- POLICY STATEMENT
AFRICAN AVIATION AND AEROSPACE UNIVERSITY (“the University”) is committed to protecting the privacy, confidentiality, integrity, and availability of personal data entrusted to it by students, prospective students, staff, alumni, researchers, contractors, visitors, and other stakeholders.
The University recognizes privacy as a fundamental right and undertakes to process personal data in accordance with the Nigerian Data Protection Act (NDP Act) 2023, the General Application and Implementation Directive (GAID) 2025, and other applicable legal and regulatory requirements.
This Privacy Policy explains how the University collects, uses, stores, shares, secures, retains, and disposes of personal data.
- OBJECTIVES
This Policy aims to:
- Protect the privacy rights of data subjects.
- Ensure lawful processing of personal data.
- Promote transparency and accountability.
- Establish institutional responsibilities for data protection.
- Support compliance with applicable laws and regulations.
- Foster trust among students, staff, and stakeholders.
- SCOPE
This Policy applies to all personal data processed by the University through:
- Admission and registration processes;
- Academic administration;
- Research activities;
- Human resource management;
- Alumni relations;
- Student affairs and welfare services;
- ICT systems and digital platforms;
- Library services;
- Procurement and vendor management;
- Campus security operations;
- Financial administration.
This Policy applies to:
- Prospective students;
- Current students;
- Graduates and alumni;
- Academic staff;
- Non-academic staff;
- Visiting scholars;
- Research participants;
- Contractors and consultants;
- Vendors and service providers;
- Visitors.
- DATA PROTECTION PRINCIPLES
The University processes personal data in accordance with the following principles:
- Lawfulness, Fairness and Transparency
Personal data shall be processed lawfully, fairly, and transparently.
- Purpose Limitation
Personal data shall be collected for specified, explicit, and legitimate purposes.
- Data Minimization
Only personal data necessary for stated purposes shall be collected.
- Accuracy
Reasonable steps shall be taken to ensure data accuracy and completeness.
- Storage Limitation
Personal data shall not be retained longer than necessary.
- Integrity and Confidentiality
Appropriate security measures shall protect personal data.
- Accountability
The University shall demonstrate compliance with applicable privacy requirements.
- PERSONAL DATA WE COLLECT
5.1 Student Data
- Full name
- Date of birth
- Gender
- Nationality
- Passport photograph
- NIN
- Contact information
- Academic records
- Examination records
- Attendance records
- Disciplinary records
- Graduation records
- Research outputs
5.2 Staff Data
- Employment records
- Qualifications
- Professional certifications
- Payroll information
- Pension information
- Performance records
- Training records
5.3 Alumni Data
- Graduation information
- Academic transcripts
- Alumni engagement records
5.4 Visitor Data
- Visitor logs
- Access records
- CCTV recordings
5.5 Technical Data
- IP addresses
- Login credentials
- Device identifiers
- Access logs
- Cookies
- System usage records
- SPECIAL CATEGORY PERSONAL DATA
The University may process sensitive personal data including:
- Health information;
- Disability information;
- Biometric data;
- Student counseling records;
- Disciplinary investigation records;
- Security incident records.
Such data shall receive enhanced protection measures and shall only be processed where legally permissible.
- CHILDREN’S DATA
Where the University processes personal data relating to minors, additional safeguards shall be implemented.
Where required by law, parental or guardian consent shall be obtained before processing personal data belonging to minors.
- LEGAL BASIS FOR PROCESSING
The University processes personal data on one or more of the following lawful bases:
- Consent;
- Contractual necessity;
- Legal obligation;
- Public interest;
- Legitimate interest;
- Vital interest.
- PURPOSE OF PROCESSING
Personal data may be processed for:
Academic Administration
- Admissions
- Registration
- Course administration
- Examinations
- Graduation
- Certification
Student Welfare
- Accommodation management
- Health services
- Counseling services
- Student support programmes
Human Resources
- Recruitment
- Payroll administration
- Staff development
- Performance management
Research Activities
- Research administration
- Ethics reviews
- Publication management
- Research collaboration
Financial Administration
- Tuition management
- Scholarship administration
- Budget management
Security and Safety
- Campus security
- Incident investigations
- Access control
Regulatory Compliance
- Accreditation requirements
- Government reporting obligations
- Data protection compliance
- RESEARCH DATA PROCESSING
The University is committed to ethical and responsible research practices.
Research-related personal data shall be processed in accordance with:
- Approved research protocols;
- Ethical review requirements;
- Informed consent obligations;
- Confidentiality requirements;
- Applicable legal obligations.
