Part 3: Before the System Is Switched On: Ripeness, Evidence, and the Constitutional Governance of Emerging Surveillance Technology in Kenya

Communications Authority of Kenya v Okiya Omtata Okoiti & 8 Others [2020] KECA 754 (KLR)

Peter Ngugi

Abstract
This paper examines Communications Authority of Kenya v Okiya Omtata Okoiti & 8 Others (Civil Appeal 166 & 167 of 2018 (Consolidated)) [2020] KECA 754 (KLR), the Court of Appeal’s decision overturning a High Court finding that the Communications Authority of Kenya’s proposed Device Management System (DMS) was unconstitutional. The paper argues that the judgment’s significance extends well beyond its immediate subject matter counterfeit device detection and SIM boxing to establish a durable doctrinal framework for adjudicating disputes over emerging and contested technologies more broadly. Three elements of that framework are analysed: the doctrine of ripeness as a threshold constraint on litigating technologies still under design; the evidentiary standard the Court applied in distinguishing documented technical fact from newspaper-sourced apprehension; and the Court’s approach to balancing the constitutional right to privacy against a regulator’s statutory mandate. The paper then considers the implications of this framework for the governance of artificial-intelligence-enabled monitoring and digital forensic systems now emerging within Kenya’s state apparatus, arguing that litigants and researchers seeking judicial accountability for such systems must supply technically credible, particularised evidence of a system’s actual configuration and conduct, rather than evidence of its theoretical capability. The paper concludes that the procedural safeguards of public participation and stakeholder consultation, rather than pre-emptive constitutional litigation, remain the primary available check on technologies that have not yet crystallised into reviewable state conduct.
constitutional law ripeness digital privacy Article 31 surveillance technology Communications Authority of Kenya public participation digital forensics Kenya

1. Introduction

Kenyan constitutional litigation over digital technology has tended to arrive too late or too early: too late when a system is already embedded in the country’s infrastructure, and its harms have become difficult to reverse, or too early when litigants, alarmed by a proposal, approach the courts before the technology has taken any final shape. Communications Authority of Kenya v Okiya Omtata Okoiti & 8 Others (Civil Appeal 166 & 167 of 2018 (Consolidated)) [2020] KECA 754 (KLR) is a study in the second scenario, and the Court of Appeal’s handling of it merits closer scholarly attention than it has so far received. The case concerned the Communications Authority of Kenya’s (CAK) proposed Device Management System (DMS) a centralised technical architecture intended to identify counterfeit and stolen mobile devices, detect cloned IMEI numbers, and curb SIM boxing. Civil society actors and mobile network operators feared it was something else entirely: a surveillance apparatus capable of intercepting calls, texts, and mobile money data across the entire subscriber base of Kenya’s telecommunications network.

The High Court, per Mativo J, sided emphatically with the petitioners, declaring the DMS project unconstitutional for want of adequate public participation and as a standing threat to the right to privacy under Article 31 of the Constitution of Kenya, 2010. The Court of Appeal reversed. In doing so, it did not hold that mass surveillance is constitutionally permissible, nor did it dismiss the underlying privacy concerns as fanciful. It held something narrower, and for present purposes more instructive: that a court cannot adjudicate the constitutionality of a technology that has not yet been built, configured, or deployed, based on newspaper cuttings, unnamed experts, and apprehension about what a system might eventually do.

This holding sits at the intersection of several strands relevant to the constitutional governance of digital infrastructure in Kenya: the question of how courts should evaluate contested technologies before those technologies are finished being built; how evidentiary standards translate into a domain in which the underlying facts are technical specifications rather than completed acts; and how regulatory bodies can be held accountable for surveillance capability without their statutory mandate being pre-emptively curtailed. As Kenya’s digital governance architecture becomes increasingly populated by artificial-intelligence-assisted monitoring, predictive analytics, and automated forensic tools, CAK v Okoiti offers one of the clearest judicial statements available on how the courts are likely to treat pre-emptive challenges to such systems and what litigants, regulators, and researchers alike would need to do differently to secure a different outcome.

