
← Practical Privacy with Orla Dormer12 mei · 8 min
Building a Scalable Vendor Assessment Process (GDPR & NIS2) | Natalija Bitiukova
Building a scalable vendor assessment process sounds straightforward—until you’re dealing with 50,000+ vendors across 40+ countries.In this episode, Natalija Bitiukova (Head of Data Protection & Digital Law at Carlsberg) shares how her team tackled this challenge in practice, moving beyond fragmented systems and “paper compliance” to a more operational, scalable approach.We discuss:
The pitfalls of running privacy and security assessments separatelyWhy most vendor assessments fail after the questionnaire stageHow to simplify assessments for real users (not lawyers)The importance of data quality and realistic resourcingChange management in large, decentralized organisationsGetting leadership buy-in by framing compliance as a business issueA practical conversation for anyone working on vendor risk, GDPR, NIS2, or scaling compliance processes.
About the podcast:
Practical Privacy explores how privacy and security teams solve real-world challenges at scale.
Brought to you by TrustWorks https://www.trustworks.io/
📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.
🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at https://www.trustworks.io/