The Communications Authority of Kenya (CA) has clarified its recently published licensing regulations for cyber cafes, easing concerns over privacy. Contrary to earlier interpretations, the regulator confirmed that operators are not obligated to record customers’ browsing history.

The new rules, officially gazetted and set to take effect on September 7, require public communication access centers, including cyber cafes, to:

  • Verify customers’ identities
  • Clearly display service charges
  • Issue receipts for paid services
  • Maintain basic session records

Basic records refer specifically to terminal identification and session start and end times. The CA emphasized this does not extend to tracking the websites or pages visited by users.

This distinction addresses privacy concerns raised after initial reports suggested more intrusive data collection. Furthermore, the CA does not mandate specific identification systems or the installation of CCTV cameras. Operators may implement Know Your Customer (KYC) measures voluntarily and within existing legal frameworks.

The regulator highlighted that maintaining session logs aids in investigating cybercrimes such as fraud and identity theft linked to public internet terminals, without imposing extensive surveillance on users.

Cyber cafes continue to play a crucial role in providing internet access for many Kenyans, especially for accessing government services and conducting online transactions. The CA has pledged ongoing engagement with cyber cafe operators and stakeholders as the implementation date approaches.