privacy

Kenya's Cyber Cafés Must Now ID Every Customer as New CA Rules Take Effect Friday

Kenya's Cyber Cafés Must Now ID Every Customer as New CA Rules Take Effect Friday

Anonymous browsing at Kenya's neighbourhood cyber cafés ends on Friday, August 14, 2026. New licensing conditions issued by the Communications Authority of Kenya (CA) require every cyber café in the country to register customers by name and national identification number, log which terminal they used, and record when each session started and ended.

The requirements are not a standalone law but conditions attached to the CA's Public Communications Access Centre (PCAC) Class Licence, issued under Section 24(1) of the Kenya Information and Communications Act, Cap. 411A. They apply to cyber cafés as well as telephone bureaus, community payphones and other public communication services licensed by the Authority. According to the CA, the terms take effect once published in the Kenya Gazette.

The rules mark the conclusion of a regulatory process the CA opened in December 2024, when Director General David Mugonyi issued a public notice inviting comment on proposed reforms to cyber café licensing. That original proposal was considerably more invasive than what has now been finalised.

What Changed From the December 2024 Proposal

The CA's initial draft, published under its Review of the Telecommunications Market Structure 2024, sought to reclassify cyber cafés from PCACs into a new "Internet Cafés" licence category. It proposed mandatory CCTV surveillance in every cyber café, logging software to track user activity, and detailed record-keeping that explicitly included browsing history: which websites customers visited and which applications they used.

That version drew criticism over its scope. The finalised rules taking effect this week drop both the CCTV requirement and the browsing-history mandate. The CA has confirmed that operators are required to maintain what it calls a basic session log, covering terminal ID and session start and end times, while expressly excluding personal browsing history from that log. The shift moves the regulatory focus from physical and content surveillance toward identity registration and documentary traceability: knowing who used a terminal and when, without recording what they did online.

What Operators Must Now Do

Under Clause 3.1 and 3.2 of the PCAC Class Licence, operators must establish a mechanism for registering customers and maintain basic user logs of service usage. In practice, this means:

  • Recording a customer's full name and national ID number before granting access

  • Mapping each session to a specific computer or terminal

  • Logging session start and end times and issuing receipts

  • Retaining these records for a minimum of three years

  • Making records available to the CA during inspections, audits or cybercrime investigations

Beyond registration, operators face technical obligations. They must install software and network filters that block access to illegal websites, and scan web traffic in real time to guard against malicious downloads and illegal files. Cyber cafés must also use communications equipment that has been type-approved or exempted by the CA, and source internet connectivity only from licensed Internet Service Providers holding an Application Service Provider licence.

The licence also closes a common cost-cutting practice in the sector: bulk bandwidth reselling. Operators can no longer purchase high-capacity or wholesale internet connectivity and redistribute it to external users or third parties without explicit CA approval. Some cyber cafés have historically used this approach to lower connectivity costs by sharing a single bulk line across multiple outlets or nearby businesses; that now requires regulatory sign-off.

Penalties for Non-Compliance

Operators who breach the licensing conditions face fines equivalent to 0.2 percent of annual turnover, with a minimum penalty of KSh 500,000. The CA also retains the power to suspend or close a business. Under the licence terms, suspension follows a formal process: the Authority must notify the licensee of the breach and give them a specified period to comply before services can be suspended.

For a sector already running on thin margins, the compliance burden, covering registration systems, content filtering technology, real-time traffic scanning and three-year record retention, adds a meaningful operating cost. Smaller, informal cyber cafés that have operated with minimal infrastructure may find the technical requirements the hardest to meet.

Why the CA Is Acting Now

The CA frames the rules as a response to a sharply rising cyber threat environment. Data from the National Kenya Computer Incident Response Team Coordination Centre (KE-CIRT/CC) shows 3.37 billion cyber threat events were detected between January and March 2026 alone. System attacks accounted for more than 3.23 billion of these incidents, with malware, brute-force attacks, web application attacks and distributed denial-of-service activity all posting significant increases over the period.

The financial toll has also been substantial. According to the Africa Cybersecurity Report 2024/2025, Kenya lost an estimated KSh 29.9 billion (about $230 million) to cybercrime and related incidents, with financial services, government agencies and telecommunications firms among the most targeted sectors. Payment fraud, online fraud, phishing and ransomware were identified as the primary drivers of these losses, with mobile money users increasingly targeted.

Cyber cafés sit at a specific point of exposure in this picture: as walk-in, often cash-based access points, they have historically offered a degree of anonymity that authorities say has been exploited for online fraud, identity theft and document forgery. Registering users by name and ID number is intended to close that anonymity gap without requiring cafés to monitor what customers actually do online, a distinction the CA has been explicit about in describing the final rules.

A Shrinking but Still-Relevant Sector

Cyber cafés proliferated across Kenyan towns and cities in the late 2000s and early 2010s, when owning a personal computer or maintaining a home broadband connection was out of reach for many households. Rising smartphone penetration and cheaper mobile data have since eroded that role considerably; CA data has shown that smartphone numbers overtook feature phones nationally as early as 2023.

Despite that decline, cyber cafés remain a practical resource for specific tasks: filing tax returns, applying for government services, printing and scanning documents, and completing online job applications, particularly for people without reliable personal internet access or hardware. That continued utility is part of why the CA has kept the PCAC licensing framework in place rather than phasing it out, even as it tightens the conditions attached to it.

The new rules also sit within a broader tightening of Kenya's cybersecurity architecture. The government has been developing a National Cybersecurity Agency, while KE-CIRT/CC and the National Computer and Cybercrimes Coordination Committee continue to handle different components of the national cyber response. Separately, proposed amendments to the Computer Misuse and Cybercrimes Act are intended to address newer forms of digital crime not fully covered by existing law. The CA's cyber café licensing conditions, while narrow in scope, form one part of that wider regulatory push toward traceability across Kenya's digital access points.

Sandra Safari
ABOUT THE AUTHOR

Sandra Safari

Software Staff Writer,Sandra Safari serves a unique dual role at TechInKenya as both a Software Engineer and a Tech Journalist. Operating at the intersection of infrastructure engineering and media, s...see full bio

Weekly Tech Digest

Join the community getting the best Kenyan tech news delivered every Friday.

Comments

to join the discussion.