" "

Cyber cafés face new rules in Kenya as the CA tightens controls on public internet access


Cyber cafés in Kenya will face new customer identification and record-keeping requirements from Friday, August 14, as the Communications Authority of Kenya (CA) tightens controls on public internet access in response to cybercrime risks. The new regulations require operators of public communications access centres to register customers, maintain basic session logs, issue receipts and retain the records for at least three years.

The rules require cyber cafés to record information including a customer’s name and identification number, the computer or terminal used, and the start and end time of a session. The CA will also have the power to access premises, systems, equipment and records when conducting an inspection, audit or investigation.

The measures come as Kenya deals with a broad cyber threat environment covering mobile-money fraud, identity theft, malware, phishing and attacks against connected infrastructure. CA data shows that the National KE-CIRT/CC detected 3.37 billion cyber threat events between January and March 2026, including system vulnerabilities, malware, brute-force attacks, web application attacks and distributed denial-of-service activity.

The new licensing requirements are aimed at closing an attribution gap that can arise when people use shared computers and public internet connections.

Under the rules, cyber café operators must put in place a mechanism for registering customers and maintain a basic customer session log. The log is expected to capture the terminal ID and session start and end times, while excluding personal browsing history.

JOIN OUR TECHTRENDS NEWSLETTER

That distinction matters. The requirement does not, based on the provision quoted in the regulations, amount to an instruction for cyber cafés to retain a complete history of everything a customer browses. Instead, it creates a record showing which registered customer used a particular terminal and when.

For investigators dealing with an incident, that information could provide a starting point for establishing who had access to a particular computer at a particular time. It can also help distinguish legitimate users from activity carried out through a public access point.

The CA will be able to request access to the premises, systems, records and equipment of licensed operators for inspection, audit or investigation. Cyber cafés therefore become part of the evidentiary trail available to authorities when digital offences are investigated.

Why the CA is demanding customer and session records

Public computers present a different security problem from a personally owned smartphone or laptop. Multiple people may use the same machine, browsers can retain credentials, and poorly protected networks or computers can expose users to malware and credential theft.

The regulations therefore combine identity registration with technical controls. Operators will be required to install software and network filters that block access to illegal websites, while web traffic must be scanned in real time to prevent dangerous downloads or illegal files.

The CA is also restricting bandwidth reselling. Cyber cafés will not be allowed to purchase bulk or high-capacity internet connectivity and divide it among customers without the regulator’s approval.

The measures extend beyond conventional cybercrime. The rules also target internet-enabled offences and abuses including piracy, document forgery, identity theft and cyberbullying.

Businesses that breach the licensing conditions face substantial consequences. The rules provide for fines equivalent to 0.2 percent of annual turnover, with a minimum penalty of KSh500,000, as well as the possibility of business closure or suspension of licensed services.

For small cyber cafés operating on relatively thin margins, the compliance burden could therefore be significant.

Kenya’s wider cybercrime problem is changing

The regulatory intervention comes against a backdrop of a much larger digital security challenge.

Kenya’s internet economy has expanded across mobile money, banking, government services, telecommunications and online commerce. CA statistics show that the country had 53.4 million mobile-money subscriptions and 52.9 million mobile-broadband subscriptions in the quarter ending March 2026, while mobile broadband consumption reached more than 800 million GB.
That scale creates a much larger environment for criminals to exploit. The 3.37 billion cyber threat events recorded by KE-CIRT/CC should not be read as 3.37 billion successful attacks or criminal cases. The figure covers detected threat activity, much of which involves automated attempts to probe or exploit connected systems.

The composition of that activity is revealing. System vulnerabilities accounted for about 3.23 billion events, while malware, brute-force attacks, web application attacks and DDoS activity made up other significant portions of the total.

The cyber café rules address only one part of this environment, but they fit into a broader effort to give authorities better visibility into digital activity.

Identity records create a new security responsibility

There is an important complication in requiring cyber cafés to collect more personal information.

Customer registration can help investigators establish who was using a terminal, but the identity presented at the counter is not necessarily proof of who actually carried out an online offence. That problem becomes more significant as criminals use stolen personal information and fabricated identities.

