<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:podcast="https://podcastindex.org/namespace/1.0" xmlns:media="http://search.yahoo.com/mrss/" version="2.0"><channel><title>Practical Privacy with Orla Dormer</title><link>https://www.trustworks.io/</link><description><![CDATA[Practical Privacy is a podcast for <b>privacy professionals</b> who want to understand how privacy and AI governance work in the real world. <br /><br />Hosted by Orla Dormer, the series brings together <b>experienced practitioners to discuss common operational challenges</b>, from scaling GDPR programs and answering data questions internally, to navigating AI governance and legacy tooling constraints.<br /><br />Each episode focuses on practical lessons, honest reflections, and what teams wish they had known earlier. This podcast is designed as a reference for privacy leaders looking to improve how privacy actually operates inside organisations.]]></description><atom:link href="https://www.spreaker.com/show/6856695/episodes/feed" rel="self" type="application/rss+xml"/><language>en</language><category>Business</category><copyright>Copyright TrustWorks</copyright><image><url>https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9cad44d41de53c5acf422f80dbb9d594.jpg</url><title>Practical Privacy with Orla Dormer</title><link>https://www.trustworks.io/</link></image><lastBuildDate>Mon, 14 Sep 2026 12:20:22 +0000</lastBuildDate><itunes:author>Orla Dormer</itunes:author><itunes:owner><itunes:name>TrustWorks</itunes:name><itunes:email>analytics@trustworks.io</itunes:email></itunes:owner><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9cad44d41de53c5acf422f80dbb9d594.jpg"/><itunes:subtitle>Practical Privacy is a podcast for privacy professionals who want to understand how privacy and AI governance work in the real world. 

Hosted by Orla Dormer, the series brings together experienced practitioners to discuss common operational...</itunes:subtitle><itunes:summary><![CDATA[Practical Privacy is a podcast for <b>privacy professionals</b> who want to understand how privacy and AI governance work in the real world. <br /><br />Hosted by Orla Dormer, the series brings together <b>experienced practitioners to discuss common operational challenges</b>, from scaling GDPR programs and answering data questions internally, to navigating AI governance and legacy tooling constraints.<br /><br />Each episode focuses on practical lessons, honest reflections, and what teams wish they had known earlier. This podcast is designed as a reference for privacy leaders looking to improve how privacy actually operates inside organisations.]]></itunes:summary><itunes:category text="Business"/><itunes:explicit>false</itunes:explicit><podcast:guid>dd8d057d-b90d-503a-bf2f-4e2169fcd831</podcast:guid><itunes:type>episodic</itunes:type><item><title>Engage Regulators Before They Come to You | Francisco Matos</title><link>https://www.spreaker.com/episode/engage-regulators-before-they-come-to-you-francisco-matos--73555494</link><description><![CDATA[<br />New cybersecurity regulation like NIS2 is landing differently in every EU country — and a single incident can now trigger separate reports under multiple frameworks. <br /><br />Francisco Matos, Compliance Director at Legora and former Associate General Counsel for Cybersecurity Law at Meta, joins Orla Dormer to explain how his team turned that fragmentation into a proactive regulator engagement strategy: cold outreach, a focused paper that got them invited to present at ENISA in Amsterdam, and lessons on building trust with regulators before you need them.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/73555494</guid><pubDate>Mon, 14 Sep 2026 12:20:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73555494/francisco_alves_de_matos_full_episode.mp3" length="9710582" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>New cybersecurity regulation like NIS2 is landing differently in every EU country — and a single incident can now trigger separate reports under multiple frameworks. 

Francisco Matos, Compliance Director at Legora and former Associate General Counsel...</itunes:subtitle><itunes:summary><![CDATA[<br />New cybersecurity regulation like NIS2 is landing differently in every EU country — and a single incident can now trigger separate reports under multiple frameworks. <br /><br />Francisco Matos, Compliance Director at Legora and former Associate General Counsel for Cybersecurity Law at Meta, joins Orla Dormer to explain how his team turned that fragmentation into a proactive regulator engagement strategy: cold outreach, a focused paper that got them invited to present at ENISA in Amsterdam, and lessons on building trust with regulators before you need them.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></itunes:summary><itunes:duration>607</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9fc8d873f78c055387790ee2f5589a62.jpg"/><itunes:episodeType>full</itunes:episodeType></item><item><title>Building an AI agent governance framework at scale | Monika Tomczak-Górlikowska</title><link>https://www.spreaker.com/episode/building-an-ai-agent-governance-framework-at-scale-monika-tomczak-gorlikowska--73554760</link><description><![CDATA[Orla Dorner is joined by Monika Tomczak-Górlikowska, Group Head of Privacy, Digital &amp; AI Governance at Prosus, to talk about building an agentic AI governance framework at scale. <br /><br />They discuss why traditional governance controls aren't enough once anyone in an organisation can build an AI agent, how to shift from one-off assessments to continuous risk monitoring, and why staying close to high-risk teams like HR and finance is critical as adoption accelerates. <br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a><br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/73554760</guid><pubDate>Thu, 03 Sep 2026 04:55:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/73554760/utf_8_q_monika_tomczak_go_cc_81rlikowska_full_episode_mp3.mp3" length="10321639" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>Orla Dorner is joined by Monika Tomczak-Górlikowska, Group Head of Privacy, Digital &amp;amp; AI Governance at Prosus, to talk about building an agentic AI governance framework at scale. 

