Private: Beyond Epiverse: Lessons in Responsible Data and AI from Africa and Latin America

The Protection Layer

Skip to Playbook Content
Explore Playbook

Audience

Person icon
  • Builders: Learn how to embed protection mechanisms into system design and data workflows.
  • Funders: Understand how investment in safeguards strengthens trust, scalability, and long-term impact.
  • Partners: Recognize how protection enables safe collaboration across institutions and contexts.

Overview

As data systems expand in scale and complexity, the question of protection becomes central. In global health contexts, where sensitive data, vulnerable populations, and high-stakes decisions intersect, protection is not only a technical requirement; it is the foundation of trust.

Within Epiverse, protection is not treated as a single mechanism but as a layered system of safeguards. It ensures that individuals are protected from harm, that data is handled responsibly, and that decisions can be traced and justified. This layer brings together three principles: Human Data Security, Safe Data, and Data Accountability.

Together, these principles define how data systems remain reliable, secure, and ethically grounded across their lifecycle.

Protection in data systems is not only about preventing harm—it is about ensuring that systems remain trustworthy as they scale and evolve.”

Project perspective

Human Data Security: Protecting People, Not Just Data

Human Data Security places the individual at the center of data systems. It recognizes that data is not neutral; it represents people, often in contexts of vulnerability. As such, protection must go beyond technical safeguards and address issues of dignity, rights, and power.

In practice, this principle emphasizes:

  • minimizing exposure of sensitive data
  • ensuring privacy-by-design
  • protecting individuals regardless of who accesses or processes the data

The research shows a shift from ethical care (individual responsibility) toward rights-based protection embedded in governance and infrastructure. This ensures that protection does not depend solely on trust in actors, but is guaranteed by the system itself.

Safe Data: Managing Risk Across the System

While Human Data Security focuses on individuals, Safe Data addresses the system as a whole. It emphasizes the need to manage risks throughout the entire data lifecycle—from collection to storage, analysis, and sharing.

Rather than eliminating risk entirely, Safe Data operates through proportional risk management, balancing openness and protection.

Key mechanisms include:

  • controlled access and permissions
  • data minimization
  • secure storage and processing environments
  • validation and review before deployment

The research highlights that safety evolves from a precautionary approach (avoiding harm) to a systemic approach (managing ongoing risk across complex environments).

Data Accountability: Making Responsibility Visible

Data Accountability ensures that actions within the system can be traced, explained, and justified. It transforms responsibility from an implicit expectation into a visible and enforceable property of the system.

This includes:

  • documentation of processes and decisions
  • version control and reproducibility
  • clearly defined roles and responsibilities
  • mechanisms for audit and review

A key insight from the research is the shift from individual accountability to infrastructural accountability, where responsibility is embedded in systems rather than relying solely on personal integrity.

Academic grounding: Protection in data governance

Info
  1. Privacy by design
    Protection should be embedded into system architecture from the outset, not added later
  2. Risk-based governance
    Data systems must continuously assess and manage risks across the data lifecycle
  3. Rights-based approaches
    Protection should safeguard dignity, privacy, and fundamental rights across contexts
  4. Accountability in complex systems
    Responsibility must be traceable, explainable, and supported by system-level mechanisms

A Layered Protection Model

The three principles operate together as a coordinated system:

  • Human Data Security ensures that individuals are protected.
  • Safe Data ensures that risks are managed across the system.
  • Data Accountability ensures that actions are visible and traceable.

This layered model allows protection to function across different dimensions simultaneously, reinforcing both ethical integrity and operational reliability.

PrincipleWhat it ProtectsKey MechanismsRisk if Absent
Human Data SecurityIndividualsPrivacy-by-design, data minimizationHarm, loss of dignity, exposure
Safe DataData systemsAccess control, lifecycle governanceMisuse, breaches, instability
Data AccountabilityProcesses & decisionsDocumentation, auditability, traceabilityLack of trust, no responsibility

Balancing Protection and Openness

A recurring tension within the protection layer concerns the balance between openness and restriction. Open systems enable collaboration, innovation, and scalability. However, they also introduce risks if safeguards are insufficient.

The research shows that effective systems do not choose between openness and protection. Instead, they adopt a calibrated approach, where access, sharing, and use are aligned with risk levels and contextual conditions.

This balance is essential in global health environments, where data must often move across institutions and borders while maintaining consistent standards of protection. While the protection layer focuses on safeguarding individuals and systems, it does not address who participates in shaping those systems. The next chapter shifts the focus from protection to participation, exploring how inclusivity and community shape the legitimacy and effectiveness of data ecosystems.

Top Back to Top