recent updates to California privacy laws]]></description><link>https://www.mastersofprivacy.com/p/breakfast-workshop-santa-monica-may</link><guid isPermaLink="false">https://www.mastersofprivacy.com/p/breakfast-workshop-santa-monica-may</guid><dc:creator><![CDATA[Sergio Maldonado]]></dc:creator><pubDate>Mon, 04 May 2026 00:37:00 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/617e74c0-89a3-4864-9876-e5768e99a055_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>We have a new breakfast workshop coming up, this time back in Los Angeles. At the very least, expect to join a thought-provoking conversation while enjoying a proper coffee in downtown Santa Monica.</p><p>As usual, paid Masters of Privacy subscribers can use their special code (find it in your welcome email) to register at no cost - we charge $7 to ensure attendance otherwise. </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.eventbrite.com/e/breakfast-workshop-santa-monica-may-2026-tickets-1988630859433&quot;,&quot;text&quot;:&quot;Register Now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.eventbrite.com/e/breakfast-workshop-santa-monica-may-2026-tickets-1988630859433"><span>Register Now</span></a></p><p>Really hoping to see some of you there :)</p>]]></content:encoded></item><item><title><![CDATA[Mark Webber: a law firm’s perspective on AI governance]]></title><description><![CDATA[Listen now | Building guardrails at the speed of AI]]></description><link>https://www.mastersofprivacy.com/p/mark-webber-ai-speed</link><guid isPermaLink="false">https://www.mastersofprivacy.com/p/mark-webber-ai-speed</guid><dc:creator><![CDATA[Sergio Maldonado]]></dc:creator><pubDate>Sun, 03 May 2026 19:34:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/196343132/6ee7a849fd94355bd6fb2b9088edaa6a.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Mark Webber is the US Managing Partner responsible for overseeing the operations of Fieldfisher in the country - an English lawyer located full time in Silicon Valley.  </p><p>Mark is a recognised leading privacy and AI expert, with a wealth of experience working alongside the world&#8217;s leading tech companies. Much of his time today involves the responsible development, training, and scaling of AI models and solutions.</p><p>Our guest teaches classes for both the CIPP/E and AI Governance Professional Programme certification for the IAPP.  He is a Fellow in Information Privacy (IAPP).</p><p>As a leader at Fieldfisher he has been instrumental in establishing, nurturing, and expanding Fieldfisher&#8217;s presence, operations and services in the United States.</p><p>References:</p><ul><li><p><a href="https://www.linkedin.com/in/markwebber/">Mark Webber on LinkedIn</a></p></li><li><p><a href="https://www.fieldfisher.com/en/people/mark-webber">Mark Webber at Fieldfisher</a></p></li><li><p><a href="https://leg.colorado.gov/bills/sb24-205">Colorado AI Act</a></p></li><li><p><a href="https://dpocentral.todo.law">DPO Central (TODO.LAW)</a></p></li><li><p><a href="https://www.mastersofprivacy.com/p/ai-act-based-ai-governance-with-ai">EU AI Act: rolling out an AI governance framework with AI Sentinel</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Berta Balanzategui (Remastered): Binding Corporate Rules]]></title><description><![CDATA[Listen now | Planificaci&#243;n, despliegue y supervisi&#243;n de las Normas Corporativas Vinculantes para la transferencia internacional de datos personales]]></description><link>https://www.mastersofprivacy.com/p/berta-balanzategui-binding-corporate-rules</link><guid isPermaLink="false">https://www.mastersofprivacy.com/p/berta-balanzategui-binding-corporate-rules</guid><dc:creator><![CDATA[Sergio Maldonado]]></dc:creator><pubDate>Thu, 30 Apr 2026 18:57:09 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/196032391/01b3fb303d9c7d4717751db579ccccf7.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Berta es fundadora de The Privacy Coach y fue durante a&#241;os Senior Privacy Counsel en la Oficina Corporativa de Privacidad de General Electric, responsable de la implementaci&#243;n del RGPD en la UE y el Reino Unido.