Taita Taveta University Logo

Taita Taveta University

Home of Ideas

Staff Privacy Statement


1. Introduction

Taita Taveta University recognises its obligations under the Constitution of Kenya, the Data Protection Act, 2019, and other applicable laws and regulations. The University is committed to processing the personal data of its staff securely, lawfully, fairly, and transparently.

This Staff Privacy Statement explains:

  • The categories of personal data the University collects and processes;
  • How and why the University processes personal data;
  • The lawful grounds relied upon when processing personal data;
  • The circumstances under which personal data may be disclosed;
  • How long personal data may be retained;
  • The measures used to protect personal data; and
  • The rights available to staff members in relation to their personal data.

This Privacy Statement applies to:

  • Current employees;
  • Former employees;
  • Prospective employees and job applicants;
  • Interns and trainees;
  • Temporary and casual workers;
  • Consultants;
  • Contractors;
  • Visiting lecturers and researchers;
  • Volunteers; and
  • Any other person engaged to provide services to or on behalf of the University.

For purposes of this statement, these individuals are collectively referred to as "staff members."

2. Data Controller Details

Taita Taveta University is the data controller responsible for determining how and why staff personal data is processed.

Taita Taveta University
P.O. Box 635–80300
Voi, Kenya

Telephone: +254 721 113 302 / +254 774 222 064
General email: info@ttu.ac.ke
Data Protection Officer: dpo@ttu.ac.ke
Website: www.ttu.ac.ke

Questions or requests concerning the processing of staff personal data should be directed to the Data Protection Officer.

3. Data-Protection Principles

When processing staff personal data, Taita Taveta University will endeavour to ensure that the information is:

3.1 Processed lawfully, fairly, and transparently

Personal data will be processed in accordance with applicable laws and in a manner that is fair and clear to the staff member concerned.

3.2 Collected for specified purposes

The University will collect personal data for specific, explicit, and legitimate academic, employment, administrative, operational, contractual, regulatory, or legal purposes.

3.3 Adequate, relevant, and limited

The University will collect only the personal data that is reasonably necessary for the purpose for which it is required.

3.4 Accurate and up to date

Reasonable measures will be taken to ensure that personal data is accurate, complete, and updated where necessary.

Staff members are responsible for notifying the University when their personal information changes.

3.5 Retained only as long as necessary

Personal data will not be retained for longer than is reasonably required for the purpose for which it was collected, subject to applicable legal and records-management requirements.

3.6 Processed securely

Appropriate administrative, organisational, physical, and technical measures will be implemented to protect personal data against unauthorised access, accidental loss, unlawful disclosure, alteration, destruction, or misuse.

3.7 Processed in accordance with staff rights

The University will respect and facilitate the exercise of applicable data-subject rights, subject to lawful limitations.

4. Categories of Personal Data Processed

Depending on the nature of the staff member's relationship with the University, Taita Taveta University may process the following categories of personal data.

4.1 Personal identification information

  • Full name;
  • National identification number;
  • Passport number;
  • Alien identification number, where applicable;
  • Date of birth;
  • Place of birth;
  • Nationality or citizenship;
  • Gender;
  • Marital status;
  • Staff or payroll number;
  • Signature;
  • Passport-size photographs and other personal images; and
  • Copies of identification documents.

4.2 Contact information

  • Residential address;
  • Postal address;
  • Personal and official email addresses;
  • Telephone and mobile numbers; and
  • Emergency-contact information.

4.3 Family and dependant information

  • Spouse details;
  • Children's details;
  • Parents' details;
  • Dependants;
  • Beneficiaries;
  • Next-of-kin details; and
  • Emergency contacts and their telephone numbers.

4.4 Recruitment and professional information

  • Curriculum vitae;
  • Application forms;
  • Cover letters;
  • Academic certificates and transcripts;
  • Professional qualifications;
  • Membership in professional bodies;
  • Employment history;
  • References and referee reports;
  • Interview notes and assessment results;
  • Background-screening information;
  • Work permits and evidence of the right to work in Kenya;
  • Professional licences;
  • Research publications;
  • Professional achievements; and
  • Information concerning suitability for appointment.

