Taita Taveta University Logo

Taita Taveta University

Home of Ideas

Student Privacy Statement


1. Introduction

Taita Taveta University respects the privacy of its students, applicants, alumni, parents, guardians, sponsors, and other persons who interact with the University's academic and student services.

The University is committed to collecting and processing personal data lawfully, fairly, transparently, and securely in accordance with the Constitution of Kenya, the Data Protection Act, 2019, applicable regulations, and other relevant laws.

This Student Privacy Statement explains:

  • The categories of personal data collected by the University;
  • How personal data is collected;
  • Why the University processes personal data;
  • The lawful grounds relied upon when processing personal data;
  • The persons and organisations with whom personal data may be shared;
  • How personal data is protected and retained;
  • The rights available to students and applicants; and
  • How privacy questions, requests, and complaints may be submitted.

This statement should be read together with other relevant University policies, notices, procedures, regulations, and terms governing particular services.

2. Scope of This Privacy Statement

This Privacy Statement applies to personal data collected through:

  • University websites;
  • Online application and admission platforms;
  • Student portals;
  • Learning-management systems;
  • Enterprise-resource-planning systems;
  • Examination and academic-management systems;
  • Accommodation and student-welfare systems;
  • Library systems;
  • Research-management platforms;
  • University email services;
  • Mobile applications;
  • Payment platforms;
  • Official University social media pages;
  • Email, SMS, telephone, and other electronic communication channels;
  • University Wi-Fi, computer networks, and digital resources;
  • Physical application forms and other documents;
  • University campuses, offices, classes, laboratories, libraries, hostels, events, and facilities; and
  • Any other authorised academic, administrative, research, or student-support service.

Collectively, these platforms, systems, facilities, and communication channels are referred to as the "Services."

This statement applies to:

  • Prospective students;
  • Applicants;
  • Admitted students;
  • Registered students;
  • Exchange students;
  • Visiting students;
  • Short-course and professional-training participants;
  • Graduands;
  • Graduates and alumni; and
  • Former students whose records are retained by the University.

3. Data Controller Details

Taita Taveta University is the data controller responsible for determining how and why student personal data is processed.

Taita Taveta University
P.O. Box 635–80300
Voi, Kenya

Telephone: +254 721 113 302 / +254 774 222 064
General email: info@ttu.ac.ke
Data Protection Officer: dpo@ttu.ac.ke
Website: www.ttu.ac.ke

Questions, requests, or complaints concerning personal data should be submitted to the University's Data Protection Officer.

4. Data-Protection Principles

When processing student personal data, Taita Taveta University will endeavour to ensure that the information is:

4.1 Processed lawfully, fairly, and transparently

The University will process personal data in accordance with applicable law and provide appropriate information about how the data is used.

4.2 Collected for specified purposes

Personal data will be collected for specific, explicit, and legitimate academic, administrative, contractual, legal, research, welfare, security, or operational purposes.

4.3 Adequate, relevant, and limited

The University will collect only the personal data reasonably required for the stated purpose.

4.4 Accurate and up to date

Reasonable steps will be taken to ensure that personal data is accurate, complete, and updated where necessary.

Students are responsible for informing the University when their personal details change.

4.5 Retained only as long as necessary

Personal data will be retained only for as long as is reasonably required for the purpose for which it was collected, subject to academic-record, archival, legal, audit, regulatory, and institutional requirements.

4.6 Processed securely

The University will implement reasonable organisational, administrative, physical, and technical safeguards to protect personal data against unauthorised access, loss, disclosure, alteration, destruction, or misuse.

4.7 Processed in accordance with data-subject rights

The University will respect and facilitate the exercise of applicable data-protection rights, subject to lawful restrictions and exemptions.

5. Meaning of Personal Data

Personal data means any information relating to an identified or identifiable natural person.

A person may be identifiable directly or indirectly through information such as a name, identification number, location, online identifier, academic record, photograph, or another characteristic relating to that person.

Personal data collected by the University may include sensitive personal data where such information is necessary and lawfully processed.

6. Categories of Personal Data Collected

Depending on the student's or applicant's relationship with the University, Taita Taveta University may process the following categories of personal data.

6.1 Personal identification information

  • Full name;
  • National identification number;
  • Passport number;
  • Birth certificate number;
  • Alien identification number, where applicable;
  • Date of birth;
  • Place of birth;
  • Gender;
  • Nationality;
  • Citizenship;
  • Marital status, where relevant;
  • Signature;
  • Passport-size photographs;
  • Personal images;
  • Admission number;
  • Student registration number;
  • Examination number; and
  • Copies of identity documents.

