" "

Cyber cafés in Kenya won't have to keep browsing history under new CA rules


The Communications Authority of Kenya (CA) has clarified that cyber cafés will not have to keep customers’ browsing history under its new licensing rules, narrowing the scope of a policy that had raised privacy concerns after the requirements were gazetted.

The clarification also changes the implementation timeline. The licence conditions for Public Communications Access Centres (PCACs), which include cyber cafés, will now take effect on September 7, following the statutory 30-day period after publication in the Kenya Gazette on August 7, rather than the earlier August 14 date that had been widely reported.

The announcement comes after public debate over whether the new rules would require cyber cafés to monitor customers’ online activity. The CA said the regulations are intended to strengthen accountability and security while preserving access to digital services for people who rely on public internet facilities.

CA narrows the scope of the new cyber café rules

The regulator drew a clear distinction between keeping a basic audit trail and tracking what customers do online.

According to the CA, operators will only be required to maintain basic session information, comprising the terminal identification and the start and end times of a customer’s session. The Authority said that requirement does not extend to a customer’s browsing history, directly addressing the biggest point of confusion surrounding the new licence conditions.

JOIN OUR TECHTRENDS NEWSLETTER

The clarification also confirms that the new rules do not prescribe a specific customer identification system or require cyber cafés to install CCTV. Operators may introduce additional Know Your Customer (KYC) measures as part of their own security and operational controls, provided those measures comply with applicable laws.

That marks a narrower approach than many operators had feared because it removes the expectation that cyber cafés would become repositories of detailed records about customers’ internet activity.

What cyber cafés will still have to collect

The privacy clarification does not remove the core compliance requirements.

Under the new licence conditions, cyber cafés must still verify customers, display their charges clearly, issue receipts for paid services and maintain basic records demonstrating compliance with their licences. Those records are intended to create an audit trail if a public internet facility is linked to unlawful activity such as online scams, phishing or identity-related offences.

The CA argues that cyber cafés remain an important gateway for Kenyans who depend on public computers to access government services, online transactions and other digital resources. The regulator said the new framework is designed to improve accountability without restricting access to those services.

Why the implementation date changed

The revised September 7 start date gives operators more time to prepare for the new licensing conditions.

Rather than taking effect immediately, the rules will come into force after the statutory 30-day period following publication in the Kenya Gazette. That gives cyber cafés additional time to put customer verification procedures, record-keeping systems and receipt processes in place before enforcement begins.

The extension may also ease pressure on small operators that had been preparing for compliance while trying to interpret what information they would actually be required to retain.

The clarification redraws the privacy line

The CA’s latest statement changes the balance at the centre of the debate.

The original discussion centred on fears that cyber cafés would have to record what customers were reading or doing online. The regulator has now made clear that its requirement is limited to establishing who used a particular terminal and when, rather than creating a record of every website visited.

That distinction matters because it separates traceability from content surveillance. A terminal ID and session time can help investigators establish an audit trail if a public internet facility is linked to unlawful activity, while stopping short of requiring operators to monitor customers’ browsing behaviour.

For cyber café operators, the clarification removes one of the biggest sources of uncertainty surrounding the new licence conditions. For customers, it means that using a public computer will still involve identity verification and basic session records, but not a government-mandated log of the websites they visit.

Download the FREE Kaspersky Next Enterprise Security Guide here to explore the complete framework for simplifying security operations and building cyber resilience.

Go to TECHTRENDSKE.co.ke for more tech and business news from the African continent and across the world.

Follow us on WhatsAppTelegramTwitter, and Facebook, or subscribe to our weekly newsletter to ensure you don’t miss out on any future updates. Send tips to editorial@techtrendsmedia.co.ke

Facebook Comments

By George Kamau

I brunch on consumer tech. Send scoops to george@techtrendsmedia.co.ke
Back to top button
×