A board-level, self-assessment instrument prepared by Muchangi Patrick & Associates Advocates — 20 scored requirements, a compliance score band, and a priority action plan.
For each requirement below, record one of four ratings: YES — fully compliant; PARTIAL — a defined gap remains; NO — the requirement is unmet; N/A — not applicable to the organisation's operations. Download the fillable PDF to complete and retain your assessment.
Executive Summary
The Data Protection Act, 2019 requires every data controller and data processor operating in Kenya to implement appropriate legal, organisational and technical measures to protect personal data, and to be able to demonstrate that accountability to the Office of the Data Protection Commissioner ("ODPC"), data subjects and other stakeholders on request. This instrument has been prepared by Muchangi Patrick & Associates Advocates as a practical, board-level self-assessment tool. It enables in-house counsel, compliance officers and senior management to identify compliance gaps against twenty core statutory and regulatory benchmarks, and to prioritise corrective action before those gaps are tested by a supervisory inquiry, an audit, or a data subject complaint.
How to Use This Checklist
This checklist is a diagnostic tool, not a substitute for legal advice. Organisations identifying material gaps should seek a full compliance audit before relying on the results for governance or regulatory reporting purposes.
Data Protection Compliance Assessment
| No. | Requirement | Yes | Partial | No | N/A |
|---|---|---|---|---|---|
| 01 | Privacy governance framework established | ☐ | ☐ | ☐ | ☐ |
| 02 | Data Protection Officer appointed (where required) | ☐ | ☐ | ☐ | ☐ |
| 03 | Organisation registered with the ODPC (where required) | ☐ | ☐ | ☐ | ☐ |
| 04 | Records of processing activities maintained | ☐ | ☐ | ☐ | ☐ |
| 05 | Personal data inventory completed | ☐ | ☐ | ☐ | ☐ |
| 06 | Lawful basis identified for each processing activity | ☐ | ☐ | ☐ | ☐ |
| 07 | Privacy Notice published | ☐ | ☐ | ☐ | ☐ |
| 08 | Valid consent obtained where required | ☐ | ☐ | ☐ | ☐ |
| 09 | Procedures exist for handling data subject requests | ☐ | ☐ | ☐ | ☐ |
| 10 | Children\'s personal data appropriately protected | ☐ | ☐ | ☐ | ☐ |
| 11 | Sensitive personal data receives additional safeguards | ☐ | ☐ | ☐ | ☐ |
| 12 | Appropriate technical and organisational security measures implemented | ☐ | ☐ | ☐ | ☐ |
| 13 | Processor agreements executed with third parties | ☐ | ☐ | ☐ | ☐ |
| 14 | Cross-border data transfers comply with legal requirements | ☐ | ☐ | ☐ | ☐ |
| 15 | Data Protection Impact Assessments conducted where required | ☐ | ☐ | ☐ | ☐ |
| 16 | Personal data breach response plan established | ☐ | ☐ | ☐ | ☐ |
| 17 | Data retention and secure disposal procedures implemented | ☐ | ☐ | ☐ | ☐ |
| 18 | Employees receive regular privacy training | ☐ | ☐ | ☐ | ☐ |
| 19 | AI systems processing personal data are governed appropriately | ☐ | ☐ | ☐ | ☐ |
| 20 | Periodic privacy compliance audits are conducted | ☐ | ☐ | ☐ | ☐ |
Compliance Score
Aggregate the ratings above to determine the organisation's overall compliance posture:
| Score | Assessment |
|---|---|
| 18 – 20 | Excellent Compliance |
| 15 – 17 | Good Compliance |
| 11 – 14 | Moderate Compliance --- Improvements Required |
| 0 – 10 | Significant Compliance Gaps |
Priority Action Plan
Corrective actions identified during the assessment should be recorded and tracked to closure, assigned by priority (High / Medium / Low) to a named responsible officer with a target date — see the fillable PDF for a ready-made tracking table.
Overall Assessment
Record an overall rating of Excellent, Good, Moderate/Fair or Poor, together with the auditor's notes, in the space provided in the fillable PDF.
