Practical Privacy with Orla Dormer

Building a Scalable Vendor Assessment Process (GDPR & NIS2) | Natalija Bitiukova

8 min · 12. maj 2026
episode Building a Scalable Vendor Assessment Process (GDPR & NIS2) | Natalija Bitiukova cover

Description

Building a scalable vendor assessment process sounds straightforward—until you’re dealing with 50,000+ vendors across 40+ countries.In this episode, Natalija Bitiukova (Head of Data Protection & Digital Law at Carlsberg) shares how her team tackled this challenge in practice, moving beyond fragmented systems and “paper compliance” to a more operational, scalable approach.We discuss: * The pitfalls of running privacy and security assessments separately * Why most vendor assessments fail after the questionnaire stage * How to simplify assessments for real users (not lawyers) * The importance of data quality and realistic resourcing * Change management in large, decentralized organisations * Getting leadership buy-in by framing compliance as a business issue A practical conversation for anyone working on vendor risk, GDPR, NIS2, or scaling compliance processes. About the podcast: Practical Privacy explores how privacy and security teams solve real-world challenges at scale. Brought to you by TrustWorks https://www.trustworks.io/ [https://www.trustworks.io/]

Comments

0

Be the first to comment

Sign up now and become a member of the Practical Privacy with Orla Dormer community!

Get Started

1 month for 9 kr.

Then 99 kr. / month · Cancel anytime.

  • Podcasts kun på Podimo
  • 20 lydbogstimer pr. måned
  • Gratis podcasts

All episodes

13 episodes

episode How to be a digital enabler without compromising compliance | Naureen Hussain artwork

How to be a digital enabler without compromising compliance | Naureen Hussain

Traditional privacy teams were never designed for agile digital transformation. In this episode of Practical Privacy, Orla Dormer speaks with Naureen Hussain, Founder of Luminate Advisers and former DPO at Virgin Media, about how privacy leaders can support rapid digital transformation without compromising compliance or creating unacceptable risks. Naureen shares why adding more privacy resources initially failed, how her team embedded into product and digital workflows, and why adopting a product mindset fundamentally changed the way the privacy function operated. The conversation explores cross-functional collaboration, agile delivery, privacy by design, and the importance of experimentation and user-centric compliance processes.

Yesterday9 min
episode How privacy teams can deliver proactive change | Ben Westwood artwork

How privacy teams can deliver proactive change | Ben Westwood

In Episode 12 of Practical Privacy, Orla Dormer is joined by Ben Westwood, Head of Compliance and DPO at the Motor Insurers’ Bureau, to discuss one of the biggest challenges facing privacy and compliance professionals today: How do you deliver proactive change when reactive work never stops? Ben shares how structured annual planning, maturity assessments, risk registers, and alignment with business objectives have transformed the way his team delivers privacy and compliance outcomes. We discuss: * Why every privacy team should have a strategic plan * How to balance proactive vs reactive work * Using maturity assessments to prioritise effort * Connecting privacy goals to wider business objectives * Getting executive buy-in for compliance initiatives * The importance of reviewing and demonstrating progress A practical conversation packed with actionable ideas for privacy leaders, DPOs, and compliance professionals trying to create meaningful change inside busy organisations.

21. maj 202611 min
episode Building a Scalable Vendor Assessment Process (GDPR & NIS2) | Natalija Bitiukova artwork

Building a Scalable Vendor Assessment Process (GDPR & NIS2) | Natalija Bitiukova

Building a scalable vendor assessment process sounds straightforward—until you’re dealing with 50,000+ vendors across 40+ countries.In this episode, Natalija Bitiukova (Head of Data Protection & Digital Law at Carlsberg) shares how her team tackled this challenge in practice, moving beyond fragmented systems and “paper compliance” to a more operational, scalable approach.We discuss: * The pitfalls of running privacy and security assessments separately * Why most vendor assessments fail after the questionnaire stage * How to simplify assessments for real users (not lawyers) * The importance of data quality and realistic resourcing * Change management in large, decentralized organisations * Getting leadership buy-in by framing compliance as a business issue A practical conversation for anyone working on vendor risk, GDPR, NIS2, or scaling compliance processes. About the podcast: Practical Privacy explores how privacy and security teams solve real-world challenges at scale. Brought to you by TrustWorks https://www.trustworks.io/ [https://www.trustworks.io/]

12. maj 20268 min