The Co-operative University of Kenya
Data Protection & Privacy Centre
Protecting personal data. Promoting trust. Ensuring compliance.
The University holds personal information about applicants, students, staff, alumni, research participants, suppliers and visitors — because we cannot teach, examine, employ, pay or graduate anyone without it. This Centre sets out what we collect, why we are permitted to collect it, how we protect it, and what you can require of us. Every right described here comes with a form, a named contact and a deadline we are bound to meet.
The Co-operative University of Kenya is registered with the Office of the Data Protection
Commissioner.
Identification 399-967F-21D9 · Valid to 22 July 2028 · Data Protection Act, 2019
What do you need today?
Four routes cover almost everything people come here for. Take the one that matches your situation — each leads straight to the form, notice or guidance you need.
Exercise a right over your data
Get a copy of what we hold, correct something that is wrong, object to how we are using it, or withdraw a consent you gave. Eight rights, eight forms, and the deadline for each.
Your Rights →Report a breach or privacy concern
If personal information has been lost, exposed, sent to the wrong person or accessed by someone who should not have it, tell us. You do not need to be certain, and you do not need to be a member of the University.
Report a Data Breach →Find out what we do with your information
Twenty-four privacy notices, written for specific groups — students, applicants, staff, alumni, research participants, suppliers, visitors — rather than one document that serves nobody well.
Privacy Notices →Guidance for staff and departments
If you are launching a system, running a survey, procuring a supplier or starting a research project, there is a route to follow before you collect anything.
Guidance for Departments →Our commitment
We treat personal data as something held in trust rather than something owned. That framing is not decoration: it determines how we answer the practical questions — whether to collect a field, how long to keep a record, whether a supplier may hold it, and what we do on the day something goes wrong.
Our obligations are set by the Constitution of Kenya, 2010, the Data Protection Act, 2019, and the Data Protection (General) Regulations, 2021. We meet those obligations, and where an international standard of practice sits above them and serves our community better, we adopt it and say so.
We do not claim to be perfect. We claim to be accountable, and we publish the means by which you can hold us to it.
Read our full commitment- Lawful
- Transparent
- Proportionate
- Secure
- Accountable
- Answerable
Your rights at a glance
Under the Data Protection Act, 2019 you have rights over the personal data we hold about you. Each is shown below with the time the law gives us to respond. Making a request is free, and giving effect to it is free — data portability is the single exception, where the law permits a reasonable cost.
Be informed
Know what we are collecting, why, who receives it, and whether you have to provide it.
Act, 2019 — s.26(a); s.29
Access your data
Ask us to confirm what we hold about you and give you a copy of it.
Act s.26(b) · Regs 2021, reg. 9(4)
Correct your data
Require us to correct data that is inaccurate, out of date, incomplete or misleading.
Act s.26(d) · Regs 2021, reg. 10(4)
Delete your data
Ask us to delete data in defined circumstances. Award records are an exception — we explain why.
Act s.26(e) · Regs 2021, reg. 12(3)
Object to processing
Absolute for direct marketing. Qualified on other grounds — and we explain our reasoning.
Act, 2019 — s.26(c)
Restrict processing
Require us to pause use of your data while a correction or objection is resolved.
Act s.34 · Regs 2021
Port your data
Receive data you gave us in a machine-readable format. The only right that may carry a cost.
Act, 2019 · Regs 2021
Withdraw consent
Where we asked for consent, withdraw it at any time — as easily as you gave it.
Act, 2019 — s.32
If you are not satisfied with how we handle your request, you may complain to the Office of the Data Protection Commissioner. You may do so at any time, and you are not required to raise the matter with us first — though we can usually resolve it faster if you do.
Privacy notices
A privacy notice tells one specific group of people what we do with their information. We publish twenty-four, so that you are never asked to work out your own position from a document written for somebody else.
CUK/DPO/PN/03 · v1.0
Student Privacy Notice
How the University handles your personal data from registration through to graduation and beyond.