They discuss why traditional governance controls aren't enough...</itunes:subtitle><itunes:summary><![CDATA[Orla Dorner is joined by Monika Tomczak-Górlikowska, Group Head of Privacy, Digital &amp; AI Governance at Prosus, to talk about building an agentic AI governance framework at scale. <br /><br />They discuss why traditional governance controls aren't enough once anyone in an organisation can build an AI agent, how to shift from one-off assessments to continuous risk monitoring, and why staying close to high-risk teams like HR and finance is critical as adoption accelerates. <br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a><br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></itunes:summary><itunes:duration>646</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/48fa5af541701a5690611a749b9bbbde.jpg"/><itunes:season>2</itunes:season><itunes:episode>1</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Automating processor RoPAs &amp; proving privacy's business value| Adrien Hug-Korda</title><link>https://www.spreaker.com/episode/automating-processor-ropas-proving-privacy-s-business-value-adrien-hug-korda--72910017</link><description><![CDATA[Keeping a processor Record of Processing Activities up to date is one of the least glamorous—but most critical—operational challenges in privacy. <br /><br />In this episode, Orla Dormer is joined by <b>Adrien Hug-Korda, European Data Protection Board Expert and former Privacy Director at Contentsquare</b>, to discuss how privacy teams can automate processor RoPAs, manage large-scale processing operations, and build compliance processes that continue working as organisations grow. <br /><br />Adrien shares practical lessons from the digital marketing industry, explains how to avoid creating compliance processes that rely on constant manual effort, discusses handling DSRs in cookie-based environments, and offers advice on showing the business value of privacy programmes to leadership. <br /><br />If you're responsible for privacy operations, governance, or compliance at scale, this episode is full of practical ideas you can apply immediately.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/72910017</guid><pubDate>Thu, 06 Aug 2026 11:02:26 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72910017/76c0daef_1e90_43b6_a837_38d960193d49.mp3" length="13276610" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>Keeping a processor Record of Processing Activities up to date is one of the least glamorous—but most critical—operational challenges in privacy. 

In this episode, Orla Dormer is joined by Adrien Hug-Korda, European Data Protection Board Expert and...</itunes:subtitle><itunes:summary><![CDATA[Keeping a processor Record of Processing Activities up to date is one of the least glamorous—but most critical—operational challenges in privacy. <br /><br />In this episode, Orla Dormer is joined by <b>Adrien Hug-Korda, European Data Protection Board Expert and former Privacy Director at Contentsquare</b>, to discuss how privacy teams can automate processor RoPAs, manage large-scale processing operations, and build compliance processes that continue working as organisations grow. <br /><br />Adrien shares practical lessons from the digital marketing industry, explains how to avoid creating compliance processes that rely on constant manual effort, discusses handling DSRs in cookie-based environments, and offers advice on showing the business value of privacy programmes to leadership. <br /><br />If you're responsible for privacy operations, governance, or compliance at scale, this episode is full of practical ideas you can apply immediately.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></itunes:summary><itunes:duration>830</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/df9899be247acb500b479383c89d4933.jpg"/><itunes:season>1</itunes:season><itunes:episode>18</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Operationalising AI governance in a high-growth fintech environment | Taylor Galusha</title><link>https://www.spreaker.com/episode/operationalising-ai-governance-in-a-high-growth-fintech-environment-taylor-galusha--72801269</link><description><![CDATA[<b>What does practical AI governance actually look like day to day in a high-growth FinTech environment?</b><br /><br />In this episode of Practical Privacy, Orla Dormer speaks with <b>Taylor Galusha, Lead Privacy and AI Counsel at Chime</b>, about operationalising AI governance through scalable AI vendor assessments.<br /><br />Taylor explains why manual reviews are difficult to sustain, how robust playbooks can create consistency, and how AI can support the first draft of vendor assessment reviews when given clear guidance, examples, and logic trees.<br /><br />This episode explores how privacy and AI governance teams can move faster, escalate risks more clearly, and build stronger documentation — without removing human judgement from the final decision.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/72801269</guid><pubDate>Thu, 06 Aug 2026 11:02:13 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72801269/taylor_galusha_full_episode.mp3" length="6725518" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>What does practical AI governance actually look like day to day in a high-growth FinTech environment?

In this episode of Practical Privacy, Orla Dormer speaks with Taylor Galusha, Lead Privacy and AI Counsel at Chime, about operationalising AI...</itunes:subtitle><itunes:summary><![CDATA[<b>What does practical AI governance actually look like day to day in a high-growth FinTech environment?</b><br /><br />In this episode of Practical Privacy, Orla Dormer speaks with <b>Taylor Galusha, Lead Privacy and AI Counsel at Chime</b>, about operationalising AI governance through scalable AI vendor assessments.<br /><br />Taylor explains why manual reviews are difficult to sustain, how robust playbooks can create consistency, and how AI can support the first draft of vendor assessment reviews when given clear guidance, examples, and logic trees.<br /><br />This episode explores how privacy and AI governance teams can move faster, escalate risks more clearly, and build stronger documentation — without removing human judgement from the final decision.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></itunes:summary><itunes:duration>421</itunes:duration><itunes:keywords>ai,aigovernance,governance</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/a4504977c3ec64454c5455a94a068640.jpg"/><itunes:season>1</itunes:season><itunes:episode>17</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Why privacy programmes fail to scale | Cristina Costache</title><link>https://www.spreaker.com/episode/why-privacy-programmes-fail-to-scale-cristina-costache--72577081</link><description><![CDATA[Most organisations have privacy policies. Far fewer have privacy capabilities that actually scale. <br /><br />In this episode, <b>Cristina Costache, DPO &amp; CISO at Noventiq</b>, explores one of the most persistent challenges facing privacy teams: transforming compliance from a documentation exercise into an operational capability embedded within the organisation.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/72577081</guid><pubDate>Thu, 02 Jul 2026 05:55:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72577081/cristina_costache_full_episode.mp3" length="7684734" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>Most organisations have privacy policies. Far fewer have privacy capabilities that actually scale. 

