Legal Information
Privacy Policy
What the University of Cape Coast holds about you, who else sees it, how long it is kept, and how to make us change or delete it
Last checked against the site: 21 September 2026
Introduction
The University of Cape Coast ("UCC," "we," "us," or "our") is the data controller for the personal information described on this page. That means we decide what is collected and why, and we are answerable for it under Ghana's Data Protection Act, 2012 (Act 843).
This policy covers our website and the online services reached from it. It tries to answer four questions plainly: what we hold, why we are allowed to hold it, who else receives it, and how long it stays. Where the honest answer is uncomfortable, it is here anyway.
Information We Collect
Information you give us
We collect personal information that you provide when you:
- Register for admission or apply to programmes
- Create an account on our website
- Subscribe to newsletters or communications
- Attend university events or programmes
- Contact us with inquiries or requests
- Participate in surveys or research studies
This information may include:
- Name and contact information (email, phone number, address)
- Date of birth and identification numbers
- Academic records and transcripts
- Employment information
- Financial information for tuition and fees
- Photographs and videos from university events
Information collected automatically
When you visit our website, the following is collected without you doing anything:
- IP address and device information
- Browser type and version
- Pages visited and time spent on pages
- Referring website addresses
- Cookies and similar tracking technologies
Most of that is collected by other companies on our behalf rather than by us directly. They are named below, under Companies that receive your data.
Why we are allowed to hold it
Act 843 does not let an organisation process personal data simply because it finds the data useful. It has to have a reason the law recognises. Ours, purpose by purpose:
Admissions, teaching, examination and the academic record
Performance of a public function
Educating students and recording what they achieved is what the University exists to do.
Fees, payments and financial administration
Contract, and legal obligation
Your agreement with the University, and the audit rules it is subject to.
Employment and engagement of staff
Contract, and legal obligation
Newsletters and mailing lists
Consent
You asked for them, and you can stop them at any time without giving a reason.
Answering enquiries sent to us
Legitimate interests
Somebody wrote to us; replying requires keeping what they wrote.
Website analytics and usability measurement
Consent
Nothing is loaded until you agree to it, and refusing is one click on the banner. You can change your answer at any time from Cookie Settings in the footer; refusing after having agreed also deletes the cookies that were set.
Campus safety, security and emergencies
Vital interests, and legitimate interests
Answering requests about personal data
Legal obligation
Act 843 requires it.
How We Use Your Information
Within those bases, we use what we collect to:
- Process applications and admissions
- Provide educational services and student support
- Communicate important university information
- Improve our website and services
- Conduct research and institutional analysis
- Comply with legal and regulatory requirements
- Maintain campus safety and security
- Organise events and alumni relations
Information Sharing and Disclosure
Within the University's own work, we may share your information with:
- Educational Partners: Accrediting bodies, academic institutions for transfers, and research collaborators
- Service Providers: Third-party vendors who assist with website hosting, payment processing, and IT services
- Government Agencies: When required by law or to comply with legal processes
- Parents and Guardians: With student consent or as permitted by educational privacy laws
- Emergency Contacts: In case of health or safety emergencies
We do not sell or rent your personal information to third parties for marketing purposes.
Companies that receive your data when you use this website
Loading a page on this site causes your browser to contact the companies below. Each one receives something about you, and each keeps it under its own policy rather than ours. This list is maintained alongside the site's code and alongside our Cookie Policy, which lists the same arrangements cookie by cookie.
Google LLC — Google Analytics 4
- What they receive
- Your IP address, the pages you view and in what order, roughly where you are (country and city, worked out from the IP address), your device, browser and screen size, and how you arrived -- a search, a link, or typing the address in.
- What it is for
- Counting which pages are read, so the University can decide what to improve and what to retire.
- Where it goes
- United States, and other countries where Google operates.
- How long they keep it
- Google deletes the visit-level records after 14 months. Aggregate counts are kept indefinitely.
- Their privacy notice
- https://policies.google.com/privacy
Microsoft Corporation — Microsoft Clarity
- What they receive
- A recording of your session on the page: mouse movement, scrolling, clicks and taps, plus the same technical details as above. Clarity masks the text you type into form fields before the recording leaves your browser.
- What it is for
- Seeing where a page confuses people -- a button nobody finds, a form abandoned at the same field -- which counts alone cannot show.
- Where it goes
- United States, and other countries where Microsoft operates.
- How long they keep it
- Microsoft deletes session recordings after 30 days. The heatmaps and metrics built from them are kept for up to 13 months.
- Their privacy notice
- https://privacy.microsoft.com/privacystatement
Google LLC — Google Fonts
- What they receive
- Your IP address, and which page requested the typeface. Nothing is stored on your device.
- What it is for
- Serving the typeface the site is set in.
- Where it goes
- United States, and other countries where Google operates.
- How long they keep it
- Google states that font requests are logged, and that the logs are not used to build a profile or to serve advertising.
- Their privacy notice
- https://developers.google.com/fonts/faq/privacy
Google LLC — YouTube, in privacy-enhanced mode
- What they receive
- On pages carrying an embedded video: your IP address, and which page the video sits on. In privacy-enhanced mode YouTube does not store viewing data against you unless you play the video.
- What it is for
- Playing embedded video.
- Where it goes
- United States, and other countries where Google operates.
