Test Your GDPR Maturity

Download your GDPR Maturity Matrix with five maturity levels (1 = Initial, 5 = Optimised) across the requested domains. It’s written so you can lift it straight into a governance pack or audit framework. Get the template here:

 

Name(Required)
We will send the information you have asked for by email, so please ensure you put the correct email in the field below. We may also send you follow up emails to showcase some of our products and services, but you can unsubscribe from these at any time.
Would you like to sign up to our newsletter?
Get articles like this, the latest news and exclusive offers direct to your inbox with our regular newsletter. This is separate from out other emails and we won't use your data for anything else and you can unsubscribe at any time
About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

 


GDPR Maturity Matrix (Levels 1–5)

The matrix explore GDPR maturity across five domains, and five levels of achievement.

Maturity Levels (Definitions)

  • 1 — Initial: Ad hoc, reactive, minimal documentation, high reliance on individuals.
  • 2 — Developing: Some repeatable processes exist, gaps remain, limited assurance.
  • 3 — Defined: Standardised policies and processes, clear ownership, consistent delivery.
  • 4 — Managed: Measured performance, proactive controls, embedded governance and assurance.
  • 5 — Optimised: Continuous improvement, automation where appropriate, strong culture and accountability.

GDPR Maturity Domains

  • The Privacy Principles including understanding the lawful bases for data processing
  • People’s GDPR Rights
  • Information Security
  • Skills and training
  • Incident management

 

GDPR maturity matrix

 

 


A) Compliance with the Privacy Principles

Level 1 — Initial

  • Privacy principles not understood or applied consistently.
  • No reliable record of lawful bases; privacy notices generic/outdated.
  • Data minimisation and retention largely unmanaged.

Level 2 — Developing

  • Basic privacy notices and some lawful basis documentation exist.
  • Some retention rules, but inconsistent disposal and weak oversight.
  • Limited DPIA use; often conducted late or not at all.

Level 3 — Defined

  • Lawful basis mapped to main processing activities (ROPA in place).
  • Purpose limitation and minimisation built into standard forms/processes.
  • Retention schedule defined; routine deletion begins.
  • DPIAs used for new/high-risk processing with clear sign-off.

Level 4 — Managed

  • Privacy by design embedded in project governance and procurement.
  • Regular compliance reviews of privacy notices, ROPA, retention, DPIAs.
  • Measurable KPIs (e.g., DPIA completion rates, retention compliance).
  • Formal governance for special category data processing.

Level 5 — Optimised

  • Continuous improvement driven by metrics, audits, and lessons learned.
  • Automated data mapping and retention controls where feasible.
  • Strong culture of justification and minimisation (default position).
  • Demonstrable alignment across GDPR, sector guidance, and ISO/IG frameworks.

B) Compliance with People’s Data Rights

Level 1 — Initial

  • SARs handled ad hoc; deadlines often missed.
  • No standard approach to redaction, identity verification, or exemptions.
  • Rights requests (rectification/erasure/objection) poorly understood.

Level 2 — Developing

  • Basic SAR procedure exists; still reliant on manual searching.
  • Some templates; inconsistent outcomes and recordkeeping.
  • Backlogs occur during peaks; limited cross-department coordination.

Level 3 — Defined

  • End-to-end rights handling process for SAR, rectification, erasure, objection, restriction, portability.
  • Clear triage, scope clarification, and identity verification steps.
  • Central log of all rights requests with deadlines and outcomes.
  • Documented redaction and third-party data approach.

Level 4 — Managed

  • Defined service levels and KPIs (on-time completion, quality checks).
  • eDiscovery/search tools used for email and unstructured data.
  • Regular testing and quality assurance of responses.
  • Trend analysis informs training and process improvements.

Level 5 — Optimised

  • Rights handling “self-service” options where appropriate (portals, automated retrieval).
  • Proactive rights design: systems built to retrieve/export data cleanly.
  • Strong defensibility: consistently high-quality responses and audit trails.
  • Minimal friction for individuals; high transparency and trust.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 


C) Information Security

Level 1 — Initial

  • Weak access control; shared accounts or poorly managed permissions.
  • Limited incident logging; patching and backups inconsistent.
  • Security training minimal or absent.

