
Kenya’s Communications Authority (CA) has clarified new licensing requirements for cyber cafés, saying operators will not be required to monitor or retain customers’ browsing histories. The clarification follows public concern that new rules for public communications access centres could introduce broad online surveillance.
The new requirements apply to public communications access centres, commonly known as cyber cafés. While the rules introduce stronger customer-record requirements, the regulator has drawn a clear distinction between basic session information and detailed records of what customers do online.
Under the clarified rules, operators will need to maintain basic information such as the identification of the computer terminal used and the start and end times of a customer’s session. The CA says this requirement does not extend to recording the websites customers visit or maintaining their browsing history.
The clarification is important because cyber cafés remain an important access point to the internet for many Kenyans. Although smartphones and affordable mobile data have reduced reliance on public computers, cyber cafés continue to provide services such as printing, scanning, online applications, government-service access and internet browsing.
The regulator says the record-keeping requirements are intended to improve accountability and help investigations when a facility is connected to unlawful activity. Rather than creating a system that tracks every website a customer visits, the rules allow authorities to establish which terminal was being used and when a particular session took place.
The approach attempts to balance two competing priorities: cybersecurity and privacy. Kenya has been strengthening its response to online crime as fraud, identity theft and other cyber threats evolve. The government has also indicated that it wants to update cybercrime laws to address emerging threats linked to technologies such as artificial intelligence.
At the same time, extensive monitoring of browsing activity could raise significant privacy concerns. Recording every website visited by customers would create a much more detailed picture of their personal activities and could place additional responsibilities and costs on small cyber-café operators.
The CA’s clarification therefore narrows the scope of the new requirements. Operators will still need to comply with licensing and record-keeping obligations, but they will not be expected to become surveillance centres monitoring customers’ online behaviour.
The finalized rules are scheduled to take effect on September 7, 2026, following their publication in the Kenya Gazette.
For Kenya’s cyber-café industry, the development provides some relief after concerns about the practical and privacy implications of the new rules. For internet users, it reinforces the principle that improving digital security does not necessarily require tracking everything people do online.
The challenge now will be ensuring that cyber cafés understand exactly what records they must keep—and that those records are handled responsibly while Kenya continues to strengthen its digital-security framework.
Leave a Reply