6.2 Contact information

  • Residential address;
  • Postal address;
  • Personal and University email addresses;
  • Telephone and mobile numbers;
  • County, sub-county, ward, or country of residence;
  • Parent or guardian contact details;
  • Sponsor contact information;
  • Next-of-kin details; and
  • Emergency-contact information.

6.3 Application and admission information

  • Programme applied for;
  • Mode of study;
  • Campus;
  • Academic certificates;
  • Examination results;
  • Transcripts;
  • Professional qualifications;
  • Previous institutions attended;
  • Application documents;
  • Admission letters;
  • Placement information;
  • Kenya Universities and Colleges Central Placement Service information;
  • Recognition and equation of qualifications;
  • Course preferences;
  • Application status;
  • Document-verification records; and
  • Information used to determine eligibility for admission.

6.4 Academic information

  • Programme and course registration;
  • Class attendance;
  • Continuous-assessment results;
  • Examination results;
  • Academic transcripts;
  • Academic progress;
  • Credit transfers;
  • Exemptions;
  • Deferment records;
  • Academic warnings;
  • Supplementary and special examinations;
  • Research proposals;
  • Dissertations and theses;
  • Internship and industrial-attachment records;
  • Fieldwork records;
  • Academic-advising records;
  • Graduation status;
  • Awards and honours;
  • Academic disciplinary records; and
  • Certificates and other academic awards.

6.5 Financial information

  • Fee statements;
  • Payment records;
  • Bank transaction references;
  • Mobile-money payment references;
  • Sponsorship information;
  • Scholarship records;
  • Bursary information;
  • Higher Education Loans Board information;
  • Refund information;
  • Financial-aid applications;
  • Outstanding balances;
  • Accommodation charges;
  • Graduation charges;
  • Student invoices and receipts; and
  • Other authorised financial records.

The University should not ordinarily collect or retain a student's full payment-card information where payments are processed directly by an authorised payment-service provider.

6.6 Parent, guardian, sponsor, and dependant information

Where relevant, the University may process:

  • Parent or guardian names;
  • Contact information;
  • Identification information;
  • Relationship to the student;
  • Sponsor information;
  • Financial-support information;
  • Next-of-kin information; and
  • Emergency-contact information.

Students providing personal data relating to another person should ensure, where reasonably possible, that the person is aware that the information will be provided to and processed by the University.

6.7 Health, disability, and welfare information

Where necessary and lawful, the University may process:

  • Health information;
  • Disability information;
  • Medical reports;
  • Medical insurance information;
  • Allergies and medical conditions;
  • Counselling and student-support records;
  • Reasonable accommodation requirements;
  • Dietary or accessibility requirements;
  • Emergency medical information;
  • Pregnancy-related information where relevant to support services;
  • Information relating to student welfare; and
  • Information required to protect the student's or another person's vital interests.

Access to health, counselling, disability, and welfare information will be restricted to authorised personnel.

6.8 Accommodation and residential information

  • Hostel applications;
  • Room allocation;
  • Residence details;
  • Accommodation payments;
  • Check-in and check-out information;
  • Hostel access records;
  • Visitor records;
  • Residential disciplinary records;
  • Damage reports;
  • Emergency contacts; and
  • Information required to manage student accommodation.

6.9 Biometric and security information

Where applicable, the University may process:

  • Fingerprints;
  • Facial images;
  • Biometric-registration information;
  • Biometric attendance records;
  • Access-control information;
  • Student identification-card records;
  • Library-access records;
  • Closed-circuit television footage;
  • Security incident reports;
  • Visitor records;
  • Vehicle-registration details; and
  • Building, hostel, laboratory, or system access logs.

Biometric information will only be processed where there is an appropriate lawful basis and adequate security safeguards.

6.10 Information and communication technology data

The University may process information generated when students use University systems and digital resources, including:

  • Login information;
  • Internet Protocol addresses;
  • Device information;
  • Browser information;
  • Network-usage records;
  • Email-account information;
  • Student-portal activity;
  • Learning-management-system activity;
  • System access and audit logs;
  • Library-system activity;
  • Wi-Fi usage information;
  • Cybersecurity incident records;
  • Files stored on University systems; and
  • Communication made through authorised University platforms.

Monitoring of University systems will be limited to legitimate academic, administrative, security, operational, or legal purposes.

