UK organisations still falling short on GDPR compliance, benchmark report finds
John E. Kaye
- Published
- News, Technology

Analysis of more than 60 organisations shows widespread gaps in privacy by design, accountability and data subject rights across multiple sectors
UK organisations continue to show significant weaknesses in core data protection practices, particularly in privacy by design and accountability, according to a new study.
The GDPR Benchmark Report 2025, published by GRC Solutions, analyses GDPR gap-assessment data from more than 60 organisations across eight sectors.
Despite the General Data Protection Regulation entering its eighth year of enforcement, many organisations were found to remain at a “limited” or “developing” level of assurance across key control areas.
The report evaluates performance across nine GDPR control areas including governance, risk management, information management system maturity, defined roles and responsibilities, personal information management system (PIMS) implementation and data subject rights.
Technology companies outperform other sectors, supported by widespread adoption of ISO 27001 and ISO 27701, in-house expertise and established privacy and compliance functions.
Even in this sector, however, privacy by design remains in the “developing” range, suggesting ongoing difficulty in embedding data protection into systems and products at the design stage.
Construction and manufacturing show among the lowest levels of GDPR maturity. Construction organisations score well in governance and risk management but perform poorly in privacy by design, PIMS and data subject rights. Manufacturing records the lowest sector score in the report, with 3.9 out of 10 for data subject rights.
Heavily regulated sectors also show gaps. In finance, GDPR responsibilities are often absorbed into broader compliance functions, resulting in weak scores for privacy by design, PIMS and training, despite stronger performance in risk management and data subject rights. And health sector organisations show low scores for scope of compliance, often linked to weak contract management and limited due diligence on third parties.
Hospitality, retail and public and non-profit organisations also continue to struggle, according to the findings. Performance in hospitality and retail is described as highly variable, while the public and non-profit sector records some of the lowest scores in the report for information management system maturity.
Nearly a third (30 per cent) of UK charities experienced a cyber attack in the past year, citing the UK Government Cyber Security Breaches Survey 2025, the report adds.
Across all sectors, the report identifies three recurring weaknesses: lack of formal responsibility and accountability for GDPR activities, insufficient training and awareness, and poorly implemented or non-existent PIMS programmes.
Louise Brooks, the Head of Privacy Consultancy at GRC Solutions, said: “Due diligence on third parties is often lacking which means organisations have limited assurance that any personal data accessed by those partners will be handled securely.
“Getting this right clarifies roles and responsibilities, reduces the likelihood of incidents and personal data breaches and protects organisations from liability.”
She added: “When resources are limited, we often see organisations cut compliance budgets first but this is short-sighted. Data protection and information security compliance have never been more important.”
READ MORE: ‘Cracking open the black box: why AI-powered cybersecurity still needs human eyes’. As phishing threats accelerate, the next stage of defence requires transparent systems, accountable decision-making, and AI that is continually strengthened through human verification.
Do you have news to share or expertise to contribute? The European welcomes insights from business leaders and sector specialists. Get in touch with our editorial team to find out more.
Main image: Element5 Digital/Pexels
RECENT ARTICLES
-
People act more rationally when they think they are dealing with AI, study finds -
Toxic bosses may thrive at work, but the office pays the price, new research finds -
Europe launches ‘anti-kill switch’ cloud shield as Trump fears grip Brussels -
Starmer summons social media chiefs to Downing Street over child safety -
The European Spring 2026 edition – out now -
Inside Qantas’ new ultra-long-haul A350s with stretch zone, jet lag lighting and fewer seats -
Landmark UK nuclear deal to cut reliance on foreign energy after Middle East tensions -
Breitling launches £9,500 Artemis II watch as Moon crew returns to Earth -
Ivy and Annabel’s owner agrees £1.4bn sale of hospitality empire to Abu Dhabi-backed buyer -
Orbán concedes defeat as Péter Magyar heads for sweeping Hungary election victory -
UAE unveils plans for major new military rescue training centre -
Electric air taxis move closer after aircraft completes key in-flight switch -
World’s largest cruise ship revealed with nine pools, 28 places to eat and giant waterpark -
Artemis II crew break Apollo 13 record for farthest human spaceflight -
Starmer uses Easter message to stress hope, service and national renewal -
‘Houston, we have a problem’: astronauts fix loo aboard Artemis II -
EU moves to make Europe’s tinderbox landscapes less prone to wildfire -
Artemis II lifts off for Moon mission – here is what the astronauts will be doing day by day -
GITEX Africa Morocco to host 1,450 exhibitors and startups as Marrakech event sharpens focus on AI and digital sovereignty -
Artemis II countdown begins as astronauts prepare for first crewed Moon mission in 50 years -
United to introduce economy seat row that converts into couch on long-haul flights from 2027 -
Australia tops global ranking of the world’s most beautiful airport landings -
Ivo Klein takes over Liechtenstein bankers’ body after nine-year handover -
EXCLUSIVE: LA unveils Ghostbusters-style car to fight post-wildfire ‘toxic soup’ -
Supermarkets move to end sale of live lobsters and crabs ahead of UK ban


























