Independent African news, markets, culture and politics.
2 min read

Kenya CA: Cyber Cafés Must Log Sessions, Not Browsing History

Kenya’s Communications Authority (CA) has clarified new licensing rules for cyber cafés, confirming that operators will be required to keep basic customer an...

Kenya says cyber cafés don’t have to track browsing history
Kenya CA: Cyber Cafés Must Log Sessions, Not Browsing History

Kenya’s Communications Authority (CA) has clarified new licensing rules for cyber cafés, confirming that operators will be required to keep basic customer and session records but will not have to track users’ browsing histories. The clarification, issued Thursday, follows public discussion and media reports about the new requirements for Public Communications Access Centres (PCACs), which provide internet access to people who may not have personal computers or reliable connectivity.

The new licence conditions were published in the Kenya Gazette Notice Vol. CXXVIII No. 135 on August 7 and take effect on September 7, after the statutory 30-day period. Under the rules, cyber café operators must verify customers before granting access, record the terminal used and the start and end times of each session, display applicable charges, and issue receipts for paid services. Customer registration and session records must be securely retained for at least three years.

The CA said the records are intended to provide an audit trail when a public internet facility is linked to unlawful activity, including cyber-enabled fraud, identity theft, online scams, and other offences. “The requirement for PCACs to maintain basic user logs does not extend to a customer’s browsing history,” the Authority stated. The rules also do not mandate a specific customer identification system or CCTV solution. Operators may introduce additional Know Your Customer measures where necessary, provided they comply with applicable laws.

Cyber cafés will, however, be expected to implement approved network filtering and security measures to block illegal or harmful content. They must also source internet capacity from licensed providers and comply with the CA’s requirements for regulatory inspections and data protection.

The decision to explicitly exclude browsing history from required records comes amid longstanding concerns in Kenya about how personal data is collected, stored, and accessed. The Huduma Namba case, which involved legal challenges to the government’s National Integrated Identity Management System between 2019 and 2021, raised questions about the protection of sensitive identity data. More recently, a landmark High Court ruling on May 13, presided over by Justice Bahati Mwamuye, awarded general damages to petitioners who sued Safaricom and M-Pesa, holding that Article 31 of the Constitution, which guarantees the right to privacy, imposes a non-delegable duty on data controllers.

The CA’s clarification means cyber cafés can now be required to establish who used a computer and when, without having to record which websites that person visited. Non-compliance with the new requirements could attract regulatory sanctions, including fines of at least KSh500,000 ($3,863.99) or 0.2% of annual turnover, whichever is higher, as well as suspension or closure.

Ifunanya

Unearthing the truth, one story at a time! Catch my reports on everything from politics to pop culture for Media Talk Africa. #StayInformed #MediaTalkAfrica

Media Talk Africa follows strict standards of accuracy and fairness. Read our Editorial Policy.

Leave a Comment

Keep it respectful, relevant, and useful to other readers. Comments are moderated.

Scroll to Top