</p><p>Con ella abordamos en su momento las Normas Corporativas Vinculantes (Binding Corporate Rules) para saber qu&#233; son, c&#243;mo se aprueban y c&#243;mo se mantienen. Tambi&#233;n dimos cobertura a otros temas como la confusa l&#237;nea divisoria entre responsables independientes, encargados y corresponsables en el tratamiento de datos personales.</p><p>Este episodio es una republicaci&#243;n &#8220;remasterizada&#8221; de nuestra entrevista original.</p><p>Referencias:</p><ul><li><p><a href="https://www.theprivacycoach.net/">The Privacy Coach</a></p></li><li><p><a href="https://www.linkedin.com/in/berta-balanzategui-vidal-4526405/">Berta Balanzategui en LinkedIn</a></p></li><li><p><a href="https://www.mastersofprivacy.com/p/berta-balanzategui-normas-corporativas-fd9">Berta Balanzategui: Normas Corporativas Vinculantes (BCR)</a>, Masters of Privacy (junio de 2023)</p></li><li><p><a href="https://edpb.europa.eu/guidelines-relevant-controllers-and-processors_es">Directrices del CEPD sobre Normas Corporativas Vinculantes para responsables y encargados del tratamiento</a></p></li><li><p><a href="https://iapp.org/news/a/binding-corporate-rules-after-the-schrems-ii-decision-a-first-analysis/">[EN] Jetty, Tielemans, una primera aproximaci&#243;n al impacto de Schrems II en las BCR</a>.</p></li></ul>]]></content:encoded></item><item><title><![CDATA[Iain Henderson: MyTerms as the missing universal opt-in signal (After The Magic repost)]]></title><description><![CDATA[Listen now | A new building block of digital trust, ePrivacy, and customer centricity]]></description><link>https://www.mastersofprivacy.com/p/iain-henderson-myterms-universal-optin</link><guid isPermaLink="false">https://www.mastersofprivacy.com/p/iain-henderson-myterms-universal-optin</guid><dc:creator><![CDATA[Sergio Maldonado]]></dc:creator><pubDate>Sun, 26 Apr 2026 18:35:34 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/195547494/ebfc7488304a9ace186d47a82a1d9658.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Universal opt-out signals (like Global Privacy Control) have gained momentum on both sides of the Atlantic, with the EU recently endorsing them (Digital Omnibus) and CalPrivacy, Colorado, or Connecticut legally enforcing them, but they do not solve for consent opt-in requirements still applicable in many cases.</p><p>Meanwhile, privacy notices remain cryptic and challenging for anyone to read or understand. They pay little attention to an individual&#8217;s real preferences or needs and sit at the opposite side of agency or the often claimed &#8220;we care about your privacy&#8221;.</p><p>MyTerms is a brand new IEEE standard that could provide the missing link.</p><p>This episode is a repost of our recent interview with Iain Henderson, one of the creators of MyTerms, on the After The Magic podcast (co-hosted by Gam Dias and Sergio Maldonado).</p><p>Iain is a long term marketer and CRM professional who long since concluded that if the &#8216;customer side&#8217; had equivalent relationship and data management tools then things would work a lot better. His day job is with JLINC (<a href="http://www.jlinc.com">www.jlinc.com</a>) as the architect for personal data solutions, and through that he is also part of the DataPal (<a href="http://www.datapal.me">www.datapal.me</a>) team in the UK. He is also a Board member of Customer Commons, and has been a core member of the team developing IEEE 7012/ MyTerms.</p><p>References:</p><ul><li><p><a href="https://www.afterthemagic.com/p/iain-henderson-myterms">Original post (on After The Magic)</a></p></li><li><p><a href="https://substack.com/@iainhenderson1">Iain Henderson on Substack</a></p></li><li><p><a href="https://www.linkedin.com/in/iainhenderson1/">Iain Henderson on LinkedIn</a></p></li><li><p><a href="https://myterms.info/">MyTerms</a></p></li><li><p><a href="http://www.jlinc.com">JLINC</a></p></li><li><p><a href="http://www.datapal.me">DataPal</a></p></li><li><p><a href="https://mydata.org/">MyData Global</a></p></li><li><p><a href="https://www.edpb.europa.eu/news/news/2026/digital-omnibus-edpb-and-edps-support-simplification-and-competitiveness-while_en">EU Digital Omnibus: EDPB and EDPS support simplification and competitiveness while raising key concerns</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Shoshana Rosenberg: logic and strategy in AI governance]]></title><description><![CDATA[Listen now | Building an AI Governance Program for Oversight and Strategy]]></description><link>https://www.mastersofprivacy.com/p/shoshana-rosenberg-logical-ai-governance</link><guid isPermaLink="false">https://www.mastersofprivacy.com/p/shoshana-rosenberg-logical-ai-governance</guid><dc:creator><![CDATA[Sergio Maldonado]]></dc:creator><pubDate>Sun, 19 Apr 2026 21:27:39 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/194732872/ed30faee54428c2c277ab30db1ae2511.