6.11 Student activities and participation information

  • Club and society membership;
  • Sports participation;
  • Leadership roles;
  • Mentorship activities;
  • Community-service participation;
  • Student elections;
  • Conference participation;
  • Innovation and incubation activities;
  • Competitions;
  • Exchange programmes;
  • Study visits;
  • University events;
  • Photographs and recordings taken during University activities; and
  • Awards and recognition.

6.12 Disciplinary and complaint information

  • Complaints made by or against a student;
  • Investigation records;
  • Academic-integrity matters;
  • Examination-irregularity records;
  • Misconduct allegations;
  • Disciplinary proceedings;
  • Decisions and sanctions;
  • Appeals;
  • Grievances;
  • Security reports; and
  • Related correspondence.

Such information will be processed in accordance with applicable University statutes, regulations, procedures, and the requirements of fairness and confidentiality.

7. How Personal Data Is Collected

Taita Taveta University may collect personal data through the following channels.

7.1 Directly from students and applicants

Personal data may be collected when a person:

  • Applies for admission;
  • Accepts an admission offer;
  • Downloads an admission letter;
  • Registers as a student;
  • Completes an online or physical form;
  • Uploads documents;
  • Registers for courses;
  • Applies for accommodation;
  • Applies for a scholarship, bursary, or financial aid;
  • Makes a payment;
  • Uses the student portal;
  • Uses University email or learning platforms;
  • Participates in classes, examinations, research, or other activities;
  • Contacts the University;
  • Requests student-support services;
  • Reports a complaint or incident;
  • Participates in a survey; or
  • Attends a University event.

7.2 From parents, guardians, sponsors, or representatives

The University may receive personal data from:

  • Parents;
  • Guardians;
  • Sponsors;
  • Authorised representatives;
  • Employers;
  • Scholarship providers; and
  • Other persons supporting a student's application or studies.

7.3 From government and education-sector bodies

The University may receive information from:

  • Kenya Universities and Colleges Central Placement Service;
  • Kenya National Examinations Council;
  • Higher Education Loans Board;
  • Kenya Revenue Authority, where applicable;
  • Ministry responsible for education;
  • Commission for University Education;
  • Technical and professional regulatory bodies;
  • Foreign qualification-recognition authorities;
  • County governments;
  • Scholarship and bursary providers; and
  • Other lawful government or education-sector sources.

7.4 From previous educational institutions and other organisations

The University may collect information from:

  • Secondary schools;
  • Colleges and universities;
  • Examination bodies;
  • Professional bodies;
  • Employers;
  • Internship and attachment organisations;
  • Research partners;
  • Referees;
  • Placement organisations; and
  • Authorised verification providers.

7.5 From publicly available sources

Where lawful and necessary, the University may collect information from publicly available sources, including professional publications, government registers, public websites, and official social media pages.

7.6 Automatically through University systems

Information may be collected automatically through:

  • University websites;
  • Student portals;
  • Learning-management systems;
  • University Wi-Fi;
  • Email systems;
  • Library systems;
  • Online examination platforms;
  • Access-control systems;
  • Security systems;
  • Payment platforms;
  • Cookies; and
  • Similar digital technologies.

8. Purposes and Lawful Grounds for Processing

The University will process personal data only where it has a lawful basis.

Applicable lawful grounds may include:

  • The student's consent;
  • Performance of a contract or steps taken before entering into a contract;
  • Compliance with a legal obligation;
  • Performance of a task carried out in the public interest;
  • Protection of the vital interests of the student or another person;
  • The legitimate interests of the University or another party, provided that these interests do not improperly override the student's rights;
  • Establishment, exercise, or defence of a legal claim; and
  • Another lawful basis recognised under applicable law.

Consent will not be used where another lawful basis is more appropriate, particularly where the University must process information to perform its academic, regulatory, contractual, or public functions.

9. Why the University Processes Student Personal Data

Taita Taveta University may process personal data for the following purposes.

9.1 Applications and admission

  • Receiving and evaluating applications;
  • Verifying identity and academic documents;
  • Confirming eligibility;
  • Processing placement information;
  • Issuing admission offers and letters;
  • Assigning admission and registration numbers;
  • Communicating admission requirements;
  • Processing acceptance of admission;
  • Managing applicant accounts; and
  • Preventing fraudulent applications.

9.2 Registration and academic administration

  • Registering students;
  • Creating and maintaining student records;
  • Registering programmes and courses;
  • Preparing class lists;
  • Managing academic calendars;
  • Monitoring attendance and academic progress;
  • Processing examinations and assessments;
  • Managing deferment, intermission, transfer, and withdrawal;
  • Producing transcripts and academic reports;
  • Managing graduation;
  • Issuing certificates and other academic awards; and
  • Confirming qualifications.

