<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:podcast="https://podcastindex.org/namespace/1.0" xmlns:media="http://search.yahoo.com/mrss/" version="2.0"><channel><title>Practical Privacy with Orla Dormer</title><link>https://www.trustworks.io/</link><description><![CDATA[Practical Privacy is a podcast for <b>privacy professionals</b> who want to understand how privacy and AI governance work in the real world. <br /><br />Hosted by Orla Dormer, the series brings together <b>experienced practitioners to discuss common operational challenges</b>, from scaling GDPR programs and answering data questions internally, to navigating AI governance and legacy tooling constraints.<br /><br />Each episode focuses on practical lessons, honest reflections, and what teams wish they had known earlier. This podcast is designed as a reference for privacy leaders looking to improve how privacy actually operates inside organisations.]]></description><atom:link href="https://www.spreaker.com/show/6856695/episodes/feed" rel="self" type="application/rss+xml"/><language>en</language><category>Business</category><copyright>Copyright TrustWorks</copyright><image><url>https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9cad44d41de53c5acf422f80dbb9d594.jpg</url><title>Practical Privacy with Orla Dormer</title><link>https://www.trustworks.io/</link></image><lastBuildDate>Thu, 02 Jul 2026 05:57:13 +0000</lastBuildDate><itunes:author>Orla Dormer</itunes:author><itunes:owner><itunes:name>TrustWorks</itunes:name><itunes:email>analytics@trustworks.io</itunes:email></itunes:owner><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/9cad44d41de53c5acf422f80dbb9d594.jpg"/><itunes:subtitle>Practical Privacy is a podcast for privacy professionals who want to understand how privacy and AI governance work in the real world. 

Hosted by Orla Dormer, the series brings together experienced practitioners to discuss common operational...</itunes:subtitle><itunes:summary><![CDATA[Practical Privacy is a podcast for <b>privacy professionals</b> who want to understand how privacy and AI governance work in the real world. <br /><br />Hosted by Orla Dormer, the series brings together <b>experienced practitioners to discuss common operational challenges</b>, from scaling GDPR programs and answering data questions internally, to navigating AI governance and legacy tooling constraints.<br /><br />Each episode focuses on practical lessons, honest reflections, and what teams wish they had known earlier. This podcast is designed as a reference for privacy leaders looking to improve how privacy actually operates inside organisations.]]></itunes:summary><itunes:category text="Business"/><itunes:explicit>false</itunes:explicit><itunes:type>episodic</itunes:type><item><title>Why privacy programmes fail to scale | Cristina Costache</title><link>https://www.spreaker.com/episode/why-privacy-programmes-fail-to-scale-cristina-costache--72577081</link><description><![CDATA[Most organisations have privacy policies. Far fewer have privacy capabilities that actually scale. <br /><br />In this episode, <b>Cristina Costache, DPO &amp; CISO at Noventiq</b>, explores one of the most persistent challenges facing privacy teams: transforming compliance from a documentation exercise into an operational capability embedded within the organisation.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/72577081</guid><pubDate>Thu, 02 Jul 2026 05:55:01 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72577081/cristina_costache_full_episode.mp3" length="7684734" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>Most organisations have privacy policies. Far fewer have privacy capabilities that actually scale. 

In this episode, Cristina Costache, DPO &amp;amp; CISO at Noventiq, explores one of the most persistent challenges facing privacy teams: transforming...</itunes:subtitle><itunes:summary><![CDATA[Most organisations have privacy policies. Far fewer have privacy capabilities that actually scale. <br /><br />In this episode, <b>Cristina Costache, DPO &amp; CISO at Noventiq</b>, explores one of the most persistent challenges facing privacy teams: transforming compliance from a documentation exercise into an operational capability embedded within the organisation.]]></itunes:summary><itunes:duration>481</itunes:duration><itunes:keywords>privacy,privacymanagement</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/652d1b1b3409e79509584408db176392.jpg"/><itunes:season>1</itunes:season><itunes:episode>16</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Scaling ROPA, PIAs &amp; privacy documentation across 1,000+ applications | Aaron Mendelsohn</title><link>https://www.spreaker.com/episode/scaling-ropa-pias-privacy-documentation-across-1-000-applications-aaron-mendelsohn--72364524</link><description><![CDATA[How do you complete privacy documentation across hundreds of teams and more than 1,000 applications without overwhelming the business? In this episode of Practical Privacy, Orla Dormer is joined by <b>Aaron Mendelsohn, Director and Senior Privacy Officer at The LEGO Group</b>, to discuss how his team rebuilt and scaled privacy documentation across a large global organisation. <br /><br />Aaron explains how they combined privacy technology, risk-based prioritisation, and extensive team enablement to successfully document over 1,000 applications within a 12-month period. He also shares why privacy professionals need to move beyond policy writing and spend more time understanding how product and engineering teams actually work. <br /><br />This episode covers: <br />• Scaling ROPAs, PIAs and privacy documentation programmes<br />• Using risk-based approaches to focus effort where it matters most<br />• The role of change management in privacy success<br />• Building stronger relationships with internal stakeholders<br />• Creating sustainable compliance processes that teams will actually use<br />• Future opportunities to combine privacy, AI and broader compliance assessments <br /><br />A practical conversation for privacy leaders, DPOs and compliance professionals looking to improve documentation processes without creating unnecessary friction for the business.