Our Commitment

Data Protection & Privacy Centre › Our Commitment

Data Protection Act, 2019 — section 25

Our commitment

The University's obligations are not aspirations it has chosen for itself. They are eight principles set out in section 25 of the Data Protection Act, 2019, binding on every data controller and every data processor in Kenya. This page sets out each of them in the words of the statute, what each one requires of a university in particular, and how we hold ourselves to it.

Held in trust, not owned

We treat personal data as something held in trust rather than something owned. That framing is not decoration. It decides the practical questions: whether to add a field to a form, how long to keep a record, whether a supplier may hold it, and what we do on the day something goes wrong.

A university is an unusual custodian. We hold information about people who have not yet joined us and people who left decades ago. We hold examination records that determine livelihoods, health information disclosed in confidence, next-of-kin details given by people who never dealt with us directly, and research data whose subjects trusted an individual researcher rather than an institution. Very little of this was given to us by someone with a real choice about whether to give it. That is precisely why the obligations are statutory rather than voluntary.

Our duties arise under Article 31 of the Constitution of Kenya, 2010, which guarantees privacy as a fundamental right; the Data Protection Act, 2019, enacted to give effect to Article 31(c) and (d); and the Data Protection (General) Regulations, 2021. Where an international standard of practice sits above those requirements and serves our community better, we adopt it and say so.

We do not claim to be perfect. We claim to be accountable, and we publish the means by which you can hold us to it.

The eight principles

Section 25 of the Act requires that every data controller and data processor ensure personal data is handled in accordance with each of the following. The quoted text is the statute. The paragraph beneath each is what it means when the controller is a university.

Processed in accordance with the right to privacy

Processed in accordance with the right to privacy of the data subject. Data Protection Act, 2019 — s.25(a)

In practice: privacy is the starting point, not a constraint applied afterwards. Where a University process could be designed two ways and one intrudes less, the burden is on the department to justify the more intrusive one — not on you to object to it.

Lawful, fair and transparent

Processed lawfully, fairly and in a transparent manner in relation to any data subject. Data Protection Act, 2019 — s.25(b)

In practice: every processing activity must rest on one of the lawful bases in section 30 — and for most of what we do that basis is not consent. Transparency is why every form carries a privacy statement and why this Centre exists. Fairness means we do not use information in ways you would find surprising given the reason you gave it to us.

Purpose limitation

Collected for explicit, specified and legitimate purposes and not further processed in a manner incompatible with those purposes. Data Protection Act, 2019 — s.25(c)

In practice: data collected for one purpose does not become a general University resource. Contact details given for examination results are not a marketing list. Health information given to a clinician does not travel to an academic department. Where a new use is genuinely compatible with the original, we can proceed; where it is not, we go back and ask.

Data minimisation

Adequate, relevant, limited to what is necessary in relation to the purposes for which it is processed. Data Protection Act, 2019 — s.25(d)

In practice: the hardest principle to keep, because forms accumulate fields and nobody is ever blamed for collecting too much. The test is not whether a field might one day be useful. It is whether the process fails without it. Fields that fail that test come off the form.

Explanation for family and private affairs

Collected only where a valid explanation is provided whenever information relating to family or private affairs is required. Data Protection Act, 2019 — s.25(e)

In practice: this principle has no direct equivalent in European law and is easily overlooked by institutions working from imported templates. It bites directly on universities. Next-of-kin details, guardian information, marital status, dependants, household circumstances for a bursary assessment — each requires a stated reason at the point we ask, not a justification produced later if challenged.

Accuracy

Accurate and, where necessary, kept up to date, with every reasonable step being taken to ensure that any inaccurate personal data is erased or rectified without delay. Data Protection Act, 2019 — s.25(f)

In practice: inaccuracy in a university record is rarely trivial. A misspelt name on an award certificate follows a graduate through every verification for the rest of their working life. Correction is a right you can exercise, but the obligation to act without delay is ours whether or not you ask.

Storage limitation

Kept in a form which identifies the data subjects for no longer than is necessary for the purposes which it was collected. Data Protection Act, 2019 — s.25(g)

In practice: note the precise wording — the limit is on holding data in a form which identifies you, not on holding it at all. Anonymised and aggregated records may be kept for planning and research. Award records are retained permanently because the University's duty to verify the qualifications it confers does not expire; that is a purpose that continues, not an exception to the principle.

