Since 14 August 2026, every cyber café and public internet access point in Kenya has been operating under a stricter rulebook. The Communications Authority of Kenya (CA) rolled out new requirements under the Public Communications Access Centre (PCAC) Class Licence, issued under the Kenya Information and Communications Act -- and for operators who've spent years running things on a paper logbook and an honesty system, the compliance bar just moved considerably higher.

What the new rules actually require

The requirements are specific. Operators must record each customer's full name and national ID or passport number before granting access, log which terminal they used along with the exact login and logout times, and issue a receipt for the service. Those records then have to be retained for at least three years. Notably, the rules also draw a clear line on what operators can't do: browsing history itself is explicitly off-limits to log or retain -- this is about who was online and when, not what they looked at.

Why the CA is doing this now

The stated rationale is traceability. Kenyan authorities have pointed to rising cybercrime risk as the reason public internet access points need a reliable paper trail linking a session back to a real, identifiable person -- something that's been largely absent from how most walk-in cyber cafés and public WiFi spots have operated. It puts internet access points under a record-keeping standard closer to what regulated financial or telecom services already follow.

The catch operators are now grappling with

The rollout has exposed a real tension. Under Kenya's Data Protection Act, 2019, any business that starts collecting names and national ID numbers automatically becomes a "data controller" -- a status that comes with its own obligations around consent, security and breach notification, sitting alongside the CA's licensing requirements. Coverage of the rollout has noted that thousands of small, largely manual operators are now expected to responsibly hold sensitive identity data for millions of customers, with the practical division of oversight between the communications regulator and the data protection regulator still not entirely settled. For an operator running a handwritten logbook, that's not a small ask.

Where this matters beyond cyber cafés

Cyber cafés are the rule's immediate target, but the underlying requirement -- identify who's on your network, log when their session started and ended, keep proof, issue a receipt -- is exactly the same shape of problem that hotspot and public WiFi billing operators across Kenya already have to solve. A shared PCAC-style licensing category means today's cyber café rule can plausibly be a template for broader public-access requirements down the line, and operators who are still reconciling access manually are the ones most exposed if that happens.

Why this is a billing infrastructure problem, not just a compliance one

This is precisely where a RADIUS-driven hotspot billing system has a structural advantage over a paper logbook. A platform like XpressRADIUS already ties every session to an identifiable customer through M-Pesa or Kopo Kopo payment details, timestamps login and logout automatically at the RADIUS layer, and generates a receipt the moment a voucher or session is purchased -- all without an attendant manually writing anything down. For an ISP or hotspot operator running prepaid access points, that's not a new feature to build for this rule; it's what proper session-based billing already produces as a byproduct. The operators who'll struggle if similar identity and retention rules expand to hotspot WiFi are the ones still tracking access with a notebook, not the ones whose billing system was already built around real-time session control.

If regulatory scrutiny of public internet access keeps tightening across the region -- and the direction of travel in Kenya suggests it will -- the operators with automated, auditable session records already in place won't need to scramble when the next rule lands.

Want session-level billing and RADIUS control that keeps a verifiable record of every login automatically?

Start a free trial
← Back to all posts