The Communications Authority of Kenya (CA) has clarified that cyber cafe operators will not be required to keep customers’ browsing histories under the new licensing conditions set to take effect next month.

The regulator said the rules only require Public Communications Access Centres (PCACs), commonly known as cyber cafes, to maintain basic session information that can help investigators trace activity if a facility is linked to unlawful conduct.

The clarification comes after widespread public concern that the new regulations would force cyber cafes to monitor and retain detailed records of customers’ online activity, raising privacy concerns.

“The requirement for PCACs to maintain basic user logs does not extend to a customer’s browsing history,” the Communications Authority said.

What cyber cafes will be required to record

According to the CA, operators will only keep limited information necessary to establish an audit trail during investigations.

The required records include:

  • The identification of the computer terminal used
  • The session start time
  • The session end time

The Authority emphasized that these logs do not include websites visited, searches made or browsing history.

Why the new rules are being introduced

The CA said the licensing conditions are aimed at strengthening accountability and improving security at public internet access centres without limiting access to digital services.

The regulator cited the increasing threat of:

  • Phishing attacks
  • Online scams
  • Identity-related offences
  • Other forms of cyber-enabled crime

Officials said the limited session logs would only assist investigations where a cyber cafe is suspected of being connected to unlawful activity.

Additional obligations for cyber cafe operators

Beyond maintaining basic session logs, cyber cafe operators will also be required to:

  • Verify customers’ identities
  • Clearly display service charges
  • Issue receipts for paid services
  • Maintain records demonstrating licence compliance

However, the CA noted that the regulations do not prescribe a specific customer identification system or CCTV solution.

Operators may adopt additional Know Your Customer (KYC) measures, provided they comply with Kenya’s existing laws on privacy and data protection.

When the rules take effect

The new licensing conditions were gazetted on August 7, 2026, and will become legally enforceable on September 7, 2026, after the expiry of the statutory 30-day notice period.

The Communications Authority said cyber cafes remain an essential part of Kenya’s digital economy, particularly for citizens who rely on public internet facilities to access government services, online applications, banking and other essential digital platforms.

According to the regulator, the objective of the new framework is not to restrict internet access but to ensure public internet facilities operate within a secure and accountable licensing regime.

Leave a Reply

Your email address will not be published. Required fields are marked *

Social Media Auto Publish Powered By : XYZScripts.com