Digital Sovereignty and Humanitarian Contexts: System Design and Country Workflows at DAC2026
Note: This summary was generated and reviewed by the dhis2 docs Ask AI tool and may contain errors. As this is a Wiki post, we encourage you to edit and improve this content with your own expertise, or reply with your questions for discussion!
This document summarizes the technical frameworks, infrastructure models, security protocols, and operational workflows for digital sovereignty and humanitarian health implementations presented at the DHIS2 2026 Annual Conference.
1. Digital Sovereignty Terminology
Technical discussions on system autonomy and control in national health systems utilize the following defined categories: [Digital Sovereignty]
| Term | Technical Definition |
|---|---|
| Digital sovereignty | The capacity of national organizations to maintain autonomous operational control over software codebases, hardware infrastructure, and system-design decisions [Digital Sovereignty]. |
| Data sovereignty | The restriction of the data lifecycle (collection, storage, processing) to the physical geography and legal jurisdiction of the host nation [Digital Sovereignty]. |
| Enshittification | A documented software lifecycle pattern where a proprietary vendor locks users into an ecosystem, subsequently degrading utility while increasing licensing or operational costs [Digital Sovereignty]. |
| Sovereignty as a Service | A cloud-hosting model where external technology providers manage systems inside a countryâs borders under local compliance labels, while maintaining proprietary control of the software stack [Digital Sovereignty]. |
Documented Hosting Pathways
- European Public Sector Hosting: In response to the US Cloud Act (which permits US regulatory audits of data held by US companies regardless of physical server location), selected European institutions are migrating to open-source self-hosted solutions [Digital Sovereignty]. The Norwegian Institute of Public Health utilizes a self-hosted DHIS2 platform (âKoSyâ) to aggregate and process municipal disease surveillance statistics [Digital Sovereignty; Country Stories].
- Bilateral Data-Sharing Models: In several low- and middle-income countries (LMICs), bilateral agreements introduce funding contingencies that require the utilization of designated proprietary cloud vendors and specify data-sharing pathways with external donor governments [Digital Sovereignty].
2. Shared Infrastructure Models: HISP South Africa Private Cloud
HISP South Africa manages 141 DHIS2 instances (100 for South African public health entities and 41 for external regional programs) [Digital Sovereignty].
Benchmarks and Costs
- Operational Cost: Private cloud hosting managed by the regional node was benchmarked at 20% (five times cheaper) than equivalent commercial hyperscaler pricing (such as AWS or Azure) [Digital Sovereignty].
- Capacity Integration: The model allocates the 80% cost savings directly to local capacity-building programs to transition database and server administration tasks to ministry staff over time [Digital Sovereignty].
- Entanglement Risk: Relying on commercial hyperscalers introduces âentanglement,â where a system is built around proprietary, non-portable cloud microservices. This makes migrating the application to alternative infrastructure difficult without re-engineering the database schema [Digital Sovereignty].
3. Data Workflows in Humanitarian and Fragile Settings
Implementations in conflict-affected or fragile areas adjust system design to accommodate infrastructural collapse and protect beneficiary security.
MSF Spain: System Simplification and Governance
MSF Spain uses DHIS2 as its core health information system across its global operations, executing a phased deployment over ten years [Fragile Settings].
- The Simplicity Tension: Field operators require system flexibility to adapt clinical screens to sudden local emergencies, while headquarters requires standard, rigid indicator structures to run multi-country aggregate analyses [Fragile Settings].
- Governance Reset: MSF is executing a system-wide governance audit to define which data elements are mandatory for global monitoring and which clinical fields can be customized locally [Fragile Settings].
Gates Foundation: Localized Data Feedback Loops
In Somalia, the Gates Foundationâs learning agenda focused on routing analyzed DHIS2 data directly back to community structures [Fragile Settings]. Local womenâs groups and elders analyzed maternal health patterns showing that maternal mortality was linked to emergency transport costs. This led to the community establishing a collective ambulance fund [Fragile Settings].
Palestine: Connectivity Adaptations and Data Minimization
- West Bank: Approximately 99% of facilities access the centralized family health system. Areas with physical access restrictions use 3G cellular SIM cards to upload records. If connectivity fails, paper forms are manually transported to the nearest connected hub for entry [Fragile Settings].
- Gaza: Following infrastructure damage, UNICEF and local partners transitioned from live online entries to decentralized, offline Excel sheets [Fragile Settings]. Operators encrypt these sheets and upload them to a secure server using access codes restricted to a single focal point, bypasssing standard email or messaging channels [Fragile Settings].