4.5 Employment information

  • Current and previous job titles;
  • Job descriptions;
  • Departments and workstations;
  • Employment category;
  • Employment contract;
  • Appointment and confirmation records;
  • Terms and conditions of employment;
  • Pay grade;
  • Salary;
  • Allowances;
  • Benefits;
  • Pension entitlement;
  • Working hours;
  • Reporting arrangements;
  • Transfers;
  • Promotions;
  • Acting appointments;
  • Secondments;
  • Contract renewals;
  • Retirement information; and
  • Separation or termination records.

4.6 Financial and statutory information

  • Bank account details;
  • Payroll information;
  • Kenya Revenue Authority Personal Identification Number;
  • National Social Security Fund details;
  • Social Health Authority and Social Health Insurance Fund details;
  • Pension or retirement-benefit information;
  • Insurance information;
  • Higher Education Loans Board obligations, where applicable;
  • Loan and salary-deduction information;
  • Tax information;
  • Statutory deductions;
  • Reimbursements;
  • Claims; and
  • Other authorised financial deductions or benefits.

4.7 Attendance and leave information

  • Attendance records;
  • Time and access records;
  • Annual leave;
  • Sick leave;
  • Maternity leave;
  • Paternity leave;
  • Adoption leave;
  • Compassionate leave;
  • Study leave;
  • Sabbatical leave;
  • Leave of absence;
  • Official travel;
  • Duty assignments; and
  • Other approved or unauthorised absences.

4.8 Performance and conduct information

  • Performance targets;
  • Performance appraisal records;
  • Work plans;
  • Supervisor assessments;
  • Recognition and award records;
  • Complaints;
  • Grievances;
  • Disciplinary investigations;
  • Formal warnings;
  • Suspension records;
  • Appeals;
  • Misconduct proceedings; and
  • Related correspondence and documentation.

4.9 Training and development information

  • Training records;
  • Professional-development activities;
  • Conference attendance;
  • Study and scholarship records;
  • Skills assessments;
  • Training needs;
  • Certifications;
  • Mentorship records; and
  • Career-development information.

4.10 Health and welfare information

Where necessary and lawful, the University may process:

  • Medical or health information;
  • Disability information;
  • Occupational-health records;
  • Medical examination reports;
  • Workplace injury records;
  • Sickness and absence information;
  • Medical insurance information;
  • Fitness-to-work assessments;
  • Reasonable accommodation requirements; and
  • Information required for emergency response or staff welfare.

4.11 Biometric and security information

Where applicable, the University may process:

  • Fingerprints;
  • Facial images;
  • Biometric attendance information;
  • Access-control records;
  • Staff identification-card records;
  • Closed-circuit television footage;
  • Security incident reports;
  • Visitor and vehicle records; and
  • Building, office, laboratory, library, or system access logs.

Biometric information will only be collected and processed where there is an appropriate lawful basis and suitable safeguards have been implemented.

4.12 Information and communication technology data

The University may process information generated through the use of its ICT resources, including:

  • University email records;
  • Login details;
  • Internet Protocol addresses;
  • Device information;
  • Browser information;
  • Network-usage records;
  • System-access logs;
  • Security and audit logs;
  • University telephone records;
  • Internet-usage information;
  • Files stored on University systems;
  • Cybersecurity incident information; and
  • Records generated through University applications, platforms, or information systems.

Any monitoring of University systems will be conducted for legitimate operational, security, legal, or administrative purposes and in accordance with applicable policies and laws.

5. How Personal Data Is Collected

Taita Taveta University may collect staff personal data through several channels.

5.1 Directly from the staff member

Personal data may be collected when a staff member:

  • Applies for employment;
  • Submits a curriculum vitae or cover letter;
  • Participates in an interview;
  • Completes employment, payroll, pension, insurance, or statutory forms;
  • Provides identity or qualification documents;
  • Requests leave, training, promotion, transfer, or other employment services;
  • Participates in performance appraisal;
  • Reports an incident, complaint, grievance, or workplace injury;
  • Accesses University systems or facilities; or
  • Communicates with the University.

