MP Muchangi Patrick& Associates Advocates
Talk to an Expert
Practice Areas Case Digest Knowledge Centre Insights About Contact Talk to an Expert
Compliance Toolkit/Website Compliance Audit Checklist
KPLR/CHK/002/2026 Standalone Checklist Websites & Digital Platforms
Compliance Toolkit · Standalone Checklist

Website Compliance Audit Checklist

A Practical Self-Assessment Guide

Prepared by
Muchangi Patrick & Co. Advocates
Published
July 2026
Format
30 items · Fillable PDF
Version
1.0
Editorial Status
Published
Language
English
Abstract

A board-level, self-assessment instrument prepared by Muchangi Patrick & Associates Advocates — 30 scored requirements, a compliance score band, and a priority action plan.

How to Use This Checklist

For each requirement below, record one of four ratings: YES — fully compliant; PARTIAL — a defined gap remains; NO — the requirement is unmet; N/A — not applicable to the organisation's operations. Download the fillable PDF to complete and retain your assessment.

Executive Summary

A website is often the first point at which an organisation collects personal data. Whether through contact forms, cookies, newsletters, recruitment portals, analytics tools, payment gateways or user accounts, websites must comply with the Data Protection Act, 2019 and applicable Regulations. This checklist has been prepared by Muchangi Patrick & Associates Advocates to enable organisations to conduct a high-level assessment of their website\'s legal, privacy and cybersecurity compliance across thirty practical benchmarks spanning notice, consent, security and governance.

How to Use This Checklist

This checklist is a diagnostic tool, not a substitute for legal advice. Organisations identifying material gaps should seek a full compliance audit before relying on the results for governance or regulatory reporting purposes.

Website Compliance Assessment

No.RequirementYesPartialNoN/A
01Website has a published Privacy Notice☐☐☐☐
02Privacy Notice is easy to locate☐☐☐☐
03Privacy Notice explains what personal data is collected☐☐☐☐
04Purpose of processing is clearly stated☐☐☐☐
05Legal basis for processing is identified☐☐☐☐
06Contact details of the organisation are provided☐☐☐☐
07Contact details of the Data Protection Officer are provided (where applicable)☐☐☐☐
08Data subject rights are explained☐☐☐☐
09Cookie Notice is available☐☐☐☐
10Cookie consent mechanism is implemented☐☐☐☐
11Users can reject non-essential cookies☐☐☐☐
12Contact forms collect only necessary information☐☐☐☐
13Newsletter subscriptions obtain valid consent☐☐☐☐
14Website uses HTTPS☐☐☐☐
15SSL certificate is valid☐☐☐☐
16Password-protected areas are secure☐☐☐☐
17Third-party plugins are regularly updated☐☐☐☐
18Website software is regularly updated☐☐☐☐
19Appropriate access controls exist☐☐☐☐
20Website backups are performed regularly☐☐☐☐
21Personal data retention period is disclosed☐☐☐☐
22Cross-border transfers are disclosed where applicable☐☐☐☐
23Third-party services (Google Analytics, Meta Pixel, etc.) are disclosed☐☐☐☐
24Terms and Conditions are available☐☐☐☐
25Accessibility features are considered☐☐☐☐
26Website includes a copyright notice☐☐☐☐
27Security headers are implemented☐☐☐☐
28Forms include anti-spam protection☐☐☐☐
29Data breach response procedure exists☐☐☐☐
30Website undergoes periodic compliance reviews☐☐☐☐

Compliance Score

Aggregate the ratings above to determine the organisation's overall compliance posture:

ScoreAssessment
27 – 30Excellent
22 – 26Good
16 – 21Fair
0 – 15Immediate Remediation Required

Priority Action Plan

Corrective actions identified during the assessment should be recorded and tracked to closure, assigned by priority (High / Medium / Low) to a named responsible officer with a target date — see the fillable PDF for a ready-made tracking table.

Overall Assessment

Record an overall rating of Excellent, Good, Moderate/Fair or Poor, together with the auditor's notes, in the space provided in the fillable PDF.

Disclaimer: This checklist is a diagnostic tool, not a substitute for legal advice. Organisations identifying material gaps should seek a full compliance audit before relying on the results for governance or regulatory reporting purposes. Reading this publication does not create an advocate-client relationship with Muchangi Patrick & Associates Advocates. For advice on a specific matter, please book a consultation.
PM

Patrick Muchangi

Advocate of the High Court of Kenya · Founder, Muchangi Patrick & Associates Advocates

Patrick Muchangi is an Advocate of the High Court of Kenya and founder of Muchangi Patrick & Associates Advocates, a Nairobi practice specialising in data protection, privacy, AI governance and technology law, and editor of the Kenya Privacy Law Review.