Level 2 — Developing

  • Basic technical controls implemented (antivirus, password policy, backups).
  • Some access control discipline; inconsistent endpoint management.
  • Security risk assessments occasional.

Level 3 — Defined

  • Documented security policies and minimum standards (access, encryption, mobile working).
  • Role-based access controls; joiner/mover/leaver process.
  • Regular patching, backups, MFA adoption, logging and monitoring in place.
  • Supplier security requirements introduced.

Level 4 — Managed

  • Formal security governance with regular audits and risk reporting.
  • Pen testing / vulnerability management programme.
  • Encryption by default for portable devices and sensitive transfers.
  • Data classification scheme and secure handling rules embedded.
  • Supplier assurance and contract controls consistently applied.

Level 5 — Optimised

  • Security aligned to recognised frameworks (e.g., ISO 27001/NCSC principles) and measured continuously.
  • Advanced monitoring and detection; rapid containment capability.
  • Strong security culture, minimal “shadow IT”.
  • Security-by-design integrated into every system lifecycle and vendor decision.

D) Skills and Training

Level 1 — Initial

  • Training sporadic or “tick-box”.
  • Staff unsure how GDPR applies to their role; errors common.
  • No clear ownership for capability building.

Level 2 — Developing

  • Basic annual training offered; limited role tailoring.
  • Some specialist knowledge exists (often isolated to DPO/IG lead).
  • Limited induction coverage and low confidence in practice.

Level 3 — Defined

  • Role-based training (HR, marketing, clinical/care, IT, leadership).
  • Induction includes GDPR essentials; refreshers scheduled.
  • Clear guidance for common scenarios (SARs, breaches, sharing, marketing).
  • Competence checks introduced (quizzes, sign-off, spot checks).

Level 4 — Managed

  • Training effectiveness measured (assessment scores, incident correlation).
  • Community of practice established; champions network.
  • Managers accountable for completion and competency.
  • Regular scenario-based exercises and tabletop sessions.

Level 5 — Optimised

  • Continuous learning culture: micro-learning, targeted coaching, just-in-time guidance.
  • Training informed by live risks, audits, near misses, and regulatory themes.
  • Staff demonstrate strong judgment, not just rule recall.
  • High confidence across organisation; reduced incidents and faster responses.

E) Incident / Breach Management

Level 1 — Initial

  • No clear breach definition or reporting route.
  • Incidents discovered late; responses chaotic.
  • Reporting decisions undocumented; notifications often missed.

Level 2 — Developing

  • Basic breach procedure exists; some staff awareness.
  • Manual reporting and triage; inconsistent risk assessment.
  • Limited post-incident learning.

Level 3 — Defined

  • Clear incident management workflow: detect → contain → assess → notify → remediate.
  • 72-hour ICO reporting rule understood and operationalised.
  • Breach log maintained; criteria for notifying individuals documented.
  • Communications plan in place (internal + external + processor coordination).

Level 4 — Managed

  • Regular breach drills/tabletops; time-to-containment measured.
  • Root cause analysis standard; corrective actions tracked to closure.
  • Supplier breach reporting obligations tested and enforced.
  • Board/senior oversight for material incidents; trend reporting.

Level 5 — Optimised

  • Near-miss reporting and learning culture; early detection strong.
  • Automation supports monitoring, triage, and evidence capture.
  • Rapid, consistent decisions with high-quality documentation.
  • Systemic improvements reduce recurrence; demonstrable resilience and maturity.

How to Use This GDPR Maturity Matrix (Practical Scoring)

  • Score each domain 1–5 based on best fit.
  • Add brief evidence notes (policies, logs, KPIs, audit results).
  • Prioritise improvements where risk is highest (often rights + security + breaches).
  • Reassess quarterly or biannually to show progress.

You will end up with an overall GDPR maturity score ranging from 1 to 25, and crucially it will highlight were to focus your time and resources.

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial