Cyber Cafés in Kenya Must Now Register Customers Under New Rules

August 12, 2026

Cyber cafés in Kenya will be required to register customers and keep basic user logs, including terminal IDs and session start and end times, for at least three years under new rules issued by the Communications Authority of Kenya.

The Authority said the records will help support inspections, audits, and investigations into cybercrime.

The new licensing conditions for Public Communications Access Centres take effect on August 14. They apply to cyber cafés, telephone bureaus, community payphones, and other public communication services approved by the Authority.

Under the rules, operators must set up a system for registering customers and maintain basic service-use records. The licensing requirements also specify that operators must exclude customers’ personal browsing history.

“Put in place a mechanism for registering customers. Maintain basic user logs of service usage, essentially a customer session log (excluding personal browsing history), which will cover the terminal ID, session start, and end time,” the rules state.

Operators must also keep all records necessary to demonstrate compliance for at least three years from the date the records are created, and they must provide reports to the Authority whenever it requests them.

The rules state that “the licensee shall grant the authority’s authorised officers’ reasonable access to premises, systems, records, and equipment for inspection, audit, or investigation.”

The measures aim to curb the way criminals use public internet facilities. Authorities say some offenders exploit computers without strict user identification to carry out online crimes.

The Communications Authority added that public cyber cafés can also expose users when computers or networks lack proper security. Criminals may install malware to capture usernames, passwords, and banking details, or they may intercept network activity.

The CA rules also require cyber cafés to display the charges they apply and issue receipts when fees apply. Operators must set up systems to handle customer complaints and feedback.

Operators must also notify customers about service interruptions and outages, and ensure their services remain accessible to people with disabilities.

In addition, the rules require cafés to install content-filtering systems to protect users from harmful or illegal material and to comply with online safety guidelines issued by the Authority.

Cyber cafés will need to use electronic communications equipment that the Authority approves or accepts, or equipment that qualifies for an exemption from type approval.

Additionally, operators must obtain internet connectivity from licensed Internet Service Providers with an Application Service Provider license and comply with the Kenya Information and Communications Act and relevant regulatory directives.

The Communications Authority has also ordered operators to install software and network filters that block illegal websites. It further requires cafés to scan web traffic in real time to prevent dangerous downloads and illegal files.

Under the rules, cyber cafés must not resell bandwidth or wholesale internet capacity without the Authority’s appropriate approval.

The licensing conditions target other online offenses, including piracy, document forgery, identity theft, and cyberbullying.

The CA had earlier proposed mandatory CCTV surveillance for all cyber cafés, but it removed that requirement from the latest licensing conditions.

Operators must deliver reliable, accessible, and consistent services. They must also fix service interruptions and outages promptly.

The Authority can inspect premises, systems, facilities, records, and equipment at any time to verify compliance.

Businesses that breach the rules face fines of 0.2% of annual turnover, with a minimum penalty of Sh500,000. The Authority can also suspend operations or order closure.

Don't Miss