9.3 Teaching, learning, and research

  • Providing classroom and online instruction;
  • Administering learning-management systems;
  • Supporting academic advising;
  • Conducting examinations and assessments;
  • Detecting plagiarism and academic misconduct;
  • Administering research projects;
  • Supervising dissertations and theses;
  • Managing laboratories, workshops, and fieldwork;
  • Supporting internships and industrial attachments; and
  • Providing library and learning resources.

9.4 Student communication

  • Sending admission and registration information;
  • Issuing academic notices;
  • Communicating examination information;
  • Sending fee and payment notifications;
  • Providing emergency alerts;
  • Communicating policy and timetable changes;
  • Responding to enquiries;
  • Providing student-support information; and
  • Sending other necessary administrative messages.

Students may not be able to opt out of essential academic, administrative, security, or legal communications.

9.5 Financial administration

  • Producing fee statements;
  • Processing payments;
  • Reconciling transactions;
  • Managing refunds;
  • Administering scholarships, bursaries, sponsorships, and loans;
  • Confirming financial clearance;
  • Preventing payment fraud;
  • Conducting financial audits; and
  • Meeting financial reporting obligations.

9.6 Accommodation and campus services

  • Allocating hostel rooms;
  • Managing accommodation payments;
  • Administering catering and other campus services;
  • Controlling access to facilities;
  • Supporting campus transport;
  • Managing student identification cards;
  • Administering library services;
  • Managing sports and recreational facilities; and
  • Protecting University property.

9.7 Student welfare and support

  • Providing counselling and psychosocial support;
  • Supporting students with disabilities;
  • Providing reasonable accommodation;
  • Responding to medical or welfare emergencies;
  • Administering mentorship and career services;
  • Supporting international students;
  • Managing complaints and grievances;
  • Providing chaplaincy and wellness services where requested; and
  • Referring students to appropriate support providers.

9.8 Safety, security, and discipline

  • Protecting students, staff, visitors, and property;
  • Managing campus access;
  • Investigating incidents;
  • Managing disciplinary proceedings;
  • Preventing and detecting fraud;
  • Preventing identity theft;
  • Detecting cybersecurity threats;
  • Maintaining audit logs;
  • Responding to emergencies;
  • Supporting law-enforcement investigations where lawfully required; and
  • Enforcing University rules and regulations.

9.9 Planning, reporting, and quality assurance

  • Preparing institutional reports;
  • Conducting audits;
  • Supporting accreditation;
  • Monitoring programme performance;
  • Conducting student surveys;
  • Analysing admission, retention, progression, and graduation trends;
  • Planning University services and facilities;
  • Conducting statistical analysis;
  • Improving service delivery; and
  • Meeting regulatory reporting obligations.

Where possible, information used for research, analytics, planning, or reporting will be aggregated or anonymised.

9.10 Alumni and graduate services

  • Maintaining graduate records;
  • Verifying qualifications;
  • Communicating graduation information;
  • Providing alumni services;
  • Supporting career and employment services;
  • Conducting graduate-tracer studies;
  • Maintaining historical and archival records; and
  • Communicating relevant University developments.

10. Sensitive Personal Data

Sensitive personal data may include information relating to:

  • Health;
  • Disability;
  • Race;
  • Ethnic or social origin;
  • Religion, conscience, or belief;
  • Biometric information;
  • Genetic information;
  • Property details;
  • Marital status;
  • Family details;
  • Sex;
  • Sexual orientation; and
  • Other information classified as sensitive under applicable law.

The University will only process sensitive personal data where legally permitted and where additional safeguards have been implemented.

Sensitive personal data may be processed where:

  • The student has provided explicit consent;
  • Processing is necessary to meet legal or regulatory obligations;
  • Processing is necessary to protect the vital interests of a person;
  • Processing is required for medical, counselling, disability, welfare, or safety purposes;
  • Processing is necessary for a substantial public-interest purpose;
  • The student has manifestly made the information public;
  • Processing is necessary to establish, exercise, or defend a legal claim; or
  • Another lawful basis applies.

11. Consequences of Failing to Provide Personal Data

Some personal data is necessary for the University to:

  • Evaluate an application;
  • Verify identity and qualifications;
  • Offer admission;
  • Register a student;
  • Provide teaching and academic services;
  • Process examinations and results;
  • Manage payments;
  • Provide accommodation;
  • Issue transcripts and certificates;
  • Meet legal and regulatory obligations; and
  • Protect the health and safety of the University community.

