What's actually changing, precisely
Cyber cafés in Kenya have long been licensed under the Communications Authority's Public Communication Access Centre (PCAC) category. Newly gazetted licensing conditions, taking effect August 14, 2026, add real operational requirements to that existing licence — this isn't a new law from Parliament, it's a condition attached to the licence operators already hold under the Kenya Information and Communications Act.
The core requirements:
- Customer registration — name and identification number, before use
- Session logging — which terminal was used, and the session's start and end time
- Three-year retention of these records
- Receipts issued for every service charged
- Displayed pricing and a working complaints/feedback mechanism
- Network-level filtering to block illegal websites and scan traffic for dangerous downloads
- Internet connectivity only from licensed providers, and no reselling or wholesaling of bandwidth without separate approval
What's explicitly NOT required — worth knowing, since this gets misunderstood
The session log requirement is narrower than it might first sound. It covers which terminal was used and when — not what was browsed, searched, or accessed during that session. Personal browsing history is explicitly excluded from the logging requirement. This matters for how operators should actually build their systems: a basic sign-in log satisfies this rule; browser or network-level activity monitoring goes well beyond what's required.
The part regulatory compliance alone doesn't cover
Here's the gap operators need to think through, and it's a cybersecurity question, not just a licensing one: a customer's name, ID number, and session record is itself sensitive personal data. Collecting it to satisfy the new licensing condition is only half the job — Kenya's Data Protection Act, 2019 separately requires that personal data be processed lawfully, collected only for legitimate stated purposes, and protected through appropriate safeguards once collected.
An operator can be fully compliant with the registration requirement and still create a real security problem — a shared spreadsheet on an unlocked computer, a paper register left on the counter, a single admin password everyone on staff knows. Compliance and security are two different questions, and satisfying the first doesn't automatically answer the second.
For cyber café customers
Being asked for your name and ID number at a cyber café is now a genuine licensing requirement, not an unusual request from an individual operator. That doesn't mean you have no say in how that information is handled — under the Data Protection Act, you're entitled to know why information is being collected and how it's protected. Reasonable questions to ask an operator: how are records stored, who can access them, and how long are they actually kept beyond the required minimum.
Practical precautions when using any shared computer remain unchanged by this new rule: log out of every account rather than just closing the browser, check email and financial accounts specifically, and collect every printed page — including any copies of ID documents or certificates — before leaving.
A practical starting checklist for operators
- Can you identify which customer used which terminal, and when, on demand?
- Are those records stored somewhere access-controlled, not a shared spreadsheet or an open notebook?
- Do you have a real, working process for producing records if the Authority requests them during an inspection?
- Have you set a genuine retention and disposal practice — three years kept securely, then actually disposed of, not kept indefinitely by default?
- Does your network have the filtering the new conditions require, and is it actually functioning, not just installed once and forgotten?
A structured Security Gap Assessment answers all five of these systematically, rather than guessing at compliance readiness under time pressure.