In this episode, Cristina Costache, DPO &amp;amp; CISO at Noventiq, explores one of the most persistent challenges facing privacy teams: transforming...</itunes:subtitle><itunes:summary><![CDATA[Most organisations have privacy policies. Far fewer have privacy capabilities that actually scale. <br /><br />In this episode, <b>Cristina Costache, DPO &amp; CISO at Noventiq</b>, explores one of the most persistent challenges facing privacy teams: transforming compliance from a documentation exercise into an operational capability embedded within the organisation.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></itunes:summary><itunes:duration>481</itunes:duration><itunes:keywords>privacy,privacymanagement</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/652d1b1b3409e79509584408db176392.jpg"/><itunes:season>1</itunes:season><itunes:episode>16</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Scaling ROPA, PIAs &amp; privacy documentation across 1,000+ applications | Aaron Mendelsohn</title><link>https://www.spreaker.com/episode/scaling-ropa-pias-privacy-documentation-across-1-000-applications-aaron-mendelsohn--72364524</link><description><![CDATA[How do you complete privacy documentation across hundreds of teams and more than 1,000 applications without overwhelming the business? In this episode of Practical Privacy, Orla Dormer is joined by <b>Aaron Mendelsohn, Director and Senior Privacy Officer at The LEGO Group</b>, to discuss how his team rebuilt and scaled privacy documentation across a large global organisation. <br /><br />Aaron explains how they combined privacy technology, risk-based prioritisation, and extensive team enablement to successfully document over 1,000 applications within a 12-month period. He also shares why privacy professionals need to move beyond policy writing and spend more time understanding how product and engineering teams actually work. <br /><br />This episode covers: <br />• Scaling ROPAs, PIAs and privacy documentation programmes<br />• Using risk-based approaches to focus effort where it matters most<br />• The role of change management in privacy success<br />• Building stronger relationships with internal stakeholders<br />• Creating sustainable compliance processes that teams will actually use<br />• Future opportunities to combine privacy, AI and broader compliance assessments <br /><br />A practical conversation for privacy leaders, DPOs and compliance professionals looking to improve documentation processes without creating unnecessary friction for the business.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/72364524</guid><pubDate>Tue, 23 Jun 2026 05:50:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72364524/aaron_mendelsohn_full_episode.mp3" length="10322475" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>How do you complete privacy documentation across hundreds of teams and more than 1,000 applications without overwhelming the business? In this episode of Practical Privacy, Orla Dormer is joined by Aaron Mendelsohn, Director and Senior Privacy Officer...</itunes:subtitle><itunes:summary><![CDATA[How do you complete privacy documentation across hundreds of teams and more than 1,000 applications without overwhelming the business? In this episode of Practical Privacy, Orla Dormer is joined by <b>Aaron Mendelsohn, Director and Senior Privacy Officer at The LEGO Group</b>, to discuss how his team rebuilt and scaled privacy documentation across a large global organisation. <br /><br />Aaron explains how they combined privacy technology, risk-based prioritisation, and extensive team enablement to successfully document over 1,000 applications within a 12-month period. He also shares why privacy professionals need to move beyond policy writing and spend more time understanding how product and engineering teams actually work. <br /><br />This episode covers: <br />• Scaling ROPAs, PIAs and privacy documentation programmes<br />• Using risk-based approaches to focus effort where it matters most<br />• The role of change management in privacy success<br />• Building stronger relationships with internal stakeholders<br />• Creating sustainable compliance processes that teams will actually use<br />• Future opportunities to combine privacy, AI and broader compliance assessments <br /><br />A practical conversation for privacy leaders, DPOs and compliance professionals looking to improve documentation processes without creating unnecessary friction for the business.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></itunes:summary><itunes:duration>646</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/38054da1721666c942666b71196d4434.jpg"/><itunes:season>1</itunes:season><itunes:episode>15</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Enhancing privacy, security &amp; compliance without slowing business growth | Fred Descloux</title><link>https://www.spreaker.com/episode/enhancing-privacy-security-compliance-without-slowing-business-growth-fred-descloux--72342468</link><description><![CDATA[In this episode of Practical Privacy, Orla Dormer is joined by Fred Descloux, privacy, security, and governance leader, to discuss how organisations can align engineering, security, privacy, and compliance<b> in fast-moving environments where execution speed is critical</b>. Drawing on his experience in highly regulated industries, Fred shares why traditional compliance approaches often create friction, bottlenecks, and what he describes as "compliance theatre"—generating documentation without meaningfully reducing risk.<br /><br />Together they explore how to:<br />• Embed privacy and security directly into engineering workflows<br />• Move away from compliance as a gatekeeping function<br />• Focus on outcomes rather than perfection<br />• Build scalable operating models that support growth<br />• Make privacy and security everyone's responsibility<br />• Avoid creating bottlenecks while maintaining strong controls<br />• Prepare for audits through operational excellence rather than audit-driven processes<br />• Balance business agility with regulatory expectationsA practical conversation for privacy professionals, security leaders, compliance teams, and anyone trying to support innovation without compromising governance.<br /><br />🎧 Follow Practical Privacy for more real-world lessons from privacy, security, and compliance leaders.