Walk into a cyber cafe in Kenya from Friday, and the first thing you may be handed isn’t a keyboard — it’s a form. The Communications Authority of Kenya (CAK) has ordered every cyber cafe and public internet centre in the country to register each customer by name and national ID number, log the exact times they’re online, and retain those records for at least three years. The rule takes effect August 14. Operators who don’t comply face fines starting at KES 500,000 (about $3,860), or 0.2% of their annual turnover — whichever hits harder.
What Cafes Now Have to Do
The mandate is specific and operational, not aspirational. Every customer who logs on has to be registered with their name and ID number, and operators must keep a running log of session times for a minimum of three years. Cafes are also required to install filters that block illegal websites and to seek regulatory approval before reselling bulk internet access to others. Put together, it’s a compliance burden that lands squarely on small, often single-owner businesses that were, until this week, largely free to let people walk in, pay, and browse.
Why the CAK Says This Is Necessary
The regulator’s stated goal is closing what it calls an identity gap: if a computer at a shared cafe is used to commit a cybercrime, there has historically been no reliable way to trace that activity back to the person who was actually sitting at the keyboard. Tying every session to a verified name and ID number is meant to fix that, and it’s arriving as part of Kenya’s National Cybersecurity Strategy, which runs through 2027. The philosophy behind it is a clean, if uncomfortable, one: the country is shifting from prioritising access to the internet at almost any cost, to prioritising access that comes with a built-in paper trail.
The Watered-Down Version of an Older Plan
This isn’t Kenya’s first attempt at regulating cyber cafes this way, and it’s worth noting how much less aggressive this version is than what was originally proposed. Back in 2024, the government floated a plan that would have gone considerably further: mandatory CCTV cameras inside every cafe, plus tracking of customers’ actual browsing history, not just their login times. That proposal stalled and never took effect. What’s arriving this week is a scaled-back version — identity registration and session logging survived, but real-time video surveillance and browsing-history tracking were both dropped. It’s a meaningfully lighter-touch rule than what regulators originally wanted, even if it still represents a sharp departure from how cafes have operated for two decades.
Why It Matters More in Kenya Than It Might Elsewhere
Cyber cafes aren’t a relic in Kenya the way they’ve become in many markets with cheap mobile data. Kenya remains one of the most expensive data markets on the continent, and cafes have quietly continued to function as a genuine subsidy on internet access for people who can’t justify the cost of a personal data plan for every browsing session. At least 300 cafes are listed on business directories nationally, and the CAK itself has previously acknowledged that the true number operating is considerably larger. Many have also evolved well beyond browsing, adding printing and government-service support to their offerings — which is likely a big part of why they’re still commercially relevant enough for a regulator to bother writing rules for them at all.
The Bind Operators Are Now In
The timing is awkward for an industry that was already under pressure. Cafe owners have reported shrinking revenue for years as cheaper smartphones spread and fewer people need a shared terminal for basic browsing. Now those same operators have to weigh two unattractive options at once: enforce ID checks and logging that might make privacy-conscious customers walk straight back out the door, or skip compliance and risk a fine that could run to a meaningful share of a small business’s annual revenue. Neither choice is free, and the businesses least equipped to absorb either cost are exactly the small, independent operators the rule applies to.
What to Watch From Here
The real test starts Friday, not this week’s announcement. Enforcement in Kenya has a track record of being uneven in its first months — the 2024 version of this exact plan never even got that far — so the gap between what’s written in the regulation and what actually gets checked at cafe counters across the country will say more about the rule’s real impact than the penalty figures on paper. If it holds, Kenya joins a small but growing list of African markets tightening identity requirements at the point of shared digital access, a trend worth watching well beyond its borders as more governments weigh security gains against the quiet erosion of anonymous, low-cost internet access for the people who rely on it most.