Data Protection & Privacy Centre › Privacy Notice
The Co-operative University of Kenya
Privacy Notice
How the University collects, uses, shares, stores and protects personal data — and what you can require of us. This is the University's principal privacy document. It applies across our website, our application and student systems, our staff and finance systems, our research, our campus, and the paper forms still used in many of our offices.
Contents — 20 sections
- Introduction
- Who we are
- Who this notice is for
- The information we collect
- Sensitive personal data
- Where we get your information
- Why we process it, and on what basis
- How we use your information
- Who we share information with
- Service providers acting for us
- Transfers outside Kenya
- How long we keep information
- How we protect information
- Your rights
- Children and young people
- Cookies, CCTV, research and marketing
- Automated decision-making
- When something goes wrong
- Concerns, requests and complaints
- Changes to this notice
SECTION 1Introduction
The Co-operative University of Kenya (CUK) holds personal information about a great many people. We hold it because we cannot admit, teach, examine, employ, pay or graduate anyone without it, and because the law requires us to keep records of what we do.
This notice explains, in one place, how the University collects, uses, shares, stores and protects personal data, and what you can require of us.
Privacy is not an administrative formality here. It is part of how the University governs itself and how it accounts for the trust placed in it. The people whose data we hold gave it to us because they had to in order to study, work or do business with us, and that imposes an obligation on us rather than conferring a freedom.
A note on what this notice does not say. We do not claim that the University is fully compliant with the Data Protection Act, 2019. Compliance is a continuing state, assessed against evidence, and it is for the Data Protection Commissioner to determine — not for an institution to declare about itself.
What we say is that we have established a framework, we know where our remaining work lies, and we will answer honestly if you ask.
SECTION 2Who we are
The Co-operative University of Kenya ("CUK", "the University", "we") is the data controller for the personal data described in this notice. That means we decide what personal data is collected and what is done with it, and responsibility for handling it lawfully rests with us.
The Co-operative University of Kenya
Karen, Nairobi, Kenya
P.O. Box 24814–00502, Nairobi, Kenya
cuk.ac.ke
Data Protection Officer
dpo@cuk.ac.ke
+254 724 311 606
The University is registered with the Office of the Data Protection Commissioner. Identification 399-967F-21D9, valid to 22 July 2028.
SECTION 3Who this notice is for
This notice applies to everyone whose personal data the University holds, including prospective students and applicants; students; parents, guardians and sponsors; alumni; staff; job applicants; researchers and research participants; suppliers, contractors and their personnel; visitors to our campus; people who attend our events; people who use our website; and members of the public who contact us.
More detailed notices sit beneath this one
This notice describes the University's overall approach. Because a student's position is not a supplier's position, we publish a separate, fuller notice for each group. If one of the following describes you, read it as well as this notice — it will tell you specifically what we hold about you, on what basis, and for how long.
Prospective Students and Applicants · Students · Staff · Job Applicants · Research Participants · Alumni · Suppliers and Vendors · Contractors · Visitors · Parents and Guardians · Health and Counselling Services · Library Services · Finance and Fees · ICT Services and Systems · Marketing and Communications · Graduation and Ceremonies · Convocation · Biometric Systems · CCTV and Physical Security · Cookies and Website Technologies · Mobile Applications · Wi-Fi and Network Access · Examinations and Academic Records · Website Visitors
All are published at cuk.ac.ke/data-protection-privacy/privacy-notices/
Shorter statements appear where we collect data. Wherever the University collects personal information — on a form, in a portal, at a gate, in a survey — you should find a short statement explaining why we need that particular information. If you are ever asked for personal data without being told why, that is a failure on our part, and we would like to know about it.
SECTION 4The information we collect
We do not collect all of the following from everyone. What we hold about you depends entirely on your relationship with the University.
- Identification. Names and former names; national identification or passport number; date of birth; gender; nationality; photographs; student, staff, supplier and payroll numbers.