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/72342468</guid><pubDate>Thu, 11 Jun 2026 05:15:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72342468/fred_descloux_full_episode.mp3" length="12026494" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>In this episode of Practical Privacy, Orla Dormer is joined by Fred Descloux, privacy, security, and governance leader, to discuss how organisations can align engineering, security, privacy, and compliance in fast-moving environments where execution...</itunes:subtitle><itunes:summary><![CDATA[In this episode of Practical Privacy, Orla Dormer is joined by Fred Descloux, privacy, security, and governance leader, to discuss how organisations can align engineering, security, privacy, and compliance<b> in fast-moving environments where execution speed is critical</b>. Drawing on his experience in highly regulated industries, Fred shares why traditional compliance approaches often create friction, bottlenecks, and what he describes as "compliance theatre"—generating documentation without meaningfully reducing risk.<br /><br />Together they explore how to:<br />• Embed privacy and security directly into engineering workflows<br />• Move away from compliance as a gatekeeping function<br />• Focus on outcomes rather than perfection<br />• Build scalable operating models that support growth<br />• Make privacy and security everyone's responsibility<br />• Avoid creating bottlenecks while maintaining strong controls<br />• Prepare for audits through operational excellence rather than audit-driven processes<br />• Balance business agility with regulatory expectationsA practical conversation for privacy professionals, security leaders, compliance teams, and anyone trying to support innovation without compromising governance.<br /><br />🎧 Follow Practical Privacy for more real-world lessons from privacy, security, and compliance leaders.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></itunes:summary><itunes:duration>752</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/be67de50c39687091ef94116bc4e1726.jpg"/><itunes:season>1</itunes:season><itunes:episode>14</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>How to be a digital enabler without compromising compliance | Naureen Hussain</title><link>https://www.spreaker.com/episode/how-to-be-a-digital-enabler-without-compromising-compliance-naureen-hussain--72019339</link><description><![CDATA[Traditional privacy teams were never designed for agile digital transformation.<br />In this episode of Practical Privacy, Orla Dormer speaks with <b>Naureen Hussain, Founder of Luminate Advisers and former DPO at Virgin Media,</b> about how privacy leaders can support rapid digital transformation without compromising compliance or creating unacceptable risks.<br /><br />Naureen shares why adding more privacy resources initially failed, how her team embedded into product and digital workflows, and why adopting <b>a product mindset fundamentally changed the way the privacy function operated</b>. The conversation explores cross-functional collaboration, agile delivery, privacy by design, and the importance of experimentation and user-centric compliance processes.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/72019339</guid><pubDate>Tue, 02 Jun 2026 05:15:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72019339/noreen_hussein_1.mp3" length="9225332" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>Traditional privacy teams were never designed for agile digital transformation.
In this episode of Practical Privacy, Orla Dormer speaks with Naureen Hussain, Founder of Luminate Advisers and former DPO at Virgin Media, about how privacy leaders can...</itunes:subtitle><itunes:summary><![CDATA[Traditional privacy teams were never designed for agile digital transformation.<br />In this episode of Practical Privacy, Orla Dormer speaks with <b>Naureen Hussain, Founder of Luminate Advisers and former DPO at Virgin Media,</b> about how privacy leaders can support rapid digital transformation without compromising compliance or creating unacceptable risks.<br /><br />Naureen shares why adding more privacy resources initially failed, how her team embedded into product and digital workflows, and why adopting <b>a product mindset fundamentally changed the way the privacy function operated</b>. The conversation explores cross-functional collaboration, agile delivery, privacy by design, and the importance of experimentation and user-centric compliance processes.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></itunes:summary><itunes:duration>577</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/207ad283dfceb0dc1c5fedee44a155ac.jpg"/><itunes:season>1</itunes:season><itunes:episode>13</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>How privacy teams can deliver proactive change | Ben Westwood</title><link>https://www.spreaker.com/episode/how-privacy-teams-can-deliver-proactive-change-ben-westwood--71921402</link><description><![CDATA[In Episode 12 of Practical Privacy, Orla Dormer is joined by <b>Ben Westwood, Head of Compliance and DPO at the Motor Insurers’ Bureau</b>, to discuss one of the biggest challenges facing privacy and compliance professionals today: How do you deliver proactive change when reactive work never stops? Ben shares how structured annual planning, maturity assessments, risk registers, and alignment with business objectives have transformed the way his team delivers privacy and compliance outcomes. We discuss:<ul><li>Why every privacy team should have a strategic plan</li><li>How to balance proactive vs reactive work</li><li>Using maturity assessments to prioritise effort</li><li>Connecting privacy goals to wider business objectives</li><li>Getting executive buy-in for compliance initiatives</li><li>The importance of reviewing and demonstrating progress</li></ul>A practical conversation packed with actionable ideas for privacy leaders, DPOs, and compliance professionals trying to create meaningful change inside busy organisations.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/71921402</guid><pubDate>Thu, 21 May 2026 06:15:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71921402/ben_westwood_1.mp3" length="11466847" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>In Episode 12 of Practical Privacy, Orla Dormer is joined by Ben Westwood, Head of Compliance and DPO at the Motor Insurers’ Bureau, to discuss one of the biggest challenges facing privacy and compliance professionals today: How do you deliver...