MP Muchangi Patrick& Associates Advocates
Talk to an Expert
Practice Areas Case Digest Knowledge Centre Insights About Contact Talk to an Expert
Compliance Toolkit/Data Breach Response Checklist
KPLR/CHK/005/2026 Standalone Checklist Incident Response
Compliance Toolkit · Standalone Checklist

Data Breach Response Checklist

An Incident Readiness & Response Guide

Prepared by
Muchangi Patrick & Co. Advocates
Published
July 2026
Format
24 items · Fillable PDF
Version
1.0
Editorial Status
Published
Language
English
Abstract

A board-level, self-assessment instrument prepared by Muchangi Patrick & Associates Advocates — 24 scored requirements, a compliance score band, and a priority action plan.

How to Use This Checklist

For each requirement below, record one of four ratings: YES — fully compliant; PARTIAL — a defined gap remains; NO — the requirement is unmet; N/A — not applicable to the organisation's operations. Download the fillable PDF to complete and retain your assessment.

Executive Summary

Section 43 of the Data Protection Act, 2019 requires a data controller to notify the Office of the Data Protection Commissioner within seventy-two hours of becoming aware of a breach likely to result in risk to the rights and freedoms of data subjects, and to notify affected data subjects without undue delay in appropriate cases. This checklist has been prepared by Muchangi Patrick & Associates Advocates to assess an organisation\'s breach readiness and to guide the practical steps to be taken during detection, containment, assessment, notification and post-incident review.

How to Use This Checklist

This checklist is a diagnostic tool, not a substitute for legal advice. Organisations identifying material gaps should seek a full compliance audit before relying on the results for governance or regulatory reporting purposes.

Breach Readiness & Response Assessment

No.RequirementYesPartialNoN/A
01Data breach response plan or policy documented☐☐☐☐
02Incident response team identified with defined roles and responsibilities☐☐☐☐
03Breach detection and monitoring mechanisms in place☐☐☐☐
04Employees know how to report a suspected breach internally☐☐☐☐
05Breach reporting channel and contact clearly communicated☐☐☐☐
06Initial assessment of a suspected breach conducted promptly☐☐☐☐
07Breach contained to prevent further unauthorised access or loss☐☐☐☐
08Scope and nature of the breach determined (data, subjects and volume affected)☐☐☐☐
09Risk to the rights and freedoms of affected data subjects assessed☐☐☐☐
10Decision on notification to the ODPC made and documented☐☐☐☐
11ODPC notified within seventy-two hours where required☐☐☐☐
12Affected data subjects notified without undue delay where required☐☐☐☐
13Notification includes the nature of the breach, likely consequences and measures taken☐☐☐☐
14Law enforcement notified where criminal conduct is suspected☐☐☐☐
15Evidence relating to the breach preserved☐☐☐☐
16Root cause of the breach investigated☐☐☐☐
17Remedial and corrective measures implemented☐☐☐☐
18Processors\' breach notification obligations to the controller confirmed☐☐☐☐
19Insurance provider notified where cyber insurance is in place☐☐☐☐
20Internal breach register or log maintained☐☐☐☐
21Communications with media and stakeholders managed appropriately☐☐☐☐
22Post-incident review conducted☐☐☐☐
23Breach response plan updated based on lessons learned☐☐☐☐
24Staff retrained following the incident where necessary☐☐☐☐

Compliance Score

Aggregate the ratings above to determine the organisation's overall compliance posture:

ScoreAssessment
22 – 24Excellent
17 – 21Good
10 – 16Fair
0 – 9Immediate Remediation Required

Priority Action Plan

Corrective actions identified during the assessment should be recorded and tracked to closure, assigned by priority (High / Medium / Low) to a named responsible officer with a target date — see the fillable PDF for a ready-made tracking table.

Overall Assessment

Record an overall rating of Excellent, Good, Moderate/Fair or Poor, together with the auditor's notes, in the space provided in the fillable PDF.

Disclaimer: This checklist is a diagnostic tool, not a substitute for legal advice. Organisations identifying material gaps should seek a full compliance audit before relying on the results for governance or regulatory reporting purposes. Reading this publication does not create an advocate-client relationship with Muchangi Patrick & Associates Advocates. For advice on a specific matter, please book a consultation.
PM

Patrick Muchangi

Advocate of the High Court of Kenya · Founder, Muchangi Patrick & Associates Advocates

Patrick Muchangi is an Advocate of the High Court of Kenya and founder of Muchangi Patrick & Associates Advocates, a Nairobi practice specialising in data protection, privacy, AI governance and technology law, and editor of the Kenya Privacy Law Review.