

Former AI Act negotiator Laura Caroli on the proposed EU Digital Omnibus for AI
17/12/2025 | 49 min
On November 19, the European Commission unveiled two major omnibus packages as part of its European Data Union Strategy. One package proposes several changes to the EU General Data Protection Regulation, while the other proposes significant changes to the recently minted EU AI Act, including a proposed delay to the regulation of so-called high-risk AI systems. Laura Caroli was a lead negotiator and policy advisor to AI Act co-rapporteur Brando Benifei and was immersed in the high-stakes negotiations leading to the AI regulation. She is also a former senior fellow at the Center for Strategic and International Studies, but recently moved back to Brussels during a time of major complexity in the EU. IAPP Editorial Director Jedidiah Bracy caught up with Caroli to discuss her views on the proposed changes to the AI Act in the omnibus package and how she thinks the negotiations will play out. Here's what she had to say.

'Privacy, Please!' Lorrie Cranor on why she wrote a privacy book for 4-to-6-year-olds
12/12/2025 | 25 min
Lorrie Cranor has long been a leader in the privacy space. As Director and Bosch Distinguished Prof. in Security and Privacy Technologies at Carnegie Mellon's CyLab Security and Privacy Institute, Prof. Cranor is on the cutting edge of usable privacy and security. Her work has influenced researchers to view privacy as a fundamental design standard rather than an abstract ideal and has helped reshape the technology field with more than 200 co-authored research papers on online privacy and security. She has also served as chief technologist at the US Federal Trade Commission and co-founded Wombat Security Technologies, among many other initiatives. Much of her work has focused on understanding how people interact with digital systems and where those systems failed. But, Prof. Cranor is also a mom and has raised three children. She has published new, illustrated book, called Privacy Please!, which Is geared for children aged 4-6, to help them and their parents understand what privacy means and why it matters. IAPP Editorial Director Jedidiah Bracy caught up with Prof. Cranor to discuss her new book, what inspired it, and how this book can help children develop a sense of privacy, autonomy and expression. We also discuss some of the broader children's privacy issues that are emerging in jurisdictions around the world, including through social media bans and age verification laws. Here's what she had to say.

EU data protection enforcement and guidance: A discussion with EDPB Chair Anu Talus
20/11/2025 | 34 min
Anu Talus was elected Chair of the European Data Protection Board in May of 2023. The EDPB, which was established in 2018, ensures that the EU General Data Protection Regulation and Data Protection Law Enforcement Directive are consistently applied in the EU. It also provides general GDPR guidance, adopts findings to ensure the GDPR is implemented consistently across member nations, advises the European Commission on data protection matters, and encourages DPAs to work together. In other words, leading the EDPB is no small task, especially in an increasingly complex digital marketplace during the dawn of the AI Era. While here in Brussels, IAPP Editorial Director Jedidiah Bracy sat down with Chair Talus during an especially significant week in EU data protection on the eve of the release of the EU's Digital Omnibus package, which proposes to amend parts of the GDPR and other EU digital regulations. In this wide-ranging conversation, Bracy and Talus discuss the EDPB's priorities and work in these transformative times.

Guest pod: Alex LaCasse talks AI governance with Brenda Leong and Andrew Burt
07/11/2025 | 27 min
As artificial intelligence continues to coalesce in the modern economy, AI governance only grows in significance. Brenda Leong, director of ZwillGen's AI division, and Andrew Burt, CEO of Luminos, have long been on the front lines of AI's emergence and busy helping organizations navigate this space. In a first for The Privacy Advisor Podcast, we're featuring a guest host, my colleague Alex LaCasse, a staff writer here for the IAPP. LaCasse has been covering compliance technology for the IAPP in recent years and recently caught up with Leong and Burt to learn more about their work in AI governance and the strategies and tools they leverage to help companies maintain customer trust.

Personal data defined? Ulrich Baumgartner on the implications of the CJEU's SRB ruling
10/10/2025 | 44 min
On 4 Sept., the Court of Justice of the European Union gave its highly anticipated decision in the EDPS v. SRB case. In its landmark ruling, the CJEU clarified the definition of personal data under the EU General Data Protection Regulation, and, in essence, the scope of EU data protection law. For Ulrich Baumgartner, a partner at Baumgartner Baumann and IAPP Country Leader for the DACH region, the ruling demonstrates a continued "relative approach" by the court, but it also provides a significant clarification against what he believes has been an "absolutist" approach by the European Data Protection Supervisor and other EU data protection authorities. Though the ruling provides important clarity for personal data, pseudonymity and anonymity, it also raises other questions. Either way, there are concrete takeaways for data protection professionals. IAPP Editorial Director Jedidiah Bracy recently caught up with Baumgartner to discuss the implications of the ruling, including what it can mean for the Data Act, data processing agreements and more.



The Privacy Advisor Podcast