Contact the Data Protection Office

Data Protection & Privacy Centre

Contact the Data Protection Office

The Data Protection Office is the University's point of contact for anything concerning personal data. You do not need to be a student or a member of staff to write to us, you do not need to explain why you are asking, and there is no charge for contacting us or for acting on what you ask.

How to reach us

Email is the fastest route and creates a record of the date your request was received, which matters because the statutory clock starts on that date. Telephone is available if you would rather speak to someone, and anything sent by post reaches us in the ordinary course.

If you are reporting a suspected data breach, do not wait for a reply to an email. Use the breach reporting route, which is monitored specifically for that purpose.

Email
dpo@cuk.ac.ke The preferred route for rights requests, privacy concerns and general enquiries.
Telephone
+254 724 311 606
Post
The Data Protection Officer
The Co-operative University of Kenya
P.O. Box 24814–00502
Nairobi, Kenya Mark the envelope for the attention of the Data Protection Officer so that it is not opened in the ordinary course of University correspondence.
Campus
Karen, Nairobi, Kenya

What the office handles

If your question concerns personal data, it belongs here. If it concerns something else — fees, admission decisions, results, accommodation — the relevant department will answer faster than we can, and we will redirect you rather than hold your enquiry.

Privacy concerns and complaints

If you believe the University has handled your personal data improperly, tell us. Raising it with us first is not a precondition to complaining to the regulator, but it is usually faster.

Guidance for departments

Advice before you launch a system, run a survey, engage a supplier, or begin a research project involving personal data. Earlier is cheaper than later.

Third-party and supplier enquiries

Data processing agreements, due diligence questionnaires, and requests for information about how the University handles data on behalf of partners.

What to include when you write

None of this is mandatory, and an incomplete message is far better than no message at all. But the more of it you can give us at the outset, the less likely we are to spend part of a short statutory period asking you for it.

  • Your full name, and any other name the University may hold you under — a maiden name, or the name on your original application.
  • How we should reply — an email address or postal address you can reliably access.
  • Your relationship to the University — applicant, student, former student, member of staff, supplier, research participant, visitor, or member of the public.
  • Your registration or staff number, if you have one. This is the single most useful thing you can give us, because it locates your records immediately.
  • What you are asking for — which right you wish to exercise, or what concern you are raising.
  • Which records, if you can narrow it — a department, a system, a date range, or a particular episode. A narrower request is answered faster and more completely.
  • Any relevant dates — when you noticed the problem, when you last updated your details, when the episode occurred.
  • Proof of identity, when we ask for it — we may need to verify who you are before releasing personal data, so that we do not disclose your information to someone else. We will tell you what is acceptable rather than leaving you to guess.

You are not required to use a University form, and you are not required to give a reason for your request. Forms exist because they prompt for the information above, not because they are a condition of being answered.

How quickly we must respond

These periods are set by law, not by University policy, and they are among the shortest anywhere. The clock starts when any member of University staff receives your request — not when it reaches this office. If we cannot meet a deadline, we will tell you before it passes, and we will tell you why.

Statutory response periods under the Data Protection Act, 2019 and the Data Protection (General) Regulations, 2021.
If you ask us to We must respond within
Give you access to the data we hold about you 7 daysAct s.26(b) · Regs 2021, reg. 9(4)
Correct data that is inaccurate, out of date, incomplete or misleading 14 daysAct s.26(d) · Regs 2021, reg. 10(4)
Delete data you believe we should no longer hold 14 daysAct s.26(e) · Regs 2021, reg. 12(3)
Restrict or object to how we are using your data 14 daysAct s.26(c) · s.34
Transfer data you gave us in a machine-readable format 30 daysAct, 2019 · Regs 2021
Act on a withdrawal of consent On receiptAct, 2019 — s.32

A separate obligation applies to breaches: where a personal data breach is likely to result in a real risk of harm, the University must notify the Data Protection Commissioner within 72 hours of becoming aware of it. That period runs from the moment the University becomes aware, which is why reporting promptly matters more than reporting completely.

If you are not satisfied with our response

You may complain to the Office of the Data Protection Commissioner, the independent regulator established under the Data Protection Act, 2019. You may do so at any time. You are not required to raise the matter with the University first, and you do not need our permission or our involvement to do so. We would ordinarily ask for the chance to put something right, but that is a preference on our part, not a condition on your right.

Head office
Britam Tower, 12th & 13th Floor
Hospital Road, Upper Hill
Nairobi, Kenya
P.O. Box 30920–00100 G.P.O.
Nairobi, Kenya
Email and telephone
info@odpc.go.ke
enquiries@odpc.go.ke
020 780 1800
0796 954 269
0752 896 867
Opening hours
Monday to Friday
8.00 am – 5.00 pm
The ODPC also operates regional offices in Mombasa, Nakuru, Kisumu, Garissa, Eldoret, Nyeri and Machakos.

ODPC contact details verified against odpc.go.ke on 17 August 2026. These are the regulator's own details and may change without notice to the University.

Data Protection Office

The Co-operative University of Kenya is registered with the Office of the Data Protection Commissioner under identification 399-967F-21D9, valid to 22 July 2028.

Return to the Privacy Centre
Address
The Co-operative University of Kenya
Karen, Nairobi
P.O. Box 24814–00502, Nairobi