- Kenyans using cyber cafés will be required to provide identification before accessing internet-enabled computers.
- Operators will record customer and session details under new requirements taking effect on August 14.
- The measures seek to strengthen accountability while placing additional data protection obligations on cyber café operators.
Kenyans who rely on cyber cafés for internet access, printing, online applications and government services will be required to comply with new identification rules effective August 14, 2026, following a directive issued by the Communications Authority of Kenya (CA).
Under the new regulations, all licensed cyber café operators must verify and record the identity of every customer before granting access to an internet-enabled computer.
The directive represents a significant change in the operation of cyber cafés nationwide and is intended to enhance accountability within the digital environment.
Before allowing a customer to use a computer terminal, operators will be required to verify the individual’s identity and capture key details.
The required information will include the customer’s full name, National ID or passport number, computer or terminal assigned, exact login time and exact logout time.
Operators will also be required to issue a receipt for each paid session.
These measures are intended to establish a clear record linking each user to a specific terminal and defined period of internet use.
CA to monitor compliance in cyber cafés
The Communications Authority will be empowered to conduct routine and unannounced compliance inspections at cyber café premises.
During these inspections, CA officials may review customer records and system logs to determine whether operators are adhering to the new requirements.
Cyber café owners will therefore be expected to maintain accurate and accessible records at all times. Failure to comply may attract regulatory action, including fines, suspension of operations or closure of the business.
The introduction of these measures comes amid ongoing efforts by authorities to address cyber-enabled crime.
According to the regulatory framework, maintaining accurate access logs will assist law enforcement agencies in identifying individuals who used specific computer terminals during investigations into suspected offences.
The records are expected to support investigations involving online fraud, mobile money scams, SIM-swap fraud and other forms of cybercrime.
The directive is therefore intended to strengthen traceability and accountability within Kenya’s digital ecosystem.
No requirement to monitor browsing activity
Despite concerns regarding potential surveillance, the directive does not require cyber cafés to track users’ browsing history or private online communications.
The focus is strictly on recording user identity, terminal used and duration of access.
This ensures the system is limited to session-based identification rather than detailed monitoring of online activity.
The new requirements place additional responsibility on cyber café operators, as the information collected constitutes personal data.
Operators will be expected to safeguard customer records against unauthorised access, loss, theft or disclosure.
This may require many small businesses to improve their data storage, security systems and record management practices.
The issue is particularly significant given the continued reliance on cyber cafés by thousands of Kenyans accessing essential digital services.
Continued relevance of cyber cafés in Kenya
Despite widespread smartphone adoption and mobile internet access, cyber cafés remain an important component of Kenya’s digital infrastructure.
Many users depend on them for printing and scanning documents, completing online applications, accessing government services, submitting job applications and engaging with platforms such as eCitizen.
For individuals without personal computers, printers or stable internet access, cyber cafés continue to serve as a critical access point to digital services.
The new requirements will therefore have implications for both operators and customers nationwide.
From the effective date, customers will be required to present valid identification before being assigned a computer terminal.
Operators will maintain records detailing customer identity, terminal usage and session duration.
Customers should also expect their personal data to be handled in accordance with applicable data protection laws and regulations.
For cyber café operators, immediate compliance will be essential ahead of enforcement by the Communications Authority.
READ ALSO: Leadership lessons from Prof Ayiro, pioneering principal of Sunshine School
The directive marks a further step in Kenya’s efforts to strengthen oversight and accountability within its expanding digital ecosystem, while introducing new compliance obligations for providers of public internet services.
By Hillary Muhalya
You can also follow our social media pages on Twitter: Education News KE and Facebook: Education News Newspaper for timely updates.
>>> Click here to stay up-to-date with trending regional stories
>>> Click here to read more informed opinions on the country’s education landscape





