MP Muchangi Patrick& Associates Advocates
Talk to an Expert
Practice Areas Case Digest Knowledge Centre Insights About Contact Talk to an Expert
Compliance Toolkit/DPIA Checklist
KPLR/CHK/003/2026 Standalone Checklist Data Protection Impact Assessments
Compliance Toolkit · Standalone Checklist

DPIA Checklist

A Practical Screening & Assessment Guide

Prepared by
Muchangi Patrick & Co. Advocates
Published
July 2026
Format
24 items · Fillable PDF
Version
1.0
Editorial Status
Published
Language
English
Abstract

A board-level, self-assessment instrument prepared by Muchangi Patrick & Associates Advocates — 24 scored requirements, a compliance score band, and a priority action plan.

How to Use This Checklist

For each requirement below, record one of four ratings: YES — fully compliant; PARTIAL — a defined gap remains; NO — the requirement is unmet; N/A — not applicable to the organisation's operations. Download the fillable PDF to complete and retain your assessment.

Executive Summary

Section 31 of the Data Protection Act, 2019 and the Data Protection (General) Regulations, 2021 require a Data Protection Impact Assessment ("DPIA") to be carried out before undertaking processing that is likely to result in a high risk to the rights and freedoms of data subjects, including new technologies, large-scale processing, systematic monitoring and profiling. This checklist has been prepared by Muchangi Patrick & Associates Advocates to guide organisations through the screening, assessment and documentation stages of a DPIA, from threshold identification to sign-off and periodic review.

How to Use This Checklist

This checklist is a diagnostic tool, not a substitute for legal advice. Organisations identifying material gaps should seek a full compliance audit before relying on the results for governance or regulatory reporting purposes.

Dpia Screening & Assessment

No.RequirementYesPartialNoN/A
01Screening assessment conducted to determine whether a DPIA is required☐☐☐☐
02Processing involves new technologies or novel uses of personal data☐☐☐☐
03Processing involves large-scale processing of personal data☐☐☐☐
04Processing involves systematic monitoring of a publicly accessible area☐☐☐☐
05Processing involves special (sensitive) categories of personal data at scale☐☐☐☐
06Processing involves profiling or automated decision-making with legal or significant effects☐☐☐☐
07Processing involves personal data relating to children☐☐☐☐
08Processing involves matching or combining datasets from different sources☐☐☐☐
09Processing involves transfer of personal data outside Kenya☐☐☐☐
10Nature, scope, context and purposes of the processing described☐☐☐☐
11Necessity and proportionality of the processing assessed☐☐☐☐
12Data minimisation principles applied to the processing design☐☐☐☐
13Risks to the rights and freedoms of data subjects identified☐☐☐☐
14Likelihood and severity of identified risks assessed☐☐☐☐
15Measures to mitigate identified risks documented☐☐☐☐
16Data Protection Officer consulted on the assessment (where applicable)☐☐☐☐
17Views of data subjects or their representatives sought (where appropriate)☐☐☐☐
18Processors and third parties involved in the processing identified☐☐☐☐
19Technical and organisational security measures assessed and documented☐☐☐☐
20Residual risk after mitigation evaluated☐☐☐☐
21DPIA outcome and recommendations documented in a formal report☐☐☐☐
22Senior management or data controller sign-off obtained☐☐☐☐
23Prior consultation with the ODPC undertaken where high residual risk remains☐☐☐☐
24DPIA scheduled for periodic review or review upon material change to processing☐☐☐☐

Compliance Score

Aggregate the ratings above to determine the organisation's overall compliance posture:

ScoreAssessment
22 – 24Excellent
17 – 21Good
10 – 16Fair
0 – 9Immediate Remediation Required

Priority Action Plan

Corrective actions identified during the assessment should be recorded and tracked to closure, assigned by priority (High / Medium / Low) to a named responsible officer with a target date — see the fillable PDF for a ready-made tracking table.

Overall Assessment

Record an overall rating of Excellent, Good, Moderate/Fair or Poor, together with the auditor's notes, in the space provided in the fillable PDF.

Disclaimer: This checklist is a diagnostic tool, not a substitute for legal advice. Organisations identifying material gaps should seek a full compliance audit before relying on the results for governance or regulatory reporting purposes. Reading this publication does not create an advocate-client relationship with Muchangi Patrick & Associates Advocates. For advice on a specific matter, please book a consultation.
PM

Patrick Muchangi

Advocate of the High Court of Kenya · Founder, Muchangi Patrick & Associates Advocates

Patrick Muchangi is an Advocate of the High Court of Kenya and founder of Muchangi Patrick & Associates Advocates, a Nairobi practice specialising in data protection, privacy, AI governance and technology law, and editor of the Kenya Privacy Law Review.