Short answer
Yes, in principle a university can include your student email address and certain contact details in an internal directory, but only if it does so in a way that complies with UK data protection law. Your email address and other contact details are personal data under the UK GDPR and the Data Protection Act 2018, so the university needs a lawful basis to publish them, must tell you it is doing so, must limit the audience appropriately, and must respect your rights, including the right to object.
The legal framework
Because a student email address identifies you, it is personal data. The processing (which includes publishing it in a directory) must satisfy the UK GDPR data protection principles: it must be lawful, fair and transparent, limited to specified purposes, adequate and not excessive, and kept securely.
For an ordinary internal directory the university will usually rely on one of two lawful bases under Article 6 of the UK GDPR. The most common is legitimate interests, where the university argues that a searchable directory of members is necessary for the running of the institution and internal communication, and that this is not overridden by your rights and interests. Alternatively it may rely on performance of the contract between you and the university, or on consent. If it relies on consent, that consent must be freely given, specific and capable of being withdrawn, and the directory cannot then be treated as compulsory.
The distinction the ICO draws matters here. The Information Commissioner’s Office and university information governance guidance treat publishing contact details that relate to a person’s official role or function differently from publishing purely personal details. Professional or role-based contact details, such as a work email for a member of staff or for a postgraduate researcher acting in an academic capacity, are more readily justified. Publishing a student’s private details, and especially anything like a home address or personal telephone number, is much harder to justify and generally should not be done without consent.
Internal directory versus public website
There is an important difference between a genuinely internal directory, accessible only to staff and students behind a login, and something published on the open internet. Publishing personal data on a public-facing website discloses it worldwide, which raises the data protection risk considerably and requires a stronger justification. An internal, access-controlled directory containing your name and university email address, visible only to other members of the institution, is far easier to justify under legitimate interests than the same information on an open web page.
If your university intends to include your details in an externally visible search or profile, the bar is higher, and the argument for relying on your consent, or at least for offering a straightforward opt-out, is stronger.
Transparency and your rights
Whatever lawful basis the university uses, it must be transparent. Its student privacy notice should tell you what data it holds, that it maintains a directory, who can see it, and how you can object or ask for removal. If you were never told, that is itself a compliance weakness.
You have several relevant rights. You have the right to be informed. If the university relies on legitimate interests, you have the right to object under Article 21, and the university must then stop unless it can show compelling legitimate grounds that override your interests. In practice, for a routine directory entry, a reasonable objection, particularly one based on safety or privacy concerns, will often succeed in getting your details suppressed. You also have the right to have inaccurate details corrected, and in some circumstances the right to erasure. If the university relies on consent, you can simply withdraw it.
Many universities operate exactly this way in practice. Oxford, for example, includes a webmail address in its online contact search but provides a route to ask for it to be omitted, and Manchester’s information governance guidance stresses that individuals must be told their data appears and be given a means to object and have it removed.
Special situations
If you have a particular reason to keep your details private, such as being an estranged or protected student, a survivor of domestic abuse, or someone subject to harassment or stalking, you should make that clear. In those circumstances your objection carries much more weight, and the balancing exercise under legitimate interests will tilt firmly towards suppression. It is worth flagging any safety concern explicitly rather than treating it as a general privacy preference.
Practical next steps
1. Check the university’s student privacy notice and any directory or IT policy to see what they say about the directory, the lawful basis, and how to opt out.
2. Identify what exactly is being published and to whom. Note whether it is only your name and university email in an internal, login-only system, or something more sensitive or more public.
3. If you want to be removed, contact the relevant office, often IT services, the departmental administrator, or the Data Protection Officer, and ask them to suppress your entry. Universities are required to have a Data Protection Officer, and directing an objection to them is often the most effective route.
4. Frame your request clearly. If you object to legitimate interests processing under Article 21, say so, and give any reasons, especially any safety or privacy concerns, so they can carry out the balancing exercise properly.
5. If they refuse and you are not satisfied with their explanation, you can make a formal complaint to the university and, if still unresolved, complain to the ICO, which regulates data protection compliance.
What would change the answer
The strength of your position depends on several facts that are worth pinning down: whether the directory is internal and access-controlled or on the open internet; exactly which details are shown (name and university email are far easier for the university to justify than personal phone number or address); which lawful basis the university relies on (if it is consent, you can simply withdraw it; if it is legitimate interests, you need to object and the balancing test applies); whether you were properly informed in advance; and whether you have any particular safety or privacy reason for objecting.
This answer draws on broad legal knowledge and checks current law, guidance and procedure against relevant sources.
Directories | ICOico.org.ukPersonal dataox.ac.ukPublication of Staff and PGR Student Profiles on the University Websiteessex.ac.ukPublishing names on a website | Information Governance Office | StaffNet | The University of Manchesterstaffnet.manchester.ac.ukKNOW WHERE YOU STAND
Ready to stop guessing?
The above is just an example answer. Sign up now to get personalised guidance and ask follow-up questions based on your own situation. Bring your legal issue, your contract, or your question. Lawyer Destroyer gives you clear, practical guidance so you can move forward with confidence.