We are not after your browsing history; CA clarifies new cyber café laws
An image of a cyber café. Photo:CA
Audio By Vocalize
CA said, in an earlier report, that all public cyber cafés must maintain customer login sessions showing terminal IDs and start/end times for 3 years— excluding personal browsing history in a bid to tame cybercrime.
The Authority has now maintained that Public Communications Access Centre operators will be required to verify customers, display applicable charges, issue receipts for paid services, and maintain basic records necessary to demonstrate compliance with licences.
Operators will only be required to maintain basic session information, comprising the terminal identification and the start and end times of a customer session.
“The requirement for PCACs to maintain basic user logs does not extend to a customer's browsing history,” the Authority reiterated.
The new licence conditions were published in the Kenya Gazette Notice Vol. CXXVIII No. 135 on August 7, 2026, and will take effect on September 7.
Operators have, however, been allowed the option of introducing additional Know Your Customer (KYC) measures as part of their security and operational controls, provided the measures comply with applicable laws.
"The clarification follows public discussion and media coverage of the new conditions, which have raised questions over the extent of monitoring and identification requirements imposed on cyber cafés," CA added.
Businesses that breach the licensing conditions will also pay fines equivalent to 0.2 per cent of annual turnover, with a minimum penalty of Ksh.500,000.

Join the Discussion
Share your perspective with the Citizen Digital community.
No comments yet
This discussion is waiting for your voice. Be the first to share your thoughts!