Legal Information

Privacy Policy

What the University of Cape Coast holds about you, who else sees it, how long it is kept, and how to make us change or delete it

Last checked against the site: 21 September 2026

Introduction

The University of Cape Coast ("UCC," "we," "us," or "our") is the data controller for the personal information described on this page. That means we decide what is collected and why, and we are answerable for it under Ghana's Data Protection Act, 2012 (Act 843).

This policy covers our website and the online services reached from it. It tries to answer four questions plainly: what we hold, why we are allowed to hold it, who else receives it, and how long it stays. Where the honest answer is uncomfortable, it is here anyway.

Information We Collect

Information you give us

We collect personal information that you provide when you:

  • Register for admission or apply to programmes
  • Create an account on our website
  • Subscribe to newsletters or communications
  • Attend university events or programmes
  • Contact us with inquiries or requests
  • Participate in surveys or research studies

This information may include:

  • Name and contact information (email, phone number, address)
  • Date of birth and identification numbers
  • Academic records and transcripts
  • Employment information
  • Financial information for tuition and fees
  • Photographs and videos from university events

Information collected automatically

When you visit our website, the following is collected without you doing anything:

  • IP address and device information
  • Browser type and version
  • Pages visited and time spent on pages
  • Referring website addresses
  • Cookies and similar tracking technologies

Most of that is collected by other companies on our behalf rather than by us directly. They are named below, under Companies that receive your data.

Why we are allowed to hold it

Act 843 does not let an organisation process personal data simply because it finds the data useful. It has to have a reason the law recognises. Ours, purpose by purpose:

Admissions, teaching, examination and the academic record

Performance of a public function

Educating students and recording what they achieved is what the University exists to do.

Fees, payments and financial administration

Contract, and legal obligation

Your agreement with the University, and the audit rules it is subject to.

Employment and engagement of staff

Contract, and legal obligation

Newsletters and mailing lists

Consent

You asked for them, and you can stop them at any time without giving a reason.

Answering enquiries sent to us

Legitimate interests

Somebody wrote to us; replying requires keeping what they wrote.

Website analytics and usability measurement

Consent

Nothing is loaded until you agree to it, and refusing is one click on the banner. You can change your answer at any time from Cookie Settings in the footer; refusing after having agreed also deletes the cookies that were set.

Campus safety, security and emergencies

Vital interests, and legitimate interests

Answering requests about personal data

Legal obligation

Act 843 requires it.

How We Use Your Information

Within those bases, we use what we collect to:

  • Process applications and admissions
  • Provide educational services and student support
  • Communicate important university information
  • Improve our website and services
  • Conduct research and institutional analysis
  • Comply with legal and regulatory requirements
  • Maintain campus safety and security
  • Organise events and alumni relations

Information Sharing and Disclosure

Within the University's own work, we may share your information with:

  • Educational Partners: Accrediting bodies, academic institutions for transfers, and research collaborators
  • Service Providers: Third-party vendors who assist with website hosting, payment processing, and IT services
  • Government Agencies: When required by law or to comply with legal processes
  • Parents and Guardians: With student consent or as permitted by educational privacy laws
  • Emergency Contacts: In case of health or safety emergencies

We do not sell or rent your personal information to third parties for marketing purposes.

Companies that receive your data when you use this website

Loading a page on this site causes your browser to contact the companies below. Each one receives something about you, and each keeps it under its own policy rather than ours. This list is maintained alongside the site's code and alongside our Cookie Policy, which lists the same arrangements cookie by cookie.

Google LLC — Google Analytics 4

What they receive
Your IP address, the pages you view and in what order, roughly where you are (country and city, worked out from the IP address), your device, browser and screen size, and how you arrived -- a search, a link, or typing the address in.
What it is for
Counting which pages are read, so the University can decide what to improve and what to retire.
Where it goes
United States, and other countries where Google operates.
How long they keep it
Google deletes the visit-level records after 14 months. Aggregate counts are kept indefinitely.

Microsoft Corporation — Microsoft Clarity

What they receive
A recording of your session on the page: mouse movement, scrolling, clicks and taps, plus the same technical details as above. Clarity masks the text you type into form fields before the recording leaves your browser.
What it is for
Seeing where a page confuses people -- a button nobody finds, a form abandoned at the same field -- which counts alone cannot show.
Where it goes
United States, and other countries where Microsoft operates.
How long they keep it
Microsoft deletes session recordings after 30 days. The heatmaps and metrics built from them are kept for up to 13 months.

Google LLC — Google Fonts

What they receive
Your IP address, and which page requested the typeface. Nothing is stored on your device.
What it is for
Serving the typeface the site is set in.
Where it goes
United States, and other countries where Google operates.
How long they keep it
Google states that font requests are logged, and that the logs are not used to build a profile or to serve advertising.

Google LLC — YouTube, in privacy-enhanced mode

What they receive
On pages carrying an embedded video: your IP address, and which page the video sits on. In privacy-enhanced mode YouTube does not store viewing data against you unless you play the video.
What it is for
Playing embedded video.
Where it goes
United States, and other countries where Google operates.
How long they keep it
Set by Google; see its notice.