5.2 From third parties

The University may obtain personal data from:

  • Referees;
  • Former employers;
  • Educational institutions;
  • Professional bodies;
  • Recruitment agencies;
  • Government departments and agencies;
  • Regulatory authorities;
  • Financial institutions;
  • Medical or occupational-health professionals;
  • Insurance providers;
  • Background-screening service providers; and
  • Publicly accessible professional sources.

Where information is obtained from third parties, the University will process it only where there is a lawful and legitimate basis.

5.3 Automatically through University systems

Information may also be collected automatically when staff members use:

  • University websites;
  • Staff portals;
  • Human-resource information systems;
  • Enterprise-resource-planning systems;
  • Email platforms;
  • Learning-management systems;
  • Internet and Wi-Fi networks;
  • Biometric attendance systems;
  • Access-control systems;
  • Security systems; or
  • Other University-owned or authorised digital platforms.

6. Storage of Personal Data

Staff personal data may be stored:

  • In physical personnel files;
  • In recruitment records;
  • In departmental records;
  • In payroll and finance systems;
  • In the University's human-resource information system;
  • In enterprise-resource-planning systems;
  • In official email and document-management systems;
  • In authorised cloud or hosting environments;
  • In backup and disaster-recovery systems; and
  • In other approved University databases and information systems.

Access to staff records will be limited to authorised persons who require the information to perform their official duties.

7. Cookies and Similar Technologies

Cookies are small files stored on a user's device when accessing a website or online service.

Taita Taveta University may use cookies and similar technologies to collect information such as:

  • Browser type;
  • Device type;
  • Internet Protocol address;
  • Language preference;
  • Time spent on University services;
  • Pages visited;
  • Login sessions;
  • System preferences;
  • Referring websites; and
  • Other technical or usage information.

The University may use this information to:

  • Maintain system security;
  • Facilitate navigation;
  • Authenticate users;
  • Improve website and system performance;
  • Remember user preferences;
  • Analyse service usage; and
  • Present information more effectively.

Staff members may manage cookies through their browser settings. Disabling certain cookies may affect the functionality of University systems or websites.

8. Purposes and Lawful Grounds for Processing

The University will process staff personal data only where there is an appropriate lawful basis.

The lawful grounds may include:

  • Performance of an employment or service contract;
  • Compliance with a legal obligation;
  • Performance of a task carried out in the public interest;
  • Protection of the vital interests of the staff member or another person;
  • Pursuit of the legitimate interests of the University or another party, provided that these interests do not improperly override the staff member's rights;
  • Establishment, exercise, or defence of a legal claim; and
  • Consent, where consent is the appropriate lawful basis.

9. Why the University Processes Staff Personal Data

Taita Taveta University may process staff personal data for the following purposes.

9.1 Recruitment and appointment

  • Advertising employment opportunities;
  • Receiving and evaluating applications;
  • Shortlisting candidates;
  • Conducting interviews and assessments;
  • Verifying qualifications and references;
  • Conducting lawful background checks;
  • Determining suitability for employment;
  • Preparing appointment documents; and
  • Communicating recruitment decisions.

9.2 Managing the employment relationship

  • Administering employment contracts;
  • Maintaining personnel records;
  • Allocating duties and responsibilities;
  • Managing departments and reporting arrangements;
  • Confirming appointments;
  • Processing transfers, promotions, secondments, and acting appointments;
  • Managing contract renewals;
  • Administering staff benefits;
  • Managing staff exits, retirement, or termination; and
  • Communicating employment-related information.

9.3 Payroll and financial administration

  • Calculating and paying salaries;
  • Processing allowances, reimbursements, and benefits;
  • Making statutory deductions;
  • Administering pension contributions;
  • Processing Social Health Insurance Fund contributions;
  • Processing National Social Security Fund contributions;
  • Remitting taxes to the Kenya Revenue Authority;
  • Processing Higher Education Loans Board deductions, where applicable;
  • Administering insurance;
  • Conducting financial audits; and
  • Preventing and detecting payroll fraud.

