ODPC Crest
IDMIS
ODPC Portal
Self-Service Portal
Data Protection Self-Assessment (Section 8(e))
New Application
COMPLIANCE ASSESSMENT SECTION 8(e) ANNUAL OBLIGATION

Annual Data Protection Self-Assessment Questionnaire

Statutory compliance self-assessment tool pursuant to Section 8(e) of the Data Protection Act, 2019 to ascertain whether information is processed in accordance with the Act and Regulations.

ODPC/REG/2026/004821
Kiboko Bites Ltd
Section 1 of 8: Basic Details Step 1 of 8 (12%)

SECTION 1 — BASIC DETAILS

SECTION 2 — ACCOUNTABILITY & GOVERNANCE

Has your organization developed a Data Protection Policy to guide practices?*
Which of the following documents has your organization developed?
Has your organization appointed a DPO or assigned DPO roles?*
Have you communicated the details of the DPO to the ODPC?*

SECTION 3 — PROCESSING ACTIVITIES & PRINCIPLES

Has your organization identified and documented all processing activities (ROPA)?*
Has your organization described the specific purpose for each processing activity?*
Has your organization determined the lawful basis for each processing activity?*
Which lawful bases does your organization rely on for processing personal data?
Where Legitimate Interest is relied on, do you conduct a Legitimate Interest Assessment?*
Does your organization align its processing activities to the principles of data protection?*
Which principles of data processing are adhered to by your organization?

SECTION 4 — DATA SUBJECT RIGHTS

Has your organization created and published privacy notices?*
Has your organization established Data Subject Requests Procedures & response templates?*
Which Data Subject Rights are mostly exercised by your data subjects?

SECTION 5 — INTEGRITY, CONFIDENTIALITY & BREACH READINESS

Which of the following security policies has your organization developed?
Has your organization documented an inventory of all data supporting assets?*
Has your organization identified threats and vulnerabilities for each data asset?*
Has your organization implemented privacy and security controls for each data asset?*
Is your organization aware of the requirement to report data breaches to ODPC within 72 hrs?*
Has your organization reported any data breach incident to the ODPC?*

SECTION 6 — VENDOR (THIRD PARTIES) MANAGEMENT

Does your organization have vendor selection and onboarding procedures?*
Do you ensure each vendor processing data is registered with ODPC as a processor?*
Does your organization conduct periodic privacy and security assessments of vendors?*

SECTION 7 — DATA SHARING & DATA TRANSFERS

Does your organization share personal data with other entities?*
If yes, does your organization sign Data Sharing Agreements (DSAs) with those entities?*
Does your organization transfer personal data outside Kenya (including overseas cloud hosting)?*
Before transfer outside Kenya, do you establish proof of adequate safeguards or obtain consent?*

SECTION 8 — SUBMISSION & DECLARATION

The Office of the Data Protection Commissioner (ODPC) appreciates your organization for taking time to undertake the data protection self-assessment exercise.
Cancel