< Back to all clusters
[TECHNOLOGY] · Kenya · 6 sources

started · updated

Kenya mandates identity logging for cyber cafés to combat cybercrime

The Communications Authority of Kenya (CA) has issued new directives requiring all licensed cyber cafés, operating as Public Communications Access Centres (PCACs), to record customer identities and internet session details. Effective August 14, 2026, operators must verify customers using their full name and national ID or passport number before granting access.

Under the new licensing requirements, cafés must maintain logs including the specific terminal ID used and the exact login and logout times for every session. These records must be securely stored for at least three years. The CA has specified that these logs should not include personal browsing histories or private messages.

The measures aim to combat cybercrimes such as mobile money fraud, online scams, and SIM-swap offences by establishing a clear audit trail. However, the directive also imposes new data protection responsibilities on small business operators to prevent unauthorized access to collected personal information. Non-compliance may result in regulatory penalties, including fines, service suspension, or closure.

Entities

Communications Authority of Kenya · Kenya