Cyber cafés across Kenya are set to operate under tighter rules as the Communications Authority of Kenya (CA) introduces new licensing conditions requiring operators to register customers and keep basic records of their sessions for at least three years.
The new requirements will take effect on August 14, 2026, and will apply not only to cyber cafés but also to telephone bureaus, community payphones and other public communication services licensed by the Authority.
Under the new rules, cyber café operators will have to establish a system for registering customers and maintain basic user logs showing details such as the terminal used and the time a session started and ended. However, the records will not include customers’ personal browsing history.
The Communications Authority says the information will help in inspections, audits and investigations involving cybercrime. Operators will also be required to keep records that demonstrate compliance with the licensing conditions for at least three years from the date they are created.
The Authority will have powers to access the premises, systems, equipment and records of licensed operators when carrying out inspections, audits or investigations. Cyber café owners will also be expected to provide reports and other information whenever requested by the regulator.
The changes come as Kenya continues to deal with different forms of cybercrime, including identity theft, online fraud, document forgery, piracy and cyberbullying. Public internet facilities can sometimes be used by criminals who take advantage of computers and networks where users are not properly identified.
The Authority has also pointed to security risks faced by customers using public computers and networks. Unsecured systems can expose users to malware and other threats that may allow criminals to obtain sensitive information such as passwords, usernames and banking details.
The new rules also require cyber cafés to install software and network filters designed to block illegal websites and harmful content. Operators will also be expected to scan web traffic in real time to help prevent dangerous downloads and access to illegal files.
Beyond security requirements, cyber cafés will have several obligations concerning customer service. Operators must clearly display applicable charges and provide receipts where customers are required to pay for services. They must also establish systems for receiving and responding to complaints and customer feedback.
Customers will have to be informed about service interruptions and outages, while operators will be required to provide services that are accessible to persons with disabilities. The Authority has also directed businesses to maintain reliable and consistent services and address disruptions promptly.
Cyber cafés will further be required to use communications equipment that has been approved or accepted by the Authority, or equipment that is exempt from type approval. Their internet connections must come from licensed Internet Service Providers holding the required Application Service Provider licence.
The operators will also have to comply with the Kenya Information and Communications Act and other regulatory directives issued by the Authority. They will not be allowed to resell bandwidth or wholesale internet capacity without the necessary approval.
The rules come at a time when Kenya is experiencing growing concerns over online and mobile-related fraud. SIM-swap attacks, for example, have allowed criminals to take control of victims’ phone numbers and use them to access mobile money accounts, bank accounts and other services protected through phone-based verification.
Although cyber cafés are less popular than they were during the late 2000s and early 2010s because of smartphones and cheaper mobile internet, they remain important in some communities. Many people still use them for printing, scanning, accessing online government services, making applications and carrying out other digital tasks.
The CA had previously considered requiring cyber cafés to install CCTV cameras but the surveillance requirement was not included in the latest licensing conditions.
Operators who fail to comply with the new requirements could face financial penalties. The rules provide for fines equivalent to 0.2 per cent of annual turnover, subject to a minimum penalty of Sh500,000. Businesses may also face suspension or closure depending on the nature and seriousness of the breach.
The new framework therefore places greater responsibility on cyber café owners to identify users, maintain basic service records, improve network security and protect customers while also giving regulators greater access to information when investigating suspected cybercrime.
