A board-level, self-assessment instrument prepared by Muchangi Patrick & Associates Advocates — 30 scored requirements, a compliance score band, and a priority action plan.
For each requirement below, record one of four ratings: YES — fully compliant; PARTIAL — a defined gap remains; NO — the requirement is unmet; N/A — not applicable to the organisation's operations. Download the fillable PDF to complete and retain your assessment.
Executive Summary
A website is often the first point at which an organisation collects personal data. Whether through contact forms, cookies, newsletters, recruitment portals, analytics tools, payment gateways or user accounts, websites must comply with the Data Protection Act, 2019 and applicable Regulations. This checklist has been prepared by Muchangi Patrick & Associates Advocates to enable organisations to conduct a high-level assessment of their website\'s legal, privacy and cybersecurity compliance across thirty practical benchmarks spanning notice, consent, security and governance.
How to Use This Checklist
This checklist is a diagnostic tool, not a substitute for legal advice. Organisations identifying material gaps should seek a full compliance audit before relying on the results for governance or regulatory reporting purposes.
Website Compliance Assessment
| No. | Requirement | Yes | Partial | No | N/A |
|---|---|---|---|---|---|
| 01 | Website has a published Privacy Notice | ☐ | ☐ | ☐ | ☐ |
| 02 | Privacy Notice is easy to locate | ☐ | ☐ | ☐ | ☐ |
| 03 | Privacy Notice explains what personal data is collected | ☐ | ☐ | ☐ | ☐ |
| 04 | Purpose of processing is clearly stated | ☐ | ☐ | ☐ | ☐ |
| 05 | Legal basis for processing is identified | ☐ | ☐ | ☐ | ☐ |
| 06 | Contact details of the organisation are provided | ☐ | ☐ | ☐ | ☐ |
| 07 | Contact details of the Data Protection Officer are provided (where applicable) | ☐ | ☐ | ☐ | ☐ |
| 08 | Data subject rights are explained | ☐ | ☐ | ☐ | ☐ |
| 09 | Cookie Notice is available | ☐ | ☐ | ☐ | ☐ |
| 10 | Cookie consent mechanism is implemented | ☐ | ☐ | ☐ | ☐ |
| 11 | Users can reject non-essential cookies | ☐ | ☐ | ☐ | ☐ |
| 12 | Contact forms collect only necessary information | ☐ | ☐ | ☐ | ☐ |
| 13 | Newsletter subscriptions obtain valid consent | ☐ | ☐ | ☐ | ☐ |
| 14 | Website uses HTTPS | ☐ | ☐ | ☐ | ☐ |
| 15 | SSL certificate is valid | ☐ | ☐ | ☐ | ☐ |
| 16 | Password-protected areas are secure | ☐ | ☐ | ☐ | ☐ |
| 17 | Third-party plugins are regularly updated | ☐ | ☐ | ☐ | ☐ |
| 18 | Website software is regularly updated | ☐ | ☐ | ☐ | ☐ |
| 19 | Appropriate access controls exist | ☐ | ☐ | ☐ | ☐ |
| 20 | Website backups are performed regularly | ☐ | ☐ | ☐ | ☐ |
| 21 | Personal data retention period is disclosed | ☐ | ☐ | ☐ | ☐ |
| 22 | Cross-border transfers are disclosed where applicable | ☐ | ☐ | ☐ | ☐ |
| 23 | Third-party services (Google Analytics, Meta Pixel, etc.) are disclosed | ☐ | ☐ | ☐ | ☐ |
| 24 | Terms and Conditions are available | ☐ | ☐ | ☐ | ☐ |
| 25 | Accessibility features are considered | ☐ | ☐ | ☐ | ☐ |
| 26 | Website includes a copyright notice | ☐ | ☐ | ☐ | ☐ |
| 27 | Security headers are implemented | ☐ | ☐ | ☐ | ☐ |
| 28 | Forms include anti-spam protection | ☐ | ☐ | ☐ | ☐ |
| 29 | Data breach response procedure exists | ☐ | ☐ | ☐ | ☐ |
| 30 | Website undergoes periodic compliance reviews | ☐ | ☐ | ☐ | ☐ |
Compliance Score
Aggregate the ratings above to determine the organisation's overall compliance posture:
| Score | Assessment |
|---|---|
| 27 – 30 | Excellent |
| 22 – 26 | Good |
| 16 – 21 | Fair |
| 0 – 15 | Immediate Remediation Required |
Priority Action Plan
Corrective actions identified during the assessment should be recorded and tracked to closure, assigned by priority (High / Medium / Low) to a named responsible officer with a target date — see the fillable PDF for a ready-made tracking table.
Overall Assessment
Record an overall rating of Excellent, Good, Moderate/Fair or Poor, together with the auditor's notes, in the space provided in the fillable PDF.