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/72364524</guid><pubDate>Tue, 23 Jun 2026 05:50:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72364524/aaron_mendelsohn_full_episode.mp3" length="10322475" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>How do you complete privacy documentation across hundreds of teams and more than 1,000 applications without overwhelming the business? In this episode of Practical Privacy, Orla Dormer is joined by Aaron Mendelsohn, Director and Senior Privacy Officer...</itunes:subtitle><itunes:summary><![CDATA[How do you complete privacy documentation across hundreds of teams and more than 1,000 applications without overwhelming the business? In this episode of Practical Privacy, Orla Dormer is joined by <b>Aaron Mendelsohn, Director and Senior Privacy Officer at The LEGO Group</b>, to discuss how his team rebuilt and scaled privacy documentation across a large global organisation. <br /><br />Aaron explains how they combined privacy technology, risk-based prioritisation, and extensive team enablement to successfully document over 1,000 applications within a 12-month period. He also shares why privacy professionals need to move beyond policy writing and spend more time understanding how product and engineering teams actually work. <br /><br />This episode covers: <br />• Scaling ROPAs, PIAs and privacy documentation programmes<br />• Using risk-based approaches to focus effort where it matters most<br />• The role of change management in privacy success<br />• Building stronger relationships with internal stakeholders<br />• Creating sustainable compliance processes that teams will actually use<br />• Future opportunities to combine privacy, AI and broader compliance assessments <br /><br />A practical conversation for privacy leaders, DPOs and compliance professionals looking to improve documentation processes without creating unnecessary friction for the business.]]></itunes:summary><itunes:duration>646</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/38054da1721666c942666b71196d4434.jpg"/><itunes:season>1</itunes:season><itunes:episode>15</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Enhancing privacy, security &amp; compliance without slowing business growth | Fred Descloux</title><link>https://www.spreaker.com/episode/enhancing-privacy-security-compliance-without-slowing-business-growth-fred-descloux--72342468</link><description><![CDATA[In this episode of Practical Privacy, Orla Dormer is joined by Fred Descloux, privacy, security, and governance leader, to discuss how organisations can align engineering, security, privacy, and compliance<b> in fast-moving environments where execution speed is critical</b>. Drawing on his experience in highly regulated industries, Fred shares why traditional compliance approaches often create friction, bottlenecks, and what he describes as "compliance theatre"—generating documentation without meaningfully reducing risk.<br /><br />Together they explore how to:<br />• Embed privacy and security directly into engineering workflows<br />• Move away from compliance as a gatekeeping function<br />• Focus on outcomes rather than perfection<br />• Build scalable operating models that support growth<br />• Make privacy and security everyone's responsibility<br />• Avoid creating bottlenecks while maintaining strong controls<br />• Prepare for audits through operational excellence rather than audit-driven processes<br />• Balance business agility with regulatory expectationsA practical conversation for privacy professionals, security leaders, compliance teams, and anyone trying to support innovation without compromising governance.<br /><br />🎧 Follow Practical Privacy for more real-world lessons from privacy, security, and compliance leaders.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/72342468</guid><pubDate>Thu, 11 Jun 2026 05:15:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72342468/fred_descloux_full_episode.mp3" length="12026494" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>In this episode of Practical Privacy, Orla Dormer is joined by Fred Descloux, privacy, security, and governance leader, to discuss how organisations can align engineering, security, privacy, and compliance in fast-moving environments where execution...</itunes:subtitle><itunes:summary><![CDATA[In this episode of Practical Privacy, Orla Dormer is joined by Fred Descloux, privacy, security, and governance leader, to discuss how organisations can align engineering, security, privacy, and compliance<b> in fast-moving environments where execution speed is critical</b>. Drawing on his experience in highly regulated industries, Fred shares why traditional compliance approaches often create friction, bottlenecks, and what he describes as "compliance theatre"—generating documentation without meaningfully reducing risk.