Open search
Accessibility
Piret Hirv blog

Why data governance defines digital cooperation

Written by Piret Hirv, Head of AI and Data Management Competence Centre

Digital public services now depend on data. Health systems, schools, social protection agencies, tax authorities, and local governments all rely on information that moves between institutions and systems, and sometimes across borders.

That makes data sovereignty and privacy practical questions, not abstract policy language.

Citizens encounter these questions when they register for a health service, apply for support, check their record, or ask who has accessed their information.

The practical issue is trust. People need to know why their data is collected, who can use it, how long it will be kept, and what happens if something goes wrong.

Partners need clarity, too. Without shared rules, even useful cooperation can become politically fragile.

On 4 December 2025, Kenya and the United States signed a five-year Health Cooperation Framework to strengthen disease surveillance and support essential health programmes.  The agreement quickly sparked public debate about how sensitive health data would be governed, protected and shared.

Legal challenges soon followed, prompting a broader national conversation about data protection, public participation and institutional safeguards. Despite the ongoing legal process, both countries continued developing implementation arrangements under the framework.

Shared rules create trust

Kenya is not alone in facing this problem. Across the world, governments are expanding digital public services while relying on international partnerships, donor funding and shared technology platforms.

As more information moves between institutions and across borders, questions about who controls that data and under what conditions become harder to avoid.

Citizens may welcome better services, but they also want to know who can access their information, how it will be used and what safeguards apply once it leaves the system that collected it.

Effective international cooperation depends on addressing these concerns rather than treating them as secondary. Partnerships are more resilient when the rules governing data are clear.

Public confidence is easier to maintain when people understand why data is being collected, who is responsible for it, and what protections are in place.

Decisions about access, sharing, retention and deletion determine how data moves through public services.

Clear oversight arrangements help ensure that information is used only for legitimate purposes, that responsibilities are understood, and that safeguards are established before data moves between organisations or jurisdictions.

Where these arrangements are still developing, even well-intentioned agreements can become contentious. The challenge is rarely the technology itself. More often, it is uncertainty about accountability, oversight, and the limits on data use.

The Kenyan debate illustrates how quickly public confidence can erode when those questions are left unanswered.

Clear rules help address that risk by ensuring that personal data is shared only when there is a lawful basis, appropriate protection measures, and clear lines of responsibility for its handling.

From principles to practice

Purpose limitation is one of the most important safeguards in any data-sharing arrangement.

Before information is collected or exchanged, organisations should be clear about why it is needed and how it will be used. Without those boundaries, data gathered for one purpose can gradually be reused for others that were never anticipated or communicated.

Clear purpose definitions protect individuals and give institutions and partners a clearer boundary between permitted and prohibited use. Rights and accountability matter just as much.

People are more likely to trust digital services when they can understand how their information is being used, access their records, correct inaccuracies, and seek redress when something goes wrong.

In practice, this means giving consent where required, establishing access rights and complaint mechanisms in everyday operations rather than treating them as afterthoughts.

The challenge is not simply collecting data but managing it responsibly as it moves between systems and organisations.

A health ministry, for example, may need to share disease surveillance information with international partners without granting access to identifiable patient records.

Achieving that balance depends on practical safeguards such as role-based access controls, encryption, audit logs, and the classification of sensitive information. These measures help limit access to authorised users and make misuse easier to detect and investigate.

Transparency reinforces those safeguards. When organisations document how data is used, who can access it and under what authority, they make decisions easier to scrutinise and explain.

Audit trails and independent oversight cannot eliminate every concern, but they provide evidence that agreed-upon rules are being followed and help resolve disputes when questions arise.

Attention to the full data lifecycle is equally important.Decisions about retention are often overlooked, yet they can create significant long-term risks.

Subject to legal retention requirements, personal information should not remain in active systems longer than necessary simply because storage is available.

Clear retention schedules, deletion procedures and archiving rules help reduce unnecessary exposure, particularly for sensitive information such as health records, where the consequences of unauthorised access may persist for years.

Strong governance reduces the risk of data colonialism

Taken together, these safeguards do more than protect personal information; they shape the terms on which countries participate in the digital economy.

International cooperation increasingly depends on the exchange of data, yet concerns about control, accountability and benefit-sharing can quickly undermine public confidence.

Clear rules on data use, access and oversight help countries engage with external partners without relinquishing control over data that underpins public services and policy decisions.

They also reduce the risk of arrangements in which value flows disproportionately to those with greater technological or financial leverage.

The benefits are particularly visible in public services. Citizens are more likely to use digital platforms when they understand how their information is handled and believe appropriate safeguards are in place.

Higher levels of participation can improve the quality of administrative data, helping governments design policies, allocate resources, and evaluate outcomes more effectively.

In this way, data becomes a strategic public asset that supports better decision-making rather than simply a resource to be collected and exchanged.

The debate surrounding the Kenya–United States health cooperation framework highlights a broader lesson. Disputes over data are rarely about technology alone.

They often reflect deeper questions about who makes decisions, who is accountable, and how public interests are protected as information crosses institutional or national boundaries.

Addressing those questions requires more than legislation. It requires capable institutions, clearly defined responsibilities, effective oversight, and safeguards that can be applied consistently in practice.

The work is never finished. New technologies, evolving public expectations, and increasingly complex partnerships will continue to test existing frameworks.

Countries that invest in strong governance arrangements are better positioned to adapt to those changes, cooperate on equal terms, and ensure that digital transformation improves services without weakening accountability.