Governance Framework, Classification & Quality
This lecture covers the first half of NHIC’s data governance journey: who NHIC is and what it manages, the layered governance framework it built, the committee and roles that own it, and the data classification and quality standards that turn policy into applied controls.
- Describe NHIC's mandate, data holdings, and the regulatory context it operates in
- Explain the six-layer governance framework and how its 68 documents are organised
- Distinguish the four named governance roles and the Data Governance Committee that oversees them
- Apply the four-tier classification model and trace how a tier drives access, encryption, DLP, and retention controls
- State the four data quality dimensions NHIC governs and who is accountable for them
About NHIC
The National Health Information Centre is a unit under Rwanda’s Ministry of Health, responsible for the systems that hold the country’s health data.
What NHIC manages
| Data holding | Description |
|---|---|
| Clinical records | Patient-level clinical data across facilities |
| Disease surveillance | National surveillance and outbreak data |
| Patient registries | Longitudinal patient registry systems |
| Health statistics | National health statistics for policy and planning |
Regulatory context
- Governed by Rwanda’s Data Protection and Privacy Law (DPPL No. 058/2021).
- Operates under the Ministry of Health’s Data Controller certification.
- The National Cyber Security Authority (NCSA) is the national regulatory authority.
The governance framework
NHIC’s foundation is a layered library of governance documentation — 68 governance documents across 6 framework layers, owned by 4 named governance roles and overseen by a dedicated committee.
The framework is a funnel: the widest layer at the top is the foundation everything else rests on, and each layer above narrows toward the most specialised controls.
The Data Governance Committee and named roles
The framework is governed by a Data Governance Committee (DGC), and every governance responsibility is attached to a named role — not left as an abstract definition:
| Role | Responsibility |
|---|---|
| Data Stewards | Business accountability for data within their domain |
| Data Custodians | Technical stewardship of the systems holding the data |
| Data Protection Officer (DPO) | Privacy and data protection oversight |
| ISMS Owner | Ownership of the information security management system |
All roles and documents are aligned to the DPPL, Ministry of Health directives, and NCSA obligations.
Discussion question. How is data governance structured in your organisation? Who owns it, who enforces it, and how are governance decisions made?
Technical deep dive — governance.
- Centralised, federated, or hybrid governance model — what drove the choice?
- How do you enforce the boundary between Data Steward and Data Custodian?
- What does your policy lifecycle look like from drafting to enforcement?
- How do you measure governance maturity?
- What tools do you use to manage and track policy compliance?
Data classification
Classification is where governance stops being paperwork and starts driving controls. NHIC’s Data Classification Policy (MOH-POL-DCL) defines a four-tier system, ascending from least to most sensitive, and the tier a dataset lands in determines the controls applied to it.
A full data inventory and classification exercise is currently underway across all systems, so every dataset ends up with an explicit tier rather than an assumed one.
Data quality management
Classification says how carefully data must be handled; quality standards say how much it can be trusted. NHIC governs four quality dimensions:
| Dimension | What it demands |
|---|---|
| Accuracy | Data correctly reflects the real-world facts it records |
| Completeness | Required fields and records are present, not partially captured |
| Consistency | The same fact holds the same value across systems |
| Timeliness | Data is available when decisions and reporting need it |
Three practices keep the dimensions enforced rather than aspirational:
- Quality is validated at the point of collection, not repaired downstream.
- Periodic quality audits are reported to the Data Governance Committee.
- Data Stewards are accountable for quality within their domain.
Discussion question. How do you classify health data, and how does that classification drive the controls you apply — access, encryption, and retention?
Technical deep dive — classification and quality.
- Automated vs. manual classification — how do you handle data spanning multiple tiers?
- How do you manage master data across multiple systems?
- What data quality framework do you apply?
- What metadata schema or catalogue do you use?
- How do you track data lineage from source through transformation to final use?
Next
Continue with Security, Privacy & Legal Compliance, which covers how these classifications and roles translate into access management, security controls, vendor risk management, and lineage tracking.