- Contact details. Postal and physical addresses; email addresses; telephone numbers; emergency contacts and next of kin.
- Academic information. KCSE results and index numbers; previous qualifications and the institutions that awarded them; application and admission records; programme and registration details; attendance; examination and assessment records; transcripts; graduation and award records.
- Financial information. Fee accounts and payment records; bank details; sponsorship, scholarship and bursary information; payroll, allowances and deductions; supplier payment details.
- Employment information. Applications and references; contracts and terms of service; job title, grade and department; performance and appraisal records; training and development; leave and absence; disciplinary and grievance records.
- Family and next-of-kin information, where there is a specific reason to hold it — emergency contact, dependants, or family circumstances relevant to an application for financial support.
- Sensitive personal data, where there is a specific reason and only with tighter restrictions on access. This includes health information; disability information; biometric information; and information about family circumstances. Section 5 explains how we treat it.
- ICT and digital information. Account and authentication records; system and access logs; IP addresses; device information; Wi-Fi and network session records; records of activity in University systems.
- Physical security information. CCTV footage; visitor records; access-control and door-entry records; vehicle registration numbers recorded at the gate.
- Research information, where you take part in University research — participant records, interview material, survey responses and recordings, as described to you at the time.
SECTION 5Sensitive personal data
Some categories of information carry a higher risk of harm if misused, and the Data Protection Act, 2019 treats them more strictly. They include information revealing health status, race, ethnic or social origin, conscience or belief, genetic and biometric data, property details, marital status, family details, and sex or sexual orientation.
Where the University holds such information, three rules apply without exception.
- We collect it only where there is a specific reason. We do not gather sensitive information because it might one day be useful.
- Access is restricted far more tightly than for ordinary records. Records held by the Health Centre and the counselling service are not part of your general student or staff file and are not visible to academic or administrative staff. Where a disability has been disclosed so that we can make adjustments, the people arranging the adjustment are told what they need to arrange it; they are not told your diagnosis unless you choose to tell them.
- We do not repurpose it. Sensitive information given for one reason is not used for another.
SECTION 6Where we get your information
Most of it comes directly from you — through applications, registration, forms, correspondence, and your use of University systems and premises.
Some is generated by us in the ordinary course of our work: examination results, appraisal records, fee accounts, system logs.
Some comes from other people and organisations. The Data Protection Act, 2019 permits collection other than directly from you in defined circumstances, and where we do so we are required to inform you within fourteen days. This may include examination and qualification bodies verifying results you have declared; schools, colleges and universities you previously attended; referees you have named; the national placement service; student funding bodies; sponsors; statutory bodies administering tax, social security and health insurance; and, occasionally, a person who raises a concern that names you.
SECTION 7Why we process your information, and on what basis
Being informed is not the same as consenting
This distinction matters more than any other in this notice, and it is widely misunderstood.
When we inform you, we are telling you what we are doing and why, because the law requires transparency. When we ask for your consent, we are asking permission, and you are free to say no.
Most of what the University does with personal data does not rest on consent, and it would be misleading to suggest otherwise. You do not consent to being examined, to being paid, to having tax deducted, or to the University reporting student numbers to its regulator. Those things follow from your contract with us, from our function as a public university, and from laws we must obey. If we framed them as consent, we would be implying you could withdraw and have us stop — which we could not do.
So we use consent only where you genuinely have a free choice, and we say plainly which is which.
The lawful bases we rely on
| Basis | What it covers at the University |
|---|---|
| Legal obligation | Tax and statutory deductions; social security and health insurance; identity verification; statutory returns to regulators; records we are required by law to keep |
| Public interest or official authority | Our core functions as a public university — admissions, registration, teaching, examination, awarding qualifications, academic administration, quality assurance |
| Performance of a contract | The contract between you and the University as a student; contracts of employment; supplier and service contracts; steps taken before entering a contract, such as assessing a job application |
| Legitimate interests | Narrow operational needs where you would not be surprised — network and system security, campus safety, responding to your enquiry, alumni relations |
| Vital interests | Medical emergencies, where processing is necessary to protect life |
| Consent | Genuinely optional matters only — see below |
Where we rely on consent
Photography, filming and publicity · marketing emails and newsletters · voluntary participation in research · optional disclosure of a disability so that we can make adjustments · optional dietary and accessibility information at events · optional alumni communications.