<br /><br />Together they explore how to:<br />• Embed privacy and security directly into engineering workflows<br />• Move away from compliance as a gatekeeping function<br />• Focus on outcomes rather than perfection<br />• Build scalable operating models that support growth<br />• Make privacy and security everyone's responsibility<br />• Avoid creating bottlenecks while maintaining strong controls<br />• Prepare for audits through operational excellence rather than audit-driven processes<br />• Balance business agility with regulatory expectationsA practical conversation for privacy professionals, security leaders, compliance teams, and anyone trying to support innovation without compromising governance.<br /><br />🎧 Follow Practical Privacy for more real-world lessons from privacy, security, and compliance leaders.]]></itunes:summary><itunes:duration>752</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/be67de50c39687091ef94116bc4e1726.jpg"/><itunes:season>1</itunes:season><itunes:episode>14</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>How to be a digital enabler without compromising compliance | Naureen Hussain</title><link>https://www.spreaker.com/episode/how-to-be-a-digital-enabler-without-compromising-compliance-naureen-hussain--72019339</link><description><![CDATA[Traditional privacy teams were never designed for agile digital transformation.<br />In this episode of Practical Privacy, Orla Dormer speaks with <b>Naureen Hussain, Founder of Luminate Advisers and former DPO at Virgin Media,</b> about how privacy leaders can support rapid digital transformation without compromising compliance or creating unacceptable risks.<br /><br />Naureen shares why adding more privacy resources initially failed, how her team embedded into product and digital workflows, and why adopting <b>a product mindset fundamentally changed the way the privacy function operated</b>. The conversation explores cross-functional collaboration, agile delivery, privacy by design, and the importance of experimentation and user-centric compliance processes.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/72019339</guid><pubDate>Tue, 02 Jun 2026 05:15:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/72019339/noreen_hussein_1.mp3" length="9225332" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>Traditional privacy teams were never designed for agile digital transformation.
In this episode of Practical Privacy, Orla Dormer speaks with Naureen Hussain, Founder of Luminate Advisers and former DPO at Virgin Media, about how privacy leaders can...</itunes:subtitle><itunes:summary><![CDATA[Traditional privacy teams were never designed for agile digital transformation.<br />In this episode of Practical Privacy, Orla Dormer speaks with <b>Naureen Hussain, Founder of Luminate Advisers and former DPO at Virgin Media,</b> about how privacy leaders can support rapid digital transformation without compromising compliance or creating unacceptable risks.<br /><br />Naureen shares why adding more privacy resources initially failed, how her team embedded into product and digital workflows, and why adopting <b>a product mindset fundamentally changed the way the privacy function operated</b>. The conversation explores cross-functional collaboration, agile delivery, privacy by design, and the importance of experimentation and user-centric compliance processes.]]></itunes:summary><itunes:duration>577</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/207ad283dfceb0dc1c5fedee44a155ac.jpg"/><itunes:season>1</itunes:season><itunes:episode>13</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>How privacy teams can deliver proactive change | Ben Westwood</title><link>https://www.spreaker.com/episode/how-privacy-teams-can-deliver-proactive-change-ben-westwood--71921402</link><description><![CDATA[In Episode 12 of Practical Privacy, Orla Dormer is joined by <b>Ben Westwood, Head of Compliance and DPO at the Motor Insurers’ Bureau</b>, to discuss one of the biggest challenges facing privacy and compliance professionals today: How do you deliver proactive change when reactive work never stops? Ben shares how structured annual planning, maturity assessments, risk registers, and alignment with business objectives have transformed the way his team delivers privacy and compliance outcomes. We discuss:<ul><li>Why every privacy team should have a strategic plan</li><li>How to balance proactive vs reactive work</li><li>Using maturity assessments to prioritise effort</li><li>Connecting privacy goals to wider business objectives</li><li>Getting executive buy-in for compliance initiatives</li><li>The importance of reviewing and demonstrating progress</li></ul>A practical conversation packed with actionable ideas for privacy leaders, DPOs, and compliance professionals trying to create meaningful change inside busy organisations.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/71921402</guid><pubDate>Thu, 21 May 2026 06:15:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71921402/ben_westwood_1.mp3" length="11466847" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>In Episode 12 of Practical Privacy, Orla Dormer is joined by Ben Westwood, Head of Compliance and DPO at the Motor Insurers’ Bureau, to discuss one of the biggest challenges facing privacy and compliance professionals today: How do you deliver...