Private: Beyond Epiverse: Lessons in Responsible Data and AI from Africa and Latin America

Protection Principles: Indicators and Solutions

Skip to Playbook Content
Explore Playbook

Protection Indicators in Practice

The indicators below translate protection principles into operational dimensions that organizations can monitor, evaluate, and strengthen over time. These indicators are not intended as rigid compliance measures, but as practical reference points for assessing the maturity and consistency of protection mechanisms across systems.

Interpreting maturity signals

🟢 Established
Mechanisms are formally implemented, consistently applied, and regularly reviewed.

🟡 Emerging
Mechanisms exist partially or inconsistently across projects or institutions.

🔴 Limited
Significant gaps remain in implementation, oversight, or operational consistency.

PrincipleOperational IndicatorExample MetricMaturity Signal
Human Data SecurityPrivacy safeguards integrated into workflows% of workflows using anonymization or pseudonymization procedures🟢 / 🟡 / 🔴
Human Data SecuritySensitive-data handling protocolsPresence of formal procedures for handling sensitive information🟢 / 🟡 / 🔴
Human Data SecurityPrivacy review practicesFrequency of privacy or ethics reviews conducted annually🟢 / 🟡 / 🔴
Safe DataAccess control mechanisms% of systems using role-based access permissions🟢 / 🟡 / 🔴
Safe DataLifecycle risk managementPresence of documented risk assessments across collection, storage, and sharing stages🟢 / 🟡 / 🔴
Safe DataSecure infrastructure practicesUse of encrypted storage and secure processing environments🟢 / 🟡 / 🔴
Data AccountabilityDocumentation and traceability% of projects using version control and audit logs🟢 / 🟡 / 🔴
Data AccountabilityGovernance clarityClearly assigned oversight and decision-making responsibilities🟢 / 🟡 / 🔴
Data AccountabilityReview and audit mechanismsNumber of governance or compliance reviews conducted per year🟢 / 🟡 / 🔴

Epiverse Evidence: What These Indicators Look Like in Practice

Applying the scale above to Epiverse itself, drawing on both interview rounds: 18 stakeholders across the wider ecosystem, and seven core team leads spanning technical, program, and community-building roles:

IndicatorEpiverse Maturity SignalEvidence From Interviews
Privacy safeguards integrated into workflows🟢Team leads described avoiding personal data by design: trainings and tools rely on sample, aggregated, or open-source data from the outset, rather than adding privacy protections after the fact.
Sensitive-data handling protocols🟢Countries retain full ownership of health data; differential privacy techniques are applied to sensitive datasets such as transaction data; contextual data (e.g., interview responses) follows informed-consent and data-minimization protocols.
Privacy review practices🟡A code of conduct for respectful, safe engagement is applied at all events, and data-ethics modules are embedded across trainings; however, no interviewee described a recurring, scheduled privacy review cycle distinct from general compliance work.
Access control mechanisms🟢Cloud infrastructure uses role-based access and two-factor authentication; masked or anonymized data is required whenever formal sharing agreements are not yet in place.
Lifecycle risk management🟢Secure transfer protocols (SFTP), formal data-sharing agreements with partner institutions, and consent requirements at collection, storage, and sharing stages were each independently described by different team leads.
Secure infrastructure practices🟢Cloud storage (AWS), encrypted transfer, and backup practices were described in technical detail by the team responsible for software architecture.
Documentation and traceability🟢Full development transparency through open, public repositories with traceable change logs was described as a project-wide norm, reinforced by open external code review.
Governance clarity🟡Responsibility is expected to sit at the institutional level and is exercised through a single designated point of accountability, but team members across roles described this as an expectation rather than a formally documented governance structure.
Review and audit mechanisms🟡Internal systems are described as audited for compliance and GDPR alignment is consistently referenced, but interviewees also acknowledged the absence of a structured, recurring audit or feedback-loop process for the initiative as a whole.

Overall assessment across both interview rounds: Human Data Security and Safe Data are the most consistently operationalized principles in Epiverse, with strong legal, technical, and procedural safeguards aligned across roles. Governance clarity and review/audit mechanisms remain the weaker sub-dimensions within Protection.

Using Indicators in Practice

Indicators should not be interpreted as isolated metrics. Their value lies in supporting reflection, identifying implementation gaps, and guiding institutional improvement over time.

In practice, organizations may use these indicators to:

  • assess governance maturity across projects
  • identify areas requiring additional safeguards or resources
  • support accountability and reporting processes
  • strengthen consistency across institutions and teams

Importantly, implementation levels may vary depending on context, institutional capacity, and regulatory conditions. As a result, indicators should be understood as adaptive tools rather than universal benchmarks.