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Shoshana Rosenberg advises boards and executive teams on AI governance, privacy, security compliance, and data strategy. She is the author of Practical AI Governance (Kogan Page, May 2026) and the creator of the PRISM&#8482; framework, a practitioner&#8217;s model for responsible AI.</p><p>She is Managing Director of Logical AI Governance, founder of SafePorter, and co-founder of Women in AI Governance. Before turning to her current work, she spent nearly two decades building and leading privacy, data governance, and AI and technology governance programs at global professional services firms, most recently as Senior Vice President, Chief AI Governance and Privacy Officer, and an Innovation Advisory Board Member.</p><p>Shoshana was named in the top fifty of the Top 100 Women in AI for 2026 by AI Magazine. A U.S. Navy veteran, she organizes TEDxPrinceton and lives in Princeton, New Jersey.</p><p>References:</p><ul><li><p><a href="https://www.practicalaigovernance.com/">Practical AI Governance: Building a Program for Oversight and Strategy</a> (Shoshana Rosenberg, to be released on May 26th 2026)</p></li><li><p><a href="https://www.logicalaigovernance.com/training-and-certifications">Logical AI Governance: Training and Certifications</a></p></li><li><p><a href="https://www.linkedin.com/in/shoshanarosenberg/">Shoshana Rosenberg on LinkedIn</a></p></li><li><p><a href="https://www.mastersofprivacy.com/p/daniel-solove-on-privacy-and-technology-9e0">Daniel Solove: On Privacy and Technology</a> (Masters of Privacy, March 2025)</p></li><li><p><a href="https://www.mastersofprivacy.com/p/introducing-ai-sentinel-ai-governance">Introducing AI Sentinel: AI Governance, simplified</a> (Masters of Privacy toolbox).</p></li></ul>]]></content:encoded></item><item><title><![CDATA[Breakfast workshop: NYC April 2026]]></title><description><![CDATA[An informal chat about the evolution of AI Governance at medium and large law firms]]></description><link>https://www.mastersofprivacy.com/p/breakfast-workshop-nyc-april-2026</link><guid isPermaLink="false">https://www.mastersofprivacy.com/p/breakfast-workshop-nyc-april-2026</guid><dc:creator><![CDATA[Sergio Maldonado]]></dc:creator><pubDate>Thu, 16 Apr 2026 08:41:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!bO-V!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F224e5c83-64dd-4cc9-ae3b-28bd5c382d7c_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bO-V!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F224e5c83-64dd-4cc9-ae3b-28bd5c382d7c_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bO-V!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F224e5c83-64dd-4cc9-ae3b-28bd5c382d7c_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!bO-V!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F224e5c83-64dd-4cc9-ae3b-28bd5c382d7c_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!bO-V!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F224e5c83-64dd-4cc9-ae3b-28bd5c382d7c_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!bO-V!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F224e5c83-64dd-4cc9-ae3b-28bd5c382d7c_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bO-V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F224e5c83-64dd-4cc9-ae3b-28bd5c382d7c_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/224e5c83-64dd-4cc9-ae3b-28bd5c382d7c_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1015252,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.mastersofprivacy.com/i/191798073?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F224e5c83-64dd-4cc9-ae3b-28bd5c382d7c_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bO-V!