Cyber cafés to give State users’ names, computer logs

New regulations in Kenya require cyber cafés to maintain detailed customer logs, including names and identification numbers, to combat rising cybercrime and mobile money fraud. Businesses failing to comply with these data-retention requirements face significant financial penalties.
Why it matters
This highlights the tension between digital privacy and the state's need to regulate public internet access to prevent financial crimes in developing digital economies.
Cyber cafés in Kenya will from Friday be required to keep customers' records such as names, identification numbers, the computer used and login time in fresh efforts to curb cybercrimes like mobile money theft and SIM swap fraud.
New regulations published by the Communications Authority of Kenya (CA) demand that the internet shops issue receipts and keep the records for a minimum of three years, during which the regulator can request them for investigation.
Public internet cafés do not enforce strict user identification, making them attractive to cybercriminals seeking to browse, steal data and hack without being traced through their personal IP addresses.
They also give criminals access to a large pool of personal data like ID numbers, names, passwords and phone numbers of users who log into their accounts using unsecured public computers.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in