Kenya’s New Cyber Café Licensing Rules Explained

DMjini Digital

Kenya’s New Cyber Café Licensing Rules Explained

Kenya’s New Cyber Café Licensing Rules Explained | Mjini Digital | Website Developers in Kenya

From September 7, 2026, cyber cafés in Kenya will have new requirements for recording customer information.

The Communications Authority of Kenya, CA, says licensed cyber cafés, officially known as Public Communications Access Centres, must record basic information about customers who use their computers.

What will cyber cafés record?

Cyber café operators will be required to record:

The customer’s full name

National ID or passport number

The computer or terminal used

The time the customer logs in

The time the customer logs out

A receipt for the session

These records must be kept for three years.

The rules do not require cyber cafés to record browsing history. The CA has also said that operators do not have to record the websites customers visit, their searches, or their private online communications.

The rules were published in the Kenya Gazette on August 7, 2026. They will take effect on September 7, after the required notice period.

Why has the CA introduced the rules?

The main reason given by the CA is to help fight cybercrime.

Kenya continues to face problems such as mobile money fraud, SIM swap fraud, identity theft, and online scams. KE-CIRT/CC recorded 3.37 billion cyber threat events during the first quarter of 2026.

The CA believes cyber cafés can make investigations difficult because several people may use the same computer. If a crime is committed from a cyber café, investigators may know the location or internet connection but may not know who was using the computer at that time.

By recording the customer’s identity, computer number, and session time, investigators may have more information when investigating a crime.

What does this mean for customers?

For customers, the biggest change is that using a cyber café will no longer be as anonymous as before.

Someone visiting a cyber café to print documents, access eCitizen services, apply for a service, or use the internet will need to provide identification.

Their information will then be stored by the cyber café for three years.

However, customers should understand that the CA says the rules are about identifying users and recording their sessions. They are not a requirement to record browsing history or private communications.

What does this mean for cyber café owners?

The new rules place a greater responsibility on cyber café operators.

They must collect customer information, keep accurate records, issue receipts, and protect the information they collect.

This could be difficult for small cyber cafés that use paper notebooks or basic spreadsheets to keep records.

The Data Protection Act, 2019 also applies when businesses collect personal information. A cyber café that collects names and identification numbers has a responsibility to protect that information.

Small businesses may be exempt from registering with the Office of the Data Protection Commissioner if they fall below certain business thresholds, but this does not mean they can ignore data protection requirements.

What happens if a cyber café does not follow the rules?

The new licence conditions include serious penalties.

Operators who fail to comply may face a fine of at least KES 500,000, or 0.2 percent of their annual turnover, whichever is higher. In serious cases, their licence may also be suspended or the business may be closed.

This means cyber café owners will need to take the new requirements seriously.

The main concern, data protection

One of the biggest concerns is what happens to the personal information collected by thousands of cyber cafés.

A national ID number is sensitive personal information. If these records are poorly protected, they could be stolen, copied, or misused.

This is especially important because some cyber cafés are very small businesses. Some may keep customer information in handwritten books rather than secure computer systems.

The Office of the Data Protection Commissioner has the power to take action against businesses that misuse or fail to protect personal information. However, concerns remain about whether small cyber cafés will receive enough practical guidance on how to safely store customer records for three years.

Will the rules stop cybercrime?

This is still uncertain.

The rules may help investigators identify someone who commits a crime from a cyber café. However, many modern cybercrimes do not depend on cyber cafés.

Criminals can use smartphones, mobile networks, private internet connections, public Wi-Fi, and online services from almost anywhere.

Kenya has also seen a major increase in cybercrime involving artificial intelligence. An INTERPOL assessment reported that AI was linked to more than half of reported cybercrime in Africa. The report also identified Kenya as one of the countries facing high cybercrime risks.

This means Kenya's fight against cybercrime cannot focus only on cyber cafés.

The country also needs stronger protection for mobile money, better online security, stronger systems for detecting scams, public awareness, and better protection of personal information.

What Kenyans should know

The most important points are simple.

From September 7, 2026:

• Cyber cafés will record customer names and ID or passport numbers.

• They will record the computer used and the login and logout times.

• They must keep these records for three years.

• Customers will receive receipts for their sessions.

• Cyber cafés will not be required to record browsing history under these rules.

• Cyber cafés must protect the personal information they collect.

• Operators who fail to follow the rules can face large fines, suspension, or closure.

The new rules are intended to improve Kenya's ability to investigate cybercrime. The main question is whether they will actually reduce crime while also protecting the privacy of ordinary Kenyans.

The CA will need to enforce the rules properly, and cyber café owners will need clear guidance on how to collect and protect customer information.

At the same time, Kenya needs to address the wider cybercrime problem, especially mobile fraud, online scams, identity theft, and the growing use of artificial intelligence by criminals.