
Masters of Privacy · 2026-06-21 · 26 min
Key moments - from our scoring
Substance score
54 / 100
Five dimensions, 20 points each
Eduardo Ustaran, global co-head of privacy and cybersecurity at Hogan Lovells, maps the collision between privacy regulation and AI in 2026, examining why the UK and EU are now diverging sharply on automated decision-making despite their shared regulatory heritage. The conversation unpacks the shift from Article 22 of the GDPR - which effectively prohibits fully automated decisions on significant life matters - to the UK's reformed Article 22A-C, which permits such decisions subject only to safeguards when non-special-category data is involved. Ustaran discusses the philosophical challenge of regulating every AI decision versus only those affecting fundamental freedoms (credit scoring, education, healthcare, financial services), and why explainability requirements may be unrealistic as agentic AI becomes more prevalent. The interview also addresses how international data transfer concerns have evolved from post-Snowden data security issues to geopolitical tensions around digital sovereignty, technological protectionism, and AI control - tensions requiring cross-border cooperation mechanisms like the Council of Europe's principles frameworks. For privacy officers, legal teams, and compliance leaders navigating EU-UK divergence, this episode clarifies the regulatory gap emerging on automated decision-making and the broader shift from data protection to data protectionism.
Under EU law (Article 22 GDPR), fully automated decisions with significant life effects are essentially prohibited subject to exemptions. Under UK law (Article 22A-C), such decisions are now permitted for normal personal data if certain safeguards are in place - a shift from prohibition to permissive regulation with conditions.
Ustaran argues that regulating every AI decision is unrealistic as agentic AI becomes the norm; instead, the focus should be on decisions that truly affect fundamental rights (education, finance, health) while acknowledging that not all decisions made by machines can be explained by humans.
The concern has shifted from protecting data security during international flows to controlling government access to data (post-SCHREMS cases) and now to digital sovereignty and technological protectionism - moving from data protection to preventing economic and technological dependence on foreign governments.
Ustaran mentions initiatives like cross-border privacy rules and Council of Europe principles frameworks designed to enable jurisdictions to cooperate on AI safety and harm mitigation, even as protectionist pressures increase.
Rather than disappearing, lawyers must emphasize skills that AI cannot replicate: helping others, building bridges between stakeholders, relating to and understanding human context, and solving problems where regulators and companies have different outcomes - making themselves relevant through human-centered value rather than pure legal knowledge delivery.
Our reviewer’s read on each dimension, with quotes from the episode.
There are genuine substantive legal insights - particularly the UK Article 22 to 22A-C shift and the evolution from data protection to data protectionism - but these are interspersed with significant filler, generic AI commentary, and a wholly unsubstantive final segment on lawyer job displacement. The episode rewards patience but doesn't sustain a high density throughout.
In the UK, it's no longer prohibited unless we're talking of this special category data. But for normal personal data, we've moved from what is effectively a prohibition to a situation where it is permitted subject to certain safeguards.
automated decision-making was already regulated by the original 1995 Data Protection Directive
The 'data protection to data protectionism' reframe is a crisp and useful coinage, and the reminder that ADM regulation is 30 years old cuts against naive novelty claims about AI, but most of the episode's other positions - regulate important decisions, humans in the loop are philosophically contested, global cooperation is needed - are well-circulated takes in privacy circles rather than genuinely contrarian arguments.
we've gone from data protection to almost data protectionism and technological protectionism
some of these things are not explainable by humans because machines are making the decisions in a way that perhaps humans cannot explain
Eduardo Ustaran is legitimately among the most senior practising privacy lawyers globally - global co-head of Hogan Lovells' practice, directly involved in EU data protection framework development, and actively working on cross-jurisdictional transfer mechanisms. This is a genuine practitioner-at-scale, not a conference circuit thought leader, though the transcript does not fully exploit that depth.
he is global co-head of the Hogan-Lovall's privacy and cybersecurity practice, widely recognized as one of the world's leading privacy and data protection lawyers and thought leaders. With over 30 years of experience
I am working quite actively in still securing mechanisms and opportunities for global companies and global organizations to operate in that way
The episode earns its points through precise legal citations - Article 22 vs 22A-C, the 1995 Directive, Schufa, SRAM 1/2, DPF, cross-border privacy rules - but stops well short of concrete case outcomes, client data, enforcement numbers, or decision timelines; it stays comfortably at the level of legal concepts rather than operational evidence.
