Publications
Selected writing
Articles by Sergio Maldonado on privacy, data protection, AI governance and the future of legal practice.
January 29, 2026 · LinkedIn
Legal AI vs. AI-native law firms
Why the truly AI-native law firm serves AI-native customers and treats AI as infrastructure, rather than bolting Legal AI products onto legacy workflows.
readJanuary 25, 2026 · LinkedIn
Combining Privacy Protection with a Smooth Internet Browsing Experience Through Built-in Opt-Out Signals
A comparative EU/UK-US analysis of built-in browser opt-out signals (GPC, MyTerms, the Digital Omnibus) and whether they can finally replace consent banners.
readNovember 19, 2025 · PrivacyCloud
Accountability and third-party vetting in the age of wild automation
Why security certifications and cookie-cutter compliance paperwork no longer suffice for vetting data processors, and how AI-driven automation rewards vendors that genuinely practice Privacy by Design.
readNovember 17, 2025 · LinkedIn
The US internet is falling prey to the consent-banner plague. A more effective opt-out system will soon deliver greater agency
How CIPA and VPPA class actions are pushing consent banners onto the US internet, why EU-style compliance is no magic pill, and how a working browser-level opt-out could beat the opt-in regime at its own game.
readMay 12, 2025 · Medium
Consent or Pay in the EU: a timeline
A visual timeline (2016 to Q2 2025) charting how Meta, publishers, EU supervisory authorities, the CJEU, EU law and the EU Commission arrived at the consent-or-pay standoff.
readMay 12, 2025 · Medium
How the Digital Content Directive will break the GDPR
The friction created when the Digital Content Directive lets consumers pay for services with personal data while the GDPR still governs consent and its withdrawal.
readMarch 9, 2025 · Medium
Daniel Solove: On Privacy and Technology
A Masters of Privacy conversation with Professor Daniel J. Solove on the secrecy paradigm, privacy torts, private rights of action, and the fiction of consent.
readFebruary 1, 2025 · Privacy Laws & Business International Report 193 · PDF
Avoiding the scope of the ePrivacy Directive in advertising
How the EDPB's 2024 guidelines on Article 5(3) push advertisers toward server-side processing and AI-driven anonymisation, and what each escape route actually holds.
readOctober 2, 2024 · Medium
P.S.R. Los Angeles 2024: Vendor Audits; My Health, My Data
Session notes from the IAPP's Privacy, Security, Risk 2024 conference: Washington's My Health My Data Act, third-party vendor audits, and DPA negotiation in practice.
readSeptember 3, 2024 · Medium
Nobody was ready for the Privacy Sandbox, but deprecating cookie banners is long overdue
Why no stakeholder trusted Google's Privacy Sandbox, what shelving third-party cookie deprecation really means, and why a single persistent choice could finally kill consent banners.
readJune 6, 2024 · Medium
Some takeaways from PEPR'24 (USENIX Conference on Privacy Engineering Practice and Respect)
Talk-by-talk takeaways from USENIX PEPR 2024: synthetic data, differential privacy, PET combinations, DSAR usability, consent management, and machine unlearning.
readMay 27, 2023 · Medium
5 negative, unintended consequences of the GDPR on its 5th anniversary
Five ways the GDPR has backfired, from hampering competition to blurred controller/processor lines and under-delivered data subject rights.
read