</itunes:subtitle><itunes:summary><![CDATA[In Episode 12 of Practical Privacy, Orla Dormer is joined by <b>Ben Westwood, Head of Compliance and DPO at the Motor Insurers’ Bureau</b>, to discuss one of the biggest challenges facing privacy and compliance professionals today: How do you deliver proactive change when reactive work never stops? Ben shares how structured annual planning, maturity assessments, risk registers, and alignment with business objectives have transformed the way his team delivers privacy and compliance outcomes. We discuss:<ul><li>Why every privacy team should have a strategic plan</li><li>How to balance proactive vs reactive work</li><li>Using maturity assessments to prioritise effort</li><li>Connecting privacy goals to wider business objectives</li><li>Getting executive buy-in for compliance initiatives</li><li>The importance of reviewing and demonstrating progress</li></ul>A practical conversation packed with actionable ideas for privacy leaders, DPOs, and compliance professionals trying to create meaningful change inside busy organisations.]]></itunes:summary><itunes:duration>717</itunes:duration><itunes:keywords>compliance,dataprotection,dpo,privacyleadership,privacyprofessionals,riskmanagement</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/1c420b2302e8edc29a520463fd544cda.jpg"/><itunes:season>1</itunes:season><itunes:episodeType>full</itunes:episodeType></item><item><title>Building a Scalable Vendor Assessment Process (GDPR &amp; NIS2) | Natalija Bitiukova</title><link>https://www.spreaker.com/episode/building-a-scalable-vendor-assessment-process-gdpr-nis2-natalija-bitiukova--71852478</link><description><![CDATA[Building a scalable v<b>endor assessment process</b> sounds straightforward—until you’re dealing with 50,000+ vendors across 40+ countries.In this episode, <b>Natalija Bitiukova (Head of Data Protection &amp; Digital Law at Carlsberg)</b> shares how her team tackled this challenge in practice, moving beyond fragmented systems and “paper compliance” to a more operational, scalable approach.We discuss:<br /><ul><li>The pitfalls of running privacy and security assessments separately</li><li>Why most vendor assessments fail after the questionnaire stage</li><li>How to simplify assessments for real users (not lawyers)</li><li>The importance of data quality and realistic resourcing</li><li>Change management in large, decentralized organisations</li><li>Getting leadership buy-in by framing compliance as a business issue</li></ul>A practical conversation for anyone working on vendor risk, <b>GDPR</b>, <b>NIS2</b>, or scaling compliance processes.<br />About the podcast:<br />Practical Privacy explores how privacy and security teams solve real-world challenges at scale.<br />Brought to you by TrustWorks <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/71852478</guid><pubDate>Tue, 12 May 2026 05:45:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71852478/natalija_bitiukova_full_episode.mp3" length="7990680" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>Building a scalable vendor assessment process sounds straightforward—until you’re dealing with 50,000+ vendors across 40+ countries.In this episode, Natalija Bitiukova (Head of Data Protection &amp;amp; Digital Law at Carlsberg) shares how her team...</itunes:subtitle><itunes:summary><![CDATA[Building a scalable v<b>endor assessment process</b> sounds straightforward—until you’re dealing with 50,000+ vendors across 40+ countries.In this episode, <b>Natalija Bitiukova (Head of Data Protection &amp; Digital Law at Carlsberg)</b> shares how her team tackled this challenge in practice, moving beyond fragmented systems and “paper compliance” to a more operational, scalable approach.We discuss:<br /><ul><li>The pitfalls of running privacy and security assessments separately</li><li>Why most vendor assessments fail after the questionnaire stage</li><li>How to simplify assessments for real users (not lawyers)</li><li>The importance of data quality and realistic resourcing</li><li>Change management in large, decentralized organisations</li><li>Getting leadership buy-in by framing compliance as a business issue</li></ul>A practical conversation for anyone working on vendor risk, <b>GDPR</b>, <b>NIS2</b>, or scaling compliance processes.<br />About the podcast:<br />Practical Privacy explores how privacy and security teams solve real-world challenges at scale.<br />Brought to you by TrustWorks <a href="https://www.trustworks.io/" target="_blank" rel="noreferrer noopener">https://www.trustworks.io/</a>]]></itunes:summary><itunes:duration>500</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/20ba38426eb41f5534c1ce509279010d.jpg"/><itunes:season>1</itunes:season><itunes:episode>11</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Being a global data protection leader (why privacy alone isn’t enough) | Vicky Owens</title><link>https://www.spreaker.com/episode/being-a-global-data-protection-leader-why-privacy-alone-isn-t-enough-vicky-owens--71402270</link><description><![CDATA[In this episode of Practical Privacy, Orla Dormer speaks with Vicky Owens, Senior Data Privacy and Compliance Counsel at SkyShowtime, about the challenges of being a global data protection leader.<br /><br />Vicky shares why a privacy-only mindset often falls short, and how understanding business priorities, aligning with stakeholders, and positioning privacy as an enabler is key to success. A practical conversation on influence, prioritisation, and making privacy work in complex organisations.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/71402270</guid><pubDate>Mon, 04 May 2026 09:30:51 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71402270/vicky_owens_full_episode.mp3" length="4413368" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>In this episode of Practical Privacy, Orla Dormer speaks with Vicky Owens, Senior Data Privacy and Compliance Counsel at SkyShowtime, about the challenges of being a global data protection leader.

