Access to Information

Abstract
Kenya's legal framework for access to information is anchored in Article 35 of the Constitution and operationalised by the Access to Information Act, 2016. This framework mandates public entities, including the Communications Authority of Kenya (CAK), to proactively disclose and respond to requests for official information. The CAK, as the independent regulator of the ICT sector, holds a vast array of data, making its compliance with the Act crucial for transparency and accountability. However, the exercise of this right is often balanced against other fundamental rights, particularly the right to privacy enshrined in Article 31 of the Constitution and elaborated in the Data Protection Act, 2019, creating a complex regulatory landscape for legal practitioners.
Introduction
The right to access information is a cornerstone of good governance, transparency, and accountability in any democratic society. In Kenya, this fundamental right is explicitly guaranteed under Article 35 of the Constitution of Kenya, 2010, which provides that every citizen has the right of access to information held by the State, and to information held by another person and required for the exercise or protection of any right or fundamental freedom. This constitutional imperative was given legislative effect through the enactment of the Access to Information Act, 2016 (the "ATI Act").
Within this evolving legal landscape, the Communications Authority of Kenya (CAK) plays a pivotal role. As the independent regulatory agency for the Information, Communications and Technology (ICT) industry in Kenya, the CAK's mandate spans telecommunications, e-commerce, broadcasting, cybersecurity, and postal/courier services. The Authority collects and holds a significant volume of official information, including licensee data, internal policies, and financial records. Consequently, understanding the CAK's obligations and procedures regarding access to information is paramount for legal professionals navigating the intersection of public information, regulatory oversight, and privacy rights in Kenya.
Background
The foundation of access to information in Kenya rests firmly on Article 35 of the Constitution, which not only grants citizens the right to information but also places a duty on the State to publish and publicise any important information affecting the nation. Prior to the 2010 Constitution, a culture of secrecy, often underpinned by laws like the Official Secrets Act, hindered public access to government information. The ATI Act, enacted in August 2016, was a transformative piece of legislation designed to operationalise this constitutional right, making it easier for citizens to obtain information from both public entities and, under certain conditions, private bodies.
The Communications Authority of Kenya (CAK) was established under the Kenya Information and Communications Act, 1998 (KICA), which provides the overarching framework for regulating the communications sector. KICA empowers the CAK to license services, manage frequency spectrum, facilitate e-commerce, protect consumer rights, and ensure competition within the sector. As a public entity, the CAK is directly subject to the provisions of the ATI Act, requiring it to make official information freely available and to establish clear procedures for handling information requests.
Complementing, and at times creating tension with, the right to information is the right to privacy, enshrined in Article 31 of the Constitution. This right is further elaborated and protected by the Data Protection Act, 2019 (the "DPA"), which came into force in November 2019. The DPA establishes principles for the lawful processing of personal data, grants data subjects various rights, and created the Office of the Data Protection Commissioner (ODPC) to oversee its implementation and enforcement. The interplay between the ATI Act and the DPA is particularly relevant for the CAK, given its role in collecting and processing extensive personal and licensee data within the communications sector.
Analysis
The Access to Information Act, 2016, fundamentally reshaped the landscape of information disclosure for public entities in Kenya, including the Communications Authority of Kenya. The CAK, in recognition of its obligations under the ATI Act, has developed specific guidelines for handling access to information requests, detailing the procedures for submission, processing, and response. These guidelines affirm that the basic principle is that all information held by government agencies shall be made available to the public, unless specific reasons for withholding it exist.
However, the right to information is not absolute and must be balanced against other legitimate interests, most notably the right to privacy. Article 31 of the Constitution protects individuals from the unnecessary revelation of information relating to their family or private affairs and the infringement of the privacy of their communications. The Data Protection Act, 2019, provides a robust framework for safeguarding personal data, requiring lawful processing, consent, and adherence to principles such as purpose limitation and data minimization. The CAK, as a regulator that handles sensitive personal data of subscribers and detailed information from its licensees, must navigate this delicate balance. For instance, while a citizen may request information about a licensee, the CAK must ensure that such disclosure does not infringe on the privacy rights of individuals or proprietary commercial information protected under the DPA or other confidentiality clauses.
The ATI Act outlines specific grounds upon which access to information may be refused, including information whose disclosure would prejudice national security, impede law enforcement, or involve the unwarranted invasion of privacy. Kenyan courts have reinforced the constitutional supremacy of the right to information, holding that statutory non-disclosure clauses, such as those found in the Official Secrets Act, cannot override Article 35 unless the limitation passes the constitutional test of reasonableness and justifiability. This judicial stance places a significant burden on public entities like the CAK to justify any refusal to disclose information, demonstrating that the information falls squarely within the permissible limitations of the ATI Act.
Furthermore, the ATI Act encourages proactive disclosure of information by public bodies. The CAK, through its regulatory functions under KICA, contributes to public access to information by publishing sector reports, licensing frameworks, and consumer protection guidelines. However, challenges persist in the effective implementation of the ATI Act, including a lack of comprehensive regulations to articulate processes and a need for greater public awareness regarding their rights and how to exercise them. The ongoing evolution of ICT regulations, such as the proposed Kenya Information and Communications (Amendment) Bill, 2025, also highlights potential areas of conflict between regulatory oversight, data collection, and fundamental rights like privacy, necessitating careful scrutiny by legal professionals.
Conclusion
The right to access information in Kenya is a powerful tool for fostering transparency and accountability, with the Access to Information Act, 2016, providing the legal mechanism for its exercise. For legal practitioners, understanding the intricacies of requesting information from public bodies like the Communications Authority of Kenya is essential. This involves not only familiarity with the ATI Act and the CAK's specific guidelines but also a keen awareness of the potential interplay with the Data Protection Act, 2019, especially when dealing with requests involving personal or commercially sensitive data. The CAK, as a critical regulator in the digital space, must meticulously balance its obligation to facilitate public access with its duty to protect privacy and other legitimate interests.
Practitioners advising clients seeking information from the CAK or other public entities must be prepared to articulate the necessity of the information for the exercise or protection of a right, anticipate potential grounds for refusal, and be ready to challenge unjustified denials. Conversely, those advising public entities must ensure robust internal policies and procedures for handling information requests that align with both the ATI Act and the DPA, while also being mindful of evolving legislative and judicial interpretations. As Kenya's digital economy expands, the effective and balanced implementation of these access and protection frameworks will remain crucial for upholding constitutional rights and fostering a transparent regulatory environment.
Citations
- 1.Constitution of Kenya, 2010
- 2.Access to Information Act, 2016
- 3.Data Protection Act, 2019
- 4.Kenya Information and Communications Act, 1998
- 5.Communications Authority of Kenya Guidelines on Access to Information Requests
- 6.Kenya Information and Communications (Amendment) Bill, 2025
How does this affect your business?
Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.