MP Muchangi Patrick& Associates Advocates
Talk to an Expert
Practice Areas Case Digest Knowledge Centre Insights About Contact Talk to an Expert
Compliance Toolkit/Data Audit Checklist
KPLR/CHK/006/2026 Standalone Checklist Data Mapping & Governance
Compliance Toolkit · Standalone Checklist

Data Audit Checklist

A Practical Data Mapping & Governance Guide

Prepared by
Muchangi Patrick & Co. Advocates
Published
July 2026
Format
26 items · Fillable PDF
Version
1.0
Editorial Status
Published
Language
English
Abstract

A board-level, self-assessment instrument prepared by Muchangi Patrick & Associates Advocates — 26 scored requirements, a compliance score band, and a priority action plan.

How to Use This Checklist

For each requirement below, record one of four ratings: YES — fully compliant; PARTIAL — a defined gap remains; NO — the requirement is unmet; N/A — not applicable to the organisation's operations. Download the fillable PDF to complete and retain your assessment.

Executive Summary

Periodic data audits enable an organisation to maintain an accurate record of processing activities, identify unknown or unauthorised data flows, and demonstrate accountability in accordance with section 41 of the Data Protection Act, 2019. This checklist has been prepared by Muchangi Patrick & Associates Advocates to guide organisations through a structured data mapping and audit exercise, from data inventory and classification to reporting and remediation.

How to Use This Checklist

This checklist is a diagnostic tool, not a substitute for legal advice. Organisations identifying material gaps should seek a full compliance audit before relying on the results for governance or regulatory reporting purposes.

Data Audit Assessment

No.RequirementYesPartialNoN/A
01All personal data holdings identified and catalogued☐☐☐☐
02Data inventory or map covering all departments completed☐☐☐☐
03Categories of data subjects identified☐☐☐☐
04Categories of personal data identified, including special categories☐☐☐☐
05Sources of personal data documented☐☐☐☐
06Purpose of collection recorded for each data category☐☐☐☐
07Lawful basis identified for each processing activity☐☐☐☐
08Data flows within the organisation mapped☐☐☐☐
09Data flows to external third parties mapped☐☐☐☐
10Cross-border data transfers identified and documented☐☐☐☐
11Data storage locations identified (on-premise, cloud or hybrid)☐☐☐☐
12Data retention periods defined for each data category☐☐☐☐
13Data disposal and secure deletion procedures verified☐☐☐☐
14Processor and sub-processor relationships identified☐☐☐☐
15Data processing agreements in place with all processors☐☐☐☐
16Access controls reviewed for each data repository☐☐☐☐
17Data quality and accuracy controls assessed☐☐☐☐
18Legacy or orphaned data systems identified☐☐☐☐
19Shadow IT and unauthorised data repositories investigated☐☐☐☐
20Records of Processing Activities (ROPA) updated☐☐☐☐
21Data protection risks identified during the audit☐☐☐☐
22Findings compared against the previous audit cycle☐☐☐☐
23Remedial actions assigned with owners and timelines☐☐☐☐
24Audit findings reported to senior management or the board☐☐☐☐
25Data audit methodology and scope documented☐☐☐☐
26Next audit cycle scheduled☐☐☐☐

Compliance Score

Aggregate the ratings above to determine the organisation's overall compliance posture:

ScoreAssessment
23 – 26Excellent
18 – 22Good
11 – 17Fair
0 – 10Immediate Remediation Required

Priority Action Plan

Corrective actions identified during the assessment should be recorded and tracked to closure, assigned by priority (High / Medium / Low) to a named responsible officer with a target date — see the fillable PDF for a ready-made tracking table.

Overall Assessment

Record an overall rating of Excellent, Good, Moderate/Fair or Poor, together with the auditor's notes, in the space provided in the fillable PDF.

Disclaimer: This checklist is a diagnostic tool, not a substitute for legal advice. Organisations identifying material gaps should seek a full compliance audit before relying on the results for governance or regulatory reporting purposes. Reading this publication does not create an advocate-client relationship with Muchangi Patrick & Associates Advocates. For advice on a specific matter, please book a consultation.
PM

Patrick Muchangi

Advocate of the High Court of Kenya · Founder, Muchangi Patrick & Associates Advocates

Patrick Muchangi is an Advocate of the High Court of Kenya and founder of Muchangi Patrick & Associates Advocates, a Nairobi practice specialising in data protection, privacy, AI governance and technology law, and editor of the Kenya Privacy Law Review.