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F224e5c83-64dd-4cc9-ae3b-28bd5c382d7c_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!bO-V!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F224e5c83-64dd-4cc9-ae3b-28bd5c382d7c_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!bO-V!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F224e5c83-64dd-4cc9-ae3b-28bd5c382d7c_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!bO-V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F224e5c83-64dd-4cc9-ae3b-28bd5c382d7c_1200x630.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>We have a new breakfast workshop coming up, this time back in New York City. We will however put most privacy topics aside this time around to focus on AI governance in the context of legal services. </p><p>Reserve your spot today. Paid Masters of Privacy subscribers will be reimbursed for their ($7) tickets, and a healthy breakfast -with proper coffee- is on the house. </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.eventbrite.com/e/masters-of-privacy-breakfast-workshop-april-2026-tickets-1985677933151&quot;,&quot;text&quot;:&quot;Register Now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.eventbrite.com/e/masters-of-privacy-breakfast-workshop-april-2026-tickets-1985677933151"><span>Register Now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Mirena Taskova: the human-AI interaction as a growing dimension of consumer profiling, and its impact on human behavior]]></title><description><![CDATA[Listen now | Dealing with the overlap between AI-powered human-human communications and human-AI exchanges.]]></description><link>https://www.mastersofprivacy.com/p/mirena-taskova-the-human-ai-interaction</link><guid isPermaLink="false">https://www.mastersofprivacy.com/p/mirena-taskova-the-human-ai-interaction</guid><dc:creator><![CDATA[Sergio Maldonado]]></dc:creator><pubDate>Sun, 12 Apr 2026 14:05:37 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/193930845/f74a132f1049ad243fddfbbf198ad0f4.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Our interactions with generative AI tools start to affect our personal relationships, communication style, and mental health, as well as our own perception of each other&#8217;s capabilities. They also leave a new trace of signals that privacy professionals never had to contend with in the past.</p><p>As we approach the &#8220;personal agent&#8221; era, understanding where our individual freedoms and agency truly start and end becomes paramount. After a deeper offline conversation with Marina Taskova, we are today dipping our toes into a subject with profound implications for individual rights, freedom, data protection, commerce, advertising, and media. We will follow it up with other conversations on the topic, which falls right into our sweet spot. </p><p>Mirena is a senior expert in data governance, privacy, cybersecurity &amp; AI as well as a lawyer. She was Chief Privacy Officer at Aura until recently, and has over 18 years of experience driving high-growth initiatives in privacy &amp; data governance, AI, and enterprise technology, having held executive roles, including CPO and Managing Director positions. Mirena is a graduate of Stanford University in Law, Science &amp; Technology and has worked in Europe and the US.</p><p>References:</p><ul><li><p><a href="https://www.linkedin.com/in/mirenataskova/">Mirena Taskova on LinkedIn</a></p></li><li><p><a href="https://www.mastersofprivacy.com/p/yngvi-karlson-kin-the-rise-of-the">Yngvi Karlson (Kin): the rise of the Personal AI Assistant</a> (Masters of Privacy, August 2025)</p></li><li><p><a href="https://thenextweb.com/news/google-assistant-puts-an-end-to-impolite-queries-with-pretty-please-feature">Google Assistant puts an end to impolite queries with &#8216;Pretty Please&#8217; feature</a> (The Next Web, 2018)</p></li><li><p><a href="https://www.wsj.com/tech/ai/seven-lawsuits-allege-openai-encouraged-suicide-and-harmful-delusions-25def1a3?gaa_at=eafs&amp;gaa_n=AWEtsqef2DujMMBNiTUvJqIa-YK46JfmaiQq9RZW2uAvWj_Zhp0PQ36TyEroqcTVGGI%3D&amp;gaa_ts=6913ee8e&amp;gaa_sig=K2Gt_oAC_aiekEz6d2yz-l2zpnXPt7Yq4ndNMWx0B3Bdm9MF_trOoDnmqt3MdrvMfbq2DVXLSExcWbRX5aY2gA%3D%3D">Seven