Data Governance Overview
This sub-module walks through the data governance journey of Rwanda’s National Health Information Centre (NHIC) — how a unit responsible for the country’s most sensitive health data built a working governance programme from the ground up, and the practices it now runs day to day. The material is adapted from NHIC’s Data Governance Learning Exchange, a peer learning session held with visiting health data governance delegations.
- Situate NHIC — its mandate, the national health data holdings it manages, and the regulatory regime it operates under
- Recognise the two broad areas the sub-module covers: governance and quality management, and security, privacy and legal compliance
- Understand the workshop format — each theme pairs an open discussion question with a practitioner-level technical deep dive
NHIC’s governance journey in brief
The National Health Information Centre is a unit under Rwanda’s Ministry of Health, responsible for the systems that hold the country’s health data. Its holdings span four broad categories:
| Data holding | What it contains |
|---|---|
| Clinical records | Patient-level clinical data across facilities |
| Disease surveillance | National surveillance and outbreak data |
| Patient registries | Longitudinal patient registry systems |
| Health statistics | National health statistics for policy and planning |
That footprint puts NHIC squarely inside Rwanda’s data protection regime:
- Processing is governed by Rwanda’s Data Protection and Privacy Law — DPPL No. 058/2021.
- NHIC operates under the Ministry of Health’s Data Controller certification.
- The National Cyber Security Authority (NCSA) is the national regulatory authority.
Against that backdrop, NHIC drafted a layered library of 68 governance documents, stood up a Data Governance Committee, defined named governance roles, classified its data into four tiers, and wired those decisions into the technical controls — access, encryption, data loss prevention, retention — that protect the data in practice.
What this sub-module covers
The journey is presented in two lectures:
| Lecture | What it covers |
|---|---|
| Governance Framework, Classification & Quality | About NHIC in detail; the six-layer governance framework and the Data Governance Committee; role definitions; the four-tier data classification system and the controls it drives; data quality standards |
| Security, Privacy & Legal Compliance | The data access workflow and privacy programme; information security controls, incident response and audit; third-party and vendor risk; metadata and data lineage; key lessons learned |
How the material is structured
The source session was a workshop, not a briefing, and the lectures keep that shape. Each theme ends with two prompts, in this order:
- A Discussion Question — an open question for the room, shown in an info callout.
- A Technical Deep Dive — five practitioner-level follow-up questions on the same theme, shown in a warning callout.
Treat them as working material: answer them for your own organisation as you read, and use them to compare NHIC’s choices against your own. The second lecture closes with NHIC’s key lessons learned and a final open discussion.
Start with Governance Framework, Classification & Quality.