The Communications Authority of Kenya (CA) has addressed public concerns regarding new licensing rules for cyber cafes, confirming that operators will not be required to retain customers' browsing histories.

Instead, public communications access centres (PCACs), commonly known as cyber cafes, will maintain only essential session data. This includes the identification of the terminal used and the start and end times of each session, enabling traceability if a facility is linked to unlawful activities.

Key points of the new licensing requirements include:

  • Verification of customer identity, though no specific system is mandated.
  • Display of applicable service charges and issuance of receipts.
  • Maintenance of basic user logs limited to session details, excluding browsing content.
  • Possibility for operators to implement additional Know Your Customer (KYC) measures compliant with existing laws.

The CA emphasized that these measures aim to enhance accountability and security at cyber cafes without compromising users' privacy. The authority highlighted the growing threats of cybercrime such as phishing, online scams, and identity theft as motivations for these changes.

These licensing conditions were gazetted on August 7, 2026, and will become effective on September 7, following the standard 30-day notice period. Cyber cafes remain vital to Kenya’s digital ecosystem, providing internet access to individuals without personal devices or reliable connections.

According to the CA, the updated rules are designed to ensure that public internet access points operate securely and transparently, supporting Kenyans' participation in the digital economy while safeguarding their privacy.