East Africa University Data Protection Policy and Privacy Statement

1. Introduction East Africa University (EAU) is committed to protecting the privacy and security of personal data entrusted to us by our students, faculty, staff, visitors, and other stakeholders. This Data Protection Policy outlines our practices concerning the collection, use, and management of personal data, in compliance with applicable data protection laws and regulations in East Africa University. 2. Purpose The purpose of this policy is to ensure that East Africa University (EAU) complies with all applicable data protection laws and guidelines, safeguarding personal data to the highest standards while maintaining transparency about how such data is handled. 3. Scope This policy applies to all personal data collected and processed by East Africa University in relation to students, staff, faculty, applicants, and other individuals interacting with the university, whether on-campus or through online services. 4. Definition of Personal Data For the purposes of this policy, personal data refers to any information that can directly or indirectly identify an individual, including but not limited to: • Full Name • Identification Numbers (e.g., National ID, Passport Number, Student ID) • Contact details (Phone numbers, Email addresses, etc.) • Demographic Information (Date of Birth, Gender, etc.) • Academic and employment records 5. Data Collection East Africa University collects personal data for the following purposes: • Academic administration and record-keeping • Enrollment, registration, and graduation processes • Providing educational services and student support • Communication regarding university updates, events, and activities • Processing of staff and faculty employment details • Compliance with legal, regulatory, and accreditation requirements 6. Data Use and Processing Personal data collected by East Africa University will be used for legitimate purposes as stated above. The university will only process data that is necessary for these specific purposes, and will do so lawfully, fairly, and transparently. 7. Data Retention Personal data will be retained by East Africa University only for as long as necessary to fulfill the purposes for which it was collected. Once the data is no longer needed, it will be securely deleted or anonymized, in compliance with data retention policies and legal requirements. 9. Data Sharing and Disclosure East Africa University will not sell, rent, or lease personal data to third parties. However, data may be shared in the following circumstances: • With third-party service providers, contractors, and partners who help facilitate university operations, provided they adhere to data protection requirements • As required by law, regulation, or in response to valid legal requests (e.g., government authorities, courts, etc.) • With other educational institutions for collaboration, research, and academic purposes, under strict confidentiality agreements 10. Data Security East Africa University takes reasonable precautions to protect the personal data under its care. This includes physical, technical, and organizational measures to prevent unauthorized access, alteration, or destruction of data, including: • Use of encryption and secure communication protocols • Regular auditing of access to sensitive data • Employee training on data protection practices • Implementing access controls and user authentication mechanisms • Physical security measures to safeguard data storage facilities 11. Updates to the Policy East Africa University may update this Data Protection Policy from time to time to reflect changes in legal requirements, business practices, or technological advancements. Updates will be communicated to stakeholders via official university channels, and the revised policy will be made available on the university’s website. 12. Contact Information For any inquiries related to personal data protection or to exercise any of the rights outlined in this policy, please contact: ingo@eau.edu.so