9.4 Performance and development

  • Establishing performance targets;
  • Conducting staff appraisals;
  • Monitoring performance;
  • Identifying training needs;
  • Administering training and professional development;
  • Supporting career progression;
  • Managing promotions;
  • Recognising staff achievements; and
  • Addressing performance concerns.

9.5 Attendance and leave management

  • Recording attendance;
  • Managing working hours;
  • Administering annual and statutory leave;
  • Monitoring absence;
  • Managing sickness absence;
  • Processing study leave, sabbatical leave, and leave of absence;
  • Making reasonable workplace adjustments; and
  • Supporting workforce planning.

9.6 Health, safety, and welfare

  • Protecting staff health and safety;
  • Responding to workplace injuries or emergencies;
  • Assessing fitness for work;
  • Providing reasonable accommodation;
  • Managing medical or occupational-health referrals;
  • Administering insurance and staff-welfare programmes;
  • Supporting persons with disabilities; and
  • Complying with occupational-health and safety requirements.

9.7 Discipline and grievance management

  • Investigating complaints and misconduct;
  • Managing disciplinary proceedings;
  • Addressing staff grievances;
  • Maintaining formal warnings and related records;
  • Supporting internal appeals;
  • Protecting the rights of all parties involved; and
  • Establishing, exercising, or defending legal claims.

9.8 Security and system administration

  • Managing access to University premises and systems;
  • Issuing staff identification cards;
  • Protecting University property and information;
  • Preventing unauthorised access;
  • Investigating security incidents;
  • Monitoring and responding to cybersecurity threats;
  • Maintaining audit trails;
  • Preventing fraud;
  • Supporting business continuity;
  • Managing backups; and
  • Ensuring that University ICT systems remain secure and reliable.

9.9 Legal, regulatory, and institutional compliance

  • Meeting statutory reporting obligations;
  • Responding to lawful requests from regulators and public authorities;
  • Supporting internal and external audits;
  • Meeting accreditation and quality-assurance requirements;
  • Complying with employment and labour laws;
  • Maintaining official University records;
  • Responding to litigation or legal claims; and
  • Performing the University's public mandate.

10. Special Categories of Personal Data

Certain categories of personal data require enhanced protection because of their sensitive nature.

Depending on applicable law and the employment context, such information may include data relating to:

  • Health;
  • Disability;
  • Race;
  • Ethnic or social origin;
  • Religion, conscience, or belief;
  • Biometric information;
  • Genetic information;
  • Property details;
  • Marital status;
  • Family details;
  • Sex;
  • Sexual orientation; and
  • Other categories of sensitive personal data recognised under applicable law.

The University will process sensitive personal data only where legally permitted and where appropriate safeguards have been implemented.

Such processing may take place where:

  • The staff member has provided explicit consent;
  • Processing is necessary for the University to carry out its obligations or exercise rights under employment law;
  • Processing is required for reasons of substantial public interest;
  • Processing is necessary to protect the vital interests of a person;
  • Processing is necessary for medical, occupational-health, or workplace-safety purposes;
  • Processing is necessary for the establishment, exercise, or defence of legal claims;
  • The staff member has manifestly made the information public; or
  • Another lawful ground recognised by applicable legislation applies.

11. Use of Sensitive Personal Data

The University may process sensitive personal data for purposes such as:

  • Providing reasonable accommodation to staff members with disabilities;
  • Managing sickness absence;
  • Assessing fitness for work;
  • Obtaining occupational or expert medical advice;
  • Administering statutory or contractual benefits;
  • Protecting health and safety;
  • Supporting emergency response;
  • Meeting equality and inclusion obligations;
  • Investigating serious workplace incidents;
  • Administering insurance or medical benefits; and
  • Establishing, exercising, or defending legal claims.

Where consent is relied upon, the staff member will be informed of the purpose of the processing and will be able to withdraw consent.

Withdrawal of consent will not affect the lawfulness of processing carried out before the consent was withdrawn. It may also not prevent continued processing where another lawful basis applies.

12. Consequences of Failing to Provide Personal Data

Some personal data is necessary for the University to:

  • Enter into or administer an employment contract;
  • Verify identity and qualifications;
  • Confirm a person's legal right to work in Kenya;
  • Process salary and benefits;
  • Make statutory deductions and remittances;
  • Provide insurance, pension, or health benefits;
  • Maintain legally required records;
  • Protect workplace health and safety; and
  • Meet regulatory obligations.