Where required information is not provided, the University may be unable to:

  • Process or complete an application;
  • Confirm admission;
  • Register the student;
  • Provide access to a University service;
  • Allocate accommodation;
  • Process a payment or refund;
  • Release results;
  • Issue an academic document;
  • Provide a requested support service; or
  • Fulfil another academic, contractual, or legal obligation.

The University will explain the consequences where providing particular information is mandatory.

12. Disclosure of Personal Data Within the University

Student personal data may be shared internally with authorised persons who require it to perform their official duties.

This may include:

  • Academic departments;
  • Deans and directors;
  • Chairpersons of departments;
  • Lecturers and supervisors;
  • Admissions officers;
  • Academic registry staff;
  • Examination officers;
  • Finance and student-account officers;
  • Student-affairs personnel;
  • Accommodation officers;
  • Library staff;
  • ICT personnel;
  • Security personnel;
  • Medical, counselling, and disability-support personnel;
  • Legal and audit officers;
  • Research and postgraduate offices;
  • Graduation and alumni offices; and
  • Authorised University committees.

Only information reasonably necessary for the relevant purpose should be disclosed.

13. Disclosure to Third Parties

The University may share student personal data with authorised third parties where it is necessary and lawful.

Such parties may include:

  • Kenya Universities and Colleges Central Placement Service;
  • Commission for University Education;
  • Ministry responsible for education;
  • Higher Education Loans Board;
  • Kenya National Examinations Council;
  • Professional and regulatory bodies;
  • Scholarship, sponsorship, and bursary providers;
  • County and national government bodies;
  • Financial institutions;
  • Payment-service providers;
  • Insurance providers;
  • Healthcare providers;
  • Internship and industrial-attachment organisations;
  • Employers conducting lawful qualification verification;
  • Research collaborators;
  • Partner universities;
  • External examiners;
  • Auditors;
  • Legal advisers;
  • Courts and tribunals;
  • Law-enforcement authorities;
  • Information technology and cloud-service providers;
  • Communication-service providers;
  • Accommodation or student-service providers; and
  • Other organisations authorised by the student or permitted by law.

Third parties processing personal data on behalf of the University will be expected to:

  • Process the information only for authorised purposes;
  • Maintain confidentiality;
  • Apply appropriate security measures;
  • Comply with applicable data-protection requirements; and
  • Delete, return, or securely dispose of the information when required.

The University does not sell student personal data.

14. Information Voluntarily Disclosed by Students

University Services may allow students to post or share information through:

  • Discussion forums;
  • Student profiles;
  • Learning-management platforms;
  • Chat services;
  • Blogs;
  • Social-media pages;
  • Club and society platforms; and
  • Other collaborative services.

Information published in publicly accessible areas may be viewed, copied, or shared by other users and members of the public.

Students should avoid posting sensitive personal data, passwords, identity documents, financial information, private contact information, or confidential material in public or shared spaces.

The University may not be able to control the further use of information that a student voluntarily makes public.

15. Social Media and Third-Party Platforms

Where a student interacts with the University through a social-media platform or connects a University service to a third-party account:

  • The relevant third party may collect and process information under its own privacy terms;
  • Information shared publicly may be accessible to other users;
  • The University may receive information made available through that interaction; and
  • The privacy practices of the third-party platform will apply to its processing activities.

Students are encouraged to review the privacy settings and policies of third-party platforms before sharing personal data.

16. Third-Party Payment Services

The University may use authorised banks, mobile-money providers, payment gateways, and other payment-service providers to process student payments.

When a student makes a payment:

  • The payment provider may collect payment and transaction information;
  • The provider may process the information under its own privacy notice;
  • The University may receive transaction references, payer details, amounts, dates, and payment status;
  • Payment information may be used for reconciliation, receipting, audit, and fraud prevention; and
  • The provider will be responsible for protecting information collected directly through its platform.

The University will take reasonable steps to engage payment providers that apply appropriate security and data-protection measures.

17. Other Technical Information

When students use University websites, portals, applications, or networks, the University may collect technical information such as:

  • Browser type;
  • Device type;
  • Operating system;
  • Internet Protocol address;
  • Date and time of access;
  • Pages visited;
  • Login history;
  • System activity;
  • Language preference;
  • Referring website;
  • Approximate location derived from an Internet Protocol address;
  • Network and performance information; and
  • Diagnostic or security information.