Practice Highlight

Info

Within Epiverse, institutional actors point to GDPR-aligned data handling, national data ownership arrangements, and open-source review of underlying models as the concrete mechanisms that make protection auditable rather than aspirational. Model transparency here is not a generic commitment—code and documentation remain open to external review, which several participants described as one of the ecosystem’s strongest accountability guarantees, precisely because it does not depend on any single institution’s goodwill.

While indicators help organizations identify the presence of protection mechanisms, assessing the consistency and institutional integration of these mechanisms requires a broader governance perspective.

To support this process, organizations may use a governance maturity framework that evaluates how protection principles evolve from informal practices into stable institutional capabilities.

Rather than functioning as a compliance score, the framework provides a structured approach for:

  • identifying implementation gaps,
  • prioritizing governance improvements,
  • supporting institutional learning,
  • and strengthening long-term operational resilience.

The maturity model reflects a progressive transition: from isolated safeguards toward integrated governance systems embedded across technical, institutional, and operational processes.

Importantly, maturity should not be interpreted as a fixed endpoint. Organizations may operate at different maturity levels across principles depending on context, institutional capacity, and regulatory environments.

Protection Governance Maturity Scale

Maturity LevelGovernance CharacteristicsOperational Signals
Level 1:
Ad hoc
Protection practices depend primarily on individual initiativeInformal safeguards, inconsistent procedures, limited documentation
Level 2:
Emerging
Basic governance mechanisms are introduced across selected projectsPartial protocols, inconsistent implementation, limited review practices
Level 3:
Structured
Protection mechanisms are formally documented and operationalizedDefined responsibilities, regular risk reviews, standardized workflows
Level 4:
Operationalized
Governance processes are integrated across institutional activitiesCross-team coordination, monitored safeguards, recurring audits
Level 5:
Institutionalized
Protection principles are embedded into long-term governance structures and continuously improvedAdaptive governance, continuous monitoring, institutional accountability culture

The maturity framework allows organizations to evaluate protection not only through technical safeguards, but through institutional consistency, governance integration, and long-term sustainability.

The framework may also support:

  • governance benchmarking across projects,
  • institutional self-assessment,
  • implementation planning,
  • and capacity-building prioritization.

Importantly, organizations may demonstrate strengths in some dimensions while remaining underdeveloped in others. As a result, maturity assessment should support reflection and improvement rather than rigid classification.

Evidence Sources and Verification Methods

Operational DimensionExample Evidence SourceVerification Method
Privacy safeguardsData-handling protocolsPolicy and workflow review
Sensitive-data proceduresInternal governance documentationCompliance assessment
Access control mechanismsPermission management systemsTechnical audit
Lifecycle risk managementRisk assessment recordsGovernance review
Documentation and traceabilityVersion-control systems and audit logsProcess verification
Governance clarityOrganizational responsibility mapsInstitutional review
Review and audit mechanismsGovernance meeting records and reportsAudit tracking

Self-Assessment Scale

To move from the qualitative maturity signals above to a practical self-assessment, organizations can score each indicator on a 1–5 scale. The Epiverse examples referenced earlier in this chapter illustrate what a high score looks like in practice. They serve as a benchmark, not as items to be scored themselves.

Likert scale key: 1 = Not implemented • 2 = Ad hoc • 3 = Partially implemented • 4 = Consistently applied • 5 = Fully institutionalized

Scoring guide (average across items):

• 1.0–1.9 → Ad hoc • 2.0–2.9 → Emerging • 3.0–3.9 → Structured • 4.0–4.5 → Operationalized • 4.6–5.0 → Institutionalized

Having seen where Epiverse stands qualitatively earlier in this chapter, the same evaluation can now be expressed numerically below, using the Likert scale introduced above.

Epiverse Example Scoring: Protection indicators

Using the Likert scale key above, each Protection indicator can be scored individually and verified against a specific evidence basis—the same logic used in the Evidence sources and verification methods table, applied here to Epiverse’s own results.