Lawsuits Allege OpenAI Encouraged Suicide and Harmful Delusions</a> (WSJ)</p></li><li><p><a href="https://www.newyorker.com/magazine/2025/07/21/ai-is-about-to-solve-loneliness-thats-a-problem">A.I. Is About to Solve Loneliness. That&#8217;s a Problem</a> (The New Yorker, July 14 2025)</p></li><li><p><a href="https://en.wikipedia.org/wiki/Myers%E2%80%93Briggs_Type_Indicator">The Myers-Briggs Type Indicator</a> (Wikipedia)</p></li><li><p><a href="https://mykin.ai/">Kin AI</a></p></li><li><p><a href="https://www.jdsupra.com/legalnews/new-california-companion-chatbot-law-7220945/#:~:text=California%20has%20enacted%20Senate%20Bill,in%20by%20July%201%2C%202027.">New California &#8216;Companion Chatbot&#8217; Law Imposes Disclosure, Safety Protocol and Annual Reporting Requirements</a> (JD Supra, Skadden)</p></li><li><p><a href="http://character.ai">Character.AI to Bar Children Under 18 From Using Its Chatbots</a> (New York Times, October 2025).</p></li></ul>]]></content:encoded></item><item><title><![CDATA[Chiara Wirz: a practical AI governance framework for in-house counsel and privacy professionals]]></title><description><![CDATA[Listen now | Are data privacy &#8220;gatekeepers&#8221; turning into &#8220;grid builders&#8221; thanks to AI governance?]]></description><link>https://www.mastersofprivacy.com/p/chiara-wirz-a-practical-ai-governance</link><guid isPermaLink="false">https://www.mastersofprivacy.com/p/chiara-wirz-a-practical-ai-governance</guid><dc:creator><![CDATA[Sergio Maldonado]]></dc:creator><pubDate>Sun, 05 Apr 2026 17:30:47 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/193091040/b7f3985127ffa75d79fb716e064e6d05.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Chiara Wirz is a dual-admitted lawyer (California-Switzerland) who advises on privacy, AI governance, and cross-border corporate matters. She has served as Corporate Counsel and AI Ambassador at eBay Inc., where she built AI governance frameworks, operationalized AI deployment at the use case level, and trained legal and compliance professionals.</p><p>Chiara holds triple IAPP certification, is completing a Professional MBA, and is Co-Chair of the WISP (Women in Security and Privacy) San Francisco Bay Area chapter. She is also an Executive Committee member of the New Lawyers Section and the Liaison of the Privacy Section of the California Lawyers Association.</p><p>Our guest is a published author and conference speaker on AI governance (PLI, SCCE, California Lawyers Association).</p><p>References</p><ul><li><p><a href="https://www.linkedin.com/in/chiara-imelda-wirz-974964152/">Chiara Wirz on LinkedIn</a></p></li><li><p><a href="https://www.wisporg.com/">Women in Security and Privacy</a> (WISP)</p></li><li><p><a href="https://www.mastersofprivacy.com/p/ai-act-based-ai-governance-with-ai">EU AI Act-based AI Governance</a> (with AI Sentinel)</p></li><li><p><a href="https://www.mastersofprivacy.com/p/iso-42001-based-ai-governance-with">ISO 42001-based AI Governance</a> (with AI Sentinel)</p></li><li><p><a href="https://www.mastersofprivacy.com/p/nist-based-ai-governance-with-ai">NIST-based AI Governance</a> (with AI Sentinel).</p></li></ul>]]></content:encoded></item><item><title><![CDATA[AI Act-based AI Governance (with AI Sentinel) ]]></title><description><![CDATA[How to build an AI Governance program under the EU AI Act framework.]]></description><link>https://www.mastersofprivacy.com/p/ai-act-based-ai-governance-with-ai</link><guid isPermaLink="false">https://www.mastersofprivacy.com/p/ai-act-based-ai-governance-with-ai</guid><dc:creator><![CDATA[Sergio Maldonado]]></dc:creator><pubDate>Fri, 03 Apr 2026 16:45:25 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/3adf1898-d477-4210-99ba-8907ddf52d1d_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This is the third of a series of videos explaining how to get your AI governance program running with little effort. We are using the freely-available <a href="https://aisentinel.todo.law/">AI Sentinel</a> tool for illustrative purposes (and certainly hoping that we can improve the product together with your valuable feedback).