Back to Blog
Kenya's Cyber Cafés Just Became Identity Desks — But No One Told the Data Regulator
Cybersecurity

Kenya's Cyber Cafés Just Became Identity Desks — But No One Told the Data Regulator

August 14, 2026GashoTech Intelligence

Kenya's Cyber Cafés Just Became Identity Desks — But No One Told the Data Regulator



From Friday 14 August 2026, every licensed cyber café in Kenya is supposed to do something it has never done at scale: treat a customer the way a bank treats a customer. Before the customer touches a keyboard, the operator must capture their full name and national identity card or passport number, log which terminal they were seated at, and record the exact minute the session started and ended. A receipt must be issued for every paid session. The records have to be kept for at least three years. The Communications Authority of Kenya (CA) announced the rules in late July, published the technical detail through the Kenya Gazette in early August, and gave the industry less than two weeks to comply. As of 12 August 2026, the Office of the Data Protection Commissioner (ODPC) has not issued a public statement on the new obligations — and the gap is starting to show.

What the rule actually requires



The CA classifies cyber cafés as "public communications access centres." Under the new rules, an operator cannot grant a customer access to a terminal without first verifying their identity. The capture is straightforward in form: full name, national ID or passport number, terminal used, login time, logout time, receipt. The retention rule is the part that will hurt — three years of secure storage, with the CA empowered to enter premises, inspect systems, and audit the records.

The fine schedule is built to bite. Non-compliance carries 0.2% of annual turnover, with a floor of KES 500,000. The CA can also suspend services or order the closure of the premises. For a small operator doing KES 200,000 a month in receipts, KES 500,000 is more than two months of revenue. For a chain of cafés in a town like Nakuru or Kisumu, the 0.2% figure starts to look like an annual IT budget that does not exist.

The rule stops short of requiring operators to log browsing history. Customers are not being asked to surrender what they read or watch. The CA is building a record of who used which machine when, not a record of what they did with it. That distinction is important, and it tells you exactly what the rule is designed for.

Why the CA did this



The CA frames the rule as a response to three patterns: SIM-swap fraud, mobile-money fraud, and online scams that use shared computers to hide the actor. SIM-swap in particular has been a live problem in Kenya for years. The July 2026 High Court ruling that held Safaricom and Diamond Trust Bank jointly liable for a KES 4.4 million SIM-swap loss put the sector on notice. Cyber cafés have long been an easy way to launder the operational layer of those scams — buy a session, run the script, leave no trace. The CA's new rule makes the operator the trace.

The framing is not unreasonable. Identity-linked access is the global default for any service that touches money or communication. Banks, telcos, and fintechs already do it. The question is not whether the principle is right. The question is who carries the cost of operationalising it — and whether the body that polices data protection is on the same page.

The ODPC silence is the story



The CA can regulate telecoms. The ODPC regulates personal data. The new cyber-café rule sits in the overlap: the operator is now collecting personal data at scale, retaining it for three years, and exposing it to a regulator that can audit it. Under Kenya's Data Protection Act, the operator is the data controller, and the law requires them to handle the data accordingly. That means registration with the ODPC, a data protection impact assessment, breach-notification procedures, and a lawful basis for processing.

Small operators are not exempt from the data protection law. They may, in some cases, be exempt from registering with the ODPC. But they cannot use that exemption to escape the underlying obligations. So the CA is telling thousands of small businesses to start collecting and storing personal data — and the ODPC has not told those businesses how.

That is the operational gap. A cyber café in a trading centre outside Eldoret does not have a data protection officer. It does not have a privacy notice ready to hand to customers. It does not have a breach plan. And it does not have a regulator on speed dial to ask what the right answer is. The CA's rule assumes the ODPC's machinery is in place. The ODPC's machinery is, by the ODPC's own silence, not yet engaged with this rule.

What this means for founders, operators, and CISOs



For cyber café operators, the immediate question is whether the cost of compliance — in time, in ID-capture hardware, in storage, in legal advice — is sustainable at current margins. The CA is offering no compliance template. Operators will improvise. Some will build spreadsheet workflows. Some will buy a managed identity-capture SaaS from a local fintech. Some will simply not comply and pay the fine when the auditor comes. The market will sort itself into compliant and non-compliant tiers, and the non-compliant tier will get smaller fast.

For SaaS founders, this is an open lane. There is now a defined regulatory demand for low-cost, ODPC-aligned, identity-capture-as-a-service for the cyber-café and SME-internet market. A KES 2,000-a-month product that bundles ID capture, three-year encrypted storage, automatic privacy notices, and a breach-response workflow is exactly what the market needs. None of that product exists at scale in Kenya today.

For CISOs at banks, telcos, and fintechs, the rule closes a small but persistent gap in their own fraud-detection stack. The hardest cases to investigate are the ones where the actor uses a shared computer they cannot tie to a person. After 14 August, every café session in the country is tied to a national ID. That is a meaningful investigative lead for fraud teams, and a meaningful signal for any operator whose platform has been abused through café traffic.

For the ODPC, the question is whether they will engage publicly and quickly, or whether the silence will force the CA to expand its own data-handling guidance and effectively absorb the data-protection role for this sector. Either path leaves Kenya's data-protection machinery looking underweight for the regulatory load it is now expected to carry.

What to watch



Three signals in the next 60 days will tell you whether this rule lands or fades. First, the ODPC's first public statement on cyber-café compliance — or its continued silence. Second, the first published CA enforcement action under the new rule, which will set the precedent for the rest of the industry. Third, the first Kenyan SaaS product launched specifically to serve this compliance gap, because that is where the market is telling you the problem is real.

The CA's rule turns every cyber café in the country into an identity desk. Whether that desk has the legal and technical infrastructure to do the job properly is a question the ODPC has not yet answered.

Want to learn more?

Contact GashoTech for personalized consultations on AI, automation, and cybersecurity solutions.

Get in Touch