Fresh questions are being raised about the Communications Authority of Kenya after its National KE-CIRT/CC cybersecurity unit was used to send takedown requests to international technology companies over disputed online publications involving private individuals and corporate executives.
KE-CIRT operates under the Communications Authority, whose Director General is David Mugonyi, with the cybersecurity function currently headed by Director of Cyber Security Dr Vincent Ngundi. The Authority’s published mandate covers telecommunications, broadcasting, cybersecurity, electronic commerce and protection of consumers in the communications sector.The latest complaints involve formal notices sent to foreign infrastructure companies seeking removal of published material on grounds including privacy, cyber harassment and disclosure of personal information.In those requests, KE-CIRT has relied on provisions of the Constitution, the Computer Misuse and Cybercrimes Act and the Data Protection Act when asking hosting companies and internet intermediaries to act against content hosted outside Kenya.The concern is that some of the disputes being pushed through KE-CIRT involve journalism, workplace accusations, reputation disputes and complaints by private executives, rather than conventional cyber attacks against government systems, companies or critical infrastructure.That distinction matters because Kenya already has courts, the Office of the Data Protection Commissioner, police investigators and prosecutors capable of determining whether publication of particular material crossed the line into criminal conduct or unlawful processing of personal information.The Data Protection Act gives people rights over their personal information, including rights to object to processing and seek correction or deletion in certain circumstances, with the Office of the Data Protection Commissioner established to handle complaints arising from those rights. (Kenya Law)The Computer Misuse and Cybercrimes Act separately deals with cyber offences and expressly recognises the need to protect privacy, freedom of expression and access to information alongside the fight against cybercrime. (Kenya Law)Questions are therefore being raised about who inside the Communications Authority decides that a particular article amounts to cyber harassment or unlawful disclosure before a court has heard the publisher and complainant.The issue becomes more serious once those findings are communicated to companies such as Cloudflare and DigitalOcean, since foreign hosting providers can restrict or remove material rather than spend money fighting disputes involving Kenyan law.That gives CA officials handling these complaints considerable practical power over what remains online, particularly where a complainant has failed to obtain an injunction or any other order from a Kenyan court.Insiders have further raised corruption concerns around the handling of some complaints, claiming that wealthy businesspeople and other well connected individuals are increasingly seeking intervention from officials when they want damaging material removed.Questions have separately been raised about the wealth and lifestyles of some officials associated with these operations, with insiders alleging that certain assets and expenditure appear difficult to reconcile with ordinary public sector earnings.Those claims are not established by the takedown notices themselves, but they provide a clear basis for the Ethics and Anti Corruption Commission to examine declarations of income, property ownership, companies, bank transactions and possible conflicts involving officials handling high value complaints.EACC should establish whether any employee of the Communications Authority or KE-CIRT has ever requested, received or been promised money, gifts, accommodation, travel, business opportunities or other benefits connected to content removal requests.Investigators should further establish whether certain complainants receive unusually quick intervention, whether the same officers repeatedly handle sensitive requests and whether communications take place outside official CA channels before formal notices are generated.There are further allegations surrounding financial pressure on senior officials and expensive private lifestyles including reports that CAK Boss David mugonyi himself puts pressure on the department to get him money for maintaining his wives and several girlfriends.
The Communications Authority should therefore publish the number of content takedown complaints handled through KE-CIRT over the last several years and state how many resulted in requests to hosting companies, social networks or other internet intermediaries.The Authority should further disclose how many of those requests were supported by court orders, ODPC decisions, police investigations or other formal legal findings before foreign companies were contacted.The public should know how many complaints involved politicians, State officials, government contractors, senior corporate executives, foreign executives working in Kenya and companies involved in disputes with journalists or whistleblowers.There should further be clarity about the role played by CA’s legal directorate, since the Authority has a dedicated Director of Legal Services and Corporation Secretary alongside the cybersecurity directorate.If decisions with serious implications for constitutional expression are being made principally by technical cybersecurity officers, the Authority should explain where the legal review occurs and who signs off before a takedown request leaves CA.Cybersecurity engineers are trained to deal with compromised networks, malware, attacks, vulnerabilities and incident response, but disputes involving privacy, publication, public interest and freedom of expression can require much more complex legal balancing.The Communications Authority cannot allow a technical cyber response mechanism to become an alternative court where complainants obtain practical removal of unwanted articles without undergoing an ordinary legal challenge.The danger becomes obvious once the system is available to powerful individuals who can avoid filing defamation suits, privacy cases or complaints before the Data Commissioner and instead seek pressure against a publication’s hosting infrastructure.Such a system would give complainants something even more effective than winning a court case, since disabling hosting can make an entire article disappear before the underlying allegations have ever been tested.That is why Parliament should demand internal KE-CIRT manuals, escalation procedures, authorisation records and statistics showing how content complaints have been handled under the Communications Authority.EACC should simultaneously establish whether officials entrusted with those powers have unexplained wealth or financial relationships with individuals whose complaints received action from the regulator.The Auditor General may also have reason to examine whether public staff time, cybersecurity infrastructure and government resources are being spent pursuing reputation disputes for private parties without a clear statutory basis.KE-CIRT performs an important national function, particularly at a time when attacks against companies, government systems and critical infrastructure are becoming more sophisticated.That makes protection of the institution from private capture even more important.A businessman embarrassed by an article should not be able to turn Kenya’s national cybersecurity machinery into his private reputation management company, just as a politician should not be able to deploy the regulator against journalists publishing uncomfortable information.Where genuinely unlawful personal information has been published, Kenya has laws and regulators capable of dealing with it, and courts remain available for urgent injunctions where immediate harm can be demonstrated.What now needs examination is whether Communications Authority officials have crossed the line between coordinating legitimate cyber incidents and privately helping powerful complainants suppress information they simply do not want online.If the process is lawful, CA should publish the rules and records explaining it.If officials have been taking money or other benefits to weaponise KE-CIRT takedown channels, then Parliament, EACC and the relevant investigative agencies are dealing with something far bigger than cybersecurity.They are dealing with possible corruption inside the institution that controls Kenya’s communications system.