Compliance Toolkit/Website Compliance Audit Checklist
KPLR/CHK/002/2026 Standalone Checklist Websites & Digital Platforms
Compliance Toolkit · Standalone Checklist

Website Compliance Audit Checklist

A Practical Self-Assessment Guide

Prepared by
Muchangi Patrick & Co. Advocates
Published
July 2026
Format
30 items · Fillable PDF
Version
1.0
Editorial Status
Published
Language
English
Abstract

A board-level, self-assessment instrument prepared by Muchangi Patrick & Associates Advocates — 30 scored requirements, a compliance score band, and a priority action plan.

How to Use This Checklist

For each requirement below, record one of four ratings: YES — fully compliant; PARTIAL — a defined gap remains; NO — the requirement is unmet; N/A — not applicable to the organisation's operations. Download the fillable PDF to complete and retain your assessment.

Executive Summary

A website is often the first point at which an organisation collects personal data. Whether through contact forms, cookies, newsletters, recruitment portals, analytics tools, payment gateways or user accounts, websites must comply with the Data Protection Act, 2019 and applicable Regulations. This checklist has been prepared by Muchangi Patrick & Associates Advocates to enable organisations to conduct a high-level assessment of their website\'s legal, privacy and cybersecurity compliance across thirty practical benchmarks spanning notice, consent, security and governance.

How to Use This Checklist

This checklist is a diagnostic tool, not a substitute for legal advice. Organisations identifying material gaps should seek a full compliance audit before relying on the results for governance or regulatory reporting purposes.

Website Compliance Assessment

No.RequirementYesPartialNoN/A
01Website has a published Privacy Notice
02Privacy Notice is easy to locate
03Privacy Notice explains what personal data is collected
04Purpose of processing is clearly stated
05Legal basis for processing is identified
06Contact details of the organisation are provided
07Contact details of the Data Protection Officer are provided (where applicable)
08Data subject rights are explained
09Cookie Notice is available
10Cookie consent mechanism is implemented
11Users can reject non-essential cookies
12Contact forms collect only necessary information
13Newsletter subscriptions obtain valid consent
14Website uses HTTPS
15SSL certificate is valid
16Password-protected areas are secure
17Third-party plugins are regularly updated
18Website software is regularly updated
19Appropriate access controls exist
20Website backups are performed regularly
21Personal data retention period is disclosed
22Cross-border transfers are disclosed where applicable
23Third-party services (Google Analytics, Meta Pixel, etc.) are disclosed
24Terms and Conditions are available
25Accessibility features are considered
26Website includes a copyright notice
27Security headers are implemented
28Forms include anti-spam protection
29Data breach response procedure exists
30Website undergoes periodic compliance reviews

Compliance Score

Aggregate the ratings above to determine the organisation's overall compliance posture:

ScoreAssessment
27 – 30Excellent
22 – 26Good
16 – 21Fair
0 – 15Immediate Remediation Required

Priority Action Plan

Corrective actions identified during the assessment should be recorded and tracked to closure, assigned by priority (High / Medium / Low) to a named responsible officer with a target date — see the fillable PDF for a ready-made tracking table.

Overall Assessment

Record an overall rating of Excellent, Good, Moderate/Fair or Poor, together with the auditor's notes, in the space provided in the fillable PDF.

Disclaimer: This checklist is a diagnostic tool, not a substitute for legal advice. Organisations identifying material gaps should seek a full compliance audit before relying on the results for governance or regulatory reporting purposes. Reading this publication does not create an advocate-client relationship with Muchangi Patrick & Associates Advocates. For advice on a specific matter, please book a consultation.
PM

Patrick Muchangi

Advocate of the High Court of Kenya · Founder, Muchangi Patrick & Associates Advocates

Patrick Muchangi is an Advocate of the High Court of Kenya and founder of Muchangi Patrick & Associates Advocates, a Nairobi practice specialising in data protection, privacy, AI governance and technology law, and editor of the Kenya Privacy Law Review.