Publications

Selected writing

Articles by Sergio Maldonado on privacy, data protection, AI governance and the future of legal practice.

January 29, 2026 · LinkedIn

Legal AI vs. AI-native law firms

Why the truly AI-native law firm serves AI-native customers and treats AI as infrastructure, rather than bolting Legal AI products onto legacy workflows.

read

January 25, 2026 · LinkedIn

Combining Privacy Protection with a Smooth Internet Browsing Experience Through Built-in Opt-Out Signals

A comparative EU/UK-US analysis of built-in browser opt-out signals (GPC, MyTerms, the Digital Omnibus) and whether they can finally replace consent banners.

read

November 19, 2025 · PrivacyCloud

Accountability and third-party vetting in the age of wild automation

Why security certifications and cookie-cutter compliance paperwork no longer suffice for vetting data processors, and how AI-driven automation rewards vendors that genuinely practice Privacy by Design.

read

November 17, 2025 · LinkedIn

The US internet is falling prey to the consent-banner plague. A more effective opt-out system will soon deliver greater agency

How CIPA and VPPA class actions are pushing consent banners onto the US internet, why EU-style compliance is no magic pill, and how a working browser-level opt-out could beat the opt-in regime at its own game.

read

May 12, 2025 · Medium

Consent or Pay in the EU: a timeline

A visual timeline (2016 to Q2 2025) charting how Meta, publishers, EU supervisory authorities, the CJEU, EU law and the EU Commission arrived at the consent-or-pay standoff.

read

May 12, 2025 · Medium

How the Digital Content Directive will break the GDPR

The friction created when the Digital Content Directive lets consumers pay for services with personal data while the GDPR still governs consent and its withdrawal.

read

March 9, 2025 · Medium

Daniel Solove: On Privacy and Technology

A Masters of Privacy conversation with Professor Daniel J. Solove on the secrecy paradigm, privacy torts, private rights of action, and the fiction of consent.

read

February 1, 2025 · Privacy Laws & Business International Report 193 · PDF

Avoiding the scope of the ePrivacy Directive in advertising

How the EDPB's 2024 guidelines on Article 5(3) push advertisers toward server-side processing and AI-driven anonymisation, and what each escape route actually holds.

read

October 2, 2024 · Medium

P.S.R. Los Angeles 2024: Vendor Audits; My Health, My Data

Session notes from the IAPP's Privacy, Security, Risk 2024 conference: Washington's My Health My Data Act, third-party vendor audits, and DPA negotiation in practice.

read

September 3, 2024 · Medium

Nobody was ready for the Privacy Sandbox, but deprecating cookie banners is long overdue

Why no stakeholder trusted Google's Privacy Sandbox, what shelving third-party cookie deprecation really means, and why a single persistent choice could finally kill consent banners.

read

June 6, 2024 · Medium

Some takeaways from PEPR'24 (USENIX Conference on Privacy Engineering Practice and Respect)

Talk-by-talk takeaways from USENIX PEPR 2024: synthetic data, differential privacy, PET combinations, DSAR usability, consent management, and machine unlearning.

read

May 27, 2023 · Medium

5 negative, unintended consequences of the GDPR on its 5th anniversary

Five ways the GDPR has backfired, from hampering competition to blurred controller/processor lines and under-delivered data subject rights.

read