Vicky shares why a privacy-only mindset often falls...</itunes:subtitle><itunes:summary><![CDATA[In this episode of Practical Privacy, Orla Dormer speaks with Vicky Owens, Senior Data Privacy and Compliance Counsel at SkyShowtime, about the challenges of being a global data protection leader.<br /><br />Vicky shares why a privacy-only mindset often falls short, and how understanding business priorities, aligning with stakeholders, and positioning privacy as an enabler is key to success. A practical conversation on influence, prioritisation, and making privacy work in complex organisations.]]></itunes:summary><itunes:duration>276</itunes:duration><itunes:keywords>privacy,privacyprofessional</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/23f5c0bad90af4bd1eb774366339cdfc.jpg"/><itunes:season>1</itunes:season><itunes:episode>10</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Designing a global privacy framework (what actually works) | Marcelo Canha</title><link>https://www.spreaker.com/episode/designing-a-global-privacy-framework-what-actually-works-marcelo-canha--71235360</link><description><![CDATA[What does it take to build a global privacy framework that actually works? In this episode, Marcelo Canha, Global Privacy Director and DPO at Organon, shares his experience designing a privacy program from scratch across 80+ countries — starting with a technically perfect framework that ultimately failed.<br /><br />The lesson? Complexity doesn’t scale. Marcelo explains how shifting to a simple, practical approach — focused on DPIAs, RoPAs, and real business needs — made the difference, and why buy-in is not just a buzzword, but a strategy. A must-listen for privacy leaders navigating global compliance, limited resources, and the gap between regulation and reality.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/71235360</guid><pubDate>Mon, 04 May 2026 09:21:54 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/71235360/marcelo_canha_full_episode_updated_v2.mp3" length="8682821" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>What does it take to build a global privacy framework that actually works? In this episode, Marcelo Canha, Global Privacy Director and DPO at Organon, shares his experience designing a privacy program from scratch across 80+ countries — starting with...</itunes:subtitle><itunes:summary><![CDATA[What does it take to build a global privacy framework that actually works? In this episode, Marcelo Canha, Global Privacy Director and DPO at Organon, shares his experience designing a privacy program from scratch across 80+ countries — starting with a technically perfect framework that ultimately failed.<br /><br />The lesson? Complexity doesn’t scale. Marcelo explains how shifting to a simple, practical approach — focused on DPIAs, RoPAs, and real business needs — made the difference, and why buy-in is not just a buzzword, but a strategy. A must-listen for privacy leaders navigating global compliance, limited resources, and the gap between regulation and reality.]]></itunes:summary><itunes:duration>543</itunes:duration><itunes:keywords>privacy</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/b581eee6e758a7f35fc796675c02bcd9.jpg"/><itunes:season>1</itunes:season><itunes:episode>9</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>How to become a DPO (without a traditional background) | Naveed Malik</title><link>https://www.spreaker.com/episode/how-to-become-a-dpo-without-a-traditional-background-naveed-malik--70897226</link><description><![CDATA[What does it really take to become a DPO? <br /><br />In this episode, Naveed Malik (Group DPO at Informa) shares his journey from a non-traditional background into a senior privacy role — and why technical expertise alone isn’t enough. <br /><br />From building leadership skills outside of work to learning inside established governance frameworks, this episode explores the practical steps needed to bridge the gap and grow into a DPO role.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/70897226</guid><pubDate>Wed, 08 Apr 2026 20:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70897226/naveed_malik.mp3" length="10442429" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>What does it really take to become a DPO? 

In this episode, Naveed Malik (Group DPO at Informa) shares his journey from a non-traditional background into a senior privacy role — and why technical expertise alone isn’t enough. 