</p><p>Today&#8217;s short video cover the EU&#8217;s AI Act framework exclusively. Please find guides to the alternative NIST and ISO 42001 frameworks on the DPO School section of this website.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;9e19a5a8-e02c-497b-b1e0-e82453d0e3da&quot;,&quot;duration&quot;:null}"></div><p>*Note: this video&#8217;s voiceover has been generated with Eleven Labs.</p><p>(Find more <strong>DPO School</strong> resources in <a href="https://www.mastersofprivacy.com/s/dpo-school">this section</a>, or on the official <a href="https://dposchool.com/">DPO School website</a>.)</p>]]></content:encoded></item><item><title><![CDATA[ISO 42001-based AI Governance (with AI Sentinel) ]]></title><description><![CDATA[How to build an AI Governance program under the ISO 42001 framework.]]></description><link>https://www.mastersofprivacy.com/p/iso-42001-based-ai-governance-with</link><guid isPermaLink="false">https://www.mastersofprivacy.com/p/iso-42001-based-ai-governance-with</guid><dc:creator><![CDATA[Sergio Maldonado]]></dc:creator><pubDate>Fri, 03 Apr 2026 16:44:44 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/1b93cb2f-f1e4-4322-af31-ef95af9eb203_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This is the second of a series of videos explaining how to get your AI governance program running with little effort. We are using the freely-available <a href="https://aisentinel.todo.law/">AI Sentinel</a> tool for illustrative purposes (and certainly hoping that we can improve the product together with your valuable feedback).</p><p>Today&#8217;s short video cover the ISO 42001 framework exclusively. Please find guides to the alternative NIST and EU AI Act frameworks on the DPO School section of this website.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;27066de2-ee09-4c80-b3c7-fe90d0cb6ca5&quot;,&quot;duration&quot;:null}"></div><p>*Note: this video&#8217;s voiceover has been generated with Eleven Labs.</p><p>(Find more <strong>DPO School</strong> resources in <a href="https://www.mastersofprivacy.com/s/dpo-school">this section</a>, or on the official <a href="https://dposchool.com/">DPO School website</a>.)</p><p></p>]]></content:encoded></item><item><title><![CDATA[Silvia Gerboles: el Digital Omnibus, otra vuelta de tuerca]]></title><description><![CDATA[&#191;C&#243;mo se vive el Digital Omnibus desde la gran empresa? &#191;Ayudan los cambios propuestos?]]></description><link>https://www.mastersofprivacy.com/p/silvia-gerboles-el-digital-omnibus</link><guid isPermaLink="false">https://www.mastersofprivacy.com/p/silvia-gerboles-el-digital-omnibus</guid><dc:creator><![CDATA[Sergio Maldonado]]></dc:creator><pubDate>Thu, 02 Apr 2026 21:52:09 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/193010349/8fd3ad82208fd4f1dcad8e0851e66023.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>&#191;C&#243;mo se vive el Digital Omnibus desde la gran empresa? &#191;Ayudan los cambios propuestos? &#191;Firmamos acuerdos para el tratamiento de datos &#8220;no personales&#8221;?</p><p>Silvia Gerboles es  Delegada de Protecci&#243;n de Datos y Expert Senior Group Legal Counsel en la unidad Global Privacy Ericsson. Con  m&#225;s de 25 a&#241;os de experiencia en protecci&#243;n de datos, privacidad y ciberseguridad. Dentro del Grupo Ericsson, Silvia lidera los asuntos globales de privacidad de los clientes y los flujos transfronterizos de datos a nivel mundial; actualmente est&#225; involucrada en la Gobernanza de Datos y el Uso de Datos e implementaci&#243;n AI. Tambi&#233;n desempe&#241;a el cargo de Delegada de Protecci&#243;n de Datos para algunas empresas del Grupo Ericsson.</p><p>Basada en Madrid habiendo trabajado en distintas Firmas de Consultor&#237;a y Despachos de Abogados. Miembro del Colegio de Abogados de Madrid, posee un LLM por  y un m&#225;ster en Derecho de Propiedad Intelectual por IE. Certificada como Delegada de Protecci&#243;n de Datos por la AEPD y cuenta con varias certificaciones internacionales en privacidad.</p><p>Nuestra invitada es docente habitual en materias de Privacidad de Datos, IT y Telecomunicaciones, en diferentes programas de m&#225;ster y seminarios, y ha publicado varios trabajos sobre protecci&#243;n de datos, IT y Derecho Comercial.