For each of these you may decline without any consequence, and you may withdraw at any time — it must be as easy to withdraw as it was to give. Withdrawal stops future processing that relied on your consent. It does not make past processing unlawful, and it does not affect anything resting on a different basis. Withdrawing consent to appear in a photograph does not affect your registration, because your registration never depended on consent.
If you are ever asked to consent to something you do not feel able to refuse, that is a defect in the request. Tell the Data Protection Officer.
Mandatory and optional information
Every University form should tell you which fields are required and what will happen if you do not complete them. Where information is mandatory, it is because we cannot deliver the service, meet a legal duty or administer an entitlement without it — and the consequence of withholding it is stated specifically, not left to inference.
SECTION 8How we use your information
We use personal data to admit and register students; to teach, assess, examine and award qualifications; to maintain academic records and verify qualifications long after graduation; to administer fees, payments, scholarships and financial support; to provide library, ICT, accommodation and student support services; to recruit, employ, pay, manage and develop staff; to conduct and support research; to communicate with applicants, students, staff, alumni and the public; to organise events and ceremonies; to plan, govern and improve the University; to conduct audit and quality assurance; to meet our reporting obligations to regulators; to protect the security of our systems and the safety of our campus; to prevent and investigate fraud and misconduct; and to comply with the law.
We do not use personal data for purposes that would surprise the person who gave it to us. Where we want to use information for a genuinely new purpose, we assess whether that purpose is compatible with the original one, and where it is not, we come back and ask.
SECTION 9Who we share information with
We share personal data only where it is applicable to you, legally permitted or legally required. The University does not sell personal data.
Categories of recipient include: government agencies, regulators and statutory bodies; bodies with statutory oversight of university education; examination, qualification and accreditation bodies; the national placement service; student funding bodies; banks and payment providers; sponsors, where they fund a student and require confirmation of status; ICT, cloud and system service providers acting on our instructions; research partners and collaborators; auditors, internal and external; legal advisers; insurers; and law enforcement, courts and regulators where we are required or permitted by law to disclose.
The notice for your group names the recipients that actually apply to you. The list above is the full range across the University; very little of it applies to any one person.
Inside the University, access is granted on the basis of role and necessity. Being employed by the University does not entitle anyone to look at a record; having a job that requires it does. Access to systems holding personal data is logged, and consulting records without a work reason is a disciplinary matter.
We do not routinely disclose a student's records to a parent, guardian or sponsor. Where a sponsor funds a student we may confirm registration status. Beyond that, an adult student's records are the student's own.
SECTION 10Service providers acting for us
Some University services are delivered with the help of third-party providers. Where a provider handles personal data on our behalf, it acts as a data processor: it may act only on our documented instructions, must keep the information confidential and secure, must not use it for its own purposes, and must return or delete it when the arrangement ends.
Engaging a processor does not transfer our responsibility. If a processor mishandles your data, your rights are exercised against the University, and we will answer for it.
Before a provider is engaged we assess its security and data protection arrangements, and we put a written agreement in place.
SECTION 11Transfers outside Kenya
Some systems and services used by the University may involve personal data being stored or accessed outside Kenya. This is common with cloud services, email, and internationally collaborative research.
Where a transfer occurs, it must satisfy the conditions in the Data Protection Act, 2019 and the Data Protection (General) Regulations, 2021 — appropriate safeguards, an adequacy determination by the Data Commissioner, necessity for a specified purpose, or your consent.