Where feasible, research data shall be anonymized or pseudonymized.
- AUTOMATED DECISION-MAKING
The University may utilize automated systems in relation to:
- Admission screening;
- Learning management systems;
- Scholarship administration;
- Student performance analytics;
- Digital examination systems.
Where significant decisions are made through automated means, individuals may request human review where applicable.
- DATA SHARING AND DISCLOSURE
The University may disclose personal data to:
- Government agencies;
- Regulatory bodies;
- Accreditation institutions;
- Professional bodies;
- Research partners;
- Technology service providers;
- Financial institutions;
- Law enforcement agencies.
All disclosures shall be made on a lawful basis and subject to appropriate safeguards.
The University does not sell personal data.
- INTERNATIONAL DATA TRANSFERS
Where personal data is transferred outside Nigeria, the University shall ensure that:
- Adequate safeguards are implemented;
- Transfer mechanisms comply with applicable law;
- Data subjects’ rights remain protected.
- CCTV AND CAMPUS SURVEILLANCE
The University may operate CCTV systems and related monitoring technologies for:
- Campus security;
- Crime prevention;
- Safety management;
- Incident investigation.
CCTV recordings shall only be accessed by authorized personnel and retained for approved retention periods.
- COOKIES AND DIGITAL TECHNOLOGIES
University websites, portals, and digital platforms may use:
- Cookies;
- Analytics tools;
- Session management technologies;
- Similar digital tracking technologies.
Users may manage cookie preferences through browser settings.
- DATA SUBJECT RIGHTS
Data subjects have the right to:
- Be informed;
- Access personal data;
- Request correction;
- Request deletion where applicable;
- Restrict processing;
- Object to processing;
- Withdraw consent;
- Request portability;
- Lodge complaints with the NDPC.
Requests shall be handled within applicable regulatory timelines.
- DATA SECURITY
The University maintains appropriate safeguards including:
Technical Controls
- Encryption
- Firewalls
- Access controls
- Endpoint protection
- Vulnerability management
- Backup systems
Organizational Controls
- Privacy policies
- Staff training
- Confidentiality agreements
- Risk assessments
- Incident response procedures
Physical Controls
- Restricted access areas
- Visitor controls
- Secure storage facilities
- PERSONAL DATA BREACH MANAGEMENT
The University shall maintain a Personal Data Breach Management Procedure.
In the event of a breach, the University shall:
- Detect and contain the incident;
- Assess the impact;
- Investigate root causes;
- Implement remediation measures;
- Notify the NDPC where required;
- Notify affected individuals where necessary;
- Maintain breach records.
- DATA RETENTION SCHEDULE
|
Record Type |
Retention Period |
|
Student Admission Records |
7 Years |
|
Examination Scripts |
5 Years |
|
Academic Transcripts |
Permanent |
|
Graduation Records |
Permanent |
|
Student Disciplinary Records |
7 Years |
|
Staff Personnel Files |
7 Years After Exit |
|
Payroll Records |
7 Years |
|
Research Project Files |
10 Years |
|
Visitor Logs |
12 Months |
|
CCTV Footage |
90 Days |
|
ICT Access Logs |
12 Months |
|
Procurement Records |
7 Years |
The University may retain records longer where required by law or legitimate institutional need.
- GOVERNANCE STRUCTURE
The following stakeholders are responsible for privacy governance:
Governing Council
Provides strategic oversight.
Vice Chancellor
Provides executive leadership.
Registrar
Ensures institutional compliance.
Data Protection Officer (DPO)
Coordinates privacy compliance activities.
ICT Directorate
Implements technical safeguards.
Faculties and Departments
Ensure compliance within operational areas.
Staff and Students
Comply with applicable privacy requirements.
- COMPLAINT MANAGEMENT
Any individual who believes their privacy rights have been violated may submit a complaint to the University’s Data Protection Officer.
Complaints shall be investigated and resolved within reasonable timelines.
- CONTACT DETAILS
Data Protection Officer (DPO)
AFRICAN AVIATION AND AEROSPACE UNIVERSITY
Address: Bill Clinton Drive, Airport Road, Abuja, FCT
Email: info@aaau.edu.ng
Phone: +2349169890000
Website: www.aaau.edu.ng
- POLICY REVIEW
This Policy shall be reviewed at least annually or whenever:
- Significant legal changes occur;
- New technologies are introduced;
- Major institutional changes occur;
- Significant privacy incidents occur.
Document Classification: Public
Effective Date: 22/06/26
Version: 1.0