Search

    Select Website Language

    Kenya’s Communications Authority (CA) has clarified new licencing rules for cyber cafés, saying operators will be required to keep basic customer and session records but will not have to track users’ browsing histories.

    The clarification, issued by the agency on Thursday, follows public discussion and media reports about the new requirements for Public Communications Access Centres (PCACs), which provide internet access to people who may not have personal computers, reliable connectivity, or other digital resources.

    It comes amid longstanding concerns in Kenya about how personal data is collected, stored, and accessed. The Huduma Namba case, which involved legal challenges to the government’s National Integrated Identity Management System (NIIMS) between 2019 and 2021, raised questions about the protection of sensitive identity data and the risk of personal information being used beyond its original purpose.

    The new licence conditions were published in the Kenya Gazette Notice Vol. CXXVIII No. 135 on August 7 and will take effect on September 7, after the statutory 30-day period.

    Under the rules, cyber café operators must verify customers before granting access, record the terminal used and the start and end times of each session, display applicable charges, and issue receipts for paid services. Customer registration and session records must also be securely retained for at least three years.

    The CA said the records are intended to provide an audit trail when a public internet facility is linked to unlawful activity, including cyber-enabled fraud, identity theft, online scams, and other offences.

    “The requirement for PCACs to maintain basic user logs does not extend to a customer’s browsing history,” the Authority said.

    The rules also do not mandate a specific customer identification system or CCTV solution. Operators can introduce additional Know Your Customer (KYC) measures where necessary, provided they comply with applicable laws.

    Cyber cafés will, however, be expected to implement approved network filtering and security measures to block illegal or harmful content. They must also source internet capacity from licensed providers and comply with the CA’s requirements for regulatory inspections and data protection.

    Recent scrutiny by regulators, courts, and civil rights groups over access to telecom records has kept data privacy in the spotlight. In a landmark May 13 ruling, the High Court of Kenya, presided over by Justice Bahati Mwamuye, awarded general damages to petitioners who sued Safaricom and M-Pesa and held that Article 31, which guarantees the right to privacy, imposes a non-delegable duty on data controllers.

    The CA’s decision to explicitly exclude browsing history from the required records is significant. Cyber cafés can now be required to establish who used a computer and when, without having to record which websites that person visited.

    Non-compliance with the new requirements could attract regulatory sanctions, including fines of at least KSh500,000 ($3,863.99) or 0.2% of annual turnover, whichever is higher, as well as suspension or closure.

    True scale demands moving beyond surface-level integrations to robust execution. We’ve filtered the noise out of Moonshot 2026, optimising the conference strictly for high-calibre connections between startup founders, global financial operators, enterprise leaders and individuals rewiring Africa’s technical frameworks. Get 20% off Early Bird tickets for a limited time.

    Previous Article
    Mr Eazi’s Choplife is the latest startup to move to digital free zone Itana
    Next Article
    SASSA September 2026 payment dates: Full schedule

    Related Diaspora Updates:

    Are you sure? You want to delete this comment..! Remove Cancel

    Comments (0)

      Leave a comment