</itunes:subtitle><itunes:summary><![CDATA[In Episode 12 of Practical Privacy, Orla Dormer is joined by <b>Ben Westwood, Head of Compliance and DPO at the Motor Insurers’ Bureau</b>, to discuss one of the biggest challenges facing privacy and compliance professionals today: How do you deliver proactive change when reactive work never stops? Ben shares how structured annual planning, maturity assessments, risk registers, and alignment with business objectives have transformed the way his team delivers privacy and compliance outcomes. We discuss:<ul><li>Why every privacy team should have a strategic plan</li><li>How to balance proactive vs reactive work</li><li>Using maturity assessments to prioritise effort</li><li>Connecting privacy goals to wider business objectives</li><li>Getting executive buy-in for compliance initiatives</li><li>The importance of reviewing and demonstrating progress</li></ul>A practical conversation packed with actionable ideas for privacy leaders, DPOs, and compliance professionals trying to create meaningful change inside busy organisations.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></itunes:summary><itunes:duration>717</itunes:duration><itunes:keywords>compliance,dataprotection,dpo,privacyleadership,privacyprofessionals,riskmanagement</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/1c420b2302e8edc29a520463fd544cda.jpg"/><itunes:season>1</itunes:season><itunes:episodeType>full</itunes:episodeType></item><item><title>Building a Scalable Vendor Assessment Process (GDPR &amp; NIS2) | Natalija Bitiukova</title><link>https://www.spreaker.com/episode/building-a-scalable-vendor-assessment-process-gdpr-nis2-natalija-bitiukova--71852478</link><description><![CDATA[Building a scalable v<b>endor assessment process</b> sounds straightforward—until you’re dealing with 50,000+ vendors across 40+ countries.In this episode, <b>Natalija Bitiukova (Head of Data Protection &amp; Digital Law at Carlsberg)</b> shares how her team tackled this challenge in practice, moving beyond fragmented systems and “paper compliance” to a more operational, scalable approach.We discuss:<br /><ul><li>The pitfalls of running privacy and security assessments separately</li><li>Why most vendor assessments fail after the questionnaire stage</li><li>How to simplify assessments for real users (not lawyers)</li><li>The importance of data quality and realistic resourcing</li><li>Change management in large, decentralized organisations</li><li>Getting leadership buy-in by framing compliance as a business issue</li></ul>A practical conversation for anyone working on vendor risk, <b>GDPR</b>, <b>NIS2</b>, or scaling compliance processes.<br />About the podcast:<br />Practical Privacy explores how privacy and security teams solve real-world challenges at scale.<br />Brought to you by TrustWorks <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a><br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/71852478</guid><pubDate>Tue, 12 May 2026 05:45:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71852478/natalija_bitiukova_full_episode.mp3" length="7990680" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>Building a scalable vendor assessment process sounds straightforward—until you’re dealing with 50,000+ vendors across 40+ countries.In this episode, Natalija Bitiukova (Head of Data Protection &amp;amp; Digital Law at Carlsberg) shares how her team...</itunes:subtitle><itunes:summary><![CDATA[Building a scalable v<b>endor assessment process</b> sounds straightforward—until you’re dealing with 50,000+ vendors across 40+ countries.In this episode, <b>Natalija Bitiukova (Head of Data Protection &amp; Digital Law at Carlsberg)</b> shares how her team tackled this challenge in practice, moving beyond fragmented systems and “paper compliance” to a more operational, scalable approach.We discuss:<br /><ul><li>The pitfalls of running privacy and security assessments separately</li><li>Why most vendor assessments fail after the questionnaire stage</li><li>How to simplify assessments for real users (not lawyers)</li><li>The importance of data quality and realistic resourcing</li><li>Change management in large, decentralized organisations</li><li>Getting leadership buy-in by framing compliance as a business issue</li></ul>A practical conversation for anyone working on vendor risk, <b>GDPR</b>, <b>NIS2</b>, or scaling compliance processes.<br />About the podcast:<br />Practical Privacy explores how privacy and security teams solve real-world challenges at scale.<br />Brought to you by TrustWorks <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a><br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></itunes:summary><itunes:duration>500</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/20ba38426eb41f5534c1ce509279010d.jpg"/><itunes:season>1</itunes:season><itunes:episode>11</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Being a global data protection leader (why privacy alone isn’t enough) | Vicky Owens</title><link>https://www.spreaker.com/episode/being-a-global-data-protection-leader-why-privacy-alone-isn-t-enough-vicky-owens--71402270</link><description><![CDATA[In this episode of Practical Privacy, Orla Dormer speaks with Vicky Owens, Senior Data Privacy and Compliance Counsel at SkyShowtime, about the challenges of being a global data protection leader.<br /><br />Vicky shares why a privacy-only mindset often falls short, and how understanding business priorities, aligning with stakeholders, and positioning privacy as an enabler is key to success. A practical conversation on influence, prioritisation, and making privacy work in complex organisations.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/71402270</guid><pubDate>Mon, 04 May 2026 09:30:51 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71402270/vicky_owens_full_episode.mp3" length="4413368" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>In this episode of Practical Privacy, Orla Dormer speaks with Vicky Owens, Senior Data Privacy and Compliance Counsel at SkyShowtime, about the challenges of being a global data protection leader.