Where a staff member fails to provide required personal data, the University may be unable to:

  • Complete the recruitment process;
  • Confirm or continue employment;
  • Pay the staff member correctly;
  • Provide contractual or statutory benefits;
  • Process reimbursements;
  • Make required statutory remittances;
  • Provide reasonable accommodation; or
  • Meet its legal and contractual obligations.

The University will explain the relevant consequences where the provision of particular information is mandatory.

13. Sharing Staff Personal Data Within the University

Staff personal data may be shared internally where necessary for authorised employees to perform their duties.

This may include sharing information with:

  • The Office of the Vice-Chancellor;
  • The Human Resource Department;
  • The Finance Department;
  • Payroll officers;
  • Immediate supervisors;
  • Heads of departments;
  • Deans and directors;
  • The Legal Office;
  • The Internal Audit Department;
  • The ICT Department;
  • Security personnel;
  • Occupational-health or staff-welfare personnel;
  • Disciplinary, appointment, promotion, or grievance committees; and
  • Other authorised University officers.

Only information reasonably necessary for the relevant purpose should be disclosed.

14. Sharing Staff Personal Data with Third Parties

The University may share staff personal data with authorised third parties where it is necessary and lawful.

Such parties may include:

  • Kenya Revenue Authority;
  • Social Health Authority;
  • Social Health Insurance Fund;
  • National Social Security Fund;
  • Higher Education Loans Board;
  • Pension administrators;
  • Insurance companies;
  • Financial institutions;
  • Government ministries, departments, and agencies;
  • Courts and tribunals;
  • Law-enforcement agencies;
  • Regulatory and accreditation bodies;
  • Professional organisations;
  • Auditors;
  • Legal advisers;
  • Medical and occupational-health professionals;
  • Training institutions;
  • Research partners;
  • Recruitment and background-screening providers;
  • Information technology and cloud-service providers;
  • Payroll and human-resource-system providers; and
  • Other service providers acting on behalf of the University.

Third parties processing personal data on behalf of the University will be expected to:

  • Process the information only for authorised purposes;
  • Maintain confidentiality;
  • Implement appropriate security measures;
  • Comply with applicable data-protection laws; and
  • Return, delete, or securely dispose of the information when required.

The University does not sell staff personal data.

15. Cross-Border Transfer of Personal Data

The University may occasionally need to transfer personal data outside Kenya, including when:

  • Using an authorised international cloud or technology service;
  • Working with foreign universities or research partners;
  • Administering international training, scholarships, conferences, or exchanges;
  • Processing travel or insurance arrangements; or
  • Complying with a lawful international obligation.

Before transferring personal data outside Kenya, the University will apply the safeguards required by applicable law.

These safeguards may include:

  • Confirming that the receiving country provides an adequate level of protection;
  • Entering into appropriate data-protection agreements;
  • Obtaining valid consent where appropriate;
  • Ensuring that the transfer is necessary for a contract or legal obligation; or
  • Applying another lawful transfer mechanism.

Staff members may contact the Data Protection Officer for information concerning safeguards applicable to a particular transfer.

16. Protecting Staff Personal Data

Taita Taveta University implements reasonable organisational and technical safeguards designed to protect personal data.

These measures may include:

  • Role-based access controls;
  • Password and authentication requirements;
  • Multi-factor authentication;
  • Encryption;
  • Secure networks;
  • Firewalls and security-monitoring systems;
  • Data backups;
  • Physical access controls;
  • Secure filing and storage;
  • Confidentiality obligations;
  • Staff training and awareness;
  • System logging and audit trails;
  • Vulnerability management;
  • Incident-response procedures;
  • Business-continuity measures; and
  • Secure disposal of records and storage devices.

Although the University takes reasonable precautions, no information system or electronic transmission method can be guaranteed to be completely secure.

Staff members must comply with University security policies and protect their passwords, devices, identification cards, and system credentials.

