Insights / Corporate & Commercial

Political Affiliation and Trade Union Membership Become ‘Sensitive Data’ in Kenya

By Clay & Associates Advocates · 6 min read ·

Confident African businesswoman in professional attire, representing HR and compliance professionals handling sensitive employee data in Kenya

On 11 September 2026 the Office of the Data Protection Commissioner published a draft notice proposing to add political affiliation and trade union membership to the categories of sensitive personal data protected under Kenyan law. The public comment window closes on 25 September 2026. The rule reads narrower than most coverage of it suggests, and getting the direction wrong could lead a multinational employer to either overreact or, worse, miss an obligation that genuinely applies to it.

What the Draft Notice Actually Prescribes

Section 47 of the Data Protection Act, 2019 gives the Data Commissioner power to prescribe further categories of sensitive personal data beyond those already listed in the Act, race, health status, ethnic origin, conscience, belief, genetic and biometric data, property details, marital and family details, sex, and sexual orientation. The draft notice proposes adding two: political affiliation, defined to cover political opinions, party membership, participation in political activities, and any information from which political leanings can reasonably be inferred, and trade union membership, defined to cover membership, affiliation or activity in a trade union or labour organisation, or information from which that involvement can reasonably be inferred. Both proposed categories are addressed against the four-factor test in section 47(2), risk of significant harm, expectation of confidentiality, whether a discernible class of data subjects could suffer harm, and the adequacy of protection under the ordinary rules, all of which the notice works through explicitly.

The Direction That Matters: This Is About Data Coming Into Kenya

The single most important detail in the draft notice is also the one most likely to be missed. It does not create a general Kenyan sensitive-data category that applies whenever a Kenyan controller processes political or union information about a Kenyan data subject. The notice is expressly scoped to cross-border transfers, and specifically to data transferred to Kenya, not data leaving it. Clause 2 makes the prescription apply only where “the personal data in question is transferred to Kenya by way of a Cross-Border Transfer” and where “the Originating Law of the Jurisdiction of Origin, at the time of the Cross-Border Transfer, treats, designates or classifies” the data as sensitive. In plain terms: if a multinational’s European or UK headquarters sends Kenyan-office HR data back to Nairobi, and that data included political-opinion or union-membership fields that GDPR or an equivalent regime already treats as special-category data, Kenya’s rule now applies to it on arrival. If the data originates somewhere that does not treat this information as sensitive, the Kenyan prescription does not independently create that status. This is a destination-country rule keyed to the sender’s law, not a freestanding Kenyan classification.

Why This Matters for Employers Specifically

The categories chosen are not abstract. Political affiliation and trade union membership are exactly the fields most likely to sit inside multinational employers’ HR, whistleblowing and grievance systems, DEI monitoring tools, and political-exposure due diligence records, all of which frequently flow between a Kenyan subsidiary and a foreign parent. An employer with a group-wide HR platform hosted abroad that syncs employee records into a Kenyan office, or a compliance function running background checks that touch political-exposed-person screening, should treat this notice as a direct hit on data it already handles, not a hypothetical. Once the notice is in force, that data becomes subject to the full sensitive-personal-data regime under section 49 of the Act, meaning the transfer of it into Kenya requires the data subject’s consent and confirmation of appropriate safeguards, a materially higher bar than ordinary personal data attracts.

The Stated Rationale, and What Coverage Gets Wrong

Public reporting on the draft notice has largely framed it as a measure aimed at Kenya’s 2027 general election. That framing does not appear in ODPC’s own recitals. The notice’s stated rationale is about cross-border data protection asymmetry generally, that Kenya receives significant volumes of data from other jurisdictions, and that sensitive-in-origin data arriving without equivalent Kenyan protection increases the risk of discrimination in employment, political targeting, intimidation and reputational harm. The electoral framing may well be part of the political context surrounding the timing, but a business assessing its own compliance exposure should work from the notice’s own stated legal test under section 47(2), not from the election narrative attached to it in the press.

What to Do Before 25 September 2026

The comment window is open now. Businesses that regularly transfer HR, compliance or due-diligence data into Kenya from a jurisdiction that already treats political or union data as sensitive, most obviously the EU and UK under GDPR, have a concrete stake in the outcome and can submit comments through ODPC’s online form or by email to public.participation@odpc.go.ke. Beyond the comment process, the practical step is an internal data map: identify which cross-border data flows into Kenya could carry political-opinion or trade-union fields, confirm whether the sending jurisdiction’s law already treats that data as sensitive, and if so, prepare the consent and safeguards documentation the notice will require once it takes effect.

How We Can Help

Clay & Associates Advocates advises multinational employers and compliance functions on sensitive personal data classification, cross-border HR data flows, and ODPC engagement in Kenya. See our companion piece on Kenya’s cross-border data transfer compliance regime for the broader rules this notice sits within. Contact our Regulatory & Compliance or Corporate & Commercial practice to assess exposure or prepare comments before the deadline.

Sources: Data Protection Act, 2019, section 47; ODPC, Draft Public Notice of Prescription of Additional Categories of Sensitive Personal Data (11 September 2026); Eastleigh Voice, ODPC proposes stricter protection of political and trade union data.

Frequently asked questions

Does the new ODPC notice apply to political data a Kenyan company collects about Kenyan employees directly?
No. The draft notice only applies to personal data transferred into Kenya from another jurisdiction, and only where that jurisdiction’s own law already treats political affiliation or trade union membership as sensitive data. It does not create a freestanding domestic category.

When does the comment period on this notice close?
25 September 2026. Comments can be submitted through ODPC’s online form or by email to public.participation@odpc.go.ke.

Which businesses should pay closest attention to this notice?
Multinational employers and compliance functions that transfer HR, whistleblowing, DEI or political-exposure due-diligence data into Kenya from jurisdictions such as the EU or UK, where political opinion and trade union membership are already special-category or sensitive data.

Is the 2027 election the legal basis for this notice?
Not according to ODPC’s own recitals. The notice’s stated legal basis is the four-factor sensitive-data test under section 47(2) of the Data Protection Act, focused on harm risk and confidentiality expectations. The 2027 election is context reported in the press, not the rationale ODPC itself states.

&

Clay & Associates Advocates
This article is general information, not legal advice. For advice on your matter, speak to counsel.

Related Insights

Discover more