Vicky shares why a privacy-only mindset often falls...</itunes:subtitle><itunes:summary><![CDATA[In this episode of Practical Privacy, Orla Dormer speaks with Vicky Owens, Senior Data Privacy and Compliance Counsel at SkyShowtime, about the challenges of being a global data protection leader.<br /><br />Vicky shares why a privacy-only mindset often falls short, and how understanding business priorities, aligning with stakeholders, and positioning privacy as an enabler is key to success. A practical conversation on influence, prioritisation, and making privacy work in complex organisations.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></itunes:summary><itunes:duration>276</itunes:duration><itunes:keywords>privacy,privacyprofessional</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/23f5c0bad90af4bd1eb774366339cdfc.jpg"/><itunes:season>1</itunes:season><itunes:episode>10</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Designing a global privacy framework (what actually works) | Marcelo Canha</title><link>https://www.spreaker.com/episode/designing-a-global-privacy-framework-what-actually-works-marcelo-canha--71235360</link><description><![CDATA[What does it take to build a global privacy framework that actually works? In this episode, Marcelo Canha, Global Privacy Director and DPO at Organon, shares his experience designing a privacy program from scratch across 80+ countries — starting with a technically perfect framework that ultimately failed.<br /><br />The lesson? Complexity doesn’t scale. Marcelo explains how shifting to a simple, practical approach — focused on DPIAs, RoPAs, and real business needs — made the difference, and why buy-in is not just a buzzword, but a strategy. A must-listen for privacy leaders navigating global compliance, limited resources, and the gap between regulation and reality.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/71235360</guid><pubDate>Mon, 04 May 2026 09:21:54 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71235360/marcelo_canha_full_episode_updated_v2.mp3" length="8682821" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>What does it take to build a global privacy framework that actually works? In this episode, Marcelo Canha, Global Privacy Director and DPO at Organon, shares his experience designing a privacy program from scratch across 80+ countries — starting with...</itunes:subtitle><itunes:summary><![CDATA[What does it take to build a global privacy framework that actually works? In this episode, Marcelo Canha, Global Privacy Director and DPO at Organon, shares his experience designing a privacy program from scratch across 80+ countries — starting with a technically perfect framework that ultimately failed.<br /><br />The lesson? Complexity doesn’t scale. Marcelo explains how shifting to a simple, practical approach — focused on DPIAs, RoPAs, and real business needs — made the difference, and why buy-in is not just a buzzword, but a strategy. A must-listen for privacy leaders navigating global compliance, limited resources, and the gap between regulation and reality.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></itunes:summary><itunes:duration>543</itunes:duration><itunes:keywords>privacy</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/b581eee6e758a7f35fc796675c02bcd9.jpg"/><itunes:season>1</itunes:season><itunes:episode>9</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>How to become a DPO (without a traditional background) | Naveed Malik</title><link>https://www.spreaker.com/episode/how-to-become-a-dpo-without-a-traditional-background-naveed-malik--70897226</link><description><![CDATA[What does it really take to become a DPO? <br /><br />In this episode, Naveed Malik (Group DPO at Informa) shares his journey from a non-traditional background into a senior privacy role — and why technical expertise alone isn’t enough. <br /><br />From building leadership skills outside of work to learning inside established governance frameworks, this episode explores the practical steps needed to bridge the gap and grow into a DPO role.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/70897226</guid><pubDate>Wed, 08 Apr 2026 20:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70897226/naveed_malik.mp3" length="10442429" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>What does it really take to become a DPO? 

In this episode, Naveed Malik (Group DPO at Informa) shares his journey from a non-traditional background into a senior privacy role — and why technical expertise alone isn’t enough. 

From building...</itunes:subtitle><itunes:summary><![CDATA[What does it really take to become a DPO? <br /><br />In this episode, Naveed Malik (Group DPO at Informa) shares his journey from a non-traditional background into a senior privacy role — and why technical expertise alone isn’t enough. <br /><br />From building leadership skills outside of work to learning inside established governance frameworks, this episode explores the practical steps needed to bridge the gap and grow into a DPO role.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></itunes:summary><itunes:duration>653</itunes:duration><itunes:keywords>dpo,privacy</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/b6b743b71bdbdcfe82a67efbd1dde800.jpg"/><itunes:season>1</itunes:season><itunes:episode>8</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Customer DPAs and the overuse of SCCs: Fixing data transfer friction | Roy Kamp</title><link>https://www.spreaker.com/episode/customer-dpas-and-the-overuse-of-sccs-fixing-data-transfer-friction-roy-kamp--70566468</link><description><![CDATA[In this episode of Practical Privacy, Orla Dormer speaks with Roy Kamp, Director at UKG and former DPO at Wayfair and McAfee, about a common challenge in vendor negotiations: customers insisting on Standard Contractual Clauses (SCCs) even when they may not apply. <br /><br />Roy explains why this happens, why negotiating every SCC request doesn’t scale, and how reframing the discussion around actual data flows rather than contractual positions can reduce friction and improve trust with customers. <br /><br />The conversation explores practical ways privacy teams can enable sales and legal teams, use transparency to build credibility, and avoid unnecessary complexity in customer DPAs.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/70566468</guid><pubDate>Mon, 30 Mar 2026 18:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70566468/roy_kamp_1.mp3" length="9235781" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>In this episode of Practical Privacy, Orla Dormer speaks with Roy Kamp, Director at UKG and former DPO at Wayfair and McAfee, about a common challenge in vendor negotiations: customers insisting on Standard Contractual Clauses (SCCs) even when they...</itunes:subtitle><itunes:summary><![CDATA[In this episode of Practical Privacy, Orla Dormer speaks with Roy Kamp, Director at UKG and former DPO at Wayfair and McAfee, about a common challenge in vendor negotiations: customers insisting on Standard Contractual Clauses (SCCs) even when they may not apply. <br /><br />Roy explains why this happens, why negotiating every SCC request doesn’t scale, and how reframing the discussion around actual data flows rather than contractual positions can reduce friction and improve trust with customers. <br /><br />The conversation explores practical ways privacy teams can enable sales and legal teams, use transparency to build credibility, and avoid unnecessary complexity in customer DPAs.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></itunes:summary><itunes:duration>578</itunes:duration><itunes:keywords>aigovernance,privacy</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/82cc874944a2a6e7eeb38dad960570f0.jpg"/><itunes:season>1</itunes:season><itunes:episode>7</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Stop calling it anonymous: The reality of pseudonymized data in SaaS | Noemie Weinbaum</title><link>https://www.spreaker.com/episode/stop-calling-it-anonymous-the-reality-of-pseudonymized-data-in-saas-noemie-weinbaum--70565936</link><description><![CDATA[In this episode of Practical Privacy, we explore one of the most common misconceptions in SaaS and AI development: the belief that data can truly be fully anonymized.<br /><br />Orla Dormer speaks with Noemie Weinbaum – Managing Counsel at UKG, about why organizations should stop assuming their datasets are anonymous and instead treat them as pseudonymized personal data. They discuss why true anonymization is extremely difficult under GDPR standards, how SaaS companies often use the same datasets for both service delivery and AI training, and why this creates real risks around re-identification, compliance, and customer trust.<br /><br />Noemie also shares practical advice on building the right governance approach from the start — integrating privacy into the software development lifecycle, involving product and engineering teams early, and creating a cultural shift toward transparent data protection practices. <br /><br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/70565936</guid><pubDate>Wed, 18 Mar 2026 19:10:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70565936/noemie_weinbaum_1.mp3" length="7953900" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>In this episode of Practical Privacy, we explore one of the most common misconceptions in SaaS and AI development: the belief that data can truly be fully anonymized.

