From August 14, cyber cafés must register customers and maintain session records, creating a three-year trail of who used which computer and when as Kenya tightens its fight against cybercrime.
Kenya is about to make anonymous internet access harder as the Communications Authority of Kenya introduces new licensing requirements requiring cyber cafés to identify customers and keep records of their sessions.
From August 14, 2026, cyber cafés operating as Public Communications Access Centres (PCACs) will be required to establish a mechanism for registering customers and maintain basic service-use logs. The requirements include the terminal ID and the start and end time of a customer’s session, while expressly excluding personal browsing history from the required session log. Operators must retain records relevant to compliance for at least three years.
The requirements are contained in the Communications Authority’s PCAC Class Licence, issued under the Kenya Information and Communications Act, Cap. 411A. The move puts Kenya’s cyber cafés at the centre of a growing debate over the balance between digital security and personal privacy.
The law behind Kenya’s new cyber café rules
The legal basis for the requirements is important. The Kenya Information and Communications Act, Cap. 411A, provides the statutory framework under which the Communications Authority regulates and licenses communications services. Under Section 24(1) of the Kenya Information and Communications Act, a person may not operate a telecommunications system or provide telecommunications services except in accordance with a valid licence granted under the Act.
It is through this licensing framework that the CA has imposed the new operational requirements on Public Communications Access Centres. The specific customer-registration requirement is contained in Clause 3.1 of the PCAC Class Licence, which requires licensees to put in place a mechanism for registering customers.
Under Clause 3.2, operators must maintain a customer session log containing the terminal ID and session start and end time. Crucially, the licence states that the required log excludes personal browsing history. Clause 3.3 requires licensees to retain records relevant to compliance with the licence for a minimum of three years, while Clause 3.4 requires operators to submit reports to the Authority when requested.
The Authority’s oversight powers are also spelled out in the licence.
Under Clause 5, authorised officers may access a licensee’s premises, systems, records and equipment for purposes including inspection, audit and investigation. Clause 7 provides further inspection and enforcement powers, including action where a licensee breaches the conditions of the licence.
This means the three-year cyber café record-keeping requirement is not a new provision of the Computer Misuse and Cybercrimes Act. It is a condition of the PCAC Class Licence issued by the Communications Authority under the Kenya Information and Communications Act. That distinction matters because it identifies exactly where the requirement comes from and what the Authority is regulating.
From anonymous browsing to identifiable users
Cyber cafés have traditionally offered Kenyans relatively easy access to computers and the internet without requiring them to own a computer or maintain a permanent broadband connection. That role remains important even as smartphone ownership and mobile internet access have expanded. Customers continue to use cyber cafés to file tax returns, access government services, print documents, apply for jobs, scan paperwork and complete online applications.
Under the new requirements, however, visiting a cyber café will leave behind a formal record. Operators must register customers and maintain session information showing which terminal was used and when the session started and ended. That could provide investigators with an additional trail when a computer or public internet connection is linked to suspected criminal activity.
Why the government is tightening the rules
The new requirements arrive as Kenya faces a growing cybercrime problem. Cybercriminals increasingly exploit digital channels for mobile-money theft, identity fraud, SIM-swap attacks, phishing, malware and other forms of online crime.
The Communications Authority’s cybersecurity monitoring system has recorded billions of cyber threat events, reflecting the growing scale of attacks against Kenya’s digital infrastructure. Cyber cafés can present a particular challenge for investigators because shared computers and public internet connections can make it harder to establish who was using a particular terminal at a particular time. The CA’s new requirements are designed to close some of that attribution gap.
But who gets access to the data?
That is where the policy becomes more controversial. A cyber café registration record can contain a person’s name and identification details alongside information showing when they accessed a particular terminal. The three-year retention requirement means operators will be responsible for safeguarding this information long after the customer has left the premises.
The question therefore shifts from simply whether the information should be collected to who can access it, under what circumstances and how securely it will be stored. This is particularly important because cyber cafés range from relatively sophisticated digital service businesses to small neighbourhood shops with limited technical resources. A database created to help investigators trace criminals could itself become a target if operators fail to secure it properly.
The privacy test
Kenya’s legal framework already places obligations on organisations handling personal information. The Kenya Information and Communications Act requires licensees, where applicable, to take necessary steps to secure personal data under their possession or control through appropriate technical and organisational measures.
The cyber café debate is therefore not simply about the CA’s power to impose licensing conditions. It is also about whether operators can collect, retain and protect customer information in a manner consistent with Kenya’s broader data-protection requirements.
The CA’s rules are also narrower than a system that records users’ entire internet activity. Under Clause 3.2 of the PCAC Class Licence, the required session log is limited to information such as the terminal ID and session start and end times and does not include personal browsing history. That distinction will be important in determining how intrusive the new regime ultimately becomes.
Will tracking users actually stop cybercrime?
There is also a practical question over whether the rules will significantly reduce cybercrime. A customer registration system can make it easier to identify the person associated with a particular cyber-café terminal. But criminals can use other channels, including personal smartphones, public Wi-Fi, compromised accounts and stolen identities.
A registered name and ID number therefore do not automatically prove that the individual whose details appear in a cyber-café log was the person who committed an offence. The value of the system will depend partly on the accuracy of the registration process and the ability of investigators to combine cyber-café records with other digital evidence.
A new compliance burden for cyber cafés
The new requirements also add another layer of compliance for cyber café operators. In addition to registering customers and maintaining session records, operators must retain relevant compliance records for at least three years and provide reports to the Authority when required.
For businesses already operating in a market disrupted by smartphones and cheaper mobile data, the additional administrative and data-security obligations could increase operating costs. The new licensing regime is consequently not only a cybersecurity measure. It is also a change to how public internet businesses in Kenya must operate.
Kenya’s new digital trade-off
The government is betting that greater traceability will make cybercrime harder to commit anonymously. Privacy advocates and ordinary internet users, meanwhile, will want assurances that the information collected under the new rules will not become a tool for unnecessary surveillance or expose legitimate users to new data-security risks.
The CA’s decision to exclude personal browsing history from the required session log provides an important boundary.
But the three-year retention requirement still means cyber cafés will become custodians of identifiable customer records for a significant period. For Kenya, the real test will be whether the new system can give investigators a stronger trail to follow without turning every visit to a cyber café into an unnecessarily intrusive record of an individual’s digital life.
5 Key Takeaways
- The rules take effect August 14: Cyber cafés operating as Public Communications Access Centres will have to comply with the new PCAC Class Licence requirements.
- The legal basis is KICA: The PCAC Class Licence is issued under the Kenya Information and Communications Act, Cap. 411A, with Section 24(1) providing the licensing framework.
- Customers must be registered: Clause 3.1 requires operators to establish a mechanism for registering customers, while Clause 3.2 requires basic session logs.
- The logs are limited but retained for three years: Clause 3.2 covers terminal ID and session start/end times and excludes personal browsing history, while Clause 3.3 requires relevant records to be retained for at least three years.
- The CA has inspection powers: Clauses 5 and 7 provide the Authority with powers relating to access, inspection, audits, investigations and enforcement of the licence conditions.