Vimeo, Inc. — Vimeo

What they receive
On pages carrying an embedded video: your IP address, and which page the video sits on.
What it is for
Playing embedded video.
Where it goes
United States.
How long they keep it
Set by Vimeo; see its notice.
Their privacy notice
https://vimeo.com/privacy

All of these companies are based outside Ghana, so using this website means some information about you leaves the country. We rely on the contractual terms each company offers for that transfer. If you would rather it did not happen at all, blocking scripts in your browser stops most of it — the Cookie Policy explains what that costs you, and what it does not stop.

How long we keep it

A period, per category, rather than "for as long as necessary". Where the period is set by audit rules or by the permanence of an academic record rather than by a choice of ours, it says so.

Applications that did not lead to admission

5 years from the end of the admission cycle

Long enough to answer an appeal, or a query about a past decision.

Student academic records

Permanently

A degree has to remain verifiable for the rest of the holder's life, and after it.

Fee and payment records

6 years from the end of the financial year they fall in

Audit and tax obligations.

Staff employment records

6 years after employment ends, except pension records, which are kept for as long as an entitlement can arise

Employment and pension law.

Website accounts

Until you close the account, then 12 months

A short grace period, so an account closed by mistake can be restored.

Newsletter and mailing-list subscriptions

Until you unsubscribe

The subscription is the only reason the address is held; when it ends, so does the reason.

Enquiries and correspondence sent to us

2 years from the last message in the exchange

Long enough that a follow-up still has its context.

Security incident reports

The report is kept; the reporter's name, contact details and uploaded files are erased 3 years after the report is resolved or closed

The Cybersecurity Section needs the record of what happened. It does not need to know who told them, once the case is shut.

Photographs and video from University events

5 years, except images selected for the University archive, which are kept permanently

The archive is a record of the institution; the rest is publicity material that dates.

Web server logs

90 days

Enough to investigate an outage or an attack, not enough to be a history of your reading.

Website analytics

Held by the processors named above, under their periods: 14 months at Google, 30 days for Microsoft Clarity recordings

These sit in the processor's systems rather than ours, so the period is theirs to set and ours to disclose.

Requests you make about your own data

3 years after the request is answered. A request that is never confirmed from the email address it names is deleted after 30 days

We have to be able to show that a request was answered, and within how long. An unconfirmed request is a name and an address nobody asked us to keep.

At the end of a period the records are deleted, or anonymised so that they can no longer be traced back to a person. Where a legal obligation requires us to keep something longer than stated here, that obligation wins, and we will tell you so if you ask.

Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of sensitive data
  • Secure server infrastructure
  • Regular security assessments
  • Access controls and authentication
  • Staff training on data protection

Your Rights

Act 843 gives you the following rights over the information we hold about you. Each one says how to use it. You do not need an account, and you do not need to give a reason.

  • See what we hold. Ask for a copy of your data. We will reply within 30 days.
  • Correct what is wrong. Use the same form and choose correction, or tell the office directly. Students and staff can also correct much of it themselves from their own account.
  • Have it deleted. Ask us to delete it. Where a record has to be kept by law — an academic transcript, an audited payment — we will say which record and which obligation, rather than refusing without explanation.
  • Object to how it is used. Use the same form. Objections to analytics take effect for the future; you can also block the scripts today, as described in the Cookie Policy.
  • Withdraw consent. Every newsletter carries an unsubscribe link that works without a reply from us. For anything else given by consent, the form or an email to the office is enough.
  • Complain. To us first, at dataprotection@ucc.edu.gh, and to the Data Protection Commission whether or not you have come to us — see below.

The quickest route to any of these is the one form: ask us about your data. It takes a minute. You can also write to dataprotection@ucc.edu.gh — an email is a valid request in its own right, and we will not send you back to the form.

Complaining to the Data Protection Commission

If you are not satisfied with how we have handled your information, or how we answered a request, you can complain to the Data Protection Commission of Ghana, the regulator established under Act 843. It can investigate us and order us to act.

Their contact details and complaint procedure are at https://www.dataprotection.org.gh. You do not need our permission, and you do not have to come to us first.

Cookies and Tracking Technologies

This website stores a small number of cookies on your device. Some are needed for the site to work at all — to keep you signed in, and to let you submit a form. The rest tell us which pages are being read, so that we can decide what to improve. We do not use advertising cookies, and we do not use cookies to personalise what you see.

Rather than summarise them here, we list every one of them. Our Cookie Policy names each cookie, who sets it, what it is for, how long it lasts and which consent category it falls into, along with the other companies our pages contact even where no cookie is involved. It also says plainly what control you have over each category today, and what you do not yet have.

Children's Privacy

Our website is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13 without parental consent.

Changes to This Privacy Policy

The processor list, the retention periods and the lawful bases on this page are maintained alongside the site's own code, so a change to what the site does is meant to arrive together with a change here. When it does, the date at the top moves. We do not revise this page quietly, and the date does not move by itself.

Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us:

University of Cape Coast

Data Protection Office

University of Cape Coast, Cape Coast, Ghana

Email: dataprotection@ucc.edu.gh

Phone: +233 (03321) 32440