Kenya will require licensed cyber cafés and public communications access centres to register users and retain basic session records from 14 August 2026.
The rules aim to improve traceability in cybercrime investigations without recording browsing history.
However, a three-year store of identity and usage data creates a second test: whether small operators can protect personal information while preserving affordable access to jobs, education and government services.
Public Internet Loses Anonymous Access Nationwide
Walking into a Kenyan cyber café will now create a formal record. From 14 August 2026, licensed public communications access centres must register customers, link them to the terminal they used, record session start and end times and retain compliance records for at least three years under new Communications Authority licensing conditions.
The required session log excludes personal browsing history, an important boundary.
However, the identity-and-time trail remains significant, particularly for people who depend on shared computers to apply for jobs, complete schoolwork, file taxes or access eCitizen services.
Traceability Creates A New Data Store
The Communications Authority can request reports and inspect premises, systems, equipment and records for audits or investigations.
Operators are also expected to issue receipts and comply with network-control conditions.
The policy seeks to close an attribution gap: when many people use the same device and connection, investigators may struggle to identify who was online during suspected fraud, forgery or other cyber-enabled crime.

Kenya’s threat environment gives that objective urgency.
- Identity theft, phishing, mobile money fraud, account takeover and SIM-related scams can destroy household savings and weaken confidence in digital services.
- A time-bound record connecting a verified user to a terminal may help investigations.
However, the policy transfers substantial responsibility to small businesses.
- A handwritten register can be photographed.
- A spreadsheet can be copied.
- An insecure computer can expose thousands of names and identity numbers.
The very dataset created to fight crime could become valuable to criminals unless collection, storage, access and deletion are tightly governed.
Build Security Without Excluding Users Online
The best implementation would make privacy protection part of compliance, rather than an afterthought.
- Operators need simple standards for data minimisation, encryption, access control, breach reporting and secure deletion once retention expires.
- Customers should receive clear notices explaining what is collected, why, how long it is kept and how complaints can be made.
Proportionality also matters.
- The licence condition requires customer registration, but public reporting varies on whether every operator must copy or merely record an identity document.
Regulators should remove ambiguity and prevent excessive collection.
- No café should retain photocopies, biometrics or browsing content unless a clear lawful requirement specifically demands it.
Well done, the framework could increase accountability without turning public access into continuous surveillance.
Poorly done, it could deter vulnerable users, raise prices or create poorly secured identity repositories across the country.
Pair Enforcement With Privacy Capacity Building
The Communications Authority and Office of the Data Protection Commissioner should issue joint, practical guidance before inspections begin, including approved log fields, security controls, retention procedures and model privacy notices.
- Small operators need training and low-cost tools, not only penalties.
Independent oversight should track breaches, complaints, enforcement actions and whether the logs demonstrably improve investigations.
- Civil-society groups can monitor disproportionate impacts on young people, refugees and low-income users.
- Security policy earns legitimacy when it is effective, narrowly designed and accountable.
Path Forward – Protect Access While Improving Traceability Nationwide
Kenya’s new regime will succeed only if session logs help legitimate investigations without becoming a new source of identity theft or exclusion.
Clear limits, secure storage, transparent inspection rules and automatic deletion after three years are essential.
By pairing cybercrime prevention with strong data governance and support for small operators, Kenya can protect both digital trust and the public access points, a mainstay for digital inclusion.
Culled from: Kenya Tightens Cyber Café Rules as New Customer-Tracking Measures Take Effect - Innovation Hub Kenya