Restriction on transfer outside Kenya

Not transferred outside Kenya, unless there is proof of adequate data protection safeguards or consent from the data subject. Data Protection Act, 2019 — s.25(h)

In practice: Kenya places this among the principles themselves rather than treating it as a separate compliance topic, which sets a higher bar than many institutions assume. It applies to every cloud service, learning platform, email system and international research collaboration. Sections 48 and 49 set the conditions, and section 49 requires consent as well as confirmation of safeguards before sensitive personal data is processed outside Kenya.

Two principles that are distinctly Kenyan

Kenya's data protection framework is frequently described as modelled on the European General Data Protection Regulation, and in structure it largely is. But two of the eight principles above have no direct counterpart in Article 5 of the GDPR, and both matter acutely to a university.

Section 25(e) requires a valid explanation whenever information about family or private affairs is sought. A European template will not prompt for it, because European law does not require it. Universities ask for guardian details, next-of-kin contacts and household circumstances constantly.

Section 25(h) places the restriction on transfers outside Kenya among the principles themselves. In the GDPR, international transfer is handled in a separate chapter. The Kenyan placement means a transfer without adequate safeguards is not merely a transfer failure — it is a breach of a founding principle of lawful processing.

We mention this because an institution that adopts an imported privacy framework without adjustment will comply with most of Kenyan law and miss precisely these two points. Our documents are drafted against the Kenyan text.

Privacy by design and by default

Section 41 of the Act requires more than good intentions. It requires appropriate technical and organisational measures designed to implement the principles effectively — and it applies both when the means of processing are decided and while processing is under way. The default position must be that only the personal data necessary for each specific purpose is processed at all.

Assessed before it is built, not after

Where a processing operation is likely to result in high risk to the rights and freedoms of a data subject, a data protection impact assessment is carried out before processing begins. Where the assessment shows the risk remains high, the Act requires consultation with the Data Commissioner, and the assessment must be submitted sixty days ahead of processing.

Act, 2019 — s.31(1), s.31(3), s.31(5)

The minimum by default

Systems are configured so that the least data consistent with the purpose is collected, the narrowest processing is applied, the shortest retention is set and the fewest people have access — without anyone having to choose those settings. The Act directs that the amount collected, the extent of processing, the storage period and accessibility are all weighed.

Act, 2019 — s.41(3)

Safeguards identified, applied and re-tested

The Act names the measures to be considered: identifying foreseeable internal and external risks, establishing safeguards against them, pseudonymisation and encryption, the ability to restore access after a physical or technical incident, verification that safeguards are effectively implemented, and continual updating in response to new risks. We do not publish our specific security configurations, for the obvious reason.

Act, 2019 — s.41(4)

Suppliers bound in writing

Where the University uses a processor, the Act requires that we choose one offering sufficient guarantees and that a written contract binds them to act only on our instructions. A processor who goes beyond those instructions becomes a controller in its own right, and answers for that processing itself.

Act, 2019 — s.42(2), s.42(3)

Breaches reported against a fixed clock

Where personal data has been accessed or acquired without authorisation and there is a real risk of harm, the University must notify the Data Commissioner within seventy-two hours of becoming aware, and must communicate with affected individuals in writing. Where we notify late, the Act requires us to give reasons for the delay.

Act, 2019 — s.43(1), s.43(2)

A named officer, published

The Act requires a data controller or processor to publish the contact details of its data protection officer on its website and to communicate them to the Data Commissioner. The officer advises the University and its employees, works to ensure the Act is complied with, builds staff capacity, advises on impact assessments and co-operates with the Commissioner. Those duties are owed regardless of who holds the post.

Act, 2019 — s.24(6), s.24(7)

What we do not claim

We do not claim to be compliant with the Data Protection Act. Compliance is a continuing state assessed against evidence, and it is for the Data Protection Commissioner to determine — not for an institution to assert on its own website. The Commissioner has statutory powers to audit systems and processes, to inspect, and to investigate on the Commissioner's own initiative. An organisation that declares itself compliant is describing an opinion it is not entitled to hold.

What we say instead is this. We have established the framework. We maintain a record of the matters still outstanding, each with a named owner and a date. We will tell you honestly where we stand if you ask. And where we get something wrong, we would rather hear it from you than from the regulator.

Contact the Data Protection Office

The Co-operative University of Kenya is registered with the Office of the Data Protection Commissioner under identification 399-967F-21D9, valid to 22 July 2028.

Contact the Data Protection Office
Address
The Co-operative University of Kenya
Karen, Nairobi
P.O. Box 24814–00502, Nairobi