Where technical information can identify or reasonably be linked to an individual, it will be treated as personal data.

18. Cookies and Similar Technologies

Cookies are small files placed on a device when a person visits a website or uses an online service.

The University may use essential, functional, security, and analytics cookies to:

  • Authenticate users;
  • Maintain login sessions;
  • Facilitate navigation;
  • Remember preferences;
  • Protect systems from misuse;
  • Analyse service performance;
  • Diagnose technical problems;
  • Understand how services are used; and
  • Improve the user experience.

Students may manage non-essential cookies through available cookie controls or browser settings.

Disabling certain cookies may affect the operation of University websites and systems.

19. Analytics Services

The University may use analytics tools to understand how its digital Services are used.

These tools may collect information such as:

  • Pages visited;
  • Time spent on a service;
  • Device and browser information;
  • Approximate location;
  • Referral source; and
  • User interactions.

Where third-party analytics providers are used, the University will seek to ensure that appropriate contractual and data-protection safeguards are in place.

Analytics information should, where reasonably possible, be aggregated, minimised, anonymised, or pseudonymised.

20. Aggregated and Anonymised Information

The University may aggregate or anonymise personal data so that individuals are no longer identifiable.

Aggregated or anonymised information may be used for:

  • Statistical analysis;
  • Institutional research;
  • Planning;
  • Quality assurance;
  • Regulatory reporting;
  • Academic research;
  • Service improvement;
  • Publication of general statistics; and
  • Development of University programmes and services.

Information that has been effectively anonymised is no longer treated as personal data because it cannot reasonably be linked to an identifiable person.

21. Direct Marketing and Promotional Communications

Where legally permitted, the University may send information concerning:

  • University events;
  • New programmes;
  • Alumni activities;
  • Public lectures;
  • Research opportunities;
  • Short courses;
  • Conferences;
  • Fundraising initiatives; and
  • Other optional University activities.

Consent will be obtained where required.

Students may opt out of optional promotional communications by:

  • Using the unsubscribe instructions provided;
  • Updating available communication preferences; or
  • Contacting the Data Protection Officer.

Opting out of promotional messages will not prevent the University from sending essential academic, administrative, financial, legal, emergency, or security communications.

22. Security of Personal Data

Taita Taveta University will implement reasonable organisational and technical measures designed to protect student personal data.

These measures may include:

  • Role-based access control;
  • Password controls;
  • Multi-factor authentication;
  • Encryption;
  • Firewalls;
  • Security monitoring;
  • Secure system configurations;
  • Access and audit logs;
  • Data backups;
  • Physical access controls;
  • Secure document storage;
  • Confidentiality obligations;
  • Staff training;
  • Incident-response procedures;
  • Business-continuity measures; and
  • Secure disposal of records.

No online transmission or information-storage system can be guaranteed to be completely secure.

Students are responsible for:

  • Protecting their passwords;
  • Keeping account credentials confidential;
  • Securing their devices;
  • Avoiding sharing one-time passwords or verification codes;
  • Logging out of shared devices;
  • Reporting suspected account compromise; and
  • Following University ICT and security policies.

23. Personal-Data Breaches

A personal-data breach may involve accidental or unlawful loss, destruction, alteration, disclosure, or access to personal data.

Students who suspect that:

  • Their University account has been compromised;
  • Their personal data has been disclosed without authority;
  • A University device or record containing personal data has been lost;
  • Their identity has been misused; or
  • A University system is no longer secure,

should immediately report the matter to the Data Protection Officer or through the University's approved ICT security-reporting channels.

The University will investigate reported breaches and make any notifications required by applicable law.

24. Retention of Student Personal Data

The University will retain student personal data only for as long as reasonably necessary for the purpose for which it was collected.

Retention periods may be determined by:

  • Academic-record requirements;
  • Legal and regulatory obligations;
  • Accreditation requirements;
  • Financial and audit obligations;
  • Research requirements;
  • Records-management policies;
  • Limitation periods for legal claims;
  • Public-interest archiving requirements;
  • Historical and institutional-record obligations; and
  • The continuing relationship between the student and the University.

Certain records, including academic transcripts, examination results, awards, and qualification records, may need to be retained permanently as official institutional records.

When other personal data is no longer required, it may be:

  • Securely deleted;
  • Physically destroyed;
  • Anonymised;
  • Archived where lawful; or
  • Otherwise disposed of through an approved secure process.