Article 22 of the GDPR which in the UK has become Article 22A to C
I look at create scoring, for example, the Schufe scenario in the EU or create scoring in the US
The host is clearly expert - references Schufa, SRAM cases, and the UK DUAA by name - and frames reasonably sharp comparative questions, but there is no genuine pushback or pressure-testing of the guest's positions, the final lawyer-displacement question is generic, and several questions are long, leading, and partially self-answering.
do you think that there really is a long-term viability for humans in the loop and explainability for every single use of AI within, again, for example, what's in the EU, everything that affects our freedoms and fundamental rights?
are lawyers as we know them poised to disappear in the face of ever improving A models?
Computed from the transcript - who did the talking, and the words that came up most.
Where is the privacy-AI convergence taking us in 2026? How different is the UK’s new approach to automated decision making (ADMT)? Is AI pushing young lawyers out of the profession? Eduardo Ustaran is global co-head of the Hogan Lovells Privacy and Cybersecurity practice, widely recognized as one of the world’s leading privacy and data protection lawyers and thought leaders. With over 30 years of experience, our guest advises multinationals and governments around the world on the adoption of privacy and cybersecurity strategies and policies. Eduardo has been involved in the development of the EU data protection framework and was listed by Politico as the most prepared individual in its ‘GDPR power matrix’. Eduardo obtained his JD from Universidad de Navarra and an LLM in European and International Trade Law from the University of Leicester. This is our 40th and last episode in the current (10th) season. We will be back in a few weeks. Have a great summer!
Transcribed and scored by The B2B Podcast Index.
Okay, today we're closing our season with an interview with Eduardo Ustran, who I've known for some 25 years and who many of you will be familiar with in the context of the IAPP and other global privacy law fora. Today we'll review the current status of privacy in 2026 with a focus on the privacy AI convergence and automated decision-making, with the diverging paths that we can now appreciate between the EU and the UK at a time when California has brand-new ADMT rules that apply to fully automated decisions.
So it's a good moment for some comparative law. As for Eduardo, he is global co-head of the Hogan-Lovall's privacy and cybersecurity practice, widely recognized as one of the world's leading privacy and data protection lawyers and thought leaders. With over 30 years of experience, he advises multinationals and governments around the world on the adoption of privacy and cybersecurity strategies and policies, and he has been involved in the development of the EU Data Protection Framework and also was listed by Politico as one of the most, or rather as the most prepared individual in its GDPR power matrix.
The last thing I'll tell you is that we recorded this in a noisy place, so it feels more like a live recording and you're familiar with those as well and that has its charm as well with background laughs and pop-like sounds so please bear with us here we go now and we will be back in a few weeks enjoy the summer and stay tuned hello thanks for joining me it's a pleasure to be here and i'm very happy to to join you and and share some food for thought. Fantastic. I'll tell you this, it's been six years since the last time we recorded, which was during COVID.
Really? You know? Wow. The world has changed just a little bit in six years.
Yes. It has. And privacy has too. Yeah.
So I wanted to start with this, which is what kind of key factors do you think give us a good understanding of where we are in terms of either privacy or the convergence between privacy and AI in 2026. Excellent. Well, the timing, I think, is perfect in a way for me to be sharing this with you, not least because literally a few weeks ago we had our team strategy day. And one of the things that we were discussing and debating was precisely this.
