Starting August 14, 2026, all licensed cyber cafés and public communication access centers to will be required to log and store customer identities. This directive, part of a broader strategy to curb the rising tide of cybercrime, marks a shift toward stricter accountability for users of public terminals. While the measures aim to enhance national security, they also introduce new operational and data-protection challenges for the businesses that provide these essential services.
Under the new licensing conditions, operators must establish systems to verify customer identities before granting access to any computer. Specifically, cyber cafés are required to record each user’s full name and national ID or passport number, alongside the terminal ID used and the exact start and end times of the session. Crucially, the Communications Authority has further stated that these records must not include personal browsing history or private messages, focusing instead on identifying who used a specific terminal and for how long.
Beyond identity logging, the regulations impose several technical and administrative obligations. Businesses must use communications equipment that has been duly type-approved or accepted by the CA and obtain internet connectivity from authorized service providers. Furthermore, operators are mandated to deploy content-filtering mechanisms to protect users from illegal or harmful content, display their prices clearly, and issue formal receipts for every paid session.
To ensure compliance, the CA requires that all customer logs be stored for a minimum of three years from the date of creation. Authority officers are empowered to inspect these records and enter premises to audit systems and equipment. The consequences for failing to adhere to these rules are that businesses may face suspension of services, closure, or heavy fines. Penalties for breaching licensing conditions are set at 0.2 percent of annual turnover, with a minimum fine of Ksh 500,000.
The primary driver for these measures is the identification of public internet facilities as potential hotspots for identity theft, SIM-swap fraud, phishing, and online scams. By creating a traceable link between a digital session and a physical identity, the State hopes to tame emerging cyber threats and improve the efficacy of investigations. These rules align with the Computer Misuse and Cybercrime (Amendment) Act, 2024, which provides the legal framework for addressing modern digital offences.
However, the directive has raised concerns regarding its impact on the many small businesses that constitute the cyber café sector. These establishments often serve as vital hubs for Kenyans accessing government platforms like eCitizen, printing services, and document preparation. Operators now face the added burden of protecting sensitive personal data against theft or unauthorized disclosure. There are also fears that customers may be reluctant to share their private details, potentially driving business away and harming the survival of these small enterprises.
Kenya’s move to mandate identity logging in cyber cafés represents a determined effort to balance public safety with digital access. By formalizing the relationship between users and the terminals they operate, the Communications Authority seeks to close loopholes exploited by cyber related criminals. Nevertheless, the success of this policy will depend on how effectively small businesses can manage their new data-protection responsibilities and whether the increased oversight will impact the accessibility of digital services for the general public.
Kenya isn’t the first country to implement such laws, some countries like Nigeria, South Korea, China among others have had these laws in place. The laws were however met with public scrutiny and concern due to lack of internet anonymity, lack of the freedom of expression which led to the court striking the law down in South Korea and concerns on right of privacy.
The law did have its share of positives as well, like increased traceability which is a broader network control mechanism.
Well, those are the newest news in town, carry your ID the next time you need to use a computer in your local cyber cafe.
DISCLAIMER!
This post is meant for educational purposes and does not amount to legal advice.
For our services reach out through:
Email: gichuhinadvocates@gmail.com
Phone: +254719245471
GICHUHI N ADVOCATES “Your Strategic Legal Partner, Always’’