25. Cross-Border Transfer of Personal Data

The University may transfer personal data outside Kenya where necessary for purposes such as:

  • International academic exchanges;
  • Scholarships;
  • Research collaboration;
  • External examination;
  • International accreditation;
  • Study-abroad programmes;
  • International conferences;
  • Cloud-hosted services;
  • Foreign qualification verification; or
  • Other authorised academic or administrative activities.

Before transferring personal data outside Kenya, the University will apply the safeguards required by applicable law.

These safeguards may include:

  • Confirming that an adequate level of protection exists;
  • Entering into appropriate contractual arrangements;
  • Obtaining consent where consent is appropriate;
  • Ensuring that the transfer is necessary for a contract or legal obligation;
  • Applying data minimisation and encryption; or
  • Using another lawful transfer mechanism.

Students may contact the Data Protection Officer for information about safeguards applying to a particular cross-border transfer.

26. Automated Decision-Making and Profiling

The University may use automated tools to support processes such as:

  • Application validation;
  • Document checking;
  • Fee reconciliation;
  • Course registration;
  • Timetable preparation;
  • Student-service allocation;
  • Academic analytics;
  • Fraud detection; and
  • Security monitoring.

The University will not ordinarily make a decision that has a legal or similarly significant effect on a student solely through automated processing without appropriate safeguards.

Where such processing is used, the University will, where required:

  • Inform the affected student;
  • Explain the purpose and likely effect;
  • Provide meaningful information about the decision process;
  • Allow human review;
  • Allow the student to express their views; and
  • Provide a way to challenge the decision.

27. Children and Students Who Are Minors

Some applicants, students, programme participants, or visitors may be below the legally recognised age of consent.

Where personal data relating to a minor is collected, the University will apply appropriate safeguards.

Where legally required, consent may be obtained from:

  • A parent;
  • A guardian; or
  • Another legally authorised representative.

The University may process a minor's information without consent where another lawful basis applies, including where processing is necessary for education, legal compliance, public interest, or protection of the minor's vital interests.

28. Student Data-Protection Rights

Subject to applicable law and lawful limitations, students may exercise the following rights.

28.1 Right to be informed

Students have the right to receive information about:

  • The personal data being collected;
  • The purpose of collection;
  • The lawful basis for processing;
  • Intended recipients;
  • Retention periods;
  • Relevant cross-border transfers; and
  • Their data-protection rights.

28.2 Right of access

A student may request confirmation of whether the University processes their personal data and may request access to the information.

Access may be limited where disclosure would:

  • Unreasonably affect the rights of another person;
  • Reveal confidential references;
  • Compromise an ongoing investigation;
  • Violate examination-security requirements;
  • Disclose legally privileged information; or
  • Contravene another lawful restriction.

28.3 Right to correction

A student may request the correction of personal data that is:

  • Inaccurate;
  • Incomplete;
  • False;
  • Misleading; or
  • Out of date.

Requests to change core identity, admission, or academic information may require supporting documentation.

28.4 Right to deletion

A student may request deletion of personal data that is unlawfully processed, false, misleading, or no longer necessary.

The University may retain information where it is required for:

  • Academic-record purposes;
  • Compliance with a legal obligation;
  • Performance of a public task;
  • Research or archiving in the public interest;
  • Financial and audit requirements;
  • Establishment, exercise, or defence of legal claims; or
  • Another lawful purpose.

The right to deletion does not ordinarily permit deletion of valid academic results, disciplinary outcomes, fee records, or official qualifications that the University is legally or institutionally required to retain.

28.5 Right to object

A student may object to certain processing activities, particularly where processing is based on legitimate interests or is undertaken for direct marketing.

28.6 Right to restriction of processing

A student may request restriction of processing where:

  • The accuracy of the information is disputed;
  • The processing is alleged to be unlawful;
  • The University no longer needs the data, but the student requires it for a legal claim; or
  • An objection is being considered.

28.7 Right to data portability

Where applicable, a student may request personal data they provided to the University in a structured, commonly used, and machine-readable format.

28.8 Rights concerning automated decisions

A student has the right not to be subjected to a decision based solely on automated processing where the decision has legal or similarly significant effects, subject to applicable legal exceptions.

28.9 Right to withdraw consent

Where processing is based on consent, the student may withdraw consent at any time.

Withdrawal will not affect the lawfulness of processing carried out before consent was withdrawn. It will also not prevent continued processing where another lawful basis applies.

28.10 Right to complain

A student may complain to:

  • Taita Taveta University's Data Protection Officer; or
  • The Office of the Data Protection Commissioner.

