Skip to Content
The HIC Learning Exchange begins July 13, 2026. View the agenda
ReadingItem 20 of 22 · 10 min

Data Governance Overview

This sub-module walks through the data governance journey of Rwanda’s National Health Information Centre (NHIC) — how a unit responsible for the country’s most sensitive health data built a working governance programme from the ground up, and the practices it now runs day to day. The material is adapted from NHIC’s Data Governance Learning Exchange, a peer learning session held with visiting health data governance delegations.

What you'll learn
  • Situate NHIC — its mandate, the national health data holdings it manages, and the regulatory regime it operates under
  • Recognise the two broad areas the sub-module covers: governance and quality management, and security, privacy and legal compliance
  • Understand the workshop format — each theme pairs an open discussion question with a practitioner-level technical deep dive

NHIC’s governance journey in brief

The National Health Information Centre is a unit under Rwanda’s Ministry of Health, responsible for the systems that hold the country’s health data. Its holdings span four broad categories:

Data holdingWhat it contains
Clinical recordsPatient-level clinical data across facilities
Disease surveillanceNational surveillance and outbreak data
Patient registriesLongitudinal patient registry systems
Health statisticsNational health statistics for policy and planning

That footprint puts NHIC squarely inside Rwanda’s data protection regime:

  • Processing is governed by Rwanda’s Data Protection and Privacy Law — DPPL No. 058/2021.
  • NHIC operates under the Ministry of Health’s Data Controller certification.
  • The National Cyber Security Authority (NCSA) is the national regulatory authority.

Against that backdrop, NHIC drafted a layered library of 68 governance documents, stood up a Data Governance Committee, defined named governance roles, classified its data into four tiers, and wired those decisions into the technical controls — access, encryption, data loss prevention, retention — that protect the data in practice.

What this sub-module covers

The journey is presented in two lectures:

LectureWhat it covers
Governance Framework, Classification & QualityAbout NHIC in detail; the six-layer governance framework and the Data Governance Committee; role definitions; the four-tier data classification system and the controls it drives; data quality standards
Security, Privacy & Legal ComplianceThe data access workflow and privacy programme; information security controls, incident response and audit; third-party and vendor risk; metadata and data lineage; key lessons learned

How the material is structured

The source session was a workshop, not a briefing, and the lectures keep that shape. Each theme ends with two prompts, in this order:

  1. A Discussion Question — an open question for the room, shown in an info callout.
  2. A Technical Deep Dive — five practitioner-level follow-up questions on the same theme, shown in a warning callout.

Treat them as working material: answer them for your own organisation as you read, and use them to compare NHIC’s choices against your own. The second lecture closes with NHIC’s key lessons learned and a final open discussion.

Start with Governance Framework, Classification & Quality.