Kenya’s Communications Authority (CA) has clarified new licencing rules for cyber cafés, saying operators will be required to keep basic customer and session records but will not have to track users’ browsing histories.
The clarification, issued by the agency on Thursday, follows public discussion and media reports about the new requirements for Public Communications Access Centres (PCACs), which provide internet access to people who may not have personal computers, reliable connectivity, or other digital resources.
It comes amid longstanding concerns in Kenya about how personal data is collected, stored, and accessed. The Huduma Namba case, which involved legal challenges to the government’s National Integrated Identity Management System (NIIMS) between 2019 and 2021, raised questions about the protection of sensitive identity data and the risk of personal information being used beyond its original purpose.
The new licence conditions were published in the Kenya Gazette Notice Vol. CXXVIII No. 135 on August 7 and will take effect on September 7, after the statutory 30-day period.
Under the rules, cyber café operators must verify customers before granting access, record the terminal used and the start and end times of each session, display applicable charges, and issue receipts for paid services. Customer registration and session records must also be securely retained for at least three years.









