The Communications Authority of Kenya (CA) has walked back the most alarming interpretation of its new licensing rules for cyber cafe.
In a clarification, the regulator confirmed that operators will not be required to keep customers’ browsing history, addressing the concern that drew the most pushback after the requirements first became public.
The rules themselves are now official and have been published in the Kenya Gazette Notice Vol. and will take effect on September 7, following the standard 30-day notice period, not August 14 as earlier reports suggested.
Under the finalized conditions, public communications access centers, which include cyber cafes, must verify customers, display their charges clearly, issue receipts for paid services, and keep basic records showing they’re complying with their license.
The Authority was specific about what “basic records” means here. It identifies them as terminal identification and the start and end times of a session. As the CA put it, the requirement to maintain user logs “does not extend to a customer’s browsing history.”
READ: Cyber Café Users in Kenya Must Now Show ID Under New Rules
A log showing which terminal was used and when is a narrow, security-focused record. By contrast, logging every page a customer visited would provide a much deeper look into their online behaviour.
The Authority appears to have drawn this line deliberately, likely in response to the scrutiny surrounding the earlier reporting.
Notably, the CA also confirmed it isn’t mandating a specific identification system or requiring CCTV. Operators can add their Know Your Customer (KYC) measures if they want extra security, but only within the bounds of existing law, and it’s optional rather than prescribed.
The CA still believes that keeping session records helps investigators track down fraud, identity theft, or other online crimes linked to public internet terminals without making cafés into places with constant surveillance.
It also reconfirms that these centers remain a vital gateway for Kenyans without personal computers or reliable connectivity, particularly for government services and online transactions.
The CA says it will keep engaging cyber cafe operators and other stakeholders as the September 7 deadline approaches.


























