Compliance Toolkit/Data Breach Response Checklist
KPLR/CHK/005/2026 Standalone Checklist Incident Response
Compliance Toolkit · Standalone Checklist

Data Breach Response Checklist

An Incident Readiness & Response Guide

Prepared by
Muchangi Patrick & Co. Advocates
Published
July 2026
Format
24 items · Fillable PDF
Version
1.0
Editorial Status
Published
Language
English
Abstract

A board-level, self-assessment instrument prepared by Muchangi Patrick & Associates Advocates — 24 scored requirements, a compliance score band, and a priority action plan.

How to Use This Checklist

For each requirement below, record one of four ratings: YES — fully compliant; PARTIAL — a defined gap remains; NO — the requirement is unmet; N/A — not applicable to the organisation's operations. Download the fillable PDF to complete and retain your assessment.

Executive Summary

Section 43 of the Data Protection Act, 2019 requires a data controller to notify the Office of the Data Protection Commissioner within seventy-two hours of becoming aware of a breach likely to result in risk to the rights and freedoms of data subjects, and to notify affected data subjects without undue delay in appropriate cases. This checklist has been prepared by Muchangi Patrick & Associates Advocates to assess an organisation\'s breach readiness and to guide the practical steps to be taken during detection, containment, assessment, notification and post-incident review.

How to Use This Checklist

This checklist is a diagnostic tool, not a substitute for legal advice. Organisations identifying material gaps should seek a full compliance audit before relying on the results for governance or regulatory reporting purposes.

Breach Readiness & Response Assessment

No.RequirementYesPartialNoN/A
01Data breach response plan or policy documented
02Incident response team identified with defined roles and responsibilities
03Breach detection and monitoring mechanisms in place
04Employees know how to report a suspected breach internally
05Breach reporting channel and contact clearly communicated
06Initial assessment of a suspected breach conducted promptly
07Breach contained to prevent further unauthorised access or loss
08Scope and nature of the breach determined (data, subjects and volume affected)
09Risk to the rights and freedoms of affected data subjects assessed
10Decision on notification to the ODPC made and documented
11ODPC notified within seventy-two hours where required
12Affected data subjects notified without undue delay where required
13Notification includes the nature of the breach, likely consequences and measures taken
14Law enforcement notified where criminal conduct is suspected
15Evidence relating to the breach preserved
16Root cause of the breach investigated
17Remedial and corrective measures implemented
18Processors\' breach notification obligations to the controller confirmed
19Insurance provider notified where cyber insurance is in place
20Internal breach register or log maintained
21Communications with media and stakeholders managed appropriately
22Post-incident review conducted
23Breach response plan updated based on lessons learned
24Staff retrained following the incident where necessary

Compliance Score

Aggregate the ratings above to determine the organisation's overall compliance posture:

ScoreAssessment
22 – 24Excellent
17 – 21Good
10 – 16Fair
0 – 9Immediate Remediation Required

Priority Action Plan

Corrective actions identified during the assessment should be recorded and tracked to closure, assigned by priority (High / Medium / Low) to a named responsible officer with a target date — see the fillable PDF for a ready-made tracking table.

Overall Assessment

Record an overall rating of Excellent, Good, Moderate/Fair or Poor, together with the auditor's notes, in the space provided in the fillable PDF.

Disclaimer: This checklist is a diagnostic tool, not a substitute for legal advice. Organisations identifying material gaps should seek a full compliance audit before relying on the results for governance or regulatory reporting purposes. Reading this publication does not create an advocate-client relationship with Muchangi Patrick & Associates Advocates. For advice on a specific matter, please book a consultation.
PM

Patrick Muchangi

Advocate of the High Court of Kenya · Founder, Muchangi Patrick & Associates Advocates

Patrick Muchangi is an Advocate of the High Court of Kenya and founder of Muchangi Patrick & Associates Advocates, a Nairobi practice specialising in data protection, privacy, AI governance and technology law, and editor of the Kenya Privacy Law Review.