- Data Minimization Policy: UNICEFâs data protection rules in Gaza prohibit the storage of identifying information of beneficiaries under 18 years of age without explicit, documented caregiver consent to mitigate physical security risks to the population [Fragile Settings].
The Technical Genesis of DHIS2 Tracker
The core DHIS2 individual longitudinal tracking system (Tracker) was originally designed and piloted in Palestine between 2014 and 2016 through a joint initiative between the Palestinian Ministry of Health, the Norwegian Institute of Public Health, and the WHO to manage maternal and child health workflows [Closing Ceremony].
4. Lightning Talks: Community and System Sustainability
Samaritanâs Purse: Mobile Clinics in the United States
Samaritanâs Purse configures DHIS2 to manage temporary mobile medical, dental, and vision clinics [Lightning Talks]:
- Custom Android Fork: A customized fork of the Android Capture app reduces data entry steps for clinicians [Lightning Talks].
- Workflows: Triage operators scan QR codes on patient wristbands to register visits and trigger automated SMS alerts when clinical stations become vacant [Lightning Talks].
- De-identification: Patient diagnoses are kept on paper files given to the patient. All personally identifiable information is purged from the DHIS2 database post-clinic, leaving only de-identified, aggregate diagnostic codes for programmatic supply planning [Lightning Talks].
Tanzania: Community Health Worker (CHW) System
Tanzania has integrated 7,000 formalized Community Health Workers into its national digital health infrastructure [Lightning Talks]:
- The Pipeline: CHWs are registered in the national Human Resources for Health Information System (HRHIS) and utilize the offline-capable Unified Community System (UCS) on mobile devices to document community services [Lightning Talks].
- Payments: Completed activities in UCS are transmitted to the HRHIS payroll database to trigger monthly mobile money payments based on verified work [Lightning Talks].
Sri Lanka: Documenting System Configuration
HISP Sri Lanka developed a Sustainable Documentation Package to prevent institutional âknowledge debtâ caused by staff turnover [Lightning Talks]. The documentation includes:
- A comprehensive Metadata Dictionary detailing the logical design and purpose of each program rule, data element, and validation rule [Lightning Talks].
- Step-by-step Standard Operating Procedures (SOPs) for routine administrative tasks to reduce support requests [Lightning Talks].
5. Sovereignty Checklist for Implementers
The digital sovereignty panel outlined a five-point evaluation checklist for health system architects: [Digital Sovereignty]
- Software License Model: Is the system built on open-source code that can run independently if vendor relations terminate? [Digital Sovereignty]
- Data Geography: Does patient-identifiable data exit the host nation, and what legal jurisdiction governs the processing servers? [Digital Sovereignty]
- Operational Ownership: Do local team members possess the technical credentials and training to manage the physical servers, or is the infrastructure dependent on external operators? [Digital Sovereignty]
- Ecosystem Portability: Is the software built on standard APIs, or does it utilize proprietary cloud services that prevent migration? [Digital Sovereignty]
- Capacity Investment: Are hosting budget savings actively allocated to training national developers and system administrators? [Digital Sovereignty]
6. Documented System Tensions and Constraints
- Commercial Rebranding of Sovereignty: Proprietary providers are marketing cloud-hosted services as âsovereign solutionsâ by hosting data centers inside national borders, while the underlying code, updates, and maintenance remain dependent on the vendor [Digital Sovereignty].
- The User-Demand Paradox: Increasing local user training does not make technical support teams obsolete [Country Stories]. As national and subnational users gain competency, their demand for complex database integrations, custom API routes, and advanced dashboards increases, requiring long-term technical partnerships [Country Stories].
- Humanitarian Data Fragmentation: Fragmented database deployments among separate humanitarian organizations lead to inconsistent reporting. In Somalia, 74 distinct health NGOs operate separate DHIS2 databases, creating conflicting coverage metrics [Fragile Settings].
7. What to Watch
The presentations are available on the DHIS2 YouTube channel:
- Digital Sovereignty â DAC2026
- From Information to Impact in Fragile Settings â DAC2026
- Lightning Talks: Community Health, Humanitarian & System Sustainability â DAC2026
- Country Stories: South Africa, China & Norway â DAC2026
- Closing Ceremony â DAC2026
Community Call to Action
Share your operational experiences in the thread below:
- How is your country program evaluating the trade-offs of on-premise vs. cloud-based hosting relative to data sovereignty regulations?
- What data minimization protocols has your organization implemented when deploying mobile systems in sensitive or conflict-affected regions?
- How does your team document and maintain institutional configuration knowledge to manage staff turnover?