254 News Blog News Director General David Mugonyi pressed for transparency over secret content takedown demands to foreign hosts
News

Director General David Mugonyi pressed for transparency over secret content takedown demands to foreign hosts

Questions over the role of Kenya’s communications regulator in online content disputes are becoming harder to ignore, particularly after its cybersecurity unit was reportedly used to seek the removal of publications that appear to involve journalism, workplace disputes and allegations against private individuals and company executives.

The controversy centres on the National Kenya Computer Incident Response Team Coordination Centre, commonly known as KE-CIRT/CC, which operates under the Communications Authority of Kenya.

The authority is responsible for areas including telecommunications, broadcasting, cybersecurity, electronic commerce and consumer protection within the communications sector.

According to the concerns raised in the Nyakundi Report, KE-CIRT has sent notices to international technology and hosting companies asking them to take down online material. The requests reportedly referred to issues such as privacy, cyber harassment and the disclosure of personal information, while relying on provisions of the Constitution, the Computer Misuse and Cybercrimes Act and the Data Protection Act.

The central question is not whether Kenyans should have their personal information protected. They should. The bigger issue is whether a cybersecurity agency should be used to pressure online platforms into removing disputed publications when the material in question concerns journalism, allegations of wrongdoing or reputational disputes rather than a conventional cyberattack.

That distinction is important.

Kenya already has institutions that can investigate complaints involving privacy, unlawful processing of personal information, defamation and possible criminal conduct.

The courts can issue orders where necessary, while the Office of the Data Protection Commissioner has a specific role in handling complaints involving personal data. Police investigators and prosecutors also have powers where an alleged offence falls within criminal law.

The Computer Misuse and Cybercrimes Act itself recognises the importance of balancing cybersecurity with constitutional rights, including freedom of expression and access to information.

This means that any attempt to remove online material should be handled carefully, especially when the content concerns matters of public interest.

The concern becomes greater when a government agency communicates directly with foreign companies that control hosting or internet infrastructure.

Such companies may choose to restrict content rather than become involved in a legal dispute over the application of Kenyan law.

In practice, this could mean that a publication disappears even where the complainant has not obtained a court order.

That raises a basic accountability question: who decides inside the Communications Authority that a particular publication amounts to cyber harassment, unlawful disclosure or another form of prohibited conduct?

If such decisions are being made administratively, without giving publishers a meaningful opportunity to respond or requiring an independent legal determination, then the process deserves public scrutiny.

There are also allegations from insiders about possible preferential treatment in the handling of complaints. The claims suggest that wealthy or well-connected individuals may be able to obtain the attention of officials when they want unfavourable information removed from the internet.

These are serious allegations and should not be treated as proven facts without evidence. But precisely because they involve a public institution with regulatory powers, they deserve an independent examination rather than dismissal.

The Ethics and Anti-Corruption Commission would have a legitimate interest in examining any credible evidence suggesting that officials may have received financial or other benefits in connection with content takedown requests.

Such an investigation would need to establish whether any employee requested, received or was promised money, gifts, travel, accommodation, business opportunities or other benefits in exchange for influencing a complaint.

Investigators could also examine whether some complainants receive unusually fast responses, whether particular officials repeatedly handle sensitive complaints and whether discussions happen outside official channels before formal notices are issued.

The allegations concerning the lifestyles and wealth of senior officials should also be treated with caution. Claims that an official has unexplained wealth, expensive spending patterns or financial pressures are not proof of corruption. They require documentary evidence and a proper investigation before any conclusion can be reached.

The same standard should apply to claims involving Communications Authority Director General David Mugonyi and other officials associated with KE-CIRT.

Allegations about personal relationships, private expenses or pressure over money should not be published as established facts unless they can be independently verified.

However, that does not mean the allegations should simply be ignored.

Public officials exercising regulatory powers should be able to explain how decisions are made, who authorises sensitive actions and what safeguards exist to prevent the system from being abused.

The Communications Authority should therefore provide clear information on the number of content takedown requests made by KE-CIRT, the legal basis for those requests, the types of complaints involved and whether any requests concerned journalistic publications.

It should also explain whether publishers are notified and given an opportunity to challenge allegations before foreign platforms are approached.

Transparency would help separate legitimate cybersecurity work from actions that could be interpreted as censorship.KE-CIRT has an important role in protecting Kenya from cyberattacks, malware, digital fraud and threats to critical systems.

That mandate should not be weakened. But cybersecurity powers must also not become a convenient route for settling personal disputes or suppressing uncomfortable information.

If a publication is false, unlawful or defamatory, the affected person has legal avenues to challenge it. If personal data has been unlawfully processed, the Data Protection Commissioner has a mandate to deal with the complaint.

If a criminal offence has occurred, investigators and prosecutors can pursue it.

What should concern Kenyans is any situation where a regulatory office effectively becomes the first and final judge of what information should remain online.

The Communications Authority therefore faces an important test. It can demonstrate that KE-CIRT’s interventions are based on clear law, consistent procedures and genuine cybersecurity concerns, or it can allow growing questions about selective enforcement and possible abuse of regulatory power to deepen.

For a country that continues to debate freedom of expression, digital rights and government accountability, the issue cannot simply be reduced to whether one article should remain online.

It is about who gets the power to decide what Kenyans are allowed to read, what safeguards control that power and whether those safeguards are actually being followed.

Exit mobile version