Data Protection & Privacy Centre
Contact the Data Protection Office
The Data Protection Office is the University's point of contact for anything concerning personal data. You do not need to be a student or a member of staff to write to us, you do not need to explain why you are asking, and there is no charge for contacting us or for acting on what you ask.
How to reach us
Email is the fastest route and creates a record of the date your request was received, which matters because the statutory clock starts on that date. Telephone is available if you would rather speak to someone, and anything sent by post reaches us in the ordinary course.
If you are reporting a suspected data breach, do not wait for a reply to an email. Use the breach reporting route, which is monitored specifically for that purpose.
- dpo@cuk.ac.ke The preferred route for rights requests, privacy concerns and general enquiries.
- Telephone
- +254 724 311 606
- Post
-
The Data Protection Officer
The Co-operative University of Kenya
P.O. Box 24814–00502
Nairobi, Kenya Mark the envelope for the attention of the Data Protection Officer so that it is not opened in the ordinary course of University correspondence. - Campus
- Karen, Nairobi, Kenya
What the office handles
If your question concerns personal data, it belongs here. If it concerns something else — fees, admission decisions, results, accommodation — the relevant department will answer faster than we can, and we will redirect you rather than hold your enquiry.
Requests to exercise a right
Access to what we hold, correction of something inaccurate, deletion, restriction, objection, portability, or withdrawal of a consent you previously gave.
Your rights →Suspected data breaches
Personal information lost, exposed, altered, sent to the wrong recipient or accessed by someone who should not have it. Report it even if you are not certain.
Report a breach →Privacy concerns and complaints
If you believe the University has handled your personal data improperly, tell us. Raising it with us first is not a precondition to complaining to the regulator, but it is usually faster.
Questions about a privacy notice
If something in a notice is unclear, contradicts what you were told, or does not appear to describe your situation, we would rather know than have you guess.
Privacy notices →Guidance for departments
Advice before you launch a system, run a survey, engage a supplier, or begin a research project involving personal data. Earlier is cheaper than later.
Third-party and supplier enquiries
Data processing agreements, due diligence questionnaires, and requests for information about how the University handles data on behalf of partners.
What to include when you write
None of this is mandatory, and an incomplete message is far better than no message at all. But the more of it you can give us at the outset, the less likely we are to spend part of a short statutory period asking you for it.
- Your full name, and any other name the University may hold you under — a maiden name, or the name on your original application.
- How we should reply — an email address or postal address you can reliably access.
- Your relationship to the University — applicant, student, former student, member of staff, supplier, research participant, visitor, or member of the public.
- Your registration or staff number, if you have one. This is the single most useful thing you can give us, because it locates your records immediately.
- What you are asking for — which right you wish to exercise, or what concern you are raising.
- Which records, if you can narrow it — a department, a system, a date range, or a particular episode. A narrower request is answered faster and more completely.
- Any relevant dates — when you noticed the problem, when you last updated your details, when the episode occurred.
- Proof of identity, when we ask for it — we may need to verify who you are before releasing personal data, so that we do not disclose your information to someone else. We will tell you what is acceptable rather than leaving you to guess.
You are not required to use a University form, and you are not required to give a reason for your request. Forms exist because they prompt for the information above, not because they are a condition of being answered.
How quickly we must respond
These periods are set by law, not by University policy, and they are among the shortest anywhere. The clock starts when any member of University staff receives your request — not when it reaches this office. If we cannot meet a deadline, we will tell you before it passes, and we will tell you why.
| If you ask us to | We must respond within |
|---|---|
| Give you access to the data we hold about you | 7 daysAct s.26(b) · Regs 2021, reg. 9(4) |
| Correct data that is inaccurate, out of date, incomplete or misleading | 14 daysAct s.26(d) · Regs 2021, reg. 10(4) |
| Delete data you believe we should no longer hold | 14 daysAct s.26(e) · Regs 2021, reg. 12(3) |
| Restrict or object to how we are using your data | 14 daysAct s.26(c) · s.34 |
| Transfer data you gave us in a machine-readable format | 30 daysAct, 2019 · Regs 2021 |
| Act on a withdrawal of consent | On receiptAct, 2019 — s.32 |
A separate obligation applies to breaches: where a personal data breach is likely to result in a real risk of harm, the University must notify the Data Protection Commissioner within 72 hours of becoming aware of it. That period runs from the moment the University becomes aware, which is why reporting promptly matters more than reporting completely.
If you are not satisfied with our response
You may complain to the Office of the Data Protection Commissioner, the independent regulator established under the Data Protection Act, 2019. You may do so at any time. You are not required to raise the matter with the University first, and you do not need our permission or our involvement to do so. We would ordinarily ask for the chance to put something right, but that is a preference on our part, not a condition on your right.
- Head office
- Britam Tower, 12th & 13th Floor
- Hospital Road, Upper Hill
- Nairobi, Kenya
- P.O. Box 30920–00100 G.P.O.
Nairobi, Kenya
- Email and telephone
- info@odpc.go.ke
- enquiries@odpc.go.ke
- 020 780 1800
- 0796 954 269
- 0752 896 867
- Opening hours
- Monday to Friday
- 8.00 am – 5.00 pm
- The ODPC also operates regional offices in Mombasa, Nakuru, Kisumu, Garissa, Eldoret, Nyeri and Machakos.
ODPC contact details verified against odpc.go.ke on 17 August 2026. These are the regulator's own details and may change without notice to the University.
Data Protection Office
The Co-operative University of Kenya is registered with the Office of the Data Protection Commissioner under identification 399-967F-21D9, valid to 22 July 2028.
Return to the Privacy Centre- dpo@cuk.ac.ke
- Telephone
- +254 724 311 606
- Address
- The Co-operative University of Kenya
Karen, Nairobi
P.O. Box 24814–00502, Nairobi