Kenya's cyber cafés will be required to register every customer and keep session logs from 14 August, as the Communications Authority of Kenya (CA) moves to close an identity gap in shared-computer internet access.
Operators of what the CA classifies as public communications access centres must record a customer's name and identification number, the terminal used, and the start and end time of each session, before issuing a receipt. The records must be kept for at least three years.
The CA will have powers to inspect premises, systems, equipment and records during any audit or investigation, under the new rules.
The requirement stops short of forcing cyber cafés to log browsing history. Operators must maintain a basic session log capturing the terminal ID and session times, rather than a full account of what a customer viewed online, creating a record of which registered customer used a particular machine and when.
Cyber cafés must also install software and network filters capable of blocking illegal websites, with web traffic scanned in real time to intercept dangerous downloads. Bulk or high-capacity internet connectivity can no longer be resold to customers without the CA's prior approval.
The rules follow a review the CA opened in December 2024, when it proposed reclassifying cyber cafés from public communication access centres into a dedicated "internet cafe" licence category and invited public comment.
That original proposal went further than the final rules, floating mandatory CCTV installation and full browsing-history retention alongside identity checks. The CA has since dropped the surveillance camera requirement, leaving the finalised framework focused on documentary and digital traceability rather than physical monitoring.
Non-compliant operators face fines equivalent to 0.2% of annual turnover, with a minimum penalty of $3, 860 (KSh500 000), as well as possible suspension or closure of licensed services.
The compliance burden comes as cheaper mobile data and smartphone penetration have already pushed many cyber cafés toward printing, scanning and government-service assistance as their core business.
The CA recorded 53.4 million mobile money subscriptions and 52.9 million mobile broadband subscriptions in the quarter to March 2026, with consumption exceeding 800 million GB. The National KE-CIRT/CC logged 3.37 billion cyber threat events over the same period, the bulk of them automated probes against system vulnerabilities rather than confirmed criminal cases.
The rules also introduce a new data-security obligation for operators, who must now safeguard a concentrated store of customer identity and usage records for a minimum of three years.
The regulations arrive alongside a broader national push that includes the establishment of a National Cybersecurity Agency and proposed amendments to the Computer Misuse and Cybercrimes Act.
Share


