Data Protection & Privacy | Co-operative University of Kenya

The Co-operative University of Kenya

Data Protection & Privacy Centre

Protecting personal data. Promoting trust. Ensuring compliance.

The University holds personal information about applicants, students, staff, alumni, research participants, suppliers and visitors — because we cannot teach, examine, employ, pay or graduate anyone without it. This Centre sets out what we collect, why we are permitted to collect it, how we protect it, and what you can require of us. Every right described here comes with a form, a named contact and a deadline we are bound to meet.

The Co-operative University of Kenya is registered with the Office of the Data Protection Commissioner. Identification 399-967F-21D9 · Valid to 22 July 2028 · Data Protection Act, 2019

What do you need today?

Four routes cover almost everything people come here for. Take the one that matches your situation — each leads straight to the form, notice or guidance you need.

Our commitment

We treat personal data as something held in trust rather than something owned. That framing is not decoration: it determines how we answer the practical questions — whether to collect a field, how long to keep a record, whether a supplier may hold it, and what we do on the day something goes wrong.

Our obligations are set by the Constitution of Kenya, 2010, the Data Protection Act, 2019, and the Data Protection (General) Regulations, 2021. We meet those obligations, and where an international standard of practice sits above them and serves our community better, we adopt it and say so.

We do not claim to be perfect. We claim to be accountable, and we publish the means by which you can hold us to it.

Read our full commitment
  • Lawful
  • Transparent
  • Proportionate
  • Secure
  • Accountable
  • Answerable

Your rights at a glance

Under the Data Protection Act, 2019 you have rights over the personal data we hold about you. Each is shown below with the time the law gives us to respond. Making a request is free, and giving effect to it is free — data portability is the single exception, where the law permits a reasonable cost.

AT COLLECTION

Be informed

Know what we are collecting, why, who receives it, and whether you have to provide it.

Act, 2019 — s.26(a); s.29

7 DAYS

Access your data

Ask us to confirm what we hold about you and give you a copy of it.

Act s.26(b) · Regs 2021, reg. 9(4)

14 DAYS

Correct your data

Require us to correct data that is inaccurate, out of date, incomplete or misleading.

Act s.26(d) · Regs 2021, reg. 10(4)

14 DAYS

Delete your data

Ask us to delete data in defined circumstances. Award records are an exception — we explain why.

Act s.26(e) · Regs 2021, reg. 12(3)

14 DAYS

Object to processing

Absolute for direct marketing. Qualified on other grounds — and we explain our reasoning.

Act, 2019 — s.26(c)

14 DAYS

Restrict processing

Require us to pause use of your data while a correction or objection is resolved.

Act s.34 · Regs 2021

30 DAYS

Port your data

Receive data you gave us in a machine-readable format. The only right that may carry a cost.

Act, 2019 · Regs 2021

ON RECEIPT

Withdraw consent

Where we asked for consent, withdraw it at any time — as easily as you gave it.

Act, 2019 — s.32

If you are not satisfied with how we handle your request, you may complain to the Office of the Data Protection Commissioner. You may do so at any time, and you are not required to raise the matter with us first — though we can usually resolve it faster if you do.

Privacy notices

A privacy notice tells one specific group of people what we do with their information. We publish twenty-four, so that you are never asked to work out your own position from a document written for somebody else.

CUK/DPO/PN/03 · v1.0

Student Privacy Notice

How the University handles your personal data from registration through to graduation and beyond.

CUK/DPO/PN/01 · v1.0

Prospective Students & Applicants

What we collect when you apply, how admission decisions are recorded, and what happens to unsuccessful applications.

CUK/DPO/PN/04 · v1.0

Staff Privacy Notice

Employment, payroll, performance, leave and training records, and who inside the University can see them.

CUK/DPO/PN/06 · v1.0

Research Participants

Consent, anonymisation, storage, retention and publication of data collected in University research.

CUK/DPO/PN/20 · v1.0

CCTV & Physical Security

Why cameras are used, where they operate, who may view footage, and how long it is kept.

CUK/DPO/PN/08 · v1.0

Suppliers & Vendors

Contact, contractual, banking and due-diligence information collected through procurement.

CUK/DPO/PN/07 · v1.0

Alumni Privacy Notice

What we keep after you graduate, how we contact you, and why your award record is retained permanently.

Report a data breach — urgent

If you think personal information held by the University has been lost, stolen, exposed, altered or disclosed to someone who should not have seen it, tell us straight away. Report it even if you are not sure. Deciding whether something is a breach is our job, not yours — we would far rather assess fifty reports that turn out to be nothing than miss the one that was not.

⚠ We must notify the Data Protection Commissioner within 72 hours of becoming aware — and that clock starts the moment you tell us.

Policies, forms and resources

Every controlled document carries a reference, a version number and a review date on its face, so you can always tell whether you are reading the current one.

Frequently asked questions

Five of the questions we are asked most. Forty-five more are answered in full.

No — and this is the most common misunderstanding. Consent is one of several lawful bases. Most of what we do with your data rests on other bases: performing our contract with you, complying with a legal obligation, or acting in the public interest in the exercise of our functions as a public university. We use consent for genuinely optional things — photography, marketing emails, taking part in research — where you can say no without consequence. We do not put a consent box on something you cannot actually refuse, because that would mislead you.

Seven days for access; fourteen days for correction, deletion, restriction and objection; thirty days for portability. These are set by the Data Protection (General) Regulations, 2021 and are among the shortest windows anywhere in the world. The clock starts when any member of University staff receives your request — not when it reaches the Data Protection Officer.

You can ask, and we will assess it honestly, but the answer will usually be partly no. Your degree and award records cannot be deleted: the University has a continuing duty to verify the qualifications it confers, sometimes decades later, and if we destroyed the record we could not confirm your own degree when you needed us to. Records we are legally required to keep, and records needed for a legal claim, are also retained. Where we refuse, we tell you which exemption applies and how to challenge it.

No. Making a request is free and acting on it is free. Data portability is the single exception, where the law permits a reasonable cost — and we would tell you the amount before proceeding. You also do not need to use our form, and you do not need to give a reason.

No, and deliberately so. Compliance is a continuing state assessed against evidence, and it is for the Data Protection Commissioner to determine — not for us to assert on our own website. What we say is that we have built the framework, we know where our remaining gaps are, we have an owner and a date against each of them, and we will tell you honestly if you ask.

Contact the Data Protection Office

The Data Protection Office is the University's point of contact for anything concerning personal data — rights requests, privacy concerns, breach reports, questions about a notice, and guidance for departments planning a new collection.

Contact the Data Protection Office
Address
The Co-operative University of Kenya
Karen, Nairobi
P.O. Box 24814–00502, Nairobi