MP Muchangi Patrick& Associates Advocates
Talk to an Expert
Practice Areas Case Digest Knowledge Centre Insights About Contact Talk to an Expert
Compliance Toolkit/Kenya Data Protection Compliance Checklist
KPLR/CHK/001/2026 Standalone Checklist General Compliance
Compliance Toolkit · Standalone Checklist

Kenya Data Protection Compliance Checklist

An Executive Self-Assessment Instrument

Prepared by
Muchangi Patrick & Co. Advocates
Published
July 2026
Format
20 items · Fillable PDF
Version
1.0
Editorial Status
Published
Language
English
Abstract

A board-level, self-assessment instrument prepared by Muchangi Patrick & Associates Advocates — 20 scored requirements, a compliance score band, and a priority action plan.

How to Use This Checklist

For each requirement below, record one of four ratings: YES — fully compliant; PARTIAL — a defined gap remains; NO — the requirement is unmet; N/A — not applicable to the organisation's operations. Download the fillable PDF to complete and retain your assessment.

Executive Summary

The Data Protection Act, 2019 requires every data controller and data processor operating in Kenya to implement appropriate legal, organisational and technical measures to protect personal data, and to be able to demonstrate that accountability to the Office of the Data Protection Commissioner ("ODPC"), data subjects and other stakeholders on request. This instrument has been prepared by Muchangi Patrick & Associates Advocates as a practical, board-level self-assessment tool. It enables in-house counsel, compliance officers and senior management to identify compliance gaps against twenty core statutory and regulatory benchmarks, and to prioritise corrective action before those gaps are tested by a supervisory inquiry, an audit, or a data subject complaint.

How to Use This Checklist

This checklist is a diagnostic tool, not a substitute for legal advice. Organisations identifying material gaps should seek a full compliance audit before relying on the results for governance or regulatory reporting purposes.

Data Protection Compliance Assessment

No.RequirementYesPartialNoN/A
01Privacy governance framework established☐☐☐☐
02Data Protection Officer appointed (where required)☐☐☐☐
03Organisation registered with the ODPC (where required)☐☐☐☐
04Records of processing activities maintained☐☐☐☐
05Personal data inventory completed☐☐☐☐
06Lawful basis identified for each processing activity☐☐☐☐
07Privacy Notice published☐☐☐☐
08Valid consent obtained where required☐☐☐☐
09Procedures exist for handling data subject requests☐☐☐☐
10Children\'s personal data appropriately protected☐☐☐☐
11Sensitive personal data receives additional safeguards☐☐☐☐
12Appropriate technical and organisational security measures implemented☐☐☐☐
13Processor agreements executed with third parties☐☐☐☐
14Cross-border data transfers comply with legal requirements☐☐☐☐
15Data Protection Impact Assessments conducted where required☐☐☐☐
16Personal data breach response plan established☐☐☐☐
17Data retention and secure disposal procedures implemented☐☐☐☐
18Employees receive regular privacy training☐☐☐☐
19AI systems processing personal data are governed appropriately☐☐☐☐
20Periodic privacy compliance audits are conducted☐☐☐☐

Compliance Score

Aggregate the ratings above to determine the organisation's overall compliance posture:

ScoreAssessment
18 – 20Excellent Compliance
15 – 17Good Compliance
11 – 14Moderate Compliance --- Improvements Required
0 – 10Significant Compliance Gaps

Priority Action Plan

Corrective actions identified during the assessment should be recorded and tracked to closure, assigned by priority (High / Medium / Low) to a named responsible officer with a target date — see the fillable PDF for a ready-made tracking table.

Overall Assessment

Record an overall rating of Excellent, Good, Moderate/Fair or Poor, together with the auditor's notes, in the space provided in the fillable PDF.

Disclaimer: This checklist is a diagnostic tool, not a substitute for legal advice. Organisations identifying material gaps should seek a full compliance audit before relying on the results for governance or regulatory reporting purposes. Reading this publication does not create an advocate-client relationship with Muchangi Patrick & Associates Advocates. For advice on a specific matter, please book a consultation.
PM

Patrick Muchangi

Advocate of the High Court of Kenya · Founder, Muchangi Patrick & Associates Advocates

Patrick Muchangi is an Advocate of the High Court of Kenya and founder of Muchangi Patrick & Associates Advocates, a Nairobi practice specialising in data protection, privacy, AI governance and technology law, and editor of the Kenya Privacy Law Review.