All cyber café sessions must be logged, stored for 3 years , CA rules

Moses Kinyanjui
By Moses Kinyanjui August 11, 2026 12:02 (EAT)
Add as a Preferred Source on Google
All cyber café sessions must be logged, stored for 3 years , CA rules

File photo of a cybercafé. (Photo by AFP)

Vocalize Pre-Player Loader

Audio By Vocalize

The Communications Authority of Kenya (CA) has announced that cyber cafés and other licensed services will be required to observe a set of new regulations to tame cybercrime.

In a statement, CA said that all public cyber cafés must maintain customer login sessions showing terminal IDs and start/end time sessions — excluding personal browsing history.

It also added that the café shall retain the records for a minimum of three (3) years from the date of creation. 

"The Licensee shall submit reports to the Authority upon request," CA noted.

The regulations are clustered under a Public Communications Access Centre (“Licensed Services”), which is the provision of communication services to the public regulated by CA, affecting cyber cafés, telephone bureaus and community payphones.

They must also utilise electronic communications equipment that have been duly type‐approved/accepted or exempted from type approval/acceptance by CA.

CA has also demanded that they deploy content filtering mechanisms to protect users from harmful or illegal content and comply with other online safety guidelines, as may be occasionally reviewed.

"The Authority may suspend the Licensed services where the Licensee has breached a Condition in this Licence and the Licensee has been notified of the breach of the licence condition and has been given notice to comply within a specified period and failed to comply," the statement added.

Businesses that breach the licensing conditions will also pay fines equivalent to 0.2 percent of annual turnover, with a minimum penalty of Ksh.500,000.

This comes as the State enforces stricter measures to tame emerging cybercrime threats like SIM-swap fraud, phishing, and cyber harassment with heavy fines and multi-year prison terms.

The Computer Misuse and Cybercrime (Amendment) Act, 2024, signed into law by President William Ruto in October 2025, empowers the National Computer and Cybercrimes Coordination Committee to order internet providers to make websites or applications inaccessible if they are deemed to promote pornography, terrorism, or the nebulous “extreme religious and cultic practices.”

The regulations are set to take effect on August 14, 2026.

Join the Discussion

Share your perspective with the Citizen Digital community.

Moderation applies

Sign In to Publish

No comments yet

This discussion is waiting for your voice. Be the first to share your thoughts!