17. Personal-Data Breaches

A personal-data breach may involve the accidental or unlawful:

  • Loss;
  • Destruction;
  • Alteration;
  • Unauthorised disclosure of; or
  • Access to personal data.

Staff members who become aware of an actual or suspected personal-data breach must report it immediately through the University's approved reporting channels, including the Data Protection Officer or the ICT security team.

The University will investigate reported incidents and, where required, notify the Office of the Data Protection Commissioner and affected individuals within the legally prescribed period.

18. Retention of Staff Personal Data

The University will retain staff personal data only for as long as reasonably necessary to:

  • Manage the employment relationship;
  • Fulfil the purpose for which the information was collected;
  • Maintain official employment and institutional records;
  • Comply with legal, contractual, audit, pension, tax, or regulatory obligations;
  • Resolve disputes;
  • Respond to complaints;
  • Establish, exercise, or defend legal claims; and
  • Support legitimate historical, statistical, or archival requirements.

Retention periods will be guided by:

  • Applicable laws;
  • The University's Records Management Policy;
  • Approved retention schedules;
  • Employment and pension requirements;
  • Audit and financial requirements; and
  • Limitation periods for legal claims.

At the end of the applicable retention period, personal data may be:

  • Securely deleted;
  • Physically destroyed;
  • Anonymised;
  • Permanently archived where lawful; or
  • Otherwise disposed of using an approved secure method.

19. Automated Decision-Making and Profiling

The University will not ordinarily make a decision that has a legal or similarly significant effect on a staff member solely through automated processing without appropriate safeguards.

Where automated decision-making or profiling is used, the University will, where required:

  • Inform the affected staff member;
  • Explain the nature and purpose of the processing;
  • Provide meaningful information about the logic involved;
  • Explain the likely consequences;
  • Implement measures to prevent errors, discrimination, and bias;
  • Allow the staff member to express their views;
  • Provide access to human intervention; and
  • Allow the decision to be challenged where applicable.

20. Staff Data-Protection Rights

Subject to applicable laws and lawful exemptions, staff members may exercise the following rights.

20.1 Right to be informed

Staff members have the right to be informed about:

  • The personal data being collected;
  • The purpose of collection;
  • The lawful basis for processing;
  • The intended recipients;
  • The applicable retention period;
  • Any relevant cross-border transfer; and
  • Their rights concerning the information.

20.2 Right of access

A staff member may request confirmation of whether the University processes their personal data and may request access to that information.

Access will be provided subject to applicable law, the rights of other persons, and the University's regulatory framework.

20.3 Right to correction

A staff member may request the correction of personal data that is:

  • Inaccurate;
  • False;
  • Misleading;
  • Outdated; or
  • Incomplete.

20.4 Right to deletion

A staff member may request the deletion of false, misleading, unlawfully processed, or unnecessary personal data where legally permitted.

The University may decline a deletion request where retention is required for:

  • Employment administration;
  • Compliance with a legal obligation;
  • Performance of a public task;
  • Archiving in the public interest;
  • Establishment or defence of a legal claim; or
  • Another lawful reason.

20.5 Right to object

A staff member may object to all or part of the processing of their personal data, particularly where processing is based on legitimate interests or is carried out for direct-marketing purposes.

20.6 Right to restriction of processing

A staff member may request restriction of processing in appropriate circumstances, including where:

  • The accuracy of the information is disputed;
  • The processing is alleged to be unlawful;
  • The University no longer needs the information but the staff member requires it for a legal claim; or
  • An objection to processing is under consideration.

20.7 Right to data portability

Where applicable, a staff member may request personal data they provided to the University in a structured, commonly used, and machine-readable format.

20.8 Rights concerning automated decisions

A staff member has the right not to be subjected to a decision based solely on automated processing where the decision produces legal or similarly significant effects, subject to applicable legal exceptions.

20.9 Right to withdraw consent

Where processing is based on consent, the staff member may withdraw that consent at any time.

Withdrawal of consent will not affect processing carried out lawfully before the withdrawal. It will also not prevent processing where another lawful basis applies.

