dripviewz

News

Kenya says cyber cafés won't need to monitor users' browsing history

The CA's New Rules Are a Step in the Right Direction, But Will Cyber Café Operators Comply?

||3 min read
Kenya says cyber cafés won't need to monitor users' browsing history — News news on dripviewz

In the face of growing concerns about data privacy in Kenya, the Communications Authority (CA) has finally clarified its new licencing rules for cyber cafés. The rules, which were published in the Kenya Gazette Notice Vol. CXXVIII No. 135 on August 7, will take effect on September 7 and have been met with relief by many who have been worried about the impact of the new requirements on users' browsing histories.

The CA's clarification comes amid a backdrop of longstanding concerns about how personal data is collected, stored, and accessed in Kenya. The Huduma Namba case, which involved legal challenges to the government's National Integrated Identity Management System (NIIMS) between 2019 and 2021, raised questions about the protection of sensitive identity data and the risk of personal information being used beyond its original purpose. This case serves as a warning against overreach by authorities and highlights the need for clear guidelines on data protection.

While the new rules do not mandate the tracking of users' browsing histories, they do require cyber café operators to keep basic customer and session records. This includes verifying customers before granting access, recording the terminal used and the start and end times of each session, displaying applicable charges, and issuing receipts for paid services. Customer registration and session records must also be securely retained for at least three years. The CA said the records are intended to provide an audit trail when a public internet facility is linked to unlawful activity, including cyber-enabled fraud, identity theft, online scams, and other offences.

The new rules are a step in the right direction, but the question remains: will cyber café operators comply? The rules also do not mandate a specific customer identification system or CCTV solution, allowing operators to introduce additional Know Your Customer (KYC) measures where necessary, provided they comply with applicable laws. Cyber cafés will, however, be expected to implement approved network filtering and security measures to block illegal or harmful content. They must also source internet capacity from licensed providers and comply with the CA's requirements for regulatory inspections and data protection.

Recent scrutiny by regulators, courts, and civil rights groups over access to telecom records has kept data privacy in the spotlight. In a landmark May 13 ruling, the High Court of Kenya, presided over by Justice Bahati Mwamuye, awarded general damages to petitioners who sued Safaricom and M-Pesa and held that Article 31, which guarantees the right to privacy, had been breached. This ruling has significant implications for the protection of personal data in Kenya and highlights the need for clear guidelines on data protection.

The new rules are a step in the right direction, but they also present challenges for cyber café operators who must balance user rights with regulatory requirements. The CA's clarification is a welcome development, but the question remains: will cyber café operators comply with the new rules? The answer will depend on their willingness to adapt to changing regulatory requirements and to prioritize the protection of users' personal data.

The CA's new rules may not be perfect, but they are a start. Kenya's cyber café operators must be willing to adapt to the changing regulatory landscape and to prioritize the protection of users' personal data. The road ahead will be challenging, but with the right approach, Kenya can become a leader in data protection and privacy.

More stories you'll like

Get Featured

Are you a creator? Submit your profile and get featured on dripviewz.

Share with a creator