Compliance Toolkit/DPIA Checklist
KPLR/CHK/003/2026 Standalone Checklist Data Protection Impact Assessments
Compliance Toolkit · Standalone Checklist

DPIA Checklist

A Practical Screening & Assessment Guide

Prepared by
Muchangi Patrick & Co. Advocates
Published
July 2026
Format
24 items · Fillable PDF
Version
1.0
Editorial Status
Published
Language
English
Abstract

A board-level, self-assessment instrument prepared by Muchangi Patrick & Associates Advocates — 24 scored requirements, a compliance score band, and a priority action plan.

How to Use This Checklist

For each requirement below, record one of four ratings: YES — fully compliant; PARTIAL — a defined gap remains; NO — the requirement is unmet; N/A — not applicable to the organisation's operations. Download the fillable PDF to complete and retain your assessment.

Executive Summary

Section 31 of the Data Protection Act, 2019 and the Data Protection (General) Regulations, 2021 require a Data Protection Impact Assessment ("DPIA") to be carried out before undertaking processing that is likely to result in a high risk to the rights and freedoms of data subjects, including new technologies, large-scale processing, systematic monitoring and profiling. This checklist has been prepared by Muchangi Patrick & Associates Advocates to guide organisations through the screening, assessment and documentation stages of a DPIA, from threshold identification to sign-off and periodic review.

How to Use This Checklist

This checklist is a diagnostic tool, not a substitute for legal advice. Organisations identifying material gaps should seek a full compliance audit before relying on the results for governance or regulatory reporting purposes.

Dpia Screening & Assessment

No.RequirementYesPartialNoN/A
01Screening assessment conducted to determine whether a DPIA is required
02Processing involves new technologies or novel uses of personal data
03Processing involves large-scale processing of personal data
04Processing involves systematic monitoring of a publicly accessible area
05Processing involves special (sensitive) categories of personal data at scale
06Processing involves profiling or automated decision-making with legal or significant effects
07Processing involves personal data relating to children
08Processing involves matching or combining datasets from different sources
09Processing involves transfer of personal data outside Kenya
10Nature, scope, context and purposes of the processing described
11Necessity and proportionality of the processing assessed
12Data minimisation principles applied to the processing design
13Risks to the rights and freedoms of data subjects identified
14Likelihood and severity of identified risks assessed
15Measures to mitigate identified risks documented
16Data Protection Officer consulted on the assessment (where applicable)
17Views of data subjects or their representatives sought (where appropriate)
18Processors and third parties involved in the processing identified
19Technical and organisational security measures assessed and documented
20Residual risk after mitigation evaluated
21DPIA outcome and recommendations documented in a formal report
22Senior management or data controller sign-off obtained
23Prior consultation with the ODPC undertaken where high residual risk remains
24DPIA scheduled for periodic review or review upon material change to processing

Compliance Score

Aggregate the ratings above to determine the organisation's overall compliance posture:

ScoreAssessment
22 – 24Excellent
17 – 21Good
10 – 16Fair
0 – 9Immediate Remediation Required

Priority Action Plan

Corrective actions identified during the assessment should be recorded and tracked to closure, assigned by priority (High / Medium / Low) to a named responsible officer with a target date — see the fillable PDF for a ready-made tracking table.

Overall Assessment

Record an overall rating of Excellent, Good, Moderate/Fair or Poor, together with the auditor's notes, in the space provided in the fillable PDF.

Disclaimer: This checklist is a diagnostic tool, not a substitute for legal advice. Organisations identifying material gaps should seek a full compliance audit before relying on the results for governance or regulatory reporting purposes. Reading this publication does not create an advocate-client relationship with Muchangi Patrick & Associates Advocates. For advice on a specific matter, please book a consultation.
PM

Patrick Muchangi

Advocate of the High Court of Kenya · Founder, Muchangi Patrick & Associates Advocates

Patrick Muchangi is an Advocate of the High Court of Kenya and founder of Muchangi Patrick & Associates Advocates, a Nairobi practice specialising in data protection, privacy, AI governance and technology law, and editor of the Kenya Privacy Law Review.