2. The Dispute: A System Still Being Designed

The factual matrix is worth recovering in some detail, because much of the Court of Appeal’s reasoning turns on the sequencing of events rather than on any final judgment about what the DMS was, in fact, capable of doing.

CAK’s stated rationale was rooted in a longstanding and genuine regulatory problem. Since the early 2000s, Kenya’s mobile sector, like others operating on the GSM standard, has relied on the International Mobile Equipment Identity (IMEI), a unique device identifier maintained globally by the GSM Association. A first phase of enforcement, coordinated through the East Africa Communications Organisation and executed in collaboration with the mobile network operators, had switched off approximately 1.89 million stolen or counterfeit handsets by 2012. The problem subsequently evolved: counterfeiters began cloning genuine IMEI numbers onto illegal devices, defeating the existing whitelist system, while so-called SIM boxing operators exploited the gap between internet and voice networks to terminate international calls illegally, at cost to the state in licence fees, taxation, and, per complaints from Rwanda, regional standing.

CAK’s response was to propose a centralised Equipment Identification Register, branded as the DMS, that would define an IMEI whitelist, identify counterfeit and substandard devices, flag lost or stolen phones across all service providers, and detect SIM boxing. What alarmed the respondents was not this stated purpose but the language of the correspondence CAK sent to mobile network operators. A letter dated 10 October 2016 informed operators that the DMS would facilitate the collection of information on IMEI, IMSI, and MSISDN identifiers and would require them to provide the appointed contractor with access to that subscriber information, including a dedicated network link to the DMS. A subsequent letter in January 2017 confirmed that CAK’s technical team intended to survey the integration architecture at Safaricom’s core network facility, listing among the matters for discussion access to the IMEI, IMSI, MSISDN, and Call Data Records (CDRs) of subscribers on the network. The reference to CDRs, which can reveal who called whom, when, and from where, was, understandably, the flash point of the dispute.

Safaricom’s then Chief Executive Officer wrote back raising concerns of privacy, confidentiality, and security, particularly around placing subscriber data in the custody of a third-party contractor. Technical committees were formed, and meetings were held in October 2016 and January 2017. Before those technical and regulatory discussions concluded, however, CAK wrote to Safaricom on 31 January 2017 confirming a site visit for 21 February 2017 to survey the proposed integration of the DMS with the network. The first respondent filed his petition before that visit took place. The system, in other words, had never been switched on. It had not even been finally designed. What existed was correspondence, procurement activity, and an unfinished consultative process, and it was this unfinished process that became the object of constitutional litigation.

3. The High Court’s Approach

Mativo J’s judgment engaged seriously with the constitutional text. He read the CAK correspondence as disclosing an intention to access subscriber information within the meaning of section 27A of the Kenya Information and Communications Act (KICA), and reasoned that access to such information outside the narrow parameters permitted by that section would inherently infringe the right to privacy. He then subjected the DMS to the Article 24 limitation-of-rights analysis, considering whether the infringement was reasonable and justifiable in an open and democratic society, having regard to the nature of the right, the purpose and extent of the limitation, and the availability of less restrictive means. On public participation, he found the consultative process undertaken to that point inadequate. The relief granted was correspondingly sweeping: a declaration that the DMS decision was unconstitutional and void, and a permanent order of prohibition restraining CAK from proceeding with the system in its proposed form.

This is a judgment built on a coherent doctrinal foundation. Its principal vulnerability, as the Court of Appeal would go on to demonstrate, lay in its treatment of an evolving technical negotiation, one in which the mobile operators were themselves still raising objections and extracting commitments to further consultation as though it were a completed act of surveillance already causing constitutional harm.

