Kenya Clarifies Cyber Café Licensing Rules: No Browsing History Tracking Required
Key Takeaways
- •Cyber café operators must verify customers, log the terminal used and session times, and keep records for at least three years.
- •The Communications Authority said the rules do not require operators to collect or retain users' browsing histories.
- •The new licensing conditions were published on August 7 and are due to take effect on September 7 after the 30-day notice period.
- •Operators may add their own KYC measures, but the rules do not mandate any specific identification system or CCTV setup.
- •Violations could lead to fines of at least KSh 500,000 or 0.2% of annual turnover, along with possible suspension or closure.

Kenya's Communications Authority (CA) has moved to clarify new licensing rules for cyber cafés, stating that while operators must maintain basic customer and session records, they will not be required to track or retain users' browsing histories.
The clarification, issued by the agency on Thursday, follows widespread public discussion and media coverage regarding the new requirements for Public Communications Access Centres (PCACs)—facilities that provide internet access to individuals who may lack personal computers, reliable connectivity, or other digital resources. The CA's official statement addresses concerns that arose after the rules were initially announced.
The new license conditions were published in the Kenya Gazette Notice Vol. CXXVIII No. 135 on August 7 and are scheduled to take effect on September 7, following the statutory 30-day notice period.
Under the regulations, cyber café operators are required to verify customers before granting computer access, record the specific terminal used along with the start and end times of each session, display applicable service charges, and issue receipts for all paid services. Customer registration details and session logs must be securely retained for a minimum of three years.
The CA stated that these records are intended to establish an audit trail in cases where a public internet facility is linked to unlawful activity, including cyber-enabled fraud, identity theft, online scams, and other offences.
"The requirement for PCACs to maintain basic user logs does not extend to a customer's browsing history," the Authority confirmed.
The rules do not mandate any specific customer identification system or CCTV solution. Operators retain the flexibility to introduce additional Know Your Customer (KYC) measures as needed, provided such measures comply with applicable laws.
Cyber cafés will, however, be expected to implement approved network filtering and security measures designed to block illegal or harmful content. They must also procure internet capacity from licensed providers and comply with the CA's requirements for regulatory inspections and data protection. These obligations align with Kenya's Data Protection Act, 2019, which established the legal framework governing how personal data is collected, processed, and stored, and created the Office of the Data Protection Commissioner (ODPC) to enforce compliance.
The clarification comes amid longstanding concerns in Kenya regarding how personal data is collected, stored, and accessed. The Huduma Namba case, which involved legal challenges to the government's National Integrated Identity Management System (NIIMS) between 2019 and 2021, raised significant questions about the protection of sensitive identity data and the risk of personal information being repurposed beyond its original intent.
More recently, scrutiny by regulators, courts, and civil rights groups over access to telecom records has kept data privacy firmly in the spotlight. In a landmark ruling on May 13, the High Court of Kenya, presided over by Justice Bahati Mwamuye, awarded general damages to petitioners who sued Safaricom and M-Pesa. The court held that Article 31 of Kenya's Constitution, which guarantees the right to privacy, imposes a non-delegable duty on data controllers.
The CA's decision to explicitly exclude browsing history from mandatory record-keeping is notable. Cyber cafés can now be required to establish who used a particular computer and when, without being compelled to record which websites that individual visited. The distinction matters in a country where public internet facilities continue to serve as essential access points for citizens engaging with e-government services, job applications, and online education—particularly in areas where home broadband penetration remains limited.
Non-compliance with the new requirements could result in regulatory sanctions, including fines of at least KSh 500,000 ($3,863.99) or 0.2% of annual turnover—whichever is higher—as well as potential suspension or closure of the business.