CAK: How Communications Authority of Kenya is Exposing More Kenyans to Cyberattacks and ID Theft
N

Nyakundi Report

Newsroom · just now

From August 14, Kenyans using public cyber cafés will face a new level of identification. The Communications Authority of Kenya is requiring licensed public internet cafés to register customers, record their names, identification numbers, the computer terminal used and session times. The businesses must issue receipts and retain the records for at least three years, with the Authority able to access the information for inspection, audit or investigation.

The stated reason is understandable. Public computers can be abused by criminals involved in online fraud, identity theft and other offences. The new rules are intended to make it easier for investigators to establish who used a particular machine at a particular time.

But there is another side of this story that Kenyans need to discuss.

The more personal information you collect, the bigger the damage if that information falls into the wrong hands.

A cyber café will potentially have a record connecting a person's name, national ID number, computer terminal and exact time of internet use. That may look harmless when viewed as one record. But when combined with information entered by the customer while using the computer, the risk becomes much bigger.

Think about what happens inside an ordinary cyber café.

A customer may use a public computer to access eCitizen, KRA, HELB, a bank account, email, social media, an employer's system, a SACCO account or a mobile money service. They may type their phone number, email address, username, password, account number or other personal information.

The CA's new rules do not require cafés to keep personal browsing history, and the regulator says the session log is meant to cover basic usage information rather than browsing history.

But the cybersecurity problem does not disappear simply because browsing history is excluded from the required log.

A poorly secured computer can still contain malware, keyloggers, saved passwords, browser sessions or other information entered by previous users. Business Daily reported that cybercriminals have exploited public internet cafés by installing malware capable of capturing usernames, passwords and banking details.

That creates a dangerous combination.

A criminal who gains access to a cyber café's customer register could potentially obtain an identity document number and then use other information stolen from the computer or network to build a much more detailed profile of the victim.

This is where the government needs to be extremely careful.

Kenya already has a legal framework for protecting personal information. The Office of the Data Protection Commissioner says its mandate under the Data Protection Act, 2019 includes protecting personal data and the rights of data subjects. It provides mechanisms for reporting data breaches and filing complaints.

The question is whether every small cyber café collecting this information will have the technical capacity to protect it.

A cyber café may be a small business operating from a single room with a few computers. It may have one attendant handling customers throughout the day. Customer records could be written in a book, stored on an ordinary computer or kept in a basic digital system.

What happens if that book disappears?

What happens if an employee photographs the records?

What happens if the computer storing the information is hacked?

What happens if a cyber café owner sells or shares the information?

What happens when the business closes?

What happens when the employee who has access to the register leaves?

And perhaps the biggest question: who will know if the information has been stolen?

The new rules provide for penalties for businesses that breach the licensing requirements. According to the reported regulations, a cyber café can face a fine equivalent to 0.2 percent of annual turnover, with a minimum penalty of KSh500,000, and can face closure.

But punishment after a breach does not restore a stolen identity.

If your ID number ends up in the hands of a fraudster, you cannot simply change your national ID number the way you change a password.

The Kenyan fraud problem makes this more serious

Kenya is already dealing with major digital fraud concerns.

Business Daily reported that Kenyans lost KSh491.6 million and cryptocurrency through SIM swap fraud, while mobile banking fraud reportedly reached KSh810.68 million in 2024, a sharp increase from the previous year.

SIM swap fraud is particularly dangerous because once criminals take control of a victim's phone number, they can receive calls and text messages, including one time passwords used to access financial accounts.

This means personal information is not just an abstract privacy issue.

A name and ID number can become part of a chain that leads to financial loss, impersonation, fraudulent account creation or targeted scams.

Research examining third party SIM use in Kenya and Tanzania has similarly found that privacy and identity issues can expose users to scams, financial loss and even wrongful arrest.

The cyber café itself can become a target

There is another problem.

The new system creates a central point of interest for criminals.

If hundreds of people use one cyber café every week, its customer register becomes a valuable database.

A criminal does not necessarily need access to every computer in the café. If they can obtain the customer register, they could potentially get a list of people who regularly use the facility.

That is particularly worrying in areas where cyber cafés are used for government services.

People go to these businesses because they do not own computers, lack reliable internet or need assistance accessing online services.

They may be unemployed people applying for jobs.

Students applying for government opportunities.

Business owners filing tax returns.

People applying for passports.

People accessing government services.

People making financial transactions.

These are precisely the people who may have to surrender personal information simply to access the internet.

A similar lesson from Kenya's digital finance sector

Kenya's experience with mobile money provides another warning.

The country's digital financial system depends heavily on identity verification. That has helped bring millions of people into formal financial services, but it has created a large amount of valuable personal information that criminals want to exploit.

Research on third party SIM cards in Kenya found that privacy concerns are among the issues affecting users and that people using SIM cards registered in another person's name face significant security risks.

The lesson is simple.

Identification can help investigators trace crime, but identification data can itself become a weapon when poorly protected.

The government must not stop at collecting the data

The Communications Authority should tell Kenyans exactly what safeguards will apply to the new system.

Who is allowed to see the records?

How will cyber cafés store them?

Will physical registers be permitted?

How will records be destroyed after the three year retention period?

Will cyber cafés be required to encrypt digital records?

Will staff handling the information receive data protection training?

Will cyber cafés have to report breaches?

How often will the Authority inspect their security systems?

And what happens to the information when a cyber café shuts down?

These questions matter just as much as the requirement to record customer information.

The Office of the Data Protection Commissioner already provides avenues for data subjects to complain and report breaches. But ordinary Kenyans should not have to discover after the fact that their ID details were mishandled.

The government needs to make data protection part of the rule from the beginning.

The bigger issue is trust

There is nothing inherently wrong with investigating cybercrime.

Criminals should be traceable.

Fraudsters should not be able to walk into a cyber café, use a computer anonymously and disappear after stealing from someone.

But the answer cannot simply be collect more data.

It must be collect what is necessary, protect it properly and destroy it when there is no longer a lawful reason to keep it.

Otherwise, Kenya could end up solving one problem while creating another.

A cyber criminal may once have walked into a cyber café and disappeared without leaving a trace.

Under the new system, there will be a customer record.

But if that customer record is poorly protected, the next person walking into the cyber café may not be the criminal.

It could be the victim.

The Communications Authority needs to make sure that the new rules do not turn thousands of small cyber cafés into unsecured warehouses of Kenyans' personal information.

And Kenyans need to ask one very basic question before August 14:

Who is protecting the people who are being required to surrender their identities?