The Communications Authority of Kenya (CA) has clarified its recent licensing regulations for cyber cafes, dispelling concerns about mandatory collection of customers' browsing histories.
Contrary to earlier interpretations, the regulator confirmed that operators are only required to maintain minimal session logs, specifically terminal identification and session start and end times. This measure aims to aid investigations into online crimes without infringing on users' privacy by tracking every website visited.
Key Requirements for Cyber Cafes
- Verify customer identities
- Clearly display service charges
- Issue receipts for all paid services
- Maintain basic session records limited to terminal ID and session duration
The new rules, published officially in the Kenya Gazette Notice Vol., will come into effect on September 7, following the standard 30-day notice period. This date replaces earlier reports suggesting enforcement would begin on August 14.
The CA also emphasized that there is no compulsory identification system or CCTV installation mandated. Operators may implement additional Know Your Customer (KYC) protocols voluntarily, provided they comply with existing laws.
Highlighting the role of cyber cafes as essential access points for many Kenyans—especially for government services and online transactions—the Authority reassured stakeholders it will continue engagement ahead of the deadline.
Operators and users are encouraged to consult the official gazette for the full, binding conditions of the license.