From building...</itunes:subtitle><itunes:summary><![CDATA[What does it really take to become a DPO? <br /><br />In this episode, Naveed Malik (Group DPO at Informa) shares his journey from a non-traditional background into a senior privacy role — and why technical expertise alone isn’t enough. <br /><br />From building leadership skills outside of work to learning inside established governance frameworks, this episode explores the practical steps needed to bridge the gap and grow into a DPO role.]]></itunes:summary><itunes:duration>653</itunes:duration><itunes:keywords>dpo,privacy</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/b6b743b71bdbdcfe82a67efbd1dde800.jpg"/><itunes:season>1</itunes:season><itunes:episode>8</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Customer DPAs and the overuse of SCCs: Fixing data transfer friction | Roy Kamp</title><link>https://www.spreaker.com/episode/customer-dpas-and-the-overuse-of-sccs-fixing-data-transfer-friction-roy-kamp--70566468</link><description><![CDATA[In this episode of Practical Privacy, Orla Dormer speaks with Roy Kamp, Director at UKG and former DPO at Wayfair and McAfee, about a common challenge in vendor negotiations: customers insisting on Standard Contractual Clauses (SCCs) even when they may not apply. <br /><br />Roy explains why this happens, why negotiating every SCC request doesn’t scale, and how reframing the discussion around actual data flows rather than contractual positions can reduce friction and improve trust with customers. <br /><br />The conversation explores practical ways privacy teams can enable sales and legal teams, use transparency to build credibility, and avoid unnecessary complexity in customer DPAs.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/70566468</guid><pubDate>Mon, 30 Mar 2026 18:00:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70566468/roy_kamp_1.mp3" length="9235781" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>In this episode of Practical Privacy, Orla Dormer speaks with Roy Kamp, Director at UKG and former DPO at Wayfair and McAfee, about a common challenge in vendor negotiations: customers insisting on Standard Contractual Clauses (SCCs) even when they...</itunes:subtitle><itunes:summary><![CDATA[In this episode of Practical Privacy, Orla Dormer speaks with Roy Kamp, Director at UKG and former DPO at Wayfair and McAfee, about a common challenge in vendor negotiations: customers insisting on Standard Contractual Clauses (SCCs) even when they may not apply. <br /><br />Roy explains why this happens, why negotiating every SCC request doesn’t scale, and how reframing the discussion around actual data flows rather than contractual positions can reduce friction and improve trust with customers. <br /><br />The conversation explores practical ways privacy teams can enable sales and legal teams, use transparency to build credibility, and avoid unnecessary complexity in customer DPAs.]]></itunes:summary><itunes:duration>578</itunes:duration><itunes:keywords>aigovernance,privacy</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/82cc874944a2a6e7eeb38dad960570f0.jpg"/><itunes:season>1</itunes:season><itunes:episode>7</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Stop calling it anonymous: The reality of pseudonymized data in SaaS | Noemie Weinbaum</title><link>https://www.spreaker.com/episode/stop-calling-it-anonymous-the-reality-of-pseudonymized-data-in-saas-noemie-weinbaum--70565936</link><description><![CDATA[In this episode of Practical Privacy, we explore one of the most common misconceptions in SaaS and AI development: the belief that data can truly be fully anonymized.<br /><br />Orla Dormer speaks with Noemie Weinbaum – Managing Counsel at UKG, about why organizations should stop assuming their datasets are anonymous and instead treat them as pseudonymized personal data. They discuss why true anonymization is extremely difficult under GDPR standards, how SaaS companies often use the same datasets for both service delivery and AI training, and why this creates real risks around re-identification, compliance, and customer trust.<br /><br />Noemie also shares practical advice on building the right governance approach from the start — integrating privacy into the software development lifecycle, involving product and engineering teams early, and creating a cultural shift toward transparent data protection practices. <br />]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/70565936</guid><pubDate>Wed, 18 Mar 2026 19:10:02 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70565936/noemie_weinbaum_1.mp3" length="7953900" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>In this episode of Practical Privacy, we explore one of the most common misconceptions in SaaS and AI development: the belief that data can truly be fully anonymized.

