News
Too much spill ruins the goods
Kenya's Cyber Cafes Breathe Sigh of Relief as Browsing History Exemption Takes Effect It's a balmy Sunday morning in Nairobi's bustling city centre, and the streets are alive with the hum of activity.

It's a balmy Sunday morning in Nairobi's bustling city centre, and the streets are alive with the hum of activity. But amidst the hustle and bustle, a quiet revolution is taking place in Kenya's cyber cafe scene. Just last week, the Communications Authority of Kenya (CAK) issued a clarification that has left local cyber cafe operators breathing a collective sigh of relief. The new rules, which were initially expected to take effect on August 14, have been tweaked to exclude the collection of customers' browsing history. This decision is a significant departure from the original mandate, which would have required cyber cafes to record and store customers' online activities.
As I walk into a cyber cafe in Nairobi's Westlands area, I'm greeted by the friendly face of James, a seasoned operator who's been in the business for over a decade. He's been following the developments closely, and his concerns about the original mandate are palpable. "We understand the need for security and fraud prevention, but we also have to consider the trust factor," he explains. "If customers feel like we're invading their privacy, they'll take their business elsewhere." The CAK's decision to exempt browsing history is a nod to this delicate balance. By doing so, they're acknowledging that while tracking users' online activities is essential for security purposes, it's equally important to respect customers' right to privacy.
The CAK's clarification is also a response to the controversy surrounding Huduma Namba, a biometric ID scheme that was halted by the courts due to a lack of clear data protection framework. The incident serves as a stark reminder of the importance of prioritizing data protection and respecting citizens' constitutional rights. By excluding browsing history from the new rules, the CAK is avoiding a similar fate. Instead, they're opting for a more nuanced approach that balances security concerns with the need for transparency and accountability.
Despite the clarification, cyber cafes will still be required to maintain basic session logs, including names, identity numbers, and terminal times, for at least three years. This requirement will take effect on September 7, giving operators a brief window to adapt to the new regulations. While some may view this as an added burden, James is more optimistic. "We're willing to comply with the new rules as long as they're reasonable and fair," he says. "We want to work with the regulator to ensure that we're providing a secure and trustworthy environment for our customers."
As the CAK continues to navigate the complex landscape of cybersecurity and data protection, one thing is clear: the stakes are high, and the consequences of getting it wrong are severe. By taking a more measured approach to regulating cyber cafes, the CAK is sending a powerful message: that security and privacy are not mutually exclusive, and that respecting citizens' rights is essential to building trust in the digital economy. As Kenya's cyber cafe operators continue to adapt to the new rules, one can't help but wonder what the future holds for this rapidly evolving industry.
- The Communications Authority of Kenya (CAK) has clarified that cyber cafes do not need to collect customers' browsing history.
- The new rules will take effect on September 7, requiring cyber cafes to maintain basic session logs for at least three years.
- The CAK's decision is a response to the controversy surrounding Huduma Namba and the need for clear data protection frameworks.
- Cyber cafes will still be required to comply with data protection regulations, but with a more nuanced approach that balances security concerns with the need for transparency and accountability.