4. The Doctrine of Ripeness as the Central Holding

The Court of Appeal’s most durable contribution is its reassertion of the ripeness doctrine as a live constraint on constitutional litigation involving technology. Courts, the bench held, adjudicate concrete disputes; they do not pronounce on the constitutionality of processes still under negotiation. The DMS was, on the Court’s own finding, still at the architectural or configuration design stage, with technical committees actively working through issues the mobile operators had raised. The correspondence that triggered the petition the request to survey Safaricom’s network, the reference to accessing IMEI, IMSI, MSISDN, and CDR data — was, on the Court’s reading, a request to configure the system and discuss its technical architecture, not confirmation that installation, still less data interception, had begun or was imminent.

The Court drew on its own precedent in Wanjiru Gikonyo & 2 Others v National Assembly of Kenya & 4 Others [2016] eKLR, which held that the justiciability doctrine prohibits courts from entertaining hypothetical or academic-interest cases, and that a court is prevented from determining an issue when it is raised too early or out of mere apprehension. It reiterated the position taken in John Harun Mwau & 3 Others v Attorney General & 2 Others [2012] eKLR that a court is not in the business of resolving abstract fears and drew a sharp analytical distinction worth preserving precisely: the doctrine of standing (locus standi) and the doctrine of ripeness are separate inquiries. A petitioner may well have standing to allege that a right to privacy is threatened; that alone does not establish that the threat has matured into a dispute fit for adjudication. Apprehension that a right could be infringed is not equivalent to a dispute that is ripe for judicial determination.

“This distinction has significance well beyond the DMS. It supplies Kenyan courts with a principled basis for declining to adjudicate the constitutionality of a technology, an algorithm, a monitoring platform, or an artificial-intelligence-assisted forensic tool purely on the strength of its design specification or its stated capabilities, so long as deployment, configuration, and the safeguards attached to it remain under active negotiation.”

Ripeness, applied in this manner, functions as more than a procedural gate; it constitutes a substantive statement about the kind of evidence the constitutional adjudication of technology requires: evidence of what a system does, rather than only what it is capable of doing in the abstract.

5. Evidence versus Apprehension: An Evidentiary Standard for Technology Litigation

If ripeness supplies the doctrinal spine of the judgment, the Court’s treatment of the petitioner’s evidence is its most instructive feature for technology and rights litigation more generally. The Court of Appeal was unusually direct about the quality of the pleadings before it, describing the petition as generalised and predicated on unsubstantiated statements taken from newspaper reports and from unnamed technical experts. Paragraph 9 of the petition, for instance, invoked unnamed technical experts said to have raised concerns about access to the home location register, without identifying those experts or the basis on which their views should be credited. The petitioner had annexed newspaper cuttings reporting a plan to monitor calls and texts coverage which the Court, applying its earlier reasoning in Independent Electoral and Boundaries Commission v National Super Alliance (NASA) Kenya & 6 Others [2017] eKLR, treated as hearsay of no probative value in the absence of the maker of the statement appearing in court to be tested.

The Court further reaffirmed the pleading-precision standard articulated in Anarita Karimi Njeru v Republic (1976-1980) KLR 1272: a party invoking the Constitution must set out with reasonable precision how the alleged acts amount to an infringement of a specific constitutional right, by whom, and through what conduct. General allegations of what might happen, described by the Court as conjecture at best, do not satisfy that threshold, however much public concern they may reflect.

This carries a direct implication for digital rights and cyber-forensics litigation more broadly, one that runs counter to a pattern of advocacy practice in which press coverage and public alarm frequently substitute for technical documentation. Courts appear to be signalling that fear of a system’s capability is not, without more, evidence of the system’s conduct. A litigant seeking to restrain a surveillance-adjacent technology cannot rely on the theoretical extent of what an architecture permits; the claim requires an evidentiary anchor, ideally a sworn, cross-examinable account from a party with direct technical knowledge connecting the system’s actual configuration to an identifiable, non-speculative risk of rights infringement. For research and advocacy concerned with artificial-intelligence-driven forensics, digital investigation, and communications surveillance, this represents a materially higher evidentiary bar than a demonstration that a system could, in principle, perform a given function. It requires documentation of what a system is actually configured to do at the time a claim is filed, supported by technical affidavits rather than media reporting.