Orla Dormer speaks with Noemie Weinbaum – Managing Counsel at UKG, about why...</itunes:subtitle><itunes:summary><![CDATA[In this episode of Practical Privacy, we explore one of the most common misconceptions in SaaS and AI development: the belief that data can truly be fully anonymized.<br /><br />Orla Dormer speaks with Noemie Weinbaum – Managing Counsel at UKG, about why organizations should stop assuming their datasets are anonymous and instead treat them as pseudonymized personal data. They discuss why true anonymization is extremely difficult under GDPR standards, how SaaS companies often use the same datasets for both service delivery and AI training, and why this creates real risks around re-identification, compliance, and customer trust.<br /><br />Noemie also shares practical advice on building the right governance approach from the start — integrating privacy into the software development lifecycle, involving product and engineering teams early, and creating a cultural shift toward transparent data protection practices. <br />]]></itunes:summary><itunes:duration>498</itunes:duration><itunes:keywords>privacy</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/c58e8a857288323ce0ee888ea48cfd97.jpg"/><itunes:season>1</itunes:season><itunes:episode>6</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Why privacy programs fail at implementation | Avishay Klein</title><link>https://www.spreaker.com/episode/why-privacy-programs-fail-at-implementation-avishay-klein--70386126</link><description><![CDATA[In this episode of Practical Privacy, Orla Dormer speaks with Avishay Klein, Head of Privacy, AI and Cyber Department at Barnea Jaffa Lande. They discuss why privacy programs often fail at implementation — from unrealistic data retention timelines to top-down governance models that teams cannot operationalise. The conversation explores practical ways to align GDPR and AI governance requirements with real business capabilities, emphasising collaboration, understanding operational constraints, and designing processes that teams can actually implement.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/70386126</guid><pubDate>Mon, 09 Mar 2026 14:00:03 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70386126/episode_5_full_episode_avishay.mp3" length="9720195" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>In this episode of Practical Privacy, Orla Dormer speaks with Avishay Klein, Head of Privacy, AI and Cyber Department at Barnea Jaffa Lande. They discuss why privacy programs often fail at implementation — from unrealistic data retention timelines to...</itunes:subtitle><itunes:summary><![CDATA[In this episode of Practical Privacy, Orla Dormer speaks with Avishay Klein, Head of Privacy, AI and Cyber Department at Barnea Jaffa Lande. They discuss why privacy programs often fail at implementation — from unrealistic data retention timelines to top-down governance models that teams cannot operationalise. The conversation explores practical ways to align GDPR and AI governance requirements with real business capabilities, emphasising collaboration, understanding operational constraints, and designing processes that teams can actually implement.]]></itunes:summary><itunes:duration>608</itunes:duration><itunes:keywords>privacy</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/4972169bc5bb8c918f3be76e588a31ee.jpg"/><itunes:season>1</itunes:season><itunes:episode>5</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Making privacy &amp; AI governance training actually engaging | Jared Browne</title><link>https://www.spreaker.com/episode/making-privacy-ai-governance-training-actually-engaging-jared-browne--70235951</link><description><![CDATA[How do you make AI Act and GDPR training something people actually pay attention to?<br />In this episode of Practical Privacy, Orla Dormer speaks with Jared Browne, Fexco Group Head of Privacy &amp; AI Governance, about turning regulatory training into engaging, story-driven experiences. From framing AI Act sessions as a murder mystery to delivering AI literacy as a playful “Overlords of the Rings” narrative, Jared shares how storytelling, humor, and structure dramatically improve attention and retention. ]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/70235951</guid><pubDate>Mon, 23 Feb 2026 19:41:07 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/70235951/practical_privacy_jared_b.mp3" length="9158040" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>How do you make AI Act and GDPR training something people actually pay attention to?
In this episode of Practical Privacy, Orla Dormer speaks with Jared Browne, Fexco Group Head of Privacy &amp;amp; AI Governance, about turning regulatory training into...</itunes:subtitle><itunes:summary><![CDATA[How do you make AI Act and GDPR training something people actually pay attention to?<br />In this episode of Practical Privacy, Orla Dormer speaks with Jared Browne, Fexco Group Head of Privacy &amp; AI Governance, about turning regulatory training into engaging, story-driven experiences. From framing AI Act sessions as a murder mystery to delivering AI literacy as a playful “Overlords of the Rings” narrative, Jared shares how storytelling, humor, and structure dramatically improve attention and retention. ]]></itunes:summary><itunes:duration>573</itunes:duration><itunes:keywords>aigovernnace,privacy,privacytraining</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/0e59b0740aaa9a0e657f5ddead1f8919.jpg"/><itunes:season>1</itunes:season><itunes:episode>4</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Embedding AI governance across 39 countries | Martin Woodward</title><link>https://www.spreaker.com/episode/embedding-ai-governance-across-39-countries-martin-woodward--69547146</link><description><![CDATA[Embedding AI governance across 39 countries is not just a compliance exercise, it’s a change management challenge. <br /><br />In this episode of Practical Privacy, Orla Dormer speaks with <b>Martin Woodward, Director Global Legal &amp; Global Responsible AI Officer at Randstad</b>, about building a global AI governance program in a decentralized organization. <br /><br />Martin shares why a centralized, top-down approach led to slow adoption, and how appointing Responsible AI Officers in each market transformed engagement and ownership. He also explains why culture should shape your governance strategy, especially in a human-centric organization. If you're starting or scaling AI governance, this episode offers practical lessons on turning principles into action across borders.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/69547146</guid><pubDate>Thu, 12 Feb 2026 11:27:04 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69547146/martin_woodward.mp3" length="6981309" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>Embedding AI governance across 39 countries is not just a compliance exercise, it’s a change management challenge. 

