Kenya Tightens Cyber Café Rules, Mandating Customer IDs and Three-Year Session Logs
New Communications Authority requirements take effect on 14 August, requiring public internet access centres to identify customers, record terminal and session details, and retain the records for at...
New Communications Authority requirements take effect on 14 August, requiring public internet access centres to identify customers, record terminal and session details, and retain the records for at least three years.
From 14 August 2026, cyber cafés across Kenya will face tighter customer-identification and record-keeping requirements under updated licensing conditions for Public Communications Access Centres. The measures are intended to help authorities trace individuals who use public internet facilities to commit cyber offences.
Operators will be required to record a customer’s name and identification number, the computer or terminal used, and the start and end time of the internet session. A receipt is also to be issued, with the resulting records retained for at least three years.
The requirements put cyber cafés under a more formal data-governance regime and create new responsibilities around the collection, security and retention of personal information.
The policy comes as Kenya continues to strengthen its response to cybercrime and digital fraud. Government officials have recently called for amendments to the Computer Misuse and Cybercrimes Act to address emerging threats, including AI-enabled attacks, identity manipulation and new forms of fraud
For cybercafé operators, the compliance challenge extends beyond simply checking an identity document.
Businesses will need reliable procedures for capturing customer information accurately, linking users to individual terminals, recording session times and retaining the information securely for the required period. They will also need to consider who can access those records and how they are protected against unauthorised disclosure or loss.
That creates a direct intersection between cybersecurity, data protection and law-enforcement requirements.
Kenya already has a broader data-protection framework, including the Data Protection Act, while the government is developing a wider national data-governance framework intended to strengthen standards around the management and use of data.
The new cybercafé requirements therefore create a practical compliance question: how should small businesses retain potentially sensitive identity and browsing-session information without creating a new security risk?
The answer will depend heavily on how operators implement the requirements. A three-year retention obligation increases the amount of personal information that a cybercafé may hold at any given time. Weak passwords, unsecured computers, poorly controlled staff access or informal record-keeping could expose that information to theft or misuse.
For operators, compliance should therefore be treated as a data-security obligation as well as a licensing requirement.
The new rules also create an evidentiary trail for investigators. Linking an identified customer to a particular terminal and time period could give authorities additional information when investigating cybercrime conducted through public internet facilities.
For privacy and compliance professionals, however, the effectiveness of the framework will depend on safeguards surrounding the information collected.
The central issue is no longer simply whether cyber cafés know who is using their computers. It is whether they can collect, retain, secure and disclose that information lawfully and responsibly.
With the new requirements taking effect on 14 August, cyber café operators have a clear compliance deadline and a new data-management responsibility.



No Comment! Be the first one.