INTERPOL’s 2026 assessment highlighted the growth of synthetic identities in Africa, with criminals combining genuine personal information with fabricated details and AI-generated characteristics to create identities that can appear legitimate during digital verification. Such identities have been linked to bank accounts, mobile loans and SIM registrations.

That means the value of cyber café records will depend partly on the reliability of the underlying identification process. A record containing a name and identification number can strengthen an investigation, but it cannot by itself eliminate impersonation or identity fraud.

There is another issue. Cyber cafés will now hold a concentrated collection of identity and usage information for a minimum of three years. Those records could themselves become attractive targets for criminals if operators fail to secure them properly.

The regulation therefore creates a second responsibility for cyber café owners: protecting the information they are being required to collect. The effectiveness of the system will depend not only on whether operators register customers, but also on how securely they store, restrict access to and eventually dispose of those records.

Cyber cafés face tougher compliance requirements

The new obligations arrive at a difficult time for the traditional cyber café business.

Smartphones, cheaper mobile data and widespread mobile broadband have reduced the need for customers to visit a shop simply to browse the web. Cyber cafés have instead become more closely associated with printing, scanning, document preparation, government services and other digital assistance.

The new licensing regime adds another layer of operational requirements to that business model. Operators will need systems for customer registration, receipts and record retention, alongside the technical controls required to filter traffic and prevent malicious downloads.

The CA has also dropped a previously proposed requirement for mandatory CCTV surveillance in the latest rules. That leaves the new framework more focused on digital and documentary traceability than physical surveillance.

For operators, the question will be whether they can absorb the cost of compliance while continuing to serve customers in a market where basic internet access is already widely available through mobile devices.

The rules are part of a broader cybersecurity push

The cyber café regulations make more sense when placed alongside Kenya’s wider cybersecurity agenda.

The government has been working on a National Cybersecurity Agency while existing institutions such as KE-CIRT/CC and the National Computer and Cybercrimes Coordination Committee continue to handle different parts of the national cyber response. Proposed amendments to the Computer Misuse and Cybercrimes Act are also intended to address emerging forms of digital crime.

The policy concern extends beyond individual fraud victims. Government services, financial systems, telecommunications networks and other critical infrastructure now depend heavily on connected technology, making cyber resilience part of economic and national security planning.

International enforcement activity points in the same direction. INTERPOL’s Operation First Light in 2026 brought together authorities from 97 countries to target social engineering scams, business email compromise, investment fraud, romance scams, sextortion and the financial networks used to move criminal proceeds. The operation resulted in thousands of arrests and the seizure or disruption of illicit assets.

That broader approach is important because cybercrime does not stop at the computer where an offence begins. A fraud operation can involve a public terminal, stolen credentials, a compromised phone number, an online platform, cryptocurrency or bank accounts in several jurisdictions.

The new CA rules address the first part of that chain by making public internet access more traceable. They may make it harder for someone to use a cyber café as an anonymous access point, but they cannot by themselves address the wider networks behind organised digital fraud.

For Kenya, the more significant development is the growing emphasis on visibility across the digital ecosystem. Public internet access centres will now be expected to know who is using their computers, keep basic records of when those sessions occur and maintain systems capable of supporting investigations. As the country’s digital economy grows, the ability to establish who accessed a system, when they accessed it and what infrastructure was involved will remain an important part of the cybersecurity equation.

The challenge will be ensuring that the new visibility comes with equally strong safeguards for the personal information being collected.

Download the FREE Kaspersky Next Enterprise Security Guide here to explore the complete framework for simplifying security operations and building cyber resilience.

Go to TECHTRENDSKE.co.ke for more tech and business news from the African continent and across the world.

Follow us on WhatsAppTelegramTwitter, and Facebook, or subscribe to our weekly newsletter to ensure you don’t miss out on any future updates. Send tips to editorial@techtrendsmedia.co.ke

Facebook Comments

By George Kamau

I brunch on consumer tech. Send scoops to george@techtrendsmedia.co.ke
Back to top button
×