Kenya Kenya data protection authority ODPC

Kenya's Cyber Cafe ID Rule Builds a National Identity Database Through a Telecoms Licence, Not a Privacy Law

A CA licensing clause now compels three-year ID-linked logs at cyber cafes, with no design role for Kenya's data regulator.

Kenya's Cyber Cafe ID Rule, By the Numbers People of Internet Research · Kenya 3 years Minimum record retention Customer name, ID number, terminal… KES 500,000 Minimum fine floor Non-compliant operators face at le… KES 5,000,000 Max ODPC data-breach fine The maximum penalty the data prote… peopleofinternet.com
Kenya's Cyber Cafe ID Rule, By the Num… People of Internet Research · Kenya 3 years Minimum record retention KES 500,000 Minimum fine floor KES 5,000,000 Max ODPC data-breach fine peopleofinternet.com

Key Takeaways

Starting August 14, 2026, anyone walking into a licensed cyber cafe, telephone bureau, or community payphone in Kenya must hand over a national ID or passport number before they can get online. The operator will record that customer's name and ID number, the terminal used, and the exact login and logout time, then hold the record for at least three years. Non-compliance carries a fine of at least KES 500,000 or 0.2% of annual turnover — whichever is greater — plus the possibility of closure (Tuko).

The mechanism is a licensing clause, not a statute passed by Parliament. The obligation sits in the Public Communications Access Centre (PCAC) Class Licence, issued by the Communications Authority of Kenya (CA) under the Kenya Information and Communications Act, Cap. 411A — specifically Section 24(1), which bars operating telecommunications services without a CA-issued licence. Clause 3.1 requires a customer-registration mechanism; Clause 3.2 defines the session log (terminal ID, start and end time, explicitly excluding browsing history); Clause 3.3 sets the three-year retention floor; Clauses 5 and 7 give the CA inspection and enforcement power (TechMoran). The CA's stated rationale is combating mobile money fraud, SIM-swap crime, and online scams that have exploited the anonymity of public terminals (TechCabal).

The case for the rule

The steelman is real. Kenya's mobile-money economy makes SIM-swap fraud and identity-linked financial crime a genuine public-safety problem, and public terminals — used precisely because they don't require a personal account or a registered device — are an obvious point of anonymity for anyone laundering a scam or covering their tracks online. Requiring an ID at the point of use, and giving investigators a paper trail tied to a terminal and a timestamp, is the kind of proportionate, narrowly scoped step regulators elsewhere use against similar threats: the log format the CA settled on deliberately excludes browsing history, and the retention period, while long, is bounded rather than indefinite. A cybercrime-fighting rationale for a walk-in-anonymous access point is not manufactured.

The gap the rule doesn't close

What's missing is who is answerable for the data once it exists. Kenya has had a dedicated data protection regulator since 2019: the Office of the Data Protection Commissioner, created by the Data Protection Act 2019 with a mandate to "oversee the implementation of and be responsible for the enforcement of" that Act, to "conduct an assessment, on its own initiative, of a public or private body," and to inspect entities processing personal data (ODPC — Functions of the Office). None of that machinery appears to have touched this directive. The reporting on the rule traces its authority entirely to the CA's telecoms licensing power under KICA; neither the ODPC nor the Data Protection Act 2019 surface in the CA's stated legal basis, and as of this rule taking effect the ODPC has not issued a public statement addressing it (TechWeez).

That absence matters because the ODPC is not a passive body. Four months before this directive took effect, the Data Commissioner ordered LOLC Kenya Microfinance Bank to delete a former employee's personal data within 14 days after finding the company had posted his image and details on Facebook without a lawful basis, and referred the matter for possible director prosecution — a fine of up to KES 5 million or two years' imprisonment (Capital FM). This is a regulator that audits, investigates, and fines. It was simply never brought into the design of a rule that hands potentially thousands of small, often single-terminal businesses a legal duty to collect and safeguard ID-linked records on strangers for three years.

Two regulators, one liability, no coordination

The practical result is a split-mandate problem the CA's licence doesn't resolve. A cyber cafe operator now faces CA enforcement (fines, closure) for failing to collect and retain the data, and separately faces exposure under the Data Protection Act — as a data controller processing identity documents — if that same data is breached, mishandled, or retained insecurely. Kenya's data protection framework generally exempts controllers below KES 5 million turnover or ten employees from ODPC registration, but that exemption doesn't apply where processing falls under the Act's Third Schedule categories, and it never exempted anyone from the underlying duty to secure personal data. A cyber cafe compelled by one regulator to hold ID numbers and session logs is not thereby excused by another regulator from the consequences of losing them. Nobody has said which agency a breached customer should complain to, or whether the CA's licence conditions were checked against the Act's security and processing-limitation principles before being written into a class licence that binds an entire sector.

What proportionate would look like

None of this means the underlying cybercrime problem is imagined, or that ID capture at public terminals is inherently unreasonable. It means the design process was incomplete. A rule that creates a legal duty to collect and retain sensitive identity data should be built jointly with the body Parliament created to answer for exactly that kind of data — with a data protection impact assessment, minimum security standards proportionate to what a single-terminal shop can realistically implement, and a public answer to who is liable when (not if, across thousands of small operators) a breach occurs. Kenya doesn't need less cybercrime enforcement. It needs its two 2026-era digital regulators to write rules like this one together, instead of one agency building a national identity log through a telecoms licence while the other reads about it in the news.

Sources & Citations

  1. Tuko: CA orders cyber cafes to take customer IDs from Aug 14
  2. TechMoran: PCAC Class Licence clauses and KICA legal basis
  3. TechCabal Daily: Kenya's new internet bouncers
  4. ODPC: Functions of the Office
  5. Capital FM (Africa): ODPC faults LOLC Kenya over data breach
  6. TechWeez: Examining the CA's cyber cafe ID card requirement