SECTION 12How long we keep information
We keep personal data only for as long as it is necessary for the purpose it was collected for, or for as long as we are required to keep it by law, by our regulators, or for audit, contractual or litigation purposes. When a retention period expires, records are destroyed, erased or anonymised under controlled conditions, and the disposal is recorded.
Retention periods are set in the University's Records Management and Retention Policy rather than left to the judgement of individual offices. If you want to know how long we will hold a particular record about you, ask the Data Protection Officer and we will tell you.
Award records are retained permanently
This is the one exception you should know about in advance. Records of the qualifications the University has conferred are kept indefinitely, because we have a continuing duty to verify degrees — to employers, professional bodies and other institutions, sometimes decades after graduation. If we destroyed these records we could not confirm your own qualification when you needed us to.
The right of erasure does not apply to award records. We state this openly rather than let anyone discover it when a request is refused.
SECTION 13How we protect information
The University applies technical and organisational measures appropriate to the risk, including access controls granted on the principle of least privilege; authentication requirements for University systems; encryption; backup and recovery arrangements; network and endpoint protection; monitoring and logging of access to systems holding personal data; vulnerability management; physical security of premises and paper records; staff training; secure disposal; and a defined process for responding to incidents.
We describe our security at the level of control families and do not publish configuration detail, product names or architecture, because doing so would itself create a risk. This is a deliberate limit on transparency, and it is the only one in this notice.
No system is perfectly secure. Where something goes wrong, section 18 explains what we do.
SECTION 14Your rights
Under the Data Protection Act, 2019 you have enforceable rights over the personal data we hold about you.
| Your right | We must respond within |
|---|---|
| To be informed how your data is used | At collection |
| To access a copy of your data | 7 days |
| To correct data that is inaccurate or misleading | 14 days |
| To have data deleted, in defined circumstances | 14 days |
| To object to processing | 14 days |
| To restrict processing while a matter is resolved | 14 days |
| To stop use of your data for third-party direct marketing | 7 days |
| To receive your data in a portable format | 30 days |
| To withdraw consent, where we relied on it | On receipt |
| To complain to the Office of the Data Protection Commissioner | At any time |
It is free. Making a request costs nothing and so does giving effect to it. Data portability is the only exception, where the law permits a reasonable cost, and we would tell you the amount before proceeding.
You do not need our form, and you do not need to give a reason. A request made to any member of University staff, by any means, is valid — and the period above runs from the moment they receive it, not from when it reaches the Data Protection Officer.
We will confirm your identity before releasing or changing records, because the greatest risk in handling a request is giving your data to somebody else. We ask for no more identification than the sensitivity of the request warrants.
Where rights are limited
Some rights are qualified, and we would rather tell you now than at the point of refusal.
- Award records cannot be deleted, for the reason given in section 12.
- Records we are legally required to keep cannot be deleted while that requirement runs.
- Correction covers factual inaccuracy — a misspelt name, a wrong date. It is not a route to change an examination mark, an appraisal rating or a disciplinary finding; those have their own appeal procedures, and we will point you to the right one.
- Objection to direct marketing is absolute — tell us to stop and we stop. Objection on other grounds is qualified: we must stop unless we can demonstrate compelling legitimate grounds that override your interests, and if we rely on that we explain the reasoning.
- Where records contain another person's data, or a reference given in confidence, we redact rather than refuse the whole request.
Where we cannot do what you have asked, we tell you which exemption applies, what we have done instead, and how to challenge the decision.
SECTION 15Children and young people
Some applicants and students are under 18, and the Data Protection Act, 2019 gives a child's personal data additional protection, requiring that processing be in the best interests of the child.
Where we know a person is under 18: we involve a parent or guardian in matters where consent is the lawful basis; we may discuss an application with a named parent or guardian; we do not direct marketing at children; and we apply particular care to disclosure. Assessment of an application, and the University's core academic functions, rest on our public function rather than on parental consent, as they do for every applicant.
