A summary of the Data Privacy and Governance Society of Kenya (DPGSK) webinar on data protection audits, featuring Maria Nyabera (DPO, Truma Services Limited) and Joseph Ses (cybersecurity and data governance professional).

Overview

This session — part of DPGSK’s ongoing CPD series — introduced the fundamentals of data protection audits: what they are, the legal basis for conducting them in Kenya, the types of audits organisations may encounter, and the practical steps involved in running one. The speakers drew on both legal expertise and hands-on audit experience across banking, finance, insurance, education, and health sectors.

What Is a Data Protection Audit?

A data protection audit examines an organisation’s systems, processes, records, and activities against its compliance obligations under applicable data protection law. It is conceptually similar to a financial audit, but the reference point is a data protection framework rather than financial standards. The audit is typically assessed from the perspective of the data controller, who bears the primary compliance obligations — registration, policies, and demonstrable technical and organisational measures.

Legal Basis in Kenya

  • Section 23, Data Protection Act — grants the Office of the Data Protection Commissioner (ODPC) power to conduct or direct audits.
  • Regulation 53, Data Protection (General) Regulations — ties compliance audits to Data Protection Impact Assessment (DPIA) reports, allowing the ODPC to mandate periodic audits where residual high risk was reported.
  • Draft Regulations on Data Protection Compliance Audits (currently in public participation) — will, once enacted, set out audit components, audit categories, and the accreditation process and fees for auditors.

Types of Audits

  1. Internal / self-audits — conducted voluntarily by an organisation’s own team, ideally annually, either proactively or as a corrective measure after an incident.
  2. External audits — carried out by an independent consultant or firm, recommended at least annually to counter the natural bias of self-assessment.
  3. ODPC-initiated audits — triggered by a formal audit notice specifying scope, timeframe, and reporting requirements. These are often risk-based, historically targeting sectors such as health, finance, and education, and can also follow complaints or ex-mero-motu investigations.
  4. Voluntary/requested audits — organisations may proactively request an ODPC audit or accredited-auditor engagement to benchmark their compliance posture.

Structuring an Audit

A well-run audit typically follows this lifecycle:

  1. Scope and objectives — define boundaries (departments, processes, subsidiaries, third-party processors) and the legal/compliance basis triggering the audit.
  2. Audit planning — allocate resources, set a schedule, and identify who will be interviewed.
  3. Evidence gathering — through document review, interviews, technical control testing (access controls, encryption), and system checks.
  4. Documentation — every finding and recommendation must be mapped to a specific legal or regulatory provision (the Act, sector regulators such as CBK, CMA, or Ministry of Health guidance, etc.).
  5. Reporting — findings, recommendations, and an action plan with timelines and responsible owners; reports should be comprehensive enough to meet ODPC’s minimum requirements, as incomplete reports have been returned for revision.
  6. Follow-up — auditors often remain available for a defined period after submission to answer questions and verify progress on the action plan.

A key practical point often overlooked: audits should extend to third-party data processors, and data processing agreements should include audit clauses enabling this oversight.

Audit Categories and Approach

  • Adequacy audits assess whether required data protection controls exist — similar to an initial gap analysis.
  • Compliance audits go further, evaluating whether existing controls are operating effectively.
  • Audits can be run as functional/vertical (department-specific) or process/horizontal (tracing an end-to-end process, such as a data subject rights request, across multiple departments) — the latter better reflects how data protection activities cut across business units.
  • A risk-based approach underpins most audit proposals. Beyond the standard “likelihood × impact” scoring, auditors are encouraged to also think in terms of threats, threat actors, and vulnerabilities — helping identify root causes and assess the effectiveness of existing controls before determining residual risk.
  • Audit techniques include document review, interviews/consultation, system/technical testing, and sampling.

Reporting Practice

Good audit reports include assurance ratings (overall and per control objective), clearly documented gaps and risks, and an actionable remediation plan. Speakers noted the value of “positive auditing” — framing findings constructively rather than purely negatively — while still being rigorous. Reports may be developed as white box (with prior access to policies and documentation) or, less commonly, black box audits.

Becoming an Accredited Auditor

Accreditation is issued periodically by the ODPC through a tender-style call for applications, requiring:

  • A registered legal entity (certificate of incorporation)
  • Valid compliance certificates and registration with the ODPC
  • Demonstrated experience (previous cycles required around 3 years) and supporting client contract documentation

The current accreditation window has closed; future opportunities will likely align with the pending draft regulations and are announced via the ODPC website.

Why Previous Audit Reports Matter

A recurring theme: prior audit reports are essential inputs for subsequent audits, since recommendations from earlier cycles come with assigned owners and timelines. A new auditor needs to verify whether previously flagged issues (e.g., a policy that didn’t reflect actual organisational practice) were addressed before assessing new findings — and auditors should not be responsible for auditing their own prior remediation work in a later cycle.

Key Takeaway

Compliance is not a one-time exercise. As organisations introduce new systems, processes, or technologies (including AI), their compliance posture can shift — making regular, well-scoped audits a critical tool for proactive risk management rather than a reactive, box-ticking exercise.


Source: DPGSK CPD webinar recording. For more sessions on data privacy and governance, follow DPGSK on LinkedIn or visit datprivacyke.africa.

Leave a Reply

Your email address will not be published. Required fields are marked *