It should be noted, in fairness to the respondents, that the Court of Appeal did not rely on the petitioner’s pleadings alone. It gave considerable weight to the supporting affidavit filed on behalf of Safaricom, which annexed the CAK correspondence and which the Court treated as the true evidentiary foundation of the petition. Even on that stronger evidentiary record, however, the Court assessed that it disclosed unfinished negotiation objections raised, technical assessments demanded, consultations still ongoing rather than a completed or imminent act of interception.

6. Balancing Privacy Against Regulatory Mandate: Implications for AI-Era Forensic Governance

The Court of Appeal was careful to avoid framing the case as privacy against surveillance in the abstract. It framed the dispute, instead, as one involving two legitimate and competing constitutional interests to be weighed rather than assumed to trump one another: the Article 31 right to privacy, and CAK’s statutory mandate under the Kenya Information and Communications Act to license, regulate, and safeguard the integrity of the communications sector a mandate that exists precisely because counterfeit devices, cloned IMEIs, tax-evading SIM boxing operations, and consumer harm from substandard equipment are demonstrated and ongoing problems, not hypothetical ones. The Court criticised the High Court for concentrating narrowly on the statutory term “access,” treating any access to subscriber-identifying data as necessarily an intrusion on communications privacy, without weighing the other legitimate senses in which a regulator might need to access system resources to configure a whitelist or flag stolen devices, as distinct from intercepting call content.

This balancing exercise, together with the Court’s insistence that regulatory deference is owed to a statutory body acting within its mandate absent evidence of unlawful conduct, has clear resonance for the governance of artificial-intelligence-assisted forensic and monitoring systems more broadly. Three principles merit particular attention in that connection.

First, the maturity of a technology bears directly on its justiciability. A system still under design and consultation will be treated differently from one that is operational. This creates an evident strategic asymmetry: a regulator can, in principle, insulate a project from early judicial scrutiny by keeping it in a state of continuing consultation, while litigants who wait for full deployment may find that a system has become operationally and politically entrenched before a challenge can be mounted. The judgment does not resolve this tension; it locates the present doctrinal line on one side of it. Researchers and advocates working on the governance of artificial intelligence in Kenya should treat this as a live institutional problem rather than a settled one. The more promising response is not necessarily earlier litigation but sustained monitoring of consultative processes to ensure they do not function as a permanent shield against accountability, combined with legislative and regulatory intervention through the guideline and rule-making process the Court itself directed, rather than premature constitutional litigation.

Second, the quality of technical evidence will materially determine outcomes. This finding cuts against prevailing digital-rights advocacy practice in Kenya, where press coverage and public alarm frequently substitute for technical documentation. As artificial-intelligence-enabled forensic tools, predictive policing analytics, automated content scanning, and algorithmic device-identification systems proliferate, advocates require technically literate affiants, ideally engineers or independent auditors capable of deposing to a system’s actual configuration, data flows, and access controls, rather than to its stated or feared purpose alone. This is precisely the evidentiary role that the discipline of digital forensics is institutionally positioned to fill: courts adjudicating technology disputes require forensically credible accounts of what a system does, and that evidentiary function is as relevant to constitutional proceedings as it is to criminal ones.

Third, procedural safeguards public participation, stakeholder consultation, and published guidelines remain the primary constitutional check on emerging technology, precisely because courts are reluctant to adjudicate substance before deployment. The Court of Appeal did not dispense with the requirement of public participation; it deferred judgment on its adequacy and directed CAK to complete its consultations and subject the resulting guidelines to public participation before implementation. For the governance of artificial intelligence specifically, this suggests that the more durable protection against regulatory overreach lies not in pre-emptive litigation but in embedding enforceable, judicially reviewable procedural requirements published data-flow specifications, defined retention and access limits, and independent audit rights into the regulatory instruments governing deployment, so that there is a concrete evidentiary record to litigate once deployment occurs, rather than reliance on speculative alarm before it does.