What is the changing landscape that we are seeing right now in terms of opportunities and also the challenges we see. And there are three or four things out there that are happening right now that are very, very relevant to our world. One is that we're probably seeing a new generation of what I would call previous intrusions. So previous intrusions are the kind of issues that generate regulatory scrutiny, new policies, new laws.
And there are things like, for example, automated decision making or indeed AI more generally, but also biometric and facial recognition. These are developments that are happening right here, right now, that generate this additional level of scrutiny. We also have a different level of cybersecurity risk that we are seeing with what we have witnessed in just the last few months around the new AI tools that are potentially solving the cybersecurity issues, but also exposing new vulnerabilities.
At the same time, of course, we live in a very geopolitical, uncertain world, and that itself affects the world of data, the world of digital sovereignty. And of course, linked to that is the new laws or lack of them in a way around AI specifically. And in Europe, we see things changing from more regulation to slightly less regulation, but still concerns about not enough regulation. So all of these things are happening at the same time and again generating all these opportunities, at least risk areas for us to be involved in.
So if we think that we focus on automated decision making, you recently wrote or your team published this analysis about the divergence between the UK because of the UK reforms and the DUAA and the EU in terms of automated decision making and how the UK could be departing from Article 22. What would you say about that? Yeah, that is a very interesting development. And it's kind of a nerdy development because what we have seen, of course, is that the UK following the tragic departure in a way from the EU has looked at how to make the moves of this regulatory independence.
And one of the areas, of course, has been data protection. And different governments have toyed with the idea of reforming the GDPR and impact last year we saw some changes to the UK GDPR. We could debate how extensive, how significant, how diverging these changes are from the EU, but if there is one thing where I see a gap opening in the thinking between the lower citizens today in the EU and the new law in the UK is automated decision making in the context of significant decisions.
So this is what is governed by, for the connoisseurs, this is what is governed by Article 22 of the GDPR which in the UK has become Article 22A to C. And then that idea that under EU law decision making made by machines which again we can talk about how much of that is happening right now but I can only tell but I think we would probably all agree that is happening more and more But that type of decision making, to the extent that it has a significant effect on someone's life, that is essentially almost prohibited in a way, subject to some exemptions, but in principle prohibited by EU law.
In the UK, it's no longer prohibited unless we're talking of this special category data. But for normal personal data, we've moved from what is effectively a prohibition to a situation where it is permitted subject to certain safeguards. So that slight difference in approach is in itself a very significant gap in the way both types of jurisdictions are regulating this issue. Okay.
And it feels like there's already that disparity and there's always going to be that dilemma as to how far do we take AI-specific regulation and how far do we take privacy regulation that affects AI? And it seems like they really, really are converging. So right now we are in transition, I would say, in the sense that we have a range of laws that have been in the Saturday books for in some cases for many years. and certainly in relation to data protection law, we have a history of decades, perhaps, of laws dealing with the use of data.
And, in fact, automated decision-making is something people forget or people may not be old enough to know, is that automated decision-making was already regulated by the original 1995 Data Protection Directive. So we can go back 30 years and say that automated decision was regulated. But once we see that today, and those laws are still effective, obviously, we are in the process of, I guess, passing or adopting new legislation. and what we have seen over the past two or three years is countries hesitating about how to approach the whole idea of regulating AI and whether to just leave it as it is and say, well, let's just let the existing laws take care of this issue or say, well, even if we still allow existing laws to regulate AI, there will be gaps and therefore new regulation is needed.
And as I say, countries are grappling with that challenge. And there seem to be a couple of camps on that. Those that say, well, leave the stuff alone. Don't regulate it until we know better what we're talking about.
And the camp that says, look, we don't want to be too late regulating. And therefore, we should look at this now. All right. So before we go into the geopolitics of it, which is very interesting as well, that divide.
But I really think that there's certain things where it feels like there's a clear imbalance and we do need to protect people. I look at create scoring, for example, the Schufe scenario in the EU or create scoring in the US, which I find wild the way it works. Wild. I have a terrible experience of how it works.
