GDPR Milestone · General Data Protection Regulation
Your GDPR compliance, measured article by article and turned into a costed action plan.
10 themes, a 5-level scale. And the action that moves each level to the next.
The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.
GDPR Milestone · General Data Protection Regulation
10 themes, 5-level scale.
Nordhavn Industries
53 / 100
They measure their maturity with Datamensio
An example
This could be your situation.
Take one company as an example: three sites, three spreadsheets, no shared answer.
Nobody can consolidate.
Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.
Three weeks, a single base.
One Regulation (EU) 2016/679, applicable since 25 May 2018 assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.
Two costs avoided before being committed.
A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.
What it saved them
- 3sites measured on the same base, instead of three questionnaires to reconcile
- 2duplicate actions caught before the spend
- 1committee report, with no manual rework
These figures are an example. They could be yours.
The standard imposes processes. Datamensio says where you stand.
01
The framework is already written
Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.
02
The score lands the same day
Online, by self-assessment link or in interview. Theme by theme, comparable over time.
03
The gap becomes a costed plan
Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.
04
Progress can be demonstrated
Campaign after campaign, against your target and against your own past. That is what your board asks for.
The maturity scale
One level, the next, and the action that links the two.
It’s this mechanism (a level, a level above, and the action linking the two) that turns a finding into a trajectory.
Are the defined retention periods actually applied in the systems?
- N1
No retention period is defined. Data is kept without any age limit and no purge is documented.
- N2
Retention periods appear in the register, but no purge mechanism is in place. Deletion remains manual and exceptional.
- N3
Retention periods are applied to the main processing activities, through automated purge or archiving. A few peripheral applications remain out of scope.
- N4
Retention periods are applied systematically across all processing activities, with execution evidence kept and gaps addressed.
- N5
Retention periods are reviewed periodically against usage and legal obligations, with documented tracking of revisions and a planned internal control.
Action to move from L2 to L3
Select the processing activities holding the largest volumes of personal data, define an executable purge or archiving rule with the application owners, schedule it in the systems and check its execution at the quarterly compliance committee.
« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »

Director, CCI 94CCI Île-de-France
« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »

Maja SucekChief Operating Officer, Interreg Danube
Rarely on its own
Frameworks combine. Put several together to cover your business, or have the AI write yours.
Take your first measurementon GDPR.
What this framework covers
Regulation (EU) 2016/679 has been applicable since 25 May 2018. It does more than prohibit or permit: it requires demonstration. The data controller must be able to prove at any time that the principles of Article 5 are being respected, keep the register required under Article 30, document the legal basis for each processing activity, inform data subjects, respond to their rights within the deadlines, notify breaches within 72 hours and carry out an impact assessment when processing presents a high risk. The obligation covers the practice as much as the proof of that practice.
It’s this requirement for proof that makes GDPR difficult to steer day to day. Does the register reflect the processing activities actually running in production, or the snapshot taken during the original compliance project? Are retention periods applied in the systems, or only written in a column? Is an erasure request sent to customer service logged, qualified and handled within the month? Many organisations have solid documentation and uneven execution across entities and business functions.
Two developments have shifted the effort. Litigation over transfers outside the European Union has made mapping of processors and hosting locations far more structuring than it was in 2018. And the rise of artificial intelligence uses has put data protection back at the centre: model training, input data, minimisation, information for data subjects. The most common confusion is still treating GDPR as a closed project, when the regulation describes a permanent setup that must evolve alongside new processing activities.
The maturity assessment answers a different question from a compliance audit. An audit concludes with a gap or a pass on a given requirement. The assessment places each practice on a progressive scale and points to the precise action that moves it up a level. GDPR carries no certification, so maturity is the only language that allows entities to be compared, progress to be tracked over time, and a compliance budget to be arbitrated.
In Datamensio, the framework is ready to use. You can adapt it to your context: the AI adjusts the themes, questions and levels, or builds a version from your own policies, registers and internal procedures.
Reference standard: Regulation (EU) 2016/679, applicable since 25 May 2018
The themes assessed
Governance and roles
Appointment and positioning of the DPO, resources allocated, network of correspondents, coordination with legal and security, reporting to management.
Register of processing activities
Completeness and freshness of the register, controller or processor qualification, purposes, categories of data and data subjects, update process.
Lawfulness and legal bases
Legal basis documented per processing activity, consent management and withdrawal, balancing tests for legitimate interest, processing of special category data.
Information and data subject rights
Privacy notices and policies, channels for receiving requests, qualification, traceability, compliance with the one-month deadline, rate of requests closed.
Minimisation and retention periods
Retention policy per processing activity, effective application of purges and archiving in systems, pseudonymisation, control of test data sets.
Security of processing
Technical and organisational measures under Article 32, access rights management, encryption, logging, periodic testing and reviews.
Data breaches
Detection and qualification procedure, breach register, decision to notify the authority within 72 hours, informing data subjects, lessons learned.
Impact assessments and privacy by design
Criteria triggering a DPIA, methodology and validation, integration of privacy by design into projects and architecture committees.
Processors and transfers
Mapping of processors and sub-processors, Article 28 clauses, audits, hosting location, safeguards for transfers outside the European Union.
Awareness and continuous improvement
Training for exposed business functions, planned internal controls, indicators, tracking of the action plan and comparison over time.
A short version of the framework is available for the online self-assessment.
Frequently asked questions
Is GDPR certifiable?
No. The regulation provides for certification mechanisms on defined scopes, but there is no certificate of overall GDPR compliance. Datamensio measures the maturity of your setup and prepares you for inspections, it does not issue any attestation.
What’s the difference between this assessment and a compliance audit?
An audit rules requirement by requirement and concludes with a gap or a pass. The assessment places each practice on a maturity scale and points to the action that moves it up a level. The two are complementary: the assessment prepares and prioritises, the audit validates.
How long does the assessment take?
The short version can be completed in a single working session. The full version, run collaboratively with the DPO, legal, security and business functions, typically takes one to two weeks, most of the time being spent gathering evidence.
Can the framework be adapted to our organisation?
Yes. The themes, questions and levels can be modified, and you can add your own internal or sector-specific requirements. The AI can also generate a version based on your existing policies and register.
How can we compare several subsidiaries or business units?
The same framework is rolled out to each entity, making scores comparable by theme. The benchmark positions each business unit against the others and against its own previous assessment. A cross-entity roadmap then consolidates the shared actions.
Does the assessment cover our artificial intelligence uses?
The lawfulness, minimisation and impact assessment themes cover processing that feeds models. Questions can be extended to cover a specific use case, such as training, input data or information for data subjects.
Do respondents need legal expertise?
The questions focus on practices and their traceability, not on interpreting the text. A DPO or compliance manager can answer them without difficulty. Collaborative mode allows technical questions to be assigned to the relevant correspondent.
Where is the data hosted?
In France, at OVH, with backup at Scaleway. No transfers outside the European Union. The AI models used can be selected, including from European providers.




