Authors: Everleen Nekesa Makhanu¹, Resila A. Onyango² and Henry Mwenemeru³
1,2&3National Defence University
P.O. Box 24381- 00502, Nairobi, Kenya
Abstract: Cybercafés remain important access points for e-government and digital services in Kenya, but their shared-user environments expose personal information to unauthorized access, misuse, disclosure and residual data retention. Despite Kenya’s legal framework anchored in the Data Protection Act, 2019 and the Computer Misuse and Cybercrimes Act, 2018, empirical evidence on data-security practices among cybercafé operators remains limited. This study investigated the effect of legal awareness and cybersecurity measures on data-security outcomes among cybercafé operators in Nairobi County. An explanatory research design within a mixed-methods approach was adopted. The target population comprised an estimated 1,200 cybercafés across 17 sub-counties. Using Yamane’s formula at a 5% level of precision, 300 operators were selected through stratified random sampling and proportionately allocated across the sub-counties. Eight key informants from relevant data-protection, cybersecurity, county government, law-enforcement and ICT institutions were purposively selected separately from the survey respondents. Quantitative data were collected using a structured questionnaire, while qualitative data were collected using a Key Informant Interview Guide. Quantitative data were analyzed using SPSS Version 26 through descriptive statistics, while qualitative data were analyzed thematically and reported narratively. Quantitative findings indicated high self-reported levels of legal awareness, cybersecurity measures and data-security practices. However, qualitative findings revealed that legal awareness was often superficial, cybersecurity measures were inconsistently implemented, and regulatory enforcement remained weak. The findings demonstrated a gap between awareness of data-protection requirements and their consistent application in practice. The study concluded that improving data security among cybercafés requires interventions extending beyond legal awareness to practical cybersecurity support and sustained regulatory engagement.
Keywords: Data security, legal awareness, cybersecurity measures, data protection, cybercafés, e-government services, regulatory compliance, cybersecurity governance, personal data protection, data security compliance
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Full Text
![]()
Suggested Citation
Nekesa, E.M, Onyango, R.A., and Mwenemeru, H. (2026). Policy Compliance And Data Security By Cybercafés In Nairobi County, Kenya: An Evaluation Of Awareness Of Data Protection And Computer Misuse And Cybercrimes Acts. African Research Journal of Education and Social Sciences, 13(2), 45-54. Available at https://arjess.org/uploads/policy-compliance-and-data-security-by-cybercafes-in-nairobi-county-kenya-an-evaluation-of-awareness-of-data-protection-and-computer-misuse-and-cybercrimes-acts.pdf
