A board-level, self-assessment instrument prepared by Muchangi Patrick & Associates Advocates — 26 scored requirements, a compliance score band, and a priority action plan.
For each requirement below, record one of four ratings: YES — fully compliant; PARTIAL — a defined gap remains; NO — the requirement is unmet; N/A — not applicable to the organisation's operations. Download the fillable PDF to complete and retain your assessment.
Executive Summary
Periodic data audits enable an organisation to maintain an accurate record of processing activities, identify unknown or unauthorised data flows, and demonstrate accountability in accordance with section 41 of the Data Protection Act, 2019. This checklist has been prepared by Muchangi Patrick & Associates Advocates to guide organisations through a structured data mapping and audit exercise, from data inventory and classification to reporting and remediation.
How to Use This Checklist
This checklist is a diagnostic tool, not a substitute for legal advice. Organisations identifying material gaps should seek a full compliance audit before relying on the results for governance or regulatory reporting purposes.
Data Audit Assessment
| No. | Requirement | Yes | Partial | No | N/A |
|---|---|---|---|---|---|
| 01 | All personal data holdings identified and catalogued | ☐ | ☐ | ☐ | ☐ |
| 02 | Data inventory or map covering all departments completed | ☐ | ☐ | ☐ | ☐ |
| 03 | Categories of data subjects identified | ☐ | ☐ | ☐ | ☐ |
| 04 | Categories of personal data identified, including special categories | ☐ | ☐ | ☐ | ☐ |
| 05 | Sources of personal data documented | ☐ | ☐ | ☐ | ☐ |
| 06 | Purpose of collection recorded for each data category | ☐ | ☐ | ☐ | ☐ |
| 07 | Lawful basis identified for each processing activity | ☐ | ☐ | ☐ | ☐ |
| 08 | Data flows within the organisation mapped | ☐ | ☐ | ☐ | ☐ |
| 09 | Data flows to external third parties mapped | ☐ | ☐ | ☐ | ☐ |
| 10 | Cross-border data transfers identified and documented | ☐ | ☐ | ☐ | ☐ |
| 11 | Data storage locations identified (on-premise, cloud or hybrid) | ☐ | ☐ | ☐ | ☐ |
| 12 | Data retention periods defined for each data category | ☐ | ☐ | ☐ | ☐ |
| 13 | Data disposal and secure deletion procedures verified | ☐ | ☐ | ☐ | ☐ |
| 14 | Processor and sub-processor relationships identified | ☐ | ☐ | ☐ | ☐ |
| 15 | Data processing agreements in place with all processors | ☐ | ☐ | ☐ | ☐ |
| 16 | Access controls reviewed for each data repository | ☐ | ☐ | ☐ | ☐ |
| 17 | Data quality and accuracy controls assessed | ☐ | ☐ | ☐ | ☐ |
| 18 | Legacy or orphaned data systems identified | ☐ | ☐ | ☐ | ☐ |
| 19 | Shadow IT and unauthorised data repositories investigated | ☐ | ☐ | ☐ | ☐ |
| 20 | Records of Processing Activities (ROPA) updated | ☐ | ☐ | ☐ | ☐ |
| 21 | Data protection risks identified during the audit | ☐ | ☐ | ☐ | ☐ |
| 22 | Findings compared against the previous audit cycle | ☐ | ☐ | ☐ | ☐ |
| 23 | Remedial actions assigned with owners and timelines | ☐ | ☐ | ☐ | ☐ |
| 24 | Audit findings reported to senior management or the board | ☐ | ☐ | ☐ | ☐ |
| 25 | Data audit methodology and scope documented | ☐ | ☐ | ☐ | ☐ |
| 26 | Next audit cycle scheduled | ☐ | ☐ | ☐ | ☐ |
Compliance Score
Aggregate the ratings above to determine the organisation's overall compliance posture:
| Score | Assessment |
|---|---|
| 23 – 26 | Excellent |
| 18 – 22 | Good |
| 11 – 17 | Fair |
| 0 – 10 | Immediate Remediation Required |
Priority Action Plan
Corrective actions identified during the assessment should be recorded and tracked to closure, assigned by priority (High / Medium / Low) to a named responsible officer with a target date — see the fillable PDF for a ready-made tracking table.
Overall Assessment
Record an overall rating of Excellent, Good, Moderate/Fair or Poor, together with the auditor's notes, in the space provided in the fillable PDF.