Orla Dormer speaks with Noemie Weinbaum – Managing Counsel at UKG, about why...</itunes:subtitle><itunes:summary><![CDATA[In this episode of Practical Privacy, we explore one of the most common misconceptions in SaaS and AI development: the belief that data can truly be fully anonymized.<br /><br />Orla Dormer speaks with Noemie Weinbaum – Managing Counsel at UKG, about why organizations should stop assuming their datasets are anonymous and instead treat them as pseudonymized personal data. They discuss why true anonymization is extremely difficult under GDPR standards, how SaaS companies often use the same datasets for both service delivery and AI training, and why this creates real risks around re-identification, compliance, and customer trust.<br /><br />Noemie also shares practical advice on building the right governance approach from the start — integrating privacy into the software development lifecycle, involving product and engineering teams early, and creating a cultural shift toward transparent data protection practices. <br /><br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></itunes:summary><itunes:duration>498</itunes:duration><itunes:keywords>privacy</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/c58e8a857288323ce0ee888ea48cfd97.jpg"/><itunes:season>1</itunes:season><itunes:episode>6</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Why privacy programs fail at implementation | Avishay Klein</title><link>https://www.spreaker.com/episode/why-privacy-programs-fail-at-implementation-avishay-klein--70386126</link><description><![CDATA[In this episode of Practical Privacy, Orla Dormer speaks with Avishay Klein, Head of Privacy, AI and Cyber Department at Barnea Jaffa Lande. They discuss why privacy programs often fail at implementation — from unrealistic data retention timelines to top-down governance models that teams cannot operationalise. The conversation explores practical ways to align GDPR and AI governance requirements with real business capabilities, emphasising collaboration, understanding operational constraints, and designing processes that teams can actually implement.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/70386126</guid><pubDate>Mon, 09 Mar 2026 14:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70386126/episode_5_full_episode_avishay.mp3" length="9720195" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>In this episode of Practical Privacy, Orla Dormer speaks with Avishay Klein, Head of Privacy, AI and Cyber Department at Barnea Jaffa Lande. They discuss why privacy programs often fail at implementation — from unrealistic data retention timelines to...</itunes:subtitle><itunes:summary><![CDATA[In this episode of Practical Privacy, Orla Dormer speaks with Avishay Klein, Head of Privacy, AI and Cyber Department at Barnea Jaffa Lande. They discuss why privacy programs often fail at implementation — from unrealistic data retention timelines to top-down governance models that teams cannot operationalise. The conversation explores practical ways to align GDPR and AI governance requirements with real business capabilities, emphasising collaboration, understanding operational constraints, and designing processes that teams can actually implement.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></itunes:summary><itunes:duration>608</itunes:duration><itunes:keywords>privacy</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/4972169bc5bb8c918f3be76e588a31ee.jpg"/><itunes:season>1</itunes:season><itunes:episode>5</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Making privacy &amp; AI governance training actually engaging | Jared Browne</title><link>https://www.spreaker.com/episode/making-privacy-ai-governance-training-actually-engaging-jared-browne--70235951</link><description><![CDATA[How do you make AI Act and GDPR training something people actually pay attention to?<br />In this episode of Practical Privacy, Orla Dormer speaks with Jared Browne, Fexco Group Head of Privacy &amp; AI Governance, about turning regulatory training into engaging, story-driven experiences. From framing AI Act sessions as a murder mystery to delivering AI literacy as a playful “Overlords of the Rings” narrative, Jared shares how storytelling, humor, and structure dramatically improve attention and retention. <br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/70235951</guid><pubDate>Mon, 23 Feb 2026 19:41:07 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70235951/practical_privacy_jared_b.mp3" length="9158040" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>How do you make AI Act and GDPR training something people actually pay attention to?
In this episode of Practical Privacy, Orla Dormer speaks with Jared Browne, Fexco Group Head of Privacy &amp;amp; AI Governance, about turning regulatory training into...</itunes:subtitle><itunes:summary><![CDATA[How do you make AI Act and GDPR training something people actually pay attention to?<br />In this episode of Practical Privacy, Orla Dormer speaks with Jared Browne, Fexco Group Head of Privacy &amp; AI Governance, about turning regulatory training into engaging, story-driven experiences. From framing AI Act sessions as a murder mystery to delivering AI literacy as a playful “Overlords of the Rings” narrative, Jared shares how storytelling, humor, and structure dramatically improve attention and retention. <br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></itunes:summary><itunes:duration>573</itunes:duration><itunes:keywords>aigovernnace,privacy,privacytraining</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/0e59b0740aaa9a0e657f5ddead1f8919.jpg"/><itunes:season>1</itunes:season><itunes:episode>4</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Embedding AI governance across 39 countries | Martin Woodward</title><link>https://www.spreaker.com/episode/embedding-ai-governance-across-39-countries-martin-woodward--69547146</link><description><![CDATA[Embedding AI governance across 39 countries is not just a compliance exercise, it’s a change management challenge. <br /><br />In this episode of Practical Privacy, Orla Dormer speaks with <b>Martin Woodward, Director Global Legal &amp; Global Responsible AI Officer at Randstad</b>, about building a global AI governance program in a decentralized organization. <br /><br />Martin shares why a centralized, top-down approach led to slow adoption, and how appointing Responsible AI Officers in each market transformed engagement and ownership. He also explains why culture should shape your governance strategy, especially in a human-centric organization. If you're starting or scaling AI governance, this episode offers practical lessons on turning principles into action across borders.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/69547146</guid><pubDate>Thu, 12 Feb 2026 11:27:04 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69547146/martin_woodward.mp3" length="6981309" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>Embedding AI governance across 39 countries is not just a compliance exercise, it’s a change management challenge. 

