From August 14, you can no longer walk into a Kenyan cyber café and log on without saying who you are. The Communications Authority of Kenya (CA) has revised the licensing rules for these venues, and from now on operators must record your name, your ID number, which computer you used, and when you logged in and out. They also have to issue a receipt and hold onto all of it for three years.
Non-compliance carries a penalty of 0.2% of annual turnover, with a floor of KES 500,000, and the possibility of closure.
It sounds like a lot of bureaucracy for something as ordinary as printing a document or checking email. So it’s worth asking the obvious question: does the regulation still make sense in 2026, when almost everyone in Kenya carries a smartphone?
Is This Even Relevant Anymore
The honest reality is that cyber cafés are a shrinking part of how Kenyans get online, but they haven’t disappeared. In Communications Authority surveys of internet users, 97.9% reported using a smartphone to get online, while only 0.9% reported using a desktop computer, the kind you’d find in a café. On paper, that looks like a rule aimed at a shrinking corner of the internet.
However, that shrinking corner still matters a lot to specific groups of people. Rural residents, low-income households, and anyone without a smartphone or reliable data still lean on cafés for eCitizen services, job applications, scanning, and printing. For them, the café is the only door into government services and formal paperwork.
That’s why the rule can’t be dismissed, as it targets a small but genuinely vulnerable slice of internet access, which is also, as it happens, the slice most useful to someone trying to commit fraud anonymously.
What Enforcement Problem Is the Rule Actually Solving
Kenya’s cyber threat numbers are large by any measure. The Communications Authority’s national incident response center has been logging cyber threats in the billions each quarter, amounting to 3.37 billion incidents in Q1 2026, and mobile money fraud, SIM-swap attacks, and identity theft remain persistent problems.
When a criminal wants to commit fraud without leaving a trail back to their phone or laptop, a cyber café with no ID requirement and no session log is close to ideal. Investigators are stuck with an IP address that points to a building, not a person.
This rule squarely targets that gap. By tying a terminal, a time window, and a verified identity together, it gives investigators a starting point they didn’t reliably have before. Cafés have functioned as a soft spot in Kenya’s cybercrime defenses precisely because they sit outside the identity checks that now apply to SIM cards and mobile money accounts.
The Data Protection Question Nobody Can Skip
Here’s where it gets harder. Kenya already has a serious data protection law, the Data Protection Act of 2019, where the Office of the Data Protection Commissioner (ODPC) has been handing out real fines, including payouts in the hundreds of thousands of shillings against companies that mishandled customer data, and it can impose penalties up to five million shillings or 1% of annual turnover.
That law requires anyone processing personal data to secure it properly, collect no more than necessary, and delete it once it’s no longer needed. A three-year archive of names and ID numbers sitting on a café’s back-office computer is the kind of dataset that law was written to protect.
Yet cyber cafés are small businesses, often run by one or two people, with none of the security budget a bank or telco has. National surveys have found that most Kenyan businesses know the data protection law exists, but a large share still haven’t appointed anyone to actually manage compliance.
That gap, between knowing the rule and living up to it, is where things could go wrong. A leaked spreadsheet of names, ID numbers, and browsing patterns would be a far bigger privacy failure than the fraud the rule is trying to prevent.
The Quick Takeaway
This isn’t an outdated rule chasing a dead technology. It’s a narrow, sensible response to a real gap in how Kenya tracks cybercrime, aimed at the part of the internet-access market still open enough to be exploited.
However, its success depends entirely on whether small café operators can actually meet the data protection standard the law already demands of them.




