CUK/DPO/PN/01 · v1.0
Prospective Students & Applicants
What we collect when you apply, how admission decisions are recorded, and what happens to unsuccessful applications.
CUK/DPO/PN/04 · v1.0
Staff Privacy Notice
Employment, payroll, performance, leave and training records, and who inside the University can see them.
CUK/DPO/PN/06 · v1.0
Research Participants
Consent, anonymisation, storage, retention and publication of data collected in University research.
CUK/DPO/PN/20 · v1.0
CCTV & Physical Security
Why cameras are used, where they operate, who may view footage, and how long it is kept.
CUK/DPO/PN/08 · v1.0
Suppliers & Vendors
Contact, contractual, banking and due-diligence information collected through procurement.
CUK/DPO/PN/07 · v1.0
Alumni Privacy Notice
What we keep after you graduate, how we contact you, and why your award record is retained permanently.
No notices match that filter on this page. All twenty-four are listed in the full library.
Report a data breach — urgent
If you think personal information held by the University has been lost, stolen, exposed, altered or disclosed to someone who should not have seen it, tell us straight away. Report it even if you are not sure. Deciding whether something is a breach is our job, not yours — we would far rather assess fifty reports that turn out to be nothing than miss the one that was not.
⚠ We must notify the Data Protection Commissioner within 72 hours of becoming aware — and that clock starts the moment you tell us.
Policies, forms and resources
Every controlled document carries a reference, a version number and a review date on its face, so you can always tell whether you are reading the current one.
Policies & governance documents
Data Protection, Information Security, Records Management & Retention, Acceptable Use, Research Data, ICT, Document Disposal, CCTV, Cookies and Consent.
View policies →Request & consent forms
Nine data subject request forms and seven consent forms, each with the statutory basis and response timeline stated on the form itself.
Go to Downloads Centre →Awareness & guidance
Practical guides on passwords, phishing, email, mobile and cloud storage, working away from campus, social media, and the use of AI tools with personal data.
Awareness Centre →Frequently asked questions
Five of the questions we are asked most. Forty-five more are answered in full.
No — and this is the most common misunderstanding. Consent is one of several lawful bases. Most of what we do with your data rests on other bases: performing our contract with you, complying with a legal obligation, or acting in the public interest in the exercise of our functions as a public university. We use consent for genuinely optional things — photography, marketing emails, taking part in research — where you can say no without consequence. We do not put a consent box on something you cannot actually refuse, because that would mislead you.
Seven days for access; fourteen days for correction, deletion, restriction and objection; thirty days for portability. These are set by the Data Protection (General) Regulations, 2021 and are among the shortest windows anywhere in the world. The clock starts when any member of University staff receives your request — not when it reaches the Data Protection Officer.
You can ask, and we will assess it honestly, but the answer will usually be partly no. Your degree and award records cannot be deleted: the University has a continuing duty to verify the qualifications it confers, sometimes decades later, and if we destroyed the record we could not confirm your own degree when you needed us to. Records we are legally required to keep, and records needed for a legal claim, are also retained. Where we refuse, we tell you which exemption applies and how to challenge it.
No. Making a request is free and acting on it is free. Data portability is the single exception, where the law permits a reasonable cost — and we would tell you the amount before proceeding. You also do not need to use our form, and you do not need to give a reason.
No, and deliberately so. Compliance is a continuing state assessed against evidence, and it is for the Data Protection Commissioner to determine — not for us to assert on our own website. What we say is that we have built the framework, we know where our remaining gaps are, we have an owner and a date against each of them, and we will tell you honestly if you ask.
Contact the Data Protection Office
The Data Protection Office is the University's point of contact for anything concerning personal data — rights requests, privacy concerns, breach reports, questions about a notice, and guidance for departments planning a new collection.
Contact the Data Protection Office- dpo@cuk.ac.ke
- Telephone
- +254 724 311 606
- Address
- The Co-operative University of Kenya
Karen, Nairobi
P.O. Box 24814–00502, Nairobi