20.10 Right to complain

A staff member may submit a complaint to:

  • Taita Taveta University's Data Protection Officer; or
  • The Office of the Data Protection Commissioner.

21. Exercising Data-Protection Rights

Staff members wishing to exercise their data-protection rights should contact:

The Data Protection Officer
Taita Taveta University
P.O. Box 635–80300
Voi, Kenya

Email: dpo@ttu.ac.ke
Telephone: +254 721 113 302 / +254 774 222 064

A request should clearly indicate:

  • The name of the person making the request;
  • The specific right being exercised;
  • The personal data or records concerned;
  • Any relevant dates, departments, or systems; and
  • Sufficient information to verify the requester's identity.

The University may request proof of identity to prevent unauthorised disclosure of personal data.

Requests will be handled within the timelines prescribed by applicable law.

22. Making a Complaint

A staff member who believes that the University has processed their personal data unlawfully or infringed their data-protection rights should first contact the Data Protection Officer:

Email: dpo@ttu.ac.ke

The University will review the complaint and take appropriate action.

A staff member also has the right to lodge a complaint with Kenya's data-protection supervisory authority:

Office of the Data Protection Commissioner

A complaint to the Office of the Data Protection Commissioner does not prevent a staff member from seeking another remedy available under applicable law.

23. Responsibilities of Staff Members

Staff members are responsible for:

  • Providing accurate and complete personal information;
  • Promptly notifying the University when their information changes;
  • Protecting University passwords and system credentials;
  • Following University data-protection and information-security policies;
  • Handling personal data accessed during their work confidentially;
  • Accessing personal data only where authorised;
  • Reporting actual or suspected personal-data breaches;
  • Avoiding unauthorised disclosure or transfer of University information; and
  • Returning or securely disposing of University records and equipment when required.

Failure to comply with University data-protection and information-security requirements may result in disciplinary or other appropriate action.

24. Changes to This Staff Privacy Statement

The University may revise this Staff Privacy Statement periodically to reflect:

  • Changes in applicable law;
  • Changes in University policies;
  • New technologies or systems;
  • Changes in employment or administrative processes;
  • Regulatory guidance; or
  • Changes in the University's data-processing activities.

The latest version will be published through appropriate University channels.

Where significant changes materially affect staff members, the University will provide an appropriate notice.

25. Contact Information

Questions, complaints, or requests concerning this Staff Privacy Statement should be addressed to:

The Data Protection Officer
Taita Taveta University
P.O. Box 635–80300
Voi, Kenya

Email: dpo@ttu.ac.ke
Telephone: +254 721 113 302 / +254 774 222 064
Website: www.ttu.ac.ke

Last updated: 24 July 2026

Our Collaborators & Partners

Proud to collaborate with leading institutions and organizations worldwide

DAAD

DAAD

German Academic Exchange Service

NML - CSIR India

NML - CSIR India

National Metallurgical Laboratory

WFURS

WFURS

World Forum of Universities of Resources on Sustainability

Technical University of Mombasa

Technical University of Mombasa

Kenya

HTW Dresden

HTW Dresden

University of Applied Sciences, Germany

GIA

GIA

Gemological Institute of America

TU Clausthal

TU Clausthal

Clausthal University of Technology, Germany

TU Bergakademie Freiberg

TU Bergakademie Freiberg

Technische Universität Bergakademie Freiberg, Germany

Technical University of Munich

Technical University of Munich

Germany - Engineering & Technology Exchange

Federal University of Technology Akure

Federal University of Technology Akure

Nigeria - Mineral Processing Research

University of Toronto

University of Toronto

Canada - Faculty Exchange & Research

AmCham Kenya

AmCham Kenya

USA/Kenya - Critical Supply Chains

Beijing University of Technology

Beijing University of Technology

China - Mining Engineering Collaboration

University of Nairobi

University of Nairobi

Kenya - Joint Research Projects

Apply Now
×
🎓 Congratulations!
1,689 Undergraduate Degree Students

placed through KUCCPS 2025

Admission Letters are now available for download.

Download Your Letter

Log in to the admissions portal to access your letter

Transfer applications welcome. View programmes

Your journey to excellence starts here. Welcome to Taita Taveta University.