Kenya content moderation

Kenya Turns Cyber Café Access Into an Identity-Linked Transaction

A new CA licence condition requires ID checks, 3-year session logs and content filters at every cyber café, backed by turnover-based fines.

Kenya's New Cyber Café Rules, By the Numbers People of Internet Research · Kenya 3 years Minimum session log retention Terminal ID plus session start/end… KES 500,000 Minimum non-compliance fine Or 0.2% of annual turnover, whiche… 30 days Statutory notice before rules bite Gazetted Aug 7, 2026; effective Se… 3.37 billion Cyber threat events, Q1 2026 KE-CIRT/CC detections, Jan-Mar 202… peopleofinternet.com
Kenya's New Cyber Café Rules, By the N… People of Internet Research · Kenya 3 years Minimum session log retention KES 500,000 Minimum non-compliance f… 30 days Statutory notice before rules bite 3.37 billion Cyber threat events, Q1 2026 peopleofinternet.com

Key Takeaways

Kenya's Communications Authority (CA) has rewritten the rules for one of the country's oldest digital-access points: the neighborhood cyber café. Gazette Notice Vol. CXXVIII No. 135, published on August 7, 2026, sets new licence conditions for what the CA calls Public Communications Access Centres (PCACs) — cyber cafés, phone bureaus and community payphone operators — under the Kenya Information and Communications Act (Cap 411A). The conditions take effect September 7, 2026, after the statutory 30-day notice period.

What the Rule Actually Requires

Operators must verify each customer's identity, log the terminal used and the session's start and end times, issue receipts for paid use, and retain those records for a minimum of three years. Equipment must be CA type-approved, and operators must deploy network filtering to block illegal or harmful content and malicious downloads. Non-compliance carries a fine of 0.2% of annual turnover, with a floor of KES 500,000 (roughly $3,860), plus possible suspension or closure.

The initial gazette notice triggered a sharp public reaction, and on August 13 the CA moved to narrow the scope: it confirmed cafés are not required to log customers' browsing history, only the coarser terminal-and-timestamp data needed to answer "who used which machine, when." The CA also dropped an earlier proposal, floated in a December 2024 draft, to mandate CCTV surveillance in every café — the final rule relies on documentary and digital traceability rather than physical monitoring. Both walk-backs are genuine improvements over the original proposal and deserve credit; regulators rarely narrow scope after gazetting.

The Case For It

The steelman here is real. Kenya's National KE-CIRT/CC recorded roughly 3.37 billion cyber-threat events between January and March 2026 alone — a volume that includes mobile-money fraud, phishing and identity theft, much of it enabled by exactly the kind of shared, walk-in, cash-paid internet access that cyber cafés provide. Anonymous shared terminals are a known laundering point for account takeovers and harassment campaigns, and law enforcement genuinely struggles to attribute abuse originating from a café PC to any individual. A basic audit trail — who sat at which terminal, for how long — is a proportionate, comparatively low-friction tool next to alternatives like mandatory biometric capture or real-time content scanning, both of which the CA notably did not impose in the final text.

Where It Overreaches

But the rule as gazetted still goes further than the threat model justifies. A flat three-year retention mandate applies to every session at every café regardless of any suspicion — Kenya has no comparable retention floor for, say, a supermarket's loyalty-card purchase history, yet internet access now carries a longer default data trail than most commercial transactions. There is no judicial or independent oversight step built into who can request these logs or why; the obligation sits entirely inside a telecom licence condition, adjudicated by the same authority that can suspend the licence, rather than being anchored in Kenya's Data Protection Act, 2019, with the Office of the Data Protection Commissioner in a supervisory role. That matters after May 2026, when a Kenyan High Court awarded damages in a privacy case connected to the Huduma Namba digital-ID rollout — a reminder that mandatory identity-linkage schemes in Kenya have a documented history of data-handling failures, not merely a hypothetical risk.

The compliance burden also lands unevenly. A one-room cyber café in a low-income estate — often the only affordable internet access point for someone without a smartphone data plan — now needs a customer-verification system, receipt issuance, secure three-year storage and CA-grade content filtering, on pain of a fine that can run into hundreds of thousands of shillings regardless of the operator's actual revenue. Larger, better-capitalized operators absorb that cost easily; the small, single-terminal café that serves the digitally under-resourced does not. If enforcement pushes marginal cafés to close rather than comply, the rule risks shrinking public internet access precisely for the population that relies on it most, in the name of protecting them.

The Proportionate Fix

None of this argues for scrapping traceability entirely — CA's own retreat on browsing history and CCTV shows the target can be narrowed without abandoning the goal. A tiered retention period (six to twelve months as a default, extendable only on a documented law-enforcement request, rather than a blanket three years), an explicit statutory link to the Data Protection Act with ODPC co-oversight, and a graduated, revenue-scaled penalty structure for single-terminal operators would deliver most of the traceability benefit CA is after without turning every visit to a cyber café into a three-year, ID-linked record on a small business's server. Kenya's regulators have shown in this same rulemaking that they'll walk back scope when the case for narrowing is made. The retention window and the oversight gap are the next place to make it.

Sources & Citations

  1. Kenya Gazette Vol. CXXVIII No. 135 (Aug 7, 2026)
  2. Kenya Information and Communications Act, Cap 411A
  3. TechCabal: Kenya says cyber cafés don't have to track browsing history
  4. Citizen Digital: All cyber café sessions must be logged, stored for 3 years
  5. TechMoran: Kenya to track cyber café users by ID as new rules raise surveillance concerns
  6. TechTrendsKE: Kenya clarifies cyber café rules, rules out browsing history tracking