Skip to content
News

Kenya’s Cyber Café ID Rules: A 2011 Solution to a 2026 Problem?

Starting August 14, your local cyber café must record your ID, terminal, and session times—and hold onto them for three years. It’s an old idea with a terrible global track record. Here is why Kenya is adopting it now.

For a long time, you’ve been able to walk out of your house, walk into a local cyber café, pay a few coins for an hour of internet access to quickly file your KRA returns or print an eCitizen document, or print your insurance and leave.

From Thursday, August 14, 2026, that simple, anonymous errand is history.

Under a new Public Communications Access Centres (PCAC) Class Licence, the Communications Authority of Kenya (CA) is fundamentally changing how public internet works. If you operate a cyber café, you can no longer just hand over a mouse and a keyboard. You must now:

  • Record the customer’s full name.
  • Log their National ID or Passport number.
  • Document exactly which terminal they used.
  • Record the exact minute they logged in and out.
  • Issue a receipt and retain these records for three years.

If the CA comes knocking and a café is non-compliant, the penalty is severe: 0.2% of their annual turnover, with a punishing floor of KES 500,000, and potential closure.

But why?

The regulator claims they’re trying to solve a very real problem. This is their argument:

Between January and March 2026 alone, Kenya’s national incident response centre (KE-CIRT) logged a staggering 3.37 billion cyber threat events. When cybercriminals commit fraud using a shared computer, investigators are left chasing a ghost. An IP address only leads them to a physical building, not a specific person.

By tying a verified human identity to a specific terminal at a specific time, the CA believes they are giving law enforcement a starting point. It is sounds logical.

We Have Seen This Movie Before

The problem is that this is not a new idea. It is an early-2000s policy, and history shows us exactly how this plays out. Kenya is joining a rather awkward club of nations:

CountryYear ImplementedThe PolicyThe Outcome
Italy2005The “Pisanu decree” required ID for public internet following the London bombings.Repealed. Businesses stopped offering Wi-Fi to avoid compliance costs. It stunted Italy’s public internet growth for years until its repeal in 2013.
India2011Mandatory registration, valid ID, log registers, and even webcam photos of users.Patchy at best. Heavily criticised for duplicating business laws and remains barely enforced today.
China2012Real-name registration required for all internet access.Active. Forms the backbone of a massive state surveillance apparatus.

We are essentially adopting a framework that Europe scrapped for killing the very businesses it tried to regulate, and that India has struggled to actually enforce.

The Great Irony

Timing is everything, and the CA’s timing is curious. In 2026, the cyber café is a shrinking, highly specialised access channel. It is kept alive mostly by citizens needing to print, scan, or access government portals.

The people the CA is actually worried about—the fraudsters orchestrating SIM-swaps and mobile money scams—rarely operate from a slow desktop in a public cyber. They operate from smartphones. Kenya already has mandatory SIM registration tied to national IDs, yet the mobile fraud epidemic persists.

Furthermore, there is a glaring contradiction in government policy. While the CA demands IDs inside the café, the government’s own ICT Authority is actively rolling out free, public Wi-Fi hotspots across the country. A determined criminal doesn’t need to hand over their ID; they simply have to walk past the café, sit on a bench outside, and connect to the free government hotspot.

The Data Protection Nightmare

This brings us to the most critical, unanswered question: Who is protecting your data?

Under the Data Protection Act of 2019, any business collecting names and ID numbers becomes a “Data Controller.” From August 14, thousands of small, analogue businesses across the country will suddenly be hoarding the identity data of millions of Kenyans.

Kenya’s track record with data security is already fragile. We recently saw a massive breach at the Business Registration Service leaking two million records. And that was a government agency with a dedicated IT department.

How is a small cyber café in Buruburu, logging IDs in a handwritten exercise book, expected to secure this data for three years? The Office of the Data Protection Commissioner (ODPC) has yet to issue specific guidance for these operators, leaving small businesses caught between two aggressive regulators.

What to Watch

From Thursday, you will need to carry your ID to browse. But the real test of this policy lies in the months ahead. Keep an eye on three things:

  1. Will the CA actually possess the manpower to inspect and fine these small businesses?
  2. Will the ODPC step in to protect the physical logbooks of citizens’ data?
  3. Will the government’s free public Wi-Fi programme eventually require the same strict ID checks?

If the answer to that last question is no, then this new rule will successfully track honest Kenyans printing their tax returns, while completely missing the criminals it was designed to catch.

Dickson Otieno

I love reading emails when bored. I am joking. But do send them to editor@tech-ish.com.

Join the discussion

0 comments
posting as Kicheche Mwepesi

Anonymous by default — no sign-up or email needed. Prefer to be recognised? Add a name or email above, your call. We don't email you about replies, so do check back.

protected, no CAPTCHAs
Back to top button