Communications Authority orders Kenya cyber cafés to start taking customer IDs
This story has significance for readers across Kenya and beyond.
- The Communications Authority of Kenya directed all licensed cyber cafés to begin recording customer identities and session details from August 14, 2026
- Operators will need to capture each customer's full name, national ID or passport number, terminal used, and exact login and logout times
- Cyber cafés that fail to comply risk regulatory penalties including fines, suspension of services or outright closure
Elijah Ntongai is an experienced editor at TUKO.co.ke, with more than four years in financial, business, labour and technology research and reporting. His work provides valuable insights into Kenyan, African, and global trends.
The Communications Authority of Kenya (CA) has issued a directive requiring all licensed cyber café operators to log customer identities and internet session details, with the obligation taking effect from 14 August 2026.
What the Directive Requires
Before a customer is granted access to any terminal, operators must verify the individual's identity and capture their full name alongside their national identity card or passport number.
The records must also include which terminal was used and the precise times the session began and ended. A formal receipt is required for every paid session.
All records collected under these requirements must be stored securely for a minimum of three years. CA officers will be authorised to enter cyber café premises and inspect equipment and records during compliance checks.
The CA stated that the measures are designed to strengthen accountability and support efforts to combat cybercrime, specifically offences such as mobile money fraud, online scams and SIM-swap-related crimes.
What the Directive Does Not Cover
The directive as issued does not compel cyber café operators to capture customers' browsing histories or private communications. The focus is confined to establishing a verifiable record of who accessed a terminal, which machine was used, and for how long.
The new obligations place additional data-protection responsibilities on cyber café owners, a large proportion of whom run small businesses offering services such as printing, document preparation and access to government platforms including eCitizen.
Operators will be required to safeguard all personal information collected from customers against unauthorised access, theft or disclosure. Those found in breach of the logging, record-retention or other requirements face regulatory consequences that may include fines, suspension of services or closure of the premises.
Cyber cafés remain important access points for Kenyans who rely on shared internet infrastructure for government transactions and other digital services, particularly in areas where personal devices or home connectivity are unavailable.
Source: TUKO.co.ke
Reporting originally appeared via TUKO. Read the full source for additional context.