And I think that there's going to be controls in how data is being collected and used and how automated decisions are made. But then I look at other things and it seems like we're trying, we're resistant. We're trying to make sure that there's a human in the loop for everything. when we are entering a world in which humans are not even present on either side of the equation.
So do you think that there really is a long-term viability for humans in the loop and explainability for every single use of AI within, again, for example, what's in the EU, everything that affects our freedoms and fundamental rights? There will be room for human intervention or at least human responsibility at the end of every single decision. But I think there is something really important that we need to appreciate, which is we are going in the direction of AI and automated decision making becoming the norm in all decisions in the sense that whether they are trivial issues or very important issues, we are going to rely more and more on machines and technology making those decisions for us.
And the whole agentic AI revolution, which again is still in its infancy, is all about that. We're relying on AI not just to tell us what to do, but actually to do things for us. right and therefore uh this becomes slightly philosophical now because the question is do we regulate every single decision made by ai or do we regulate the ones that are truly important and if so how do we differentiate between the two because if we say okay well we can't regulate every single decision we need to regulate just the ones that are really important where do we draw the line on what is important and what is not important i think that the original thinking behind these provisions around automated decision making in in the eu was that it was about those decisions that are truly affecting our lives as individuals in the important things in our lives our education our finances our health our life as a whole but not the day aspects of how we live And I think that is a debate I guess that needs to happen as to how do we apply the law in this context Because if we then decide, okay, there are only certain situations where we need to restrict, I guess, or qualify the lawfulness of automated decision-making by adding a human component to it, then we will be in a better position to be realistic about this rather than say, okay, well, a human always needs to explain things because ultimately some of these things are not explainable by humans because machines are making the decisions in a way that perhaps humans cannot explain.
So that is something that we're witnessing right now. Yeah, very good. Okay, so then going into the geopolitics of it, you've been very exposed to everything because you work across the Atlantic. And what's your perspective?
And you've been very present in data transfers and how things have evolved across SRAMS 1, SRAMS 2, DPF. So, and now you see that the U.S. is imposing their own restrictions on bulk data transfers.
How do you see the evolution in terms of geopolitics and that divide? Yeah, it's interesting. If you go back, say, 10, 12 years to when the Snowden disclosures happened and the SRAMS cases started to happen. Until then, it was all about making sure that the entities involving international data flows were securing the data.
With the SRAMS cases, the focus was not so much on what companies could do or those involved in the transfers, but what governments could do and how to control the access to data by government. That was and has been a tense situation for a number of years. Then after the Trends 2 case, as much as an upheaval that caused, we saw a sort of a degree of calm or calmness in this space because that led to work around transferring back assessments and the new set of standard contractor clauses.
And the last few years, because of all the focus on AI, have been relatively calm on the international data transfers point. But about a year ago or so, a year plus ago, the stakes around international data flow became higher because this whole dimension of digital sovereignty entered the scene quite visibly. And what used to be about protecting data when it was flowing around the world has become an issue of protecting the economies of countries and the technology developed by countries and the future that those countries will experience as a result of that development of technology.
So we've gone from data protection to almost data protectionism and technological protectionism. And that is what we are seeing right now. And that is somehow at odds with the world in which we live, that whether globalization is trendy or not anymore, the reality is that connectivity, global connectivity, is still happening and will continue to happen. And therefore, we still need to reconcile this idea of greater geopolitical restrictions and things like data flows and technology exports and technology use with the ability to operate globally as we want to operate.
So, I think that is what is creating the current tensions. And that is, again, a sort of work in practice exercise for many organizations. Yeah, I wonder what you're hoping for. Because at the European level, there's the digital sovereignty, as you're saying, there's that fear that now is exacerbated.
Now it's become even more important because of the fear of a kill switch on AI that is controlled by the US government. The US is also very worried about trade imbalances and if AI becomes the backbone of the economy everywhere and the development of new models is pretty much under the control of a US government. I understand that the EU is looking for not just sovereignty in terms of data, but also some sort of future for even the very viability of businesses. So how do you see that play out?