· · ·

7. Conclusion

CAK v Okoiti is not, on its face, a case about artificial intelligence. It concerns IMEI whitelists and SIM boxing, decided in 2020 on correspondence dating from 2016 and 2017. Its doctrinal architecture ripeness as the threshold question, precision-pleaded and technically credible evidence as the substantive requirement, and regulatory deference balanced against demonstrated rather than speculative harm is the same architecture likely to govern the next generation of disputes over artificial-intelligence-driven monitoring, automated digital forensics, and algorithmic decision systems deployed by Kenyan state agencies. Such systems will arrive, as the DMS did, wrapped in legitimate regulatory justifications fraud detection, cybercrime investigation, public safety and are likely to generate the same pattern of anxious correspondence, public alarm, and premature litigation that produced the High Court’s judgment in this matter.

The Court of Appeal’s answer was not that such anxieties are illegitimate. It was that constitutional courts require something more rigorous than anxiety on which to act: a system whose configuration and deployment have crystallised into conduct capable of being tested against the Bill of Rights, and an evidentiary record sworn, particularised, and technically grounded capable of demonstrating that conduct rather than merely anticipating it. For litigants, regulators, and researchers concerned with the constitutional governance of the next contested technology, whatever form it takes, that is the standard to be met before filing suit, not after.

References

Cases

  • Abok James Odera t/a A.J. Odera & Associates v John Patrick Machira t/a Machira & Co. Advocates [2013] eKLR.
  • Coalition for Reforms and Democracy & Others v Attorney General, Petition No 628 of 2014 [2015] eKLR.
  • Communications Authority of Kenya v Okiya Omtata Okoiti & 8 Others (Civil Appeal 166 & 167 of 2018 (Consolidated)) [2020] KECA 754 (KLR).
  • Doctors for Life International v Speaker of the National Assembly & Others (CCT12/05) [2006] ZACC 11; 2006 (12) BCLR 1399 (CC); 2006 (6) SA 416 (CC).
  • Galaxy Paints Co. Ltd v Falcon Guards Ltd [2000] E.A. 885.
  • Independent Electoral and Boundaries Commission (IEBC) v National Super Alliance (NASA) Kenya & 6 Others [2017] eKLR.
  • John Harun Mwau & 3 Others v Attorney General & 2 Others [2012] eKLR.
  • In the Matter of the Mui Coal Basin Local Community [2015] eKLR.
  • Omar Guled v Communications Commission of Kenya & Others, HCCC №257 of 2012.
  • Pharmaceutical Manufacturers Association of South Africa & Another: In re Ex Parte President of the Republic of South Africa & Others (CCT) 31/99 [2000] ZACC 1; 2000 (2) SA 674.
  • Anarita Karimi Njeru v Republic (1976–1980) KLR 1272.
  • Wanjiru Gikonyo & 2 Others v National Assembly of Kenya & 4 Others [2016] eKLR.

Legislation

  • Constitution of Kenya, 2010.
  • Anti-Counterfeit Act, №13 of 2008 (Kenya).
  • Consumer Protection Act, №46 of 2012 (Kenya).
  • Evidence Act, Cap 80 (Kenya).
  • Fair Administrative Action Act, №4 of 2015 (Kenya).
  • Kenya Information and Communications Act, №2 of 1998, as amended (Kenya).
  • Statutory Instruments Act, №23 of 2013 (Kenya).

Secondary Sources

· · ·

Comments

Popular posts from this blog

Part 1: Exploitation of Network-Centric Warfare Domains in Kenyan Politics 2008: The Emergence of Digital Influence Operations

Russia's African Strategy

Information Warfare and Deception: Alleged Mossad Tactics in Facilitating U.S. Military Action Against Libya (1986)