Data Governance
Data governance answers a question no technology answers: who decides? Who may define an indicator, change a data element, grant access, approve a release, or retire a dataset — and how those decisions are recorded.
Security controls protect data. Governance decides what protection is for.
What it covers
Decision rights
Named accountability for each domain of data: who owns clinical data, registry data, financial data. "The IT department" is not an answer — IT operates systems; it does not own clinical definitions.
Stewardship
Data stewards are the people who know what a field means and are accountable for its quality. Usually programme or clinical staff, not engineers.
Metadata management
Definitions, code lists, indicator formulas and their change history. In a DHIS2 deployment this is the metadata layer, and it is where governance either exists or does not — see metadata design principles.
Quality accountability
Defined dimensions, defined thresholds, defined follow-up — see health data. Quality that is everyone's responsibility is no one's.
Access management
Who may see which data at which granularity, on what basis, reviewed on a schedule. Access granted for a project that ended three years ago is a live risk.
Lifecycle
Retention, archival and deletion. Health records have long statutory retention periods; other data does not, and keeping everything forever is a liability, not prudence.
Making change management real
The single highest-value governance practice in a health information system is disciplined change control over shared metadata:
- A proposed change is documented with its rationale and impact.
- Affected stewards review it.
- Changes are batched into a release, not applied ad hoc.
- Downstream users are notified before it takes effect.
- The change is recorded with date, author and reason.
- Breaks in indicator time series are documented explicitly.
Without this, a well-meaning correction mid-year silently invalidates a national time series.
Governance bodies
Typically a small standing group with representation from clinical/programme areas, information systems, legal or privacy, and analysis. Meets on a schedule. Keeps decisions in writing. What matters is not the org chart but whether decisions are documented and findable a year later.
Signs governance is missing
- Two dashboards showing different values for the same indicator
- Nobody can say who approved a definition change
- Access lists that only grow
- Data quality discussed but never assigned
- Every integration renegotiating the meaning of the same fields
Related
- ISO 27001 and ISO 27799 — the protection side
- GDPR — legal obligations
- Open data — release decisions
- Health data