</p><p>Referencias:</p><ul><li><p><a href="https://www.linkedin.com/in/silvia-gerboles-124a736/">Silvia Gerboles en LinkedIn</a></p></li><li><p><a href="https://www.europarl.europa.eu/doceo/document/TA-10-2026-0098_EN.html">El Parlamento Europeo adopta su posici&#243;n para la simplificaci&#243;n de la normativa de inteligencia artificial (Digital Omnibus - paquete IA) en sesi&#243;n plenaria, 26 de marzo de 2026</a> (EN)</p></li><li><p><a href="https://www.mastersofprivacy.com/p/itxaso-dominguez-de-olazabal-digital-omnibus-gpc">Itxaso Dom&#237;nguez de Olaz&#225;bal: la improcedencia del Digital Omnibus, un opt-out para Europa y la broma de &#8220;consiente o paga&#8221;</a> (Masters of Privacy, febrero de 2026)</p></li><li><p><a href="https://www.mastersofprivacy.com/p/oliver-patel-how-the-digital-omnibus">Oliver Patel: How the Digital Omnibus affects the EU AI Act</a> (EN, Masters of Privacy, diciembre de 2025)</p></li><li><p><a href="https://www.edpb.europa.eu/our-work-tools/our-documents/edpbedps-joint-opinion/edpb-edps-joint-opinion-22026-proposal_en">Opini&#243;n conjunta del EDPB y el EDPS sobre el Digital Omnibus</a> (EN, 11 de febrero, 2026).</p></li></ul>]]></content:encoded></item><item><title><![CDATA[NIST-based AI Governance (with AI Sentinel)]]></title><description><![CDATA[How to build an AI Governance program under the NIST AI framework.]]></description><link>https://www.mastersofprivacy.com/p/nist-based-ai-governance-with-ai</link><guid isPermaLink="false">https://www.mastersofprivacy.com/p/nist-based-ai-governance-with-ai</guid><dc:creator><![CDATA[Sergio Maldonado]]></dc:creator><pubDate>Thu, 02 Apr 2026 13:06:00 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/2ea51ad9-d665-4f4f-9eef-a4327227574b_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This is the first of a series of videos explaining how to get your AI governance program running with little effort. We are using the freely-available <a href="https://aisentinel.todo.law/">AI Sentinel</a> tool for illustrative purposes (and certainly hoping that we can improve the product together with your valuable feedback).</p><p>Today&#8217;s short video cover the NIST framework exclusively. Subsequent videos will illustrate the rollout of a program under both the EU AI Act and ISO 42001. </p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;90419d4b-53e3-4575-b267-f398336bff42&quot;,&quot;duration&quot;:null}"></div><p>*Note: this video&#8217;s voiceover has been generated with Eleven Labs.</p><p>(Find more <strong>DPO School</strong> resources in <a href="https://www.mastersofprivacy.com/s/dpo-school">this section</a>, or on the official <a href="https://dposchool.com/">DPO School website</a>.)</p>]]></content:encoded></item><item><title><![CDATA[Amy Worley: an overarching framework for AI governance, privacy, and cybersecurity]]></title><description><![CDATA[Listen now | Optimizing Privacy, Cybersecurity and AI Governance for Growth]]></description><link>https://www.mastersofprivacy.com/p/amy-worley-an-overarching-framework</link><guid isPermaLink="false">https://www.mastersofprivacy.com/p/amy-worley-an-overarching-framework</guid><dc:creator><![CDATA[Sergio Maldonado]]></dc:creator><pubDate>Sun, 29 Mar 2026 14:14:19 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/192508218/5e6e6499cb0bc6c00a0dfbe91ad46f96.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Can you imagine an all-encompassing dashboard that shows your progress across all three pillars of &#8220;digital confidence&#8221;: AI governance, privacy, and cybersecurity?</p><p>Amy Worley is Managing Director at BRG, a global leader in data protection, information security, and AI governance. A licensed attorney, certified privacy professional, and certified information systems security professional, She formerly served as the Chief Privacy Officer for a billion-dollar pharmaceutical and medical device company and now serves as a fractional Data Protection Officer for several multinational companies.</p><p>Our guest is the author of the newly-published book &#8220;The Confidence Advantage. Optimizing Privacy, Cybersecurity and AI Governance for Growth&#8221;, and we will discuss its contents, how they came to be, and how they apply to the real world.