- How long they keep it
- Set by Google; see its notice.
- Their privacy notice
- https://policies.google.com/privacy
Vimeo, Inc. — Vimeo
- What they receive
- On pages carrying an embedded video: your IP address, and which page the video sits on.
- What it is for
- Playing embedded video.
- Where it goes
- United States.
- How long they keep it
- Set by Vimeo; see its notice.
- Their privacy notice
- https://vimeo.com/privacy
All of these companies are based outside Ghana, so using this website means some information about you leaves the country. We rely on the contractual terms each company offers for that transfer. If you would rather it did not happen at all, blocking scripts in your browser stops most of it — the Cookie Policy explains what that costs you, and what it does not stop.
How long we keep it
A period, per category, rather than "for as long as necessary". Where the period is set by audit rules or by the permanence of an academic record rather than by a choice of ours, it says so.
Applications that did not lead to admission
5 years from the end of the admission cycle
Long enough to answer an appeal, or a query about a past decision.
Student academic records
Permanently
A degree has to remain verifiable for the rest of the holder's life, and after it.
Fee and payment records
6 years from the end of the financial year they fall in
Audit and tax obligations.
Staff employment records
6 years after employment ends, except pension records, which are kept for as long as an entitlement can arise
Employment and pension law.
Website accounts
Until you close the account, then 12 months
A short grace period, so an account closed by mistake can be restored.
Newsletter and mailing-list subscriptions
Until you unsubscribe
The subscription is the only reason the address is held; when it ends, so does the reason.
Enquiries and correspondence sent to us
2 years from the last message in the exchange
Long enough that a follow-up still has its context.
Security incident reports
The report is kept; the reporter's name, contact details and uploaded files are erased 3 years after the report is resolved or closed
The Cybersecurity Section needs the record of what happened. It does not need to know who told them, once the case is shut.
Photographs and video from University events
5 years, except images selected for the University archive, which are kept permanently
The archive is a record of the institution; the rest is publicity material that dates.
Web server logs
90 days
Enough to investigate an outage or an attack, not enough to be a history of your reading.
Website analytics
Held by the processors named above, under their periods: 14 months at Google, 30 days for Microsoft Clarity recordings
These sit in the processor's systems rather than ours, so the period is theirs to set and ours to disclose.
Requests you make about your own data
3 years after the request is answered. A request that is never confirmed from the email address it names is deleted after 30 days
We have to be able to show that a request was answered, and within how long. An unconfirmed request is a name and an address nobody asked us to keep.
At the end of a period the records are deleted, or anonymised so that they can no longer be traced back to a person. Where a legal obligation requires us to keep something longer than stated here, that obligation wins, and we will tell you so if you ask.
Data Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of sensitive data
- Secure server infrastructure
- Regular security assessments
- Access controls and authentication
- Staff training on data protection
Your Rights
Act 843 gives you the following rights over the information we hold about you. Each one says how to use it. You do not need an account, and you do not need to give a reason.
- See what we hold. Ask for a copy of your data. We will reply within 30 days.
- Correct what is wrong. Use the same form and choose correction, or tell the office directly. Students and staff can also correct much of it themselves from their own account.
- Have it deleted. Ask us to delete it. Where a record has to be kept by law — an academic transcript, an audited payment — we will say which record and which obligation, rather than refusing without explanation.
- Object to how it is used. Use the same form. Objections to analytics take effect for the future; you can also block the scripts today, as described in the Cookie Policy.
- Withdraw consent. Every newsletter carries an unsubscribe link that works without a reply from us. For anything else given by consent, the form or an email to the office is enough.
- Complain. To us first, at dataprotection@ucc.edu.gh, and to the Data Protection Commission whether or not you have come to us — see below.
The quickest route to any of these is the one form: ask us about your data. It takes a minute. You can also write to dataprotection@ucc.edu.gh — an email is a valid request in its own right, and we will not send you back to the form.
Complaining to the Data Protection Commission
If you are not satisfied with how we have handled your information, or how we answered a request, you can complain to the Data Protection Commission of Ghana, the regulator established under Act 843. It can investigate us and order us to act.
Their contact details and complaint procedure are at https://www.dataprotection.org.gh. You do not need our permission, and you do not have to come to us first.
Cookies and Tracking Technologies
This website stores a small number of cookies on your device. Some are needed for the site to work at all — to keep you signed in, and to let you submit a form. The rest tell us which pages are being read, so that we can decide what to improve. We do not use advertising cookies, and we do not use cookies to personalise what you see.
Rather than summarise them here, we list every one of them. Our Cookie Policy names each cookie, who sets it, what it is for, how long it lasts and which consent category it falls into, along with the other companies our pages contact even where no cookie is involved. It also says plainly what control you have over each category today, and what you do not yet have.
Children's Privacy
Our website is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13 without parental consent.
Changes to This Privacy Policy
The processor list, the retention periods and the lawful bases on this page are maintained alongside the site's own code, so a change to what the site does is meant to arrive together with a change here. When it does, the date at the top moves. We do not revise this page quietly, and the date does not move by itself.
Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
University of Cape Coast
Data Protection Office
University of Cape Coast, Cape Coast, Ghana
Email: dataprotection@ucc.edu.gh
Phone: +233 (03321) 32440