The Communications Authority of Kenya (CA) has moved to reassure Kenyans that new licensing requirements for cyber cafés will not require operators to record or retain customers’ browsing histories.
The clarification comes after public concern over new rules governing public communications access centres (PCACs), commonly known as cyber cafés. The new requirements had raised questions about how much information operators would be expected to collect about customers’ online activities.
According to the CA, the rules are designed to improve accountability and security at public internet access points without restricting Kenyans’ access to digital services.
What information will cyber cafés record?
The regulator says cyber cafés will be required to maintain basic session information, rather than details of the websites or online content a customer accesses.
The records will include information such as:
- The identification of the computer or terminal used
- The start time of a customer’s session
- The end time of the session
- Basic customer verification information required under the licensing conditions
The CA says these records are intended to create a limited audit trail that can help authorities investigate cases where a public internet facility may have been connected to unlawful activity.
Importantly, the Authority stated that maintaining these basic user logs does not extend to a customer’s browsing history.
What does this mean for cyber café customers?
For ordinary Kenyans, the clarification means that visiting a cyber café does not automatically mean the operator will be required to maintain a list of every website you visit.
For example, if you use a cyber café to access an online government service, check your email or browse the internet, the new requirement does not instruct the operator to keep a detailed record of every webpage you opened.
Instead, the focus is on establishing who used a particular terminal and when, rather than documenting everything that person did online.
This distinction is important because earlier reports about the new rules triggered concerns that cyber cafés could be required to monitor customers’ internet activity.
Why is the CA introducing the requirements?
The regulator says public internet facilities remain important to Kenyans who may not have personal computers, reliable internet connections or other digital resources.
Cyber cafés are also widely used to access government services, complete online applications, conduct transactions and participate in the digital economy.
At the same time, the CA says public internet access points can potentially be linked to cyber-enabled fraud, phishing, online scams, identity-related offences and other forms of cybercrime.
The basic session records are therefore intended to provide investigators with an audit trail when a facility is connected to suspected unlawful activity.
Cyber cafés will have other responsibilities
The new licensing conditions also require operators to take other measures, including verifying customers, displaying applicable charges and issuing receipts for paid services.
However, the CA has clarified that the rules do not prescribe a specific customer identification system or a particular CCTV solution for cyber cafés.
Operators can introduce additional security or customer-verification measures, but these must comply with applicable laws.
When do the new rules take effect?
The CA says the new licence conditions were published in Kenya Gazette Notice Vol. CXXVIII No. 135 on August 7, 2026.
Importantly, the Authority’s latest clarification states that the conditions will take effect on September 7, 2026, following the statutory 30-day period. This differs from some earlier reports that had indicated an August 14 start date.
What Kenyans should know
The biggest takeaway is simple: the new cyber café rules do not require operators to keep customers’ browsing histories.
Cyber café operators will instead maintain limited session information to improve accountability and assist investigations where necessary.
For customers, this provides an important distinction between session logging and browsing-history surveillance.
The CA’s clarification should also ease concerns among Kenyans who depend on cyber cafés for accessing essential online services.
As the September 7 implementation date approaches, cyber café operators will need to ensure they understand the new requirements and comply with applicable privacy and data-protection obligations.
Bottom line: Kenyans using cyber cafés should expect more basic customer and session record-keeping, but the Communications Authority says operators will not be required to record or retain the websites customers visit.