</p><p>References:</p><ul><li><p><a href="https://www.linkedin.com/in/amyworley/">Amy Worley on LinkedIn</a></p></li><li><p><a href="https://confidenceadvantage.io/">The Confidence Advantage</a> (official website)</p></li><li><p><a href="https://www.amazon.com/Confidence-Advantage-Optimizing-Cybersecurity-Governance-ebook/dp/B0GJN7KYSH?sr=1-1">The Confidence Advantage</a> (Amazon.com)</p></li><li><p><a href="https://www.mastersofprivacy.com/p/amy-worley-us-privacy-compliance-24b">Amy Worley: US privacy compliance for B2B startups, cross-border AI regulation, and a first glance at the American Privacy Rights Act</a> (Masters of Privacy, April 2024)</p></li><li><p><a href="https://www.mastersofprivacy.com/p/nist-based-ai-governance-with-ai">NIST-based AI Governance with AI Sentinel</a> (explanatory video)</p></li><li><p><a href="https://dpocentral.todo.law/">DPO Central on TODO.LAW</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Jorge García Herrero: la AbogacIA ante el precipicio]]></title><description><![CDATA[Cortoplacismo e &#8220;IA legal&#8221;, futuro de los servicios legales, descontrol en los despachos.]]></description><link>https://www.mastersofprivacy.com/p/jorge-garcia-herrero-ia-y-derecho</link><guid isPermaLink="false">https://www.mastersofprivacy.com/p/jorge-garcia-herrero-ia-y-derecho</guid><dc:creator><![CDATA[Sergio Maldonado]]></dc:creator><pubDate>Mon, 23 Mar 2026 22:09:03 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/191918704/b2bf35e2039674597afea6de3f8d433f.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Se ha vuelto urgente charlar sin pelos en la lengua sobre el caos de gobernanza, comprensi&#243;n y estrategia en el uso de la IA por parte de despachos de abogados, DPOs, y otros profesionales.</p><p>Vuelve al programa Jorge Garc&#237;a Herrero para debatir sobre:</p><ul><li><p>La posible inutilidad de los llamados &#8220;legal AI&#8221;</p></li><li><p>El futuro de los servicios legales</p></li><li><p>Modelos abiertos y locales como f&#243;rmula de gobernanza e independencia</p></li><li><p>El factor silencioso que nos puede devolver a los a&#241;os ochenta.</p></li></ul><p>Sobre Jorge:</p><p>Despu&#233;s de 17 a&#241;os en el despacho Garrigues, Jorge Garc&#237;a Herrero encontr&#243; en 2017 su ikigai en la protecci&#243;n de datos personales. A d&#237;a de hoy es premio de la AEPD a las &#8220;Buenas Pr&#225;cticas en la implementaci&#243;n del RGPD y la LOPD&#8221; (2019), asesora a multinacionales espa&#241;olas y extranjeras l&#237;deres en sus mercados, y lidera dos grupos especialistas en protecci&#243;n de datos. Jorge es adem&#225;s co-autor del manual &#8220;An&#225;lisis de sanciones en Protecci&#243;n de Datos divididas por conceptos y sectores&#8221; (Wolters Kluwer, 2021) y del libro &#8220;La adaptaci&#243;n al nuevo marco de protecci&#243;n de datos tras el RGPD y la LOPDGDD&#8221; (Wolters Kluwer, 2019). Tambi&#233;n es ponente y docente habitual en las Universidades de Valladolid, Alicante, Almer&#237;a, y Pontificia de Salamanca. Junto a Dar&#237;o L&#243;pez Rinc&#243;n publica la Newsletter &#8220;best seller&#8221; Zero Party Data.</p><p>Referencias:</p><ul><li><p><a href="https://jgarciaherrero.substack.com/">Zero-Party Data</a>: Newsletter de Jorge Garc&#237;a Herrero y Dar&#237;o L&#243;pez Rinc&#243;n</p></li><li><p><a href="https://bsky.app/profile/jgarciaherrero.bsky.social">Jorge Garc&#237;a Herrero en Bluesky</a></p></li><li><p><a href="https://www.linkedin.com/in/jorgegarciaherrero/">Jorge Garc&#237;a Herrero en LinkedIn</a></p></li><li><p><a href="https://www.goodreads.com/en/book/show/239362630-reshuffle">Reshuffle: Who Wins when AI Restacks the Knowledge Economy</a> (Sangeet Paul Choudary, 2025)</p></li><li><p><a href="https://www.legalquants.com/">LegalQuants: &#8220;Build what you practice&#8221;</a></p></li><li><p><a href="https://dealroom.todo.law/">TODO.LAW : Dealroom</a></p></li><li><p><a href="https://dpocentral.todo.law/">TODO.LAW: DPO Central</a></p></li><li><p><a href="https://www.todo.law/hardware">TODO.LAW: Hardware &#8220;setup&#8221; (lista de espera)</a></p></li></ul>]]></content:encoded></item></channel></rss>