These arrangements end when the person turns 18, from which point they deal with us directly.
SECTION 16Cookies, CCTV, research and marketing
Four areas have their own detailed notices, because each raises questions this document cannot answer properly in a paragraph.
- Cookies and website technologies. Our websites use cookies. Those that are strictly necessary for the site to work are set automatically; all others, including analytics, are set only if you agree, and you can change your choice at any time through the cookie settings link in the footer. Declining does not restrict your access to any part of the site.
- CCTV. The University operates CCTV in defined areas for the safety of people and property. Signage identifies monitored areas. Access to footage is restricted and it is retained for a limited period.
- Research. Personal data collected for research is handled under the University's research ethics and data management arrangements. Participation is voluntary, consent is sought before data is collected, and participants are told before they agree at what point withdrawal ceases to be practicable.
- Direct marketing. We send marketing and promotional communications only to people who have agreed to receive them. Every message carries a means of stopping them. Your right to object to direct marketing is absolute — we do not weigh it against anything, and we do not ask you to justify it.
See the full notice library for each.
SECTION 17Automated decision-making
Decisions that significantly affect you — on admission, assessment, employment, pay or discipline — are taken by a person. Automated systems may calculate, flag or sort, but the decision itself rests with someone who is accountable for it and who can explain it to you.
Where we introduce any processing that would make such a decision automatically, we will assess it before it is used, describe it in this notice, and tell you how to obtain human review. If you believe a decision about you was made automatically, ask us and we will confirm the position.
SECTION 18When something goes wrong
A personal data breach is any security incident that leads to personal data being lost, destroyed, altered, or disclosed to or accessed by someone without authority — whether deliberately or, as is far more common, by mistake.
When the University becomes aware of a breach, we record the time we learned of it, contain the incident, and assess the risk to the people affected. Where the breach is notifiable, we must inform the Data Protection Commissioner within 72 hours of becoming aware, and where a breach is likely to affect you we will tell you in writing. We then fix the cause and, where the cause is systemic, change the process rather than just the instance.
If you think personal information held by the University has been exposed, lost or misused, tell us immediately — at dpo@cuk.ac.ke or through the breach reporting page. Report it even if you are not certain; assessing whether something is a breach is our job, not yours. The 72-hour period starts when we are told, which is why speed matters more than precision.
Anyone may report: students, staff, suppliers, contractors, members of the public. There is no login and no restriction.
SECTION 19Concerns, requests and complaints
Contact the Data Protection Office about anything in this notice — a question, a request to exercise a right, a privacy concern, or a breach report.
Data Protection Officer
The Co-operative University of Kenya
Karen, Nairobi · P.O. Box 24814–00502, Nairobi
dpo@cuk.ac.ke · +254 724 311 606
If you are not satisfied with our response, you may lodge a complaint with the Office of the Data Protection Commissioner, the independent regulator established under the Data Protection Act, 2019. You may do so at any time, and you are not required to raise the matter with us first.
We would welcome the opportunity to put things right directly, because we can usually act faster than a regulatory process can. But the right is yours, and we will neither obstruct nor discourage its use.
SECTION 20Changes to this notice
We review this notice at least once a year, and whenever there is a material change in how the University handles personal data.
Where a change materially affects you, we will bring it to your attention rather than relying on you to notice it. Superseded versions are retained by the Data Protection Officer so that we can show what we told you at the time.
Version 1.0 · Document reference CUK/DPO/PN/00
Effective 1 August 2026 · Last updated 1 August 2026 · Next review 1 August 2027
Contact the Data Protection Office
Questions about this notice, requests to exercise your rights, and reports of a suspected breach all come to this office.
Contact page and enquiry form- dpo@cuk.ac.ke
- Telephone
- +254 724 311 606
- Address
- The Co-operative University of Kenya
Karen, Nairobi
P.O. Box 24814–00502, Nairobi