Building a scalable v
endor assessment process sounds straightforward—until you’re dealing with 50,000+ vendors across 40+ countries.In this episode,
Natalija Bitiukova (Head of Data Protection & Digital Law at Carlsberg) shares how her team tackled this challenge in practice, moving beyond fragmented systems and “paper compliance” to a more operational, scalable approach.We discuss:
- The pitfalls of running privacy and security assessments separately
- Why most vendor assessments fail after the questionnaire stage
- How to simplify assessments for real users (not lawyers)
- The importance of data quality and realistic resourcing
- Change management in large, decentralized organisations
- Getting leadership buy-in by framing compliance as a business issue
A practical conversation for anyone working on vendor risk,
GDPR,
NIS2, or scaling compliance processes.
About the podcast:
Practical Privacy explores how privacy and security teams solve real-world challenges at scale.
Brought to you by TrustWorks https://www.trustworks.io/