The Communications Authority of Kenya's (CA) revised Public Communications Access Centre (PCAC) class licence, gazetted on August 7, 2026, takes effect on September 7, 2026, requiring every cyber café, telephone bureau, and community payphone operator in the country to register customers by full name and national ID or passport number before granting access, log which terminal was used and the exact login and logout time, retain those records for three years, issue receipts, and grant CA officers "reasonable access to premises, systems, records, and equipment" for inspection or investigation (Communications Authority of Kenya). Operators who don't comply face a fine of 0.2% of annual turnover, floored at KSh 500,000, plus possible suspension (Citizen Digital).
The case the CA is making
The regulator isn't inventing a threat. Kenya's SIM-swap fraud caseload jumped 327% year-on-year, with roughly KSh 491.6 million drained from mobile money accounts and crypto wallets before authorities caught up (Nairobi Law Monthly). Cyber cafés are a genuine soft spot in that chain: shared terminals with no login trail let someone harvest credentials, forge documents, or run a scam campaign and walk away with zero attribution. An audit trail that lets police tie a specific session to a specific person, after the fact and with a warrant, is not an unreasonable ask — most jurisdictions with licensed public-access terminals require something similar, and Kenya already runs SIM registration on mobile networks for the same reason. The CA also moved to blunt the most invasive version of this idea: after public pushback, it clarified that browsing history is explicitly excluded and that CCTV, which had been floated in a December 2024 consultation document alongside "logging-in software" and "identification of persons accessing the service," was dropped from the final rule (CA Telecommunications Market Structure consultation).
Where the design breaks down
The problem isn't the goal, it's the plumbing. A national-ID-linked, three-year retention database of who used which public terminal and when is squarely personal data under Kenya's Data Protection Act, 2019 — the kind of processing that ordinarily triggers registration, security safeguards, and breach-notification duties enforced by the Office of the Data Protection Commissioner (ODPC). Yet the ODPC's own site shows no guidance, joint statement, or even acknowledgment tied to the PCAC rule (ODPC), and outlets covering the rollout have found none either. That's not a technicality. The PCAC licensees required to hold this data are, disproportionately, small kiosk operators without an IT department, encryption budget, or breach-response plan — exactly the profile the Data Protection Act's own risk-based framework is supposed to flag for extra help, not leave to figure out ID-database security on their own. A ledger of every Kenyan who's walked into a cyber café, cross-referenced to their national ID, is a more attractive target sitting in an unsecured back-office laptop than it is useful evidence sitting unbreached in a police file.
The CA has also picked a lever with a shrinking hand on it. Smartphone and home-broadband penetration have hollowed out cyber café usage since the format's mid-2000s peak, and SIM-swap fraud is overwhelmingly an attack on telco-side authentication and agent networks, not on internet-café browsing sessions — the technique targets a victim's phone number through the mobile network, not a shared terminal. Regulating the shrinking, easy-to-reach channel because it's licensable, while the growing, harder-to-reach channel (agent-network insider fraud, SIM-swap-as-a-service) gets less attention, produces a rule that photographs well in a press release without moving the fraud numbers much.
Kenya isn't the first to try this. Italy imposed near-identical cyber café ID and CCTV rules by decree in 2005 and repealed them in 2013 after concluding the surveillance value didn't justify the compliance burden on small operators or the privacy exposure it created — a precedent Kenyan commentators have already raised directly against this rule (tech-ish). India and China adopted comparable frameworks in the early 2010s for the same stated reason: traceability against cybercrime. None of them paired the requirement with a data-protection compliance path for the small businesses forced to hold the data, and Kenya is repeating that gap in 2026 with a data protection law already on its books that the CA simply hasn't looped in.
What proportionate would look like
None of this requires abandoning traceability. It requires the CA and ODPC to issue a joint compliance note — a minimum security baseline (encrypted storage, access logging, no third-party sharing) scaled to a kiosk's size, not a bank's — before, not after, three years of national-ID-linked logs start accumulating in shops with no security officer. It also argues for a sunset or review clause tied to actual fraud-reduction evidence, the way any proportionate, evidence-based regulation should be built: renew it if it works, retire it if — like Italy's — it doesn't. Kenya's cyber-fraud problem is real and the CA is right to want an audit trail. But an audit trail without a data custodian is just a second honeypot, and Kenya has a regulator built for exactly that job sitting idle on the sidelines of its own statute.