Skip to content
Structured PM Structure you can stand on

The roadmap

Every step, and what it leaves behind

This is the whole programme written out. Ten steps in a fixed order, and the 33 documents they produce between them.

Nothing here is a summary of something you get told later. If you want to know what step seven actually hands you, it is on this page.

Before you start

How the programme runs

The sequence is fixed

Each step uses what the one before it produced. Step three needs the map from step one to be right.

The pace is yours

You decide when the next step starts. There is no schedule you fall behind on.

Every step finishes

You get documents at the end of each one, not at the end of the programme.

Both routes, same steps

Self-Serve and Guided run this identical list. The difference is who checks the work.

Step zero · free

Find out where you stand first

Before any of the ten steps, there is a step zero. It costs nothing and it exists so you can decide whether to carry on with something in your hands rather than on a promise.

You keep what it produces whichever route you pick, and if you pick neither.

What it leaves behind
  • A written summary of what you already have
  • The gaps a client or a regulator would find first
  • A recommended order of work for your business
  • Which of the two routes suits you, or whether you need neither
Stage 01 · steps 01 to 02

Know what you hold

You cannot write a rule about data you have not found. These two steps establish what the business holds, where it sits, and what you have already told people about it.

01

Data mapping

The record everything after this reads from.

What it leaves behind
  • Record of processing activities
  • Inventory of your systems and suppliers
  • A map of how data moves through the business
  • A risk rating for each set of data
02

Privacy notices

What you tell people about their data, matching what you actually do.

What it leaves behind
  • Privacy notice for customers and the public
  • Privacy notice for staff
  • Cookie policy and a consent banner that works
Stage 02 · steps 03 to 05

Answer for it

Every piece of data you hold needs a reason, a contract behind it where someone else touches it, and a way for people to ask what you have.

03

Lawful basis and consent

Why you are allowed to hold each set of data.

What it leaves behind
  • A register of the lawful basis for each activity
  • An audit of how consent is captured, and a rebuild where it fails
  • Legitimate interests assessments where that is the reason
04

Processors and transfers

The suppliers and tools that touch your data on your behalf.

What it leaves behind
  • A register of processors with a risk score for each
  • A data processing agreement template
  • A transfer risk assessment where data leaves the UK
05

Individual rights

What happens when someone asks what you hold, or asks you to delete it.

What it leaves behind
  • A written procedure with the one month deadline tracked
  • Response templates covering all eight rights
  • A request log and a way to verify who is asking
Stage 03 · steps 06 to 08

Operate it

Three steps that turn the paperwork into something your team runs on a normal Tuesday, and on the worst day of the year.

06

Retention and acceptable use

How long you keep things, who deletes them, and the rules for your systems.

What it leaves behind
  • Data protection policy
  • Retention and deletion schedule
  • Acceptable use policy for your systems
07

Breach response

The worst day, decided in advance rather than at the time.

What it leaves behind
  • A response plan with a decision tree
  • The 72 hour notification pack for the ICO
  • Templates for telling the people affected
  • An internal incident register
08

Security and staff awareness

The controls, and the people who have to use them.

What it leaves behind
  • Information security policy
  • Staff training programme with an attendance record
  • An annual security self assessment
Stage 04 · steps 09 to 10

Prove it

The last two steps are about evidence: catching risky work before it starts, and being able to show the whole thing to someone who asks.

09

DPIA and high risk work

Spotting the work that needs checking before it begins.

What it leaves behind
  • A screening questionnaire and assessment framework
  • A register of high risk processing
  • Two completed assessments for work you are doing now
10

The StepWise Seal

Everything gathered, signed off and dated.

What it leaves behind
  • A dated record that the ten steps are complete, with the evidence behind it
  • Sign off on every documented process
  • A log of what is automated and how
  • The evidence pack you send when someone asks

What you are holding at the end

Not a folder of templates. A set of written processes with a named owner on each one, and the evidence that they are being followed.

10

Steps, in a fixed order, each one finishing in something you can use.

33

Documents, registers and procedures, written against how your business works.

4

Stages of work, so you always know which part of the job you are in.

Note on the Seal

The StepWise Seal is a dated record of completion and the evidence behind it. That is the whole of what it is, and we do not describe it as anything more. Under Articles 42 and 43 of the UK GDPR, formal certification comes from UKAS-accredited bodies working to ICO-approved criteria. We are not one, and the Seal is not that.

What this page does not say

There are no prices here. Both routes run this same list, so putting figures beside each step would only invite you to add them up in a way that matches neither route. Every number is on the StepWise page, in one place, once.


Which of these do you already have?

Thirty minutes on a call and you will know which steps are already done in your business, which are half done, and where to start.

Book a 30 minute call