Kenya’s communications regulator has clarified that new licensing rules for cyber cafes will not require operators to retain customers’ browsing histories, seeking to ease concerns over privacy and surveillance under the updated regulations.
The Communications Authority of Kenya said public communications access centres, commonly known as cyber cafes, will instead be required to maintain basic session information, including the identification of the terminal used and the start and end times of a customer’s session. This was announced earlier this week and has already been happening in other places like Nigeria.
The new licence conditions were published in the Kenya Gazette on Aug. 7 and will take effect Sept. 7 after the statutory 30-day period.
The rules require operators to verify customers, display applicable charges, issue receipts for paid services and maintain basic records demonstrating compliance with their licences. The records are intended to provide an audit trail where a public internet facility is linked to unlawful activity, including cyber-enabled fraud, scams and identity-related offences.
“The requirement for PCACs to maintain basic user logs does not extend to a customer’s browsing history,” the authority said in a statement Thursday.
The clarification follows public debate over the scope of the new requirements, with concerns that cyber cafes could be compelled to monitor or retain detailed records of users’ online activities.
The CA said the licence conditions also do not prescribe a specific customer identification system or closed-circuit television solution. Operators may introduce additional know-your-customer measures as part of their security controls, provided they comply with applicable laws.
Public internet centres remain an important access point for Kenyans without personal computers, reliable internet connections or other digital resources, the regulator said. They are widely used for online government services, applications, transactions and other activities tied to the digital economy.
The authority said the regulatory framework is intended to balance access to digital services with consumer protection, privacy and security as cybercrime and online fraud increase.
The CA said it will continue engaging cyber cafe operators and other stakeholders ahead of the Sept. 7 implementation date.
Operators and members of the public can consult Kenya Gazette Notice Vol. CXXVIII No. 135, published Aug. 7, for the full licensing conditions.

