Kenya Clarifies Data Rules for Internet Cafes
Kenyan cyber cafes can now breathe easier as the Communications Authority of Kenya (CAK) has clarified its data collection requirements, explicitly excluding browsing history. The initial regulations, set to take effect on August 14th, mandated operators to record customer activity but sparked privacy concerns.
The CAK’s updated guidelines require only basic session logs—name, identification number, and terminal time—to be retained for at least three years. This change aims to balance national security with constitutional rights to privacy.
Why the Shift?
This decision follows a recent High Court ruling that data controllers are liable for how third parties access subscriber information, including a KES 900,000 fine imposed on Safaricom for data breaches. The government appears determined to avoid similar legal challenges by focusing on verifiable usage rather than potentially intrusive browsing tracking.
Implications for Businesses and Users
The revised rules offer relief to cyber cafe operators who faced potential financial penalties—failing to comply could result in fines of at least KES 500,000 or 0.2% of annual turnover. For users, it means greater privacy when accessing public internet services without the worry of constant monitoring.
This move signals a cautious approach to digital regulation in Kenya, prioritizing essential security measures while respecting individual rights—particularly as cyber cafes remain vital access points for millions lacking home internet connectivity.