In this episode of Practical Privacy, Orla Dormer speaks with Martin Woodward, Director Global Legal &amp;amp; Global Responsible AI...</itunes:subtitle><itunes:summary><![CDATA[Embedding AI governance across 39 countries is not just a compliance exercise, it’s a change management challenge. <br /><br />In this episode of Practical Privacy, Orla Dormer speaks with <b>Martin Woodward, Director Global Legal &amp; Global Responsible AI Officer at Randstad</b>, about building a global AI governance program in a decentralized organization. <br /><br />Martin shares why a centralized, top-down approach led to slow adoption, and how appointing Responsible AI Officers in each market transformed engagement and ownership. He also explains why culture should shape your governance strategy, especially in a human-centric organization. If you're starting or scaling AI governance, this episode offers practical lessons on turning principles into action across borders.]]></itunes:summary><itunes:duration>437</itunes:duration><itunes:keywords>aigovernance,privacy</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/12a9d5b4a6a1354981f0f9f16ad0ef95.jpg"/><itunes:season>1</itunes:season><itunes:episode>3</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>Why Privacy can’t be solved by legal teams alone | Helen Graham</title><link>https://www.spreaker.com/episode/why-privacy-can-t-be-solved-by-legal-teams-alone-helen-graham--69547144</link><description><![CDATA[In Episode 2 of Practical Privacy, Orla Dormer is joined by Helen Graham (Global Head of Privacy at IVC Evidensia) to unpack one of the biggest challenges privacy teams face today: <b>keeping up with a constant wave of new and evolving data legislation. </b><br /><br />Helen shares why compliance can’t be treated as a legal exercise alone, how <b>operational context is critical </b>to assessing real business impact, and why effective privacy programmes depend on cross-functional and cross-border collaboration. <br /><br />The conversation also <b>reflects on leadership,</b> buy-in, and the ongoing need for privacy professionals to explain and defend why privacy matters, even after years in the role. A practical discussion for anyone working to make privacy scalable, sustainable, and embedded in the business.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/69547144</guid><pubDate>Thu, 29 Jan 2026 13:54:20 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69547144/helen_graham.mp3" length="11852623" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>In Episode 2 of Practical Privacy, Orla Dormer is joined by Helen Graham (Global Head of Privacy at IVC Evidensia) to unpack one of the biggest challenges privacy teams face today: keeping up with a constant wave of new and evolving data legislation....</itunes:subtitle><itunes:summary><![CDATA[In Episode 2 of Practical Privacy, Orla Dormer is joined by Helen Graham (Global Head of Privacy at IVC Evidensia) to unpack one of the biggest challenges privacy teams face today: <b>keeping up with a constant wave of new and evolving data legislation. </b><br /><br />Helen shares why compliance can’t be treated as a legal exercise alone, how <b>operational context is critical </b>to assessing real business impact, and why effective privacy programmes depend on cross-functional and cross-border collaboration. <br /><br />The conversation also <b>reflects on leadership,</b> buy-in, and the ongoing need for privacy professionals to explain and defend why privacy matters, even after years in the role. A practical discussion for anyone working to make privacy scalable, sustainable, and embedded in the business.]]></itunes:summary><itunes:duration>741</itunes:duration><itunes:keywords>dataprotection,privacy</itunes:keywords><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/e8f19827575fee1d78286e4b2608a048.jpg"/><itunes:season>1</itunes:season><itunes:episode>2</itunes:episode><itunes:episodeType>full</itunes:episodeType></item><item><title>When RoPA becomes a checkbox (and how to fix It) | Dave Evans</title><link>https://www.spreaker.com/episode/when-ropa-becomes-a-checkbox-and-how-to-fix-it-dave-evans--69547145</link><description><![CDATA[In this first episode of Practical Privacy, Orla Dormer sits down with Dave Evans to unpack a problem many privacy teams recognise instantly: having a ROPA that technically exists, but does not actually help you answer real questions.]]></description><guid isPermaLink="false">https://api.spreaker.com/episode/69547145</guid><pubDate>Thu, 22 Jan 2026 15:19:52 +0000</pubDate><enclosure url="https://api.spreaker.com/download/episode/69547145/dave_evans.mp3" length="10091821" type="audio/mpeg"/><itunes:author>Orla Dormer</itunes:author><itunes:subtitle>In this first episode of Practical Privacy, Orla Dormer sits down with Dave Evans to unpack a problem many privacy teams recognise instantly: having a ROPA that technically exists, but does not actually help you answer real questions.</itunes:subtitle><itunes:summary><![CDATA[In this first episode of Practical Privacy, Orla Dormer sits down with Dave Evans to unpack a problem many privacy teams recognise instantly: having a ROPA that technically exists, but does not actually help you answer real questions.]]></itunes:summary><itunes:duration>631</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:image href="https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/2208c3e4a20f15c6bcc15a5ae22f76ed.jpg"/><itunes:season>1</itunes:season><itunes:episode>1</itunes:episode><itunes:episodeType>full</itunes:episodeType></item></channel></rss>