29. Exercising Data-Protection Rights

Students wishing to exercise their data-protection rights should contact:

The Data Protection Officer
Taita Taveta University
P.O. Box 635–80300
Voi, Kenya

Email: dpo@ttu.ac.ke
Telephone: +254 721 113 302 / +254 774 222 064

A request should contain:

  • The student's full name;
  • Admission or registration number, where applicable;
  • Contact information;
  • The right being exercised;
  • A clear description of the information concerned;
  • Relevant dates, departments, or systems; and
  • Supporting documents where required.

The University may request proof of identity before processing a request to prevent unauthorised access or disclosure.

Requests will be handled within the timelines prescribed by applicable law.

30. Making a Complaint

A student who believes that the University has unlawfully processed their personal data or infringed their data-protection rights should contact:

The Data Protection Officer
Email: dpo@ttu.ac.ke

The University will investigate the complaint and take appropriate action.

A student also has the right to submit a complaint to Kenya's data-protection supervisory authority:

Office of the Data Protection Commissioner

Submitting a complaint to the University does not prevent the student from approaching the Office of the Data Protection Commissioner or seeking another remedy available under applicable law.

31. Links to External Websites and Services

University websites and systems may contain links to websites, applications, or services operated by third parties.

Taita Taveta University is not responsible for the privacy practices, security controls, or content of external platforms.

Students should review the privacy notices of third-party services before submitting personal information.

32. Responsibilities of Students

Students are responsible for:

  • Providing accurate and complete personal information;
  • Updating their information when it changes;
  • Protecting passwords and account credentials;
  • Using University systems lawfully;
  • Respecting the privacy of other students, staff, and third parties;
  • Avoiding unauthorised access to personal data;
  • Not sharing another person's personal data without authority;
  • Reporting actual or suspected data breaches;
  • Following University ICT, information-security, and data-protection policies; and
  • Returning University records, identification cards, devices, or other property when required.

Misuse of personal data or University information systems may result in disciplinary, civil, or criminal action, as applicable.

33. Changes to This Student Privacy Statement

Taita Taveta University may update this Student Privacy Statement periodically to reflect:

  • Changes in applicable law;
  • Regulatory guidance;
  • New technologies;
  • Changes in University systems;
  • Changes in academic or administrative processes;
  • New University services; or
  • Changes in the University's personal-data-processing activities.

The latest version will be published through appropriate University channels.

Where a significant change materially affects students, the University will provide an appropriate notice.

34. Contacting the University

Questions, requests, concerns, or complaints relating to this Student Privacy Statement should be addressed to:

The Data Protection Officer
Taita Taveta University
P.O. Box 635–80300
Voi, Kenya

Email: dpo@ttu.ac.ke
Telephone: +254 721 113 302 / +254 774 222 064
Website: www.ttu.ac.ke

Because ordinary email may not always be secure, students should not include passwords, bank-card details, login credentials, or unnecessary sensitive information in an email.

Where supporting sensitive documents are required, the Data Protection Officer should advise the student on an approved secure submission method.

Last updated: 24 July 2026

Our Collaborators & Partners

Proud to collaborate with leading institutions and organizations worldwide

DAAD

DAAD

German Academic Exchange Service

NML - CSIR India

NML - CSIR India

National Metallurgical Laboratory

WFURS

WFURS

World Forum of Universities of Resources on Sustainability

Technical University of Mombasa

Technical University of Mombasa

Kenya

HTW Dresden

HTW Dresden

University of Applied Sciences, Germany

GIA

GIA

Gemological Institute of America

TU Clausthal

TU Clausthal

Clausthal University of Technology, Germany

TU Bergakademie Freiberg

TU Bergakademie Freiberg

Technische Universität Bergakademie Freiberg, Germany

Technical University of Munich

Technical University of Munich

Germany - Engineering & Technology Exchange

Federal University of Technology Akure

Federal University of Technology Akure

Nigeria - Mineral Processing Research

University of Toronto

University of Toronto

Canada - Faculty Exchange & Research

AmCham Kenya

AmCham Kenya

USA/Kenya - Critical Supply Chains

Beijing University of Technology

Beijing University of Technology

China - Mining Engineering Collaboration

University of Nairobi

University of Nairobi

Kenya - Joint Research Projects

Apply Now
×
🎓 Congratulations!
1,689 Undergraduate Degree Students

placed through KUCCPS 2025

Admission Letters are now available for download.

Download Your Letter

Log in to the admissions portal to access your letter

Transfer applications welcome. View programmes

Your journey to excellence starts here. Welcome to Taita Taveta University.