Kenya Clarifies Cyber Café Rules: Customer Logs Required, Browsing History Excluded
Communications Authority Explains New Requirements
Kenya's Communications Authority (CA) has clarified what cyber café operators will be required to record under updated licensing conditions for Public Communications Access Centres (PCACs).
The regulator says cyber cafés will need to maintain basic information about customers and their internet sessions, but they will not be required to record customers' browsing histories.
The clarification follows public concern over reports suggesting that the new rules could give operators broader responsibilities for monitoring internet users.
What Cyber Cafés Will Have to Record
Under the updated licensing conditions, operators will be expected to establish basic records showing who accessed their facilities and when.
The requirements include:
- Verifying customers before providing access.
- Recording the computer or terminal used.
- Documenting when a session starts and ends.
- Displaying applicable service charges.
- Providing receipts for paid services.
- Securely retaining registration and session records for at least three years.
The CA says these records are intended to create an audit trail that can assist investigations when a public internet facility is connected to illegal activity.
Possible offences include online scams, cyber-enabled fraud and identity theft.
Browsing History Is Not Required
The key clarification from the regulator is that cyber cafés do not have to record the websites or online content accessed by individual customers.
In other words, an operator may be required to establish that a particular person used a specific computer at a particular time, but the licensing conditions do not require the operator to document every website that person visited.
This distinction is significant given the wider debate around digital privacy and government access to personal information.
No Mandatory CCTV or Identification System
The new rules also do not require cyber café owners to adopt one specific form of customer identification technology or CCTV system.
Operators may introduce additional Know Your Customer (KYC) procedures where appropriate, but any such measures must comply with existing legal and data protection requirements.
This gives operators some flexibility in deciding how they meet the verification requirements.
Security Measures Will Still Be Required
While browsing histories are excluded from the mandatory records, cyber cafés will still have cybersecurity responsibilities.
Operators must implement approved network filtering and security controls designed to prevent access to illegal or harmful content.
They must also obtain internet connectivity from licensed providers and comply with requirements related to regulatory inspections and data protection.
Why the Rules Are Being Introduced
The Communications Authority says the new requirements are intended partly to improve accountability when public internet facilities are used in connection with unlawful activity.
Cyber cafés remain important access points for people who may not have their own computers, stable internet connections or other digital resources.
The regulator therefore appears to be trying to establish a basic level of traceability without requiring businesses to monitor the detailed online activities of every customer.
Data Privacy Remains a Major Concern
The clarification comes against a backdrop of continued debate in Kenya about how personal information is collected and handled.
Previous legal disputes, including challenges surrounding the country's National Integrated Identity Management System, have contributed to wider concerns about the collection, storage and potential misuse of sensitive data.
More recently, scrutiny of access to telecommunications records has kept privacy rights in the public conversation.
Kenya's Constitution protects the right to privacy, making the balance between security requirements and personal data protection an important consideration for regulators.
When Will the New Rules Take Effect?
The updated licence conditions were published in the Kenya Gazette on August 7.
They are scheduled to take effect on September 7, following the required 30-day statutory period.
Cyber café operators will therefore need to ensure that their businesses are prepared to meet the new requirements once the rules become effective.
Penalties for Non-Compliance
Operators who fail to comply could face regulatory action.
Potential penalties include fines of at least KSh500,000 or 0.2% of annual turnover, whichever is higher.
Authorities may also suspend or close facilities that fail to meet the required conditions.
What the New Rules Mean for Internet Users
For customers, the distinction between session records and browsing history is important.
A cyber café may need to know who used a computer and when, but the new licensing conditions do not require it to maintain a record of the websites that customer visited.
The policy therefore introduces additional accountability for public internet facilities while stopping short of making detailed browsing surveillance a licensing requirement.
As the rules take effect, how cyber cafés implement customer verification and protect the records they collect will likely remain an important part of Kenya's ongoing data privacy debate.