In this episode of Practical Privacy, Orla Dormer speaks with Martin Woodward, Director Global Legal &amp;amp; Global Responsible AI...</itunes:subtitle><itunes:summary><![CDATA[Embedding AI governance across 39 countries is not just a compliance exercise, it’s a change management challenge. <br /><br />In this episode of Practical Privacy, Orla Dormer speaks with <b>Martin Woodward, Director Global Legal &amp; Global Responsible AI Officer at Randstad</b>, about building a global AI governance program in a decentralized organization. <br /><br />Martin shares why a centralized, top-down approach led to slow adoption, and how appointing Responsible AI Officers in each market transformed engagement and ownership. He also explains why culture should shape your governance strategy, especially in a human-centric organization. If you're starting or scaling AI governance, this episode offers practical lessons on turning principles into action across borders.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></itunes:summary><itunes:duration>437</itunes:duration><itunes:keywords>aigovernance,privacy</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/12a9d5b4a6a1354981f0f9f16ad0ef95.jpg"/><itunes:season>1</itunes:season><itunes:episode>3</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Why Privacy can’t be solved by legal teams alone | Helen Graham</title><link>https://www.spreaker.com/episode/why-privacy-can-t-be-solved-by-legal-teams-alone-helen-graham--69547144</link><description><![CDATA[In Episode 2 of Practical Privacy, Orla Dormer is joined by Helen Graham (Global Head of Privacy at IVC Evidensia) to unpack one of the biggest challenges privacy teams face today: <b>keeping up with a constant wave of new and evolving data legislation. </b><br /><br />Helen shares why compliance can’t be treated as a legal exercise alone, how <b>operational context is critical </b>to assessing real business impact, and why effective privacy programmes depend on cross-functional and cross-border collaboration. <br /><br />The conversation also <b>reflects on leadership,</b> buy-in, and the ongoing need for privacy professionals to explain and defend why privacy matters, even after years in the role. A practical discussion for anyone working to make privacy scalable, sustainable, and embedded in the business.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/69547144</guid><pubDate>Thu, 29 Jan 2026 13:54:20 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69547144/helen_graham.mp3" length="11852623" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>In Episode 2 of Practical Privacy, Orla Dormer is joined by Helen Graham (Global Head of Privacy at IVC Evidensia) to unpack one of the biggest challenges privacy teams face today: keeping up with a constant wave of new and evolving data legislation....</itunes:subtitle><itunes:summary><![CDATA[In Episode 2 of Practical Privacy, Orla Dormer is joined by Helen Graham (Global Head of Privacy at IVC Evidensia) to unpack one of the biggest challenges privacy teams face today: <b>keeping up with a constant wave of new and evolving data legislation. </b><br /><br />Helen shares why compliance can’t be treated as a legal exercise alone, how <b>operational context is critical </b>to assessing real business impact, and why effective privacy programmes depend on cross-functional and cross-border collaboration. <br /><br />The conversation also <b>reflects on leadership,</b> buy-in, and the ongoing need for privacy professionals to explain and defend why privacy matters, even after years in the role. A practical discussion for anyone working to make privacy scalable, sustainable, and embedded in the business.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></itunes:summary><itunes:duration>741</itunes:duration><itunes:keywords>dataprotection,privacy</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/e8f19827575fee1d78286e4b2608a048.jpg"/><itunes:season>1</itunes:season><itunes:episode>2</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>When RoPA becomes a checkbox (and how to fix It) | Dave Evans</title><link>https://www.spreaker.com/episode/when-ropa-becomes-a-checkbox-and-how-to-fix-it-dave-evans--69547145</link><description><![CDATA[In this first episode of Practical Privacy, Orla Dormer sits down with Dave Evans to unpack a problem many privacy teams recognise instantly: having a ROPA that technically exists, but does not actually help you answer real questions.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/69547145</guid><pubDate>Thu, 22 Jan 2026 15:19:52 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69547145/dave_evans.mp3" length="10091821" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>In this first episode of Practical Privacy, Orla Dormer sits down with Dave Evans to unpack a problem many privacy teams recognise instantly: having a ROPA that technically exists, but does not actually help you answer real questions.</itunes:subtitle><itunes:summary><![CDATA[In this first episode of Practical Privacy, Orla Dormer sits down with Dave Evans to unpack a problem many privacy teams recognise instantly: having a ROPA that technically exists, but does not actually help you answer real questions.<br /><br />📌 Subscribe for more real-world conversations on privacy operations, AI governance, and scaling compliance without the noise.<br /><br />🟡 TrustWorks reduces operational drag through context-aware operations that align compliance with how the business actually works. Learn more at <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></itunes:summary><itunes:duration>631</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/2208c3e4a20f15c6bcc15a5ae22f76ed.jpg"/><itunes:season>1</itunes:season><itunes:episode>1</itunes:episode><itunes:episodeType>full</itunes:episodeType></item></channel></rss>
