Compliance Toolkit/Kenya Data Protection Compliance Checklist
KPLR/CHK/001/2026 Standalone Checklist General Compliance
Compliance Toolkit · Standalone Checklist

Kenya Data Protection Compliance Checklist

An Executive Self-Assessment Instrument

Prepared by
Muchangi Patrick & Co. Advocates
Published
July 2026
Format
20 items · Fillable PDF
Version
1.0
Editorial Status
Published
Language
English
Abstract

A board-level, self-assessment instrument prepared by Muchangi Patrick & Associates Advocates — 20 scored requirements, a compliance score band, and a priority action plan.

How to Use This Checklist

For each requirement below, record one of four ratings: YES — fully compliant; PARTIAL — a defined gap remains; NO — the requirement is unmet; N/A — not applicable to the organisation's operations. Download the fillable PDF to complete and retain your assessment.

Executive Summary

The Data Protection Act, 2019 requires every data controller and data processor operating in Kenya to implement appropriate legal, organisational and technical measures to protect personal data, and to be able to demonstrate that accountability to the Office of the Data Protection Commissioner ("ODPC"), data subjects and other stakeholders on request. This instrument has been prepared by Muchangi Patrick & Associates Advocates as a practical, board-level self-assessment tool. It enables in-house counsel, compliance officers and senior management to identify compliance gaps against twenty core statutory and regulatory benchmarks, and to prioritise corrective action before those gaps are tested by a supervisory inquiry, an audit, or a data subject complaint.

How to Use This Checklist

This checklist is a diagnostic tool, not a substitute for legal advice. Organisations identifying material gaps should seek a full compliance audit before relying on the results for governance or regulatory reporting purposes.

Data Protection Compliance Assessment

No.RequirementYesPartialNoN/A
01Privacy governance framework established
02Data Protection Officer appointed (where required)
03Organisation registered with the ODPC (where required)
04Records of processing activities maintained
05Personal data inventory completed
06Lawful basis identified for each processing activity
07Privacy Notice published
08Valid consent obtained where required
09Procedures exist for handling data subject requests
10Children\'s personal data appropriately protected
11Sensitive personal data receives additional safeguards
12Appropriate technical and organisational security measures implemented
13Processor agreements executed with third parties
14Cross-border data transfers comply with legal requirements
15Data Protection Impact Assessments conducted where required
16Personal data breach response plan established
17Data retention and secure disposal procedures implemented
18Employees receive regular privacy training
19AI systems processing personal data are governed appropriately
20Periodic privacy compliance audits are conducted

Compliance Score

Aggregate the ratings above to determine the organisation's overall compliance posture:

ScoreAssessment
18 – 20Excellent Compliance
15 – 17Good Compliance
11 – 14Moderate Compliance --- Improvements Required
0 – 10Significant Compliance Gaps

Priority Action Plan

Corrective actions identified during the assessment should be recorded and tracked to closure, assigned by priority (High / Medium / Low) to a named responsible officer with a target date — see the fillable PDF for a ready-made tracking table.

Overall Assessment

Record an overall rating of Excellent, Good, Moderate/Fair or Poor, together with the auditor's notes, in the space provided in the fillable PDF.

Disclaimer: This checklist is a diagnostic tool, not a substitute for legal advice. Organisations identifying material gaps should seek a full compliance audit before relying on the results for governance or regulatory reporting purposes. Reading this publication does not create an advocate-client relationship with Muchangi Patrick & Associates Advocates. For advice on a specific matter, please book a consultation.
PM

Patrick Muchangi

Advocate of the High Court of Kenya · Founder, Muchangi Patrick & Associates Advocates

Patrick Muchangi is an Advocate of the High Court of Kenya and founder of Muchangi Patrick & Associates Advocates, a Nairobi practice specialising in data protection, privacy, AI governance and technology law, and editor of the Kenya Privacy Law Review.