The Communication Authority of Kenya (CA) has announced a new sweeping compliance measures for cyber cafés, set to take effect on August 14, 2026.
The rules will fundamentally change how cyber cafés operate, introducing stricter record-keeping and accountability requirements in bid to enhance digital security and transparency. This requirement will take effect on August 14, to help manage public internet access in response to cybercrime risks.
The new regulations require operators of public communications access centres to register customers, maintain basic session logs, issue receipts and retain the records for at least three years.
Cyber Cafés will be required to record information including a customer’s name and identification number, the computer or terminal used, the start and end time of a session. The CA will also have the power to access premises, systems, equipment and records when conducting an inspection, audit or investigation.
These measures come as Kenya deals with a cyber threat involving mobile-money fraud, identity theft, malware, phishing and attacks against connected infrastructure.
According to CA data, the National KE-CIRT/CC detected 3.37 billion cyber threat events between January and March 2026.
With cyber cafés having public computers, they present different security problems compared to personally owned smartphones or laptops, as multiple people may use the same machine, browsers can retain credentials, and poorly protected networks or computers can expose users to malware and credential theft.
CA is also restricting bandwidth reselling and cyber cafés will not be allowed to purchase bulk or high-capacity internet connectivity and divide it among customers without the regulator’s approval.
It stated failure to follow the rules will result in a minimum penalty of Ksh 500,000, as well as the possibility of business closure or suspension of licensed services.