Data Protection & Privacy Centre › Report a Data Breach
Urgent — act now
Report a data breach
If you think personal information held by the University has been lost, stolen, exposed, altered or seen by someone who should not have seen it, tell us straight away.
Do not wait until you are certain. Do not investigate it yourself. Deciding whether something is a breach is our job, not yours — we would far rather assess fifty reports that turn out to be nothing than miss the one that was not.
Why telling us quickly matters more than telling us precisely
When the University becomes aware of a personal data breach, the Data Protection Act, 2019 requires us to notify the Data Protection Commissioner without delay and within 72 hours. If we notify later than that, we must explain to the Commissioner why we were late.
That clock starts when the University becomes aware — which in practice means the moment somebody tells us. A breach discovered on Friday afternoon and reported on Monday morning has consumed most of the statutory window before we have done anything at all.
Where a breach is likely to affect you, we are also required to tell you about it in writing.
Data Protection Act, 2019 — s.43(1)(a), s.43(2)
What counts as a data breach
A breach is any security incident that leads to personal data being lost, destroyed, altered, or disclosed to or accessed by someone without authority — whether accidentally or deliberately.
It does not require an attacker. Most breaches are ordinary mistakes made by people doing their jobs properly in every other respect.
- An email containing student records sent to the wrong recipient
- A spreadsheet of names and results attached to a message by mistake
- A group email where addresses are visible in To or Cc instead of Bcc
- A lost or stolen laptop, phone or USB drive holding University data
- Paper records left in a public area or put in general waste instead of confidential disposal
- A shared password, or a colleague's account used by someone else
- A member of staff opening records they have no work reason to see
- An office or filing cabinet left unlocked overnight
- A system misconfiguration exposing records to people who should not see them
- A phishing email that somebody replied to with their credentials
- A supplier or contractor telling us about an incident affecting our data
- Personal data published on a website, portal or noticeboard without a basis for doing so
Who should report
Anyone. There is no restriction, no login, and no requirement to have any connection with the University.
Staff
Immediately, and before attempting any fix that might destroy evidence. This includes an incident you caused yourself — see below.
Students
Including if you have received information that was not meant for you, or noticed data visible that should not be.
Suppliers, contractors and processors
If you process personal data for the University and become aware of an incident, tell us without delay. Where reasonably practicable this should be within 48 hours, and your agreement with us requires it.
Members of the public
If you have come across University information that appears to be exposed, please tell us. You need no connection to the University.
Security researchers
Reports of a vulnerability affecting personal data are welcome through this route. Please give us reasonable time to fix it before disclosing publicly.
Anonymously
You may report without giving your name. We can act on an anonymous report, though we will not be able to come back to you for detail or tell you the outcome.
Before you report
A few things help us considerably, and a few make the situation worse. This takes thirty seconds to read.
✓ Please do
- Report immediately, even with incomplete information
- Note the time you became aware of it
- Keep any evidence — emails, screenshots, logs — exactly as they are
- Tell us if you have already told anyone else
- Say if information reached someone outside the University
✕ Please do not
- Wait until you are certain it is a breach
- Investigate it yourself or try to identify who was responsible
- Delete emails, files or logs — that destroys the evidence we need
- Forward the exposed information any further, including to us
- Tell people outside the University while we are assessing it
If you have received information that was not meant for you
Please do not read further than necessary to identify what it is, do not forward it or save a copy, and delete it once we confirm we have what we need. Tell us how you came to receive it — that detail is often what tells us how the breach happened.
How to report
Email or telephone the Data Protection Officer. There is no form to complete and no login. An incomplete report sent now is far more useful than a complete one sent tomorrow — send what you know.
The email button opens a message already addressed to dpo@cuk.ac.ke with the questions below set out for you. You do not have to answer all of them. If your device has no email application, write to dpo@cuk.ac.ke yourself, or telephone us.
What to tell us
As much as you know, in your own words. There is no need to use technical language or to work out whether it meets any definition.
- What happened? A sentence or two is enough to start with.
- When did it happen? An approximate date and time is fine.
- When did you find out? This one matters most — it is what sets the University's 72-hour clock.
- What information was involved? For example names and examination results, or bank details.
- Roughly how many people may be affected? An estimate is fine, or say you do not know.
- Which system, department or document? For example the student portal, or a printed class list.
- Has anything been done already? For example an email recalled, or an office locked.
- How can we reach you? Optional — see below.
Reporting anonymously
You do not have to give your name. We will act on an anonymous report, though we will not be able to acknowledge it, come back to you for detail, or tell you the outcome. If you can give us a way to reach you, it often lets us resolve an incident far more quickly.
What happens after you report
So that you know what you have set in motion.
We acknowledge your report
Normally within one working day, if you have given us a way to reach you.
We record the time we became aware
Logged to the hour in the University's breach register. The statutory clock is dated from this point, which is why the time you tell us matters.
We contain it
Working with ICT Security and whoever owns the system or record, preserving evidence before making changes.
We assess the risk
What data, how much, how sensitive, and what harm could follow for the people affected.
We notify the Data Protection Commissioner
Within 72 hours where the breach is notifiable, with reasons for any delay.
We tell the people affected
In writing, where the breach is likely to affect them, together with what they should do.
We fix the cause
Root cause, corrective actions, named owners and due dates — recorded, not just discussed.
We learn from it
Reviewed at the Data Protection Committee. Where the cause is systemic we change the process, not just the instance.
Reporting in good faith
Most breaches are caused by ordinary human error, by people who are otherwise doing their jobs carefully. The University's interest is in learning about incidents quickly, and a culture in which people conceal mistakes does far more damage than the mistakes themselves.
Reporting an incident you caused, promptly and honestly, is the right thing to do and is treated as such.
[The interaction between good-faith reporting and the staff disciplinary procedure is to be confirmed and stated here.]
Outside office hours
Breaches do not keep office hours, and neither does the 72-hour clock. Until a dedicated out-of-hours route is confirmed, email dpo@cuk.ac.ke with URGENT — DATA BREACH in the subject line, at any hour. Do not wait for the next working day.
If the incident involves an active attack on University systems, contact ICT Security as well as the DPO.
[Out-of-hours escalation telephone number and roster to be confirmed.]
Data Protection Office
Breach reports, questions about a privacy notice, and requests to exercise your rights all come to this office.
Contact page and enquiry form- dpo@cuk.ac.ke
- Telephone
- +254 724 311 606
- Address
- The Co-operative University of Kenya
Karen, Nairobi
P.O. Box 24814–00502, Nairobi