The Communications Authority of Kenya (CA) has addressed public concerns regarding recently introduced licensing conditions for cyber cafés and public internet centres.

Contrary to misconceptions, the new rules do not require operators to track or store customers' browsing histories. Instead, the regulations mandate that cyber café operators maintain basic user session logs—specifically terminal identification and session start and end times—for a period of three years.

Additional obligations include verifying customers, displaying service charges, issuing receipts, and keeping records to demonstrate compliance with licensing requirements. These measures aim to enhance cybersecurity and combat cybercrime without infringing on users' privacy.

The licensing conditions were published in the Kenya Gazette Notice Vol. CXXVIII No. 135 on August 7, 2026, and will become effective on September 7, 2026. Operators may implement further Know Your Customer (KYC) procedures as long as they adhere to applicable laws.

Non-compliance with the licensing rules will attract penalties amounting to 0.2% of the operator's annual turnover, with a minimum fine of Ksh 500,000.

Key Points of the New Cyber Café Licensing Rules

  • Maintain user session logs: terminal ID and session start/end times for three years.
  • Verify customers and display service charges clearly.
  • Issue receipts for all paid services.
  • Additional KYC measures allowed within legal boundaries.
  • Fines imposed for breaches starting at Ksh 500,000 or 0.2% of annual turnover.

The CA emphasized that the licensing updates are intended to strengthen security frameworks in public internet access points rather than restrict digital access or invade user privacy.