The Internet Is Public. But Should Your History Be?

Kenya's new cyber café rules require basic customer and session records but explicitly exclude browsing history, raising fresh questions about internet access, surveillance and digital privacy.
Precious O. Unusere
Precious O. UnusereAcross Africa2 hours ago5 minute read
The Internet Is Public. But Should Your History Be?

For years, the cyber café was the place you went when the internet was something you had to physically go somewhere to access. Before smartphones put a browser in almost every pocket, a few minutes at a computer in a noisy café could mean submitting a university application, printing a document, checking an email or simply finding your way around the growing world of the internet.

Those cafés have gradually faded from everyday life as mobile data, smartphones and affordable computers have made internet access more personal. But in Kenya, cyber cafés are still part of the digital infrastructure for people who may not have reliable connectivity, personal computers or other digital resources.

Now, new rules governing these businesses have brought an old question into a very modern conversation: how much of what we do online should the place providing our internet access be allowed to know?

What Kenya's New Cyber Café Rules Actually Require

Image source: TechCabal

Kenya's Communications Authority (CA) has clarified that cyber café operators, officially classified as Public Communications Access Centres (PCACs), will have to keep basic records about their customers and internet sessions.

The new licensing conditions were published in the Kenya Gazette on August 7, 2026, and are scheduled to take effect on September 7 after the required 30-day period.

Under the rules, operators must verify customers before granting access, record the computer terminal used and the beginning and end of each session, display applicable charges and provide receipts for paid services.

These customer registration and session records must be securely retained for at least three years, creating an audit trail that authorities can use when a public internet facility is linked to offences such as cyber fraud, identity theft or online scams.

But there is an important distinction. The rules do not require cyber cafés to record customers' browsing histories. The CA specifically clarified that maintaining basic user logs does not mean recording the websites or pages a customer visits.

Operators must still implement approved network filtering and security measures to block illegal or harmful content, while sourcing internet services from licensed providers and complying with data protection and regulatory inspection requirements.

The rules also do not prescribe one particular identification or CCTV system, although businesses can introduce additional KYC measures where necessary if they comply with the law.

The Privacy Question Behind the Computer Screen

Image credit: BFA Global

The distinction between knowing who used a computer and knowing what that person did on it may appear small, but it matters.

A record showing that a particular customer used Terminal 6 from 2:15 p.m. to 3:10 p.m. is fundamentally different from a record showing every website that person visited during those 55 minutes.

The first creates accountability if the facility is connected to a crime; the second creates a much more detailed picture of someone's activities, interests and potentially sensitive personal behaviour.

Kenya's decision comes against a background of concerns over how personal information is collected and used. The country's Huduma Namba case raised questions about the handling of sensitive identity data, while more recent legal scrutiny of access to telecommunications records has kept privacy firmly in the public conversation.

The High Court of Kenya also recently reinforced the importance of privacy protections. In a May 13 ruling, Justice Bahati Mwamuye awarded damages to petitioners who sued Safaricom and M-Pesa, holding that Article 31 of Kenya's Constitution, which protects the right to privacy, places a non-delegable duty on data controllers.

That makes the cyber café rules particularly interesting. They attempt to create accountability without automatically turning every public computer into a detailed surveillance record.

And perhaps there is another question underneath all of this: do we ever completely own our browsing history once we connect to someone else's network?

The Cyber Café Never Really Disappeared

Image credit: Nyongesa Sande

The rise of cyber cafés followed the spread of public internet access in the 1990s and early 2000s. They became important gateways into the digital world, particularly in places where owning a computer or maintaining a private internet connection was expensive.

In Kenya and across much of Africa, cafés became informal digital centres. People used them for schoolwork, email, job applications, online banking, printing and government services.

Whatsapp promotion

Then smartphones arrived, mobile internet became cheaper and Wi-Fi became increasingly common. The computer terminal that once represented access to the internet gradually became unnecessary for many people. But it never became unnecessary for everyone.

For students without personal computers, job seekers who need to print documents, people applying for government services or communities with limited digital resources, public internet centres can still provide an important bridge. That is why Kenya's attempt to regulate them matters beyond the cafés themselves.

Image credit: HustleCare

The new rules acknowledge that these spaces can be useful while also recognising that they can become points of concern when criminal activity takes place through them. The challenge is ensuring that security measures do not turn into unnecessary collection of information about ordinary users.

Failure to comply with the rules could result in sanctions, including fines of at least KSh500,000 ($3,863.99) or 0.2% of annual turnover, whichever is higher, as well as possible suspension or closure.

For a business that has survived the decline of the traditional cyber café, that is a significant regulatory responsibility. For its customers, the more important takeaway may be simpler: Kenya is drawing a line between knowing that you used the internet and knowing exactly where you went once you got there.

Loading...