Kenya's cyber cafe rules do not require browsing history, but the logging debate is not over
The CA has clarified that cyber cafes must keep basic session records, not private browsing histories. The remaining question is whether the identification framework is proportionate in 2026.

Kenya's Communications Authority has moved to correct one of the most alarming interpretations of its new rules for public internet centres.
Cyber cafes will not be required to record customers' browsing histories.
The Authority says operators will keep basic session information such as the terminal used and the start and end time of a session, while also meeting customer-verification and ordinary licence-compliance requirements.
The new conditions were published in the Kenya Gazette on August 7 and take effect on September 7, 2026, after the statutory 30-day period.
That clarification narrows the privacy concern.
It does not eliminate the policy debate.
The question is now how much identification and logging is proportionate for a public internet service in 2026.
What the regulator says the framework is for
The CA argues that public communications access centres can become part of investigations involving:
- Online scams
- Identity-related offences
- Cyber-enabled fraud
- Other unlawful activity
A basic session record can help investigators connect activity from a shared terminal to a time window.
That is the regulatory logic.
A public internet terminal may be used by dozens of people.
An IP address alone may identify the cyber cafe rather than the individual sitting at a computer.
Session information adds an audit trail.
What the rules do not require
The CA's August 13 clarification is important because it directly addresses browsing history.
The Authority says basic logs do not extend to the websites a customer visited.
It also says the licence conditions do not prescribe a particular customer-identification technology or a mandatory CCTV solution.
Operators may adopt additional Know Your Customer measures if they choose, but those measures still need to comply with applicable law.
That means a cyber cafe should not interpret "security" as unlimited permission to collect information.
Data-protection principles still apply.
Why the earlier reaction was so strong
The idea of linking identity to public internet use has a long history.
It can sound like a policy designed for an older internet in which cyber cafes were the main way many people went online.
In 2026, sophisticated online fraud can happen through:
- Smartphones
- Home broadband
- VPNs
- Compromised accounts
- Cloud infrastructure
- Foreign services
That creates a reasonable challenge to the policy.
How much cybercrime will a cyber-cafe register actually prevent?
If the burden falls heavily on students, job seekers and people who rely on shared internet access, the rule could create friction without meaningfully changing sophisticated crime.
Public access still matters
Cyber cafes are less culturally visible than they were twenty years ago.
They are not irrelevant.
People still use public access centres to:
- Apply for government services
- Print documents
- Complete job applications
- Access education portals
- Scan forms
- Make online transactions
- Use a computer they do not own
That means regulation should avoid turning access into unnecessary surveillance.
Users should know:
- What information is collected
- Why it is collected
- How long it is retained
- Who can access it
- How it is protected
- When it is deleted
A paper notebook full of identity details can create a privacy problem of its own.
The cybersecurity irony
The regulator wants better records to fight cybercrime.
Poorly stored records can become a new target for cybercrime.
A small cyber cafe may not have a security team.
If operators collect identity information, they need practical guidance on:
- Access control
- Encryption where digital systems are used
- Secure disposal
- Staff permissions
- Incident response
- Retention
Collecting data creates responsibility.
A rule that demands information without ensuring safe handling can move risk from the browsing session to the register.
The principle of data minimisation
Good privacy practice asks whether an organisation is collecting only what it needs for a legitimate purpose.
If terminal ID, session time and limited identity information meet the regulatory purpose, the system should resist expanding into detailed activity monitoring without a clear legal basis.
This is where the CA clarification is welcome.
It draws an explicit line around browsing history.
The next step should be equally clear implementation guidance so operators do not invent excessive KYC practices because they fear penalties.
Can this policy deter crime?
It may deter opportunistic abuse of public terminals.
It is unlikely to stop determined cybercriminals by itself.
Attackers can use other networks, stolen credentials or infrastructure outside Kenya.
That does not make local records useless.
It means the policy should be evaluated honestly.
The regulator should eventually measure outcomes such as:
- How often logs assist investigations
- Compliance costs for small operators
- Whether public access declines
- Whether identity data is breached
- Whether legitimate users are discouraged
Policies become outdated when nobody measures whether they work.
The tecMAMBO take
The Communications Authority did the right thing by clarifying that cyber cafes are not expected to archive what customers browse.
That should have been unmistakable from the beginning.
The remaining policy deserves scrutiny rather than panic.
Basic session accountability can have a legitimate investigative purpose.
But every new log creates cost, privacy exposure and responsibility.
Kenya should not confuse more data collection with more cybersecurity.
The best rule is the smallest one that demonstrably solves the problem.
Sources
Ask MAMBO
Have a plain-English question about this topic? Send it in and we may answer it in a future guide.
Ask a question

