Local cyber cafe operators in Kenya can breathe a small sigh of relief. After mandating them to collect and record customer data and usage sessions, the country’s communications regulator has clarified that those details do not include browser history.
The rules, previously expected to take effect on August 14, could have put cyber cafe operators in a weird position, where they have to record how and when customers use Internet services; that would have caused a trust deficit, possibly leading operators to lose customers.
What happened? On Thursday, the Communications Authority of Kenya (CAK) issued a clarification stating that the new rules for Public Communications Access Centres (PCACs), including cyber cafes, do not include tracking users’ browsing histories. Instead, operators only need to keep basic session logs—names, identity numbers, and terminal times—for at least three years.
The updated rules will now take effect on September 7, in the latest regulatory effort to tackle cybercrime in the country without making business economics risky for cyber cafes.
Between the lines: The CAK is walking a tightrope between national security and the constitutional right to privacy. By explicitly excluding browsing history, the regulator is likely trying to avoid a repeat of thelegal drama surrounding Huduma Namba, a controversial biometric ID scheme that the courts halted because it lacked a clear data protection framework. It is also dodging the shadow of arecent KES 900,000 ($6,900) privacy fine slapped on Safaricom after the High Court ruled that data controllers have a non-delegable duty to prevent third parties from accessing sensitive subscriber data.
The message from the bench is clear: if you collect it, you are liable for it. It suggests the government has realised that while tracking who was in the chair is necessary for fraud audits, tracking what they were reading is a legal minefield it isn’t ready to cross.
The maths of the mandate: The penalty for ignoring the new rule is steep. Non-compliant cafes face fines of at leastKES 500,000 ($3,864) or 0.2% of their annual turnover. In a market where many cafes are already pivoting to printing and scanning just to stay afloat, a single fine could be a death sentence.
Zoom out: Kenya’s decision to dial back the surveillance aspect of the rules is a rare win for digital rights in the region. Until the identity gap in public Internet access is fully closed, the CAK has decided that a paper trail is enough of a deterrent. For now, local cyber cafes remain a place to get online—without the government looking over your shoulder every time you open a tab.