How would you like this thing to play out based on what you see businesses doing, Europeans doing? How do you see that? Well, maybe what I'm hoping, it's not only what I'm hoping for, but what I'm working on in the sense that I am working quite actively in still securing mechanisms and opportunities for global companies and global organizations to operate in that way. for the benefit of users and individuals and customers, obviously, of those organizations.
So what that actually means in practice is that whilst I can see why, particularly in Europe where I am, there is a degree of fear around relying so blindly on technology that is controlled by one particular country that may be more antagonistic than it has been in the past. The reality is that ways to collaborate across jurisdictions to ensure that technology can be used across jurisdictions and the issues that that technology raises can also be addressed across jurisdictions.
Because the thing is not only you cannot isolate the technology within a set of borders What you can certainly not do is isolate the issues and the challenges and the risk and the potential harm And therefore in a world that is connected as in the world in which we operate, those harms, those global harms are real. And that requires cooperation, that requires arrangements, and that requires that sort of dialogue. And that's what I'm involved in. And there are initiatives like the cross-border privacy rules or other initiatives more in the context of AI and the Council of Europe is very involved in trying to set a set of principles.
And of course, even mention the US, but the US is not completely immune to the dangers of AI. And they are looking at AI safety as an issue. But it's an issue with which they need to cooperate or in which they need to cooperate with other jurisdictions. So all of that is still happening despite this tendency towards greater protectionism and digital sovereignty.
Okay. And now a last question, as I know you like it. Switching gears entirely, are lawyers as we know them poised to disappear in the face of ever improving A models? What do you think?
First of all, linking AI to the sort of backlash we're seeing against AI, I think there is a sense of a lack of trust on AI, for whatever reasons, but there is a lack of trust. And that in itself is something that regulation itself should deal with, because the way you trust, you get to trust something in this kind of context is by ensuring that it is safe, it is beneficial, it doesn't create or doesn't result in damage. And one of those potential harms is, of course, job losses.
So I think that's something that perhaps needs to be regulated in some way. And it should be possible for people to say, how do we ensure that whilst we help and we sort of support the development of AI as a tool and as something that generates growth and prosperity, it doesn't turn into something that frustrates everyone because not only we no longer have a job to do and a way of generating our own success and prosperity, but actually the implications of that go beyond the financial aspects because a lot of what we do in terms of our own purpose in life is defined by our professional endeavors.
So I think all of that needs to be taken into account. And when I apply that today to our profession and to my own team, perhaps I could say, well, I have the luxury. I've been around for a while. And by the time this really becomes a true threat, I'm retired and enjoying life.
But, of course, first of all, I'm not like that. I'm not thinking that I'm finished with this professional endeavor at all. I enjoy what I do. And not only that, but I want to make sure that those who are where I was 30 years ago can continue to look at this and say, this is something I can devote my brain to and my enthusiasm to and help the world in that way.
So I think it's really important to think about how to make ourselves relevant in the age of AI and how to, in our profession, when we are dealing with these complex legal issues, we are not reduced to something that there is an answer that a computer can provide you with better than your own experience. And that's the end of it, because ultimately our job is to help others. And I think to the extent that we make ourselves more relevant by emphasizing how we can help others, how we can interact with others, how we can relate to others, how we can build bridges between different ways of thinking, how we can sort out problems when regulators are looking for one outcome and companies may be looking for a different outcome, and how can we make those two outcomes possible, and how can we play a significant role in achieving that.
That's where I think the work still is, and how that will evolve is yet to be seen. But I think it's important that we constantly think about that so that not only we continue to be relevant, but actually we continue to do something useful for ourselves and the society at large, I would say. Of course. Well, that's inspiring and motivating.
Thank you, Eduardo. Thank you. My pleasure. Thank you.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.