1. POLICY STATEMENT

AFRICAN AVIATION AND AEROSPACE UNIVERSITY (“the University”) is committed to protecting the privacy, confidentiality, integrity, and availability of personal data entrusted to it by students, prospective students, staff, alumni, researchers, contractors, visitors, and other stakeholders.

The University recognizes privacy as a fundamental right and undertakes to process personal data in accordance with the Nigerian Data Protection Act (NDP Act) 2023, the General Application and Implementation Directive (GAID) 2025, and other applicable legal and regulatory requirements.

This Privacy Policy explains how the University collects, uses, stores, shares, secures, retains, and disposes of personal data.

  1. OBJECTIVES

This Policy aims to:

  1. SCOPE

This Policy applies to all personal data processed by the University through:

This Policy applies to:

  1. DATA PROTECTION PRINCIPLES

The University processes personal data in accordance with the following principles:

Personal data shall be processed lawfully, fairly, and transparently.

Personal data shall be collected for specified, explicit, and legitimate purposes.

Only personal data necessary for stated purposes shall be collected.

Reasonable steps shall be taken to ensure data accuracy and completeness.

Personal data shall not be retained longer than necessary.

Appropriate security measures shall protect personal data.

The University shall demonstrate compliance with applicable privacy requirements.

  1. PERSONAL DATA WE COLLECT

5.1 Student Data

5.2 Staff Data

5.3 Alumni Data

5.4 Visitor Data

5.5 Technical Data

 

  1. SPECIAL CATEGORY PERSONAL DATA

The University may process sensitive personal data including:

Such data shall receive enhanced protection measures and shall only be processed where legally permissible.

  1. CHILDREN’S DATA

Where the University processes personal data relating to minors, additional safeguards shall be implemented.

Where required by law, parental or guardian consent shall be obtained before processing personal data belonging to minors.

  1. LEGAL BASIS FOR PROCESSING

The University processes personal data on one or more of the following lawful bases:

  1. PURPOSE OF PROCESSING

Personal data may be processed for:

Academic Administration

Student Welfare

Human Resources

Research Activities

Financial Administration

Security and Safety

Regulatory Compliance

  1. RESEARCH DATA PROCESSING

The University is committed to ethical and responsible research practices.

Research-related personal data shall be processed in accordance with:

Where feasible, research data shall be anonymized or pseudonymized.

  1. AUTOMATED DECISION-MAKING

The University may utilize automated systems in relation to:

Where significant decisions are made through automated means, individuals may request human review where applicable.

  1. DATA SHARING AND DISCLOSURE

The University may disclose personal data to:

All disclosures shall be made on a lawful basis and subject to appropriate safeguards.

The University does not sell personal data.

  1. INTERNATIONAL DATA TRANSFERS

Where personal data is transferred outside Nigeria, the University shall ensure that:

  1. CCTV AND CAMPUS SURVEILLANCE

The University may operate CCTV systems and related monitoring technologies for:

CCTV recordings shall only be accessed by authorized personnel and retained for approved retention periods.

  1. COOKIES AND DIGITAL TECHNOLOGIES

University websites, portals, and digital platforms may use:

Users may manage cookie preferences through browser settings.

  1. DATA SUBJECT RIGHTS

Data subjects have the right to:

Requests shall be handled within applicable regulatory timelines.

 

  1. DATA SECURITY

The University maintains appropriate safeguards including:

Technical Controls

Organizational Controls

Physical Controls

  1. PERSONAL DATA BREACH MANAGEMENT

The University shall maintain a Personal Data Breach Management Procedure.

In the event of a breach, the University shall:

  1. Detect and contain the incident;
  2. Assess the impact;
  3. Investigate root causes;
  4. Implement remediation measures;
  5. Notify the NDPC where required;
  6. Notify affected individuals where necessary;
  7. Maintain breach records.
  1. DATA RETENTION SCHEDULE

Record Type

Retention Period

Student Admission Records

7 Years

Examination Scripts

5 Years

Academic Transcripts

Permanent

Graduation Records

Permanent

Student Disciplinary Records

7 Years

Staff Personnel Files

7 Years After Exit

Payroll Records

7 Years

Research Project Files

10 Years

Visitor Logs

12 Months

CCTV Footage

90 Days

ICT Access Logs

12 Months

Procurement Records

7 Years

The University may retain records longer where required by law or legitimate institutional need.

  1. GOVERNANCE STRUCTURE

The following stakeholders are responsible for privacy governance:

Governing Council

Provides strategic oversight.

Vice Chancellor

Provides executive leadership.

Registrar

Ensures institutional compliance.

Data Protection Officer (DPO)

Coordinates privacy compliance activities.

ICT Directorate

Implements technical safeguards.

Faculties and Departments

Ensure compliance within operational areas.

Staff and Students

Comply with applicable privacy requirements.

  1. COMPLAINT MANAGEMENT

Any individual who believes their privacy rights have been violated may submit a complaint to the University’s Data Protection Officer.

Complaints shall be investigated and resolved within reasonable timelines.

  1. CONTACT DETAILS

Data Protection Officer (DPO)

AFRICAN AVIATION AND AEROSPACE UNIVERSITY

Address: Bill Clinton Drive, Airport Road, Abuja, FCT

Email: info@aaau.edu.ng 

Phone: +2349169890000

Website: www.aaau.edu.ng

  1. POLICY REVIEW

This Policy shall be reviewed at least annually or whenever:

Document Classification: Public

Effective Date: 22/06/26

Version: 1.0

Admission! Admission!!

2026/2027 Undergraduate Admission

Registration Ends 30th August 2026

Fill out the form below, and we will be in touch shortly.