This paper discusses the maturity of data protection and privacy measures in order to develop a better understanding of the importance and impacts of this domain. The practical relevance of this topic is that the General Data Protection Regulation provides that data controllers in EU Member States shall comply with uniform data protection rules. Even though European legislation sets detailed requirements for data controllers, the implementation of appropriate technical and organisational measures can be realised at different levels of maturity. Based on the analysis of the pertinent literature, various maturity models are available to assess privacy policies, but GDPR requirements are addressed just partially. The exploration of the issue of maturity offers a new relevant research opportunity to assist data controllers in finding the appropriate methodology for the assessment and further development of their data protection measures. This paper has three main objectives. First, to systematically review the relevant literature on the issue of maturity. Second, to analyse the relevant maturity models and their main methodological elements. Third, to make suggestions for a new specific model focusing on GDPR requirements.
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.
customersupport@researchsolutions.com
10624 S. Eastern Ave., Ste. A-614
Henderson, NV 89052, USA
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
Copyright © 2025 scite LLC. All rights reserved.
Made with 💙 for researchers
Part of the Research Solutions Family.