Operational DimensionEpiverse Likert Score (1–5)Verification Basis
(Interview Evidence)
Privacy safeguards integrated into workflows4Policy and workflow review: aggregated or sample data used by design across trainings and tools, confirmed by multiple team leads independently.
Sensitive-data handling protocols4Compliance assessment: differential privacy techniques, national data ownership, and informed-consent protocols confirmed across technical and program roles.
Privacy review practices3Institutional review: a code of conduct and data-ethics training modules confirmed, but no dedicated recurring review cycle identified.
Access control mechanisms4Technical audit: role-based access and two-factor authentication confirmed through direct technical description.
Lifecycle risk management4Governance review: secure transfer protocols and data-sharing agreements confirmed across collection, storage, and sharing stages.
Secure infrastructure practices4Technical audit: cloud storage (AWS), encrypted transfer, and backup practices confirmed by the software architecture team.
Documentation and traceability5Process verification: full transparency through open, public repositories and external code review confirmed as a consistent, ongoing practice.
Governance clarity2Institutional review: responsibility described as an informal expectation rather than a documented responsibility map.
Review and audit mechanisms3Audit tracking: internal audits and GDPR alignment referenced, but no structured, recurring audit cycle confirmed.

Average score: 3.7 / 5 → Structured. Protection principles in Epiverse are formally documented and largely operationalized; governance clarity is the primary gap on the path toward full institutionalization.

Protection Governance Cycle

Risk Identification
↓
Protection Design
↓
Implementation of Safeguards
↓
Monitoring and Review
↓
Governance Adjustment
↓
Continuous Institutional Learning

This governance cycle reflects the adaptive nature of protection within complex data ecosystems. Rather than relying on static safeguards, effective systems continuously evaluate emerging risks, institutional conditions, and operational challenges. Protection therefore becomes an ongoing governance process rather than a one-time technical intervention.

The interview findings suggest that sustainable protection depends not only on technical infrastructure, but also on institutional coordination, accountability practices, and the ability to adapt governance mechanisms over time.

Sample Evaluation Questions

checklist icon

The following questions can help organizations assess how protection principles are operationalized within their systems:

Human Data Security

  • Are privacy safeguards integrated from the beginning of system design?
  • Are sensitive-data handling procedures formally documented?
  • Are privacy risks reviewed regularly?

Safe Data

  • Are access permissions clearly defined and monitored?
  • Are risks assessed across the full data lifecycle?
  • Are technical safeguards consistently applied across environments?

Data Accountability

  • Are decision-making processes documented and traceable?
  • Are governance roles clearly assigned?
  • Are review and audit mechanisms conducted regularly?

Voices from Epiverse: Protection in Practice

Info
  • On access control (Safe Data): A technical program manager described access as differentiated by actor. Different roles require different permissions, and safety depends as much on who can reach the data as on what data exists.
  • On cross-border protection (Human Data Security): A Fellow from West Africa noted that protection can weaken once data crosses institutional or national boundaries. For example, safeguards need to travel with the data rather than stay tied to a single organization.
  • On demonstrable responsibility (Data Accountability): A researcher affiliated with a public health institution described a shift away from trusting individual practitioners’ judgment alone, toward explainability built into the system itself. Therefore, responsibility, in this framing, has to be demonstrable, not just assumed.

Risk Escalation and Governance Response

Not all governance risks operate at the same level of severity or institutional impact. In practice, organizations may encounter tensions between openness, collaboration, operational flexibility, and protection requirements.

To support proportional governance responses, institutions may classify risks according to:

  • severity,
  • scope of impact,
  • reversibility,
  • and institutional exposure.

This approach enables organizations to align safeguards with contextual risk conditions rather than applying uniform restrictions across all environments.

Protection Risk Severity Matrix

Risk LevelExample ScenarioGovernance ResponseEpiverse example
LowLimited operational inconsistency without sensitive exposureInternal process adjustmentPrivacy review practices score 3/5: a code of conduct and ethics training exist, but without a fixed recurring review cycle—a gap to note internally, not an active exposure.
ModerateIncomplete access-control procedures affecting multiple workflowsFormal governance review and mitigation planningReview and audit mechanisms score 3/5: GDPR alignment and internal audits are referenced, but without a structured, recurring audit cycle across the initiative as a whole.
HighSensitive-data exposure or significant governance failureImmediate containment, institutional oversight, and audit responseDocumented directly in “Voices from Epiverse”: a Fellow noted that protection can weaken once data crosses institutional or national boundaries—safeguards need to travel with the data, not stay tied to one organization.
SystemicRepeated governance breakdown across projects or institutionsStructural governance redesign and external reviewGovernance clarity is the lowest score in the chapter (2/5): responsibility is described as an informal expectation rather than a documented structure—if unaddressed, this is the indicator most likely to produce a systemic failure across multiple projects at once.

The purpose of risk classification is not only to manage incidents after they occur, but to strengthen institutional preparedness and governance responsiveness before failures emerge.

The research suggests that resilient systems combine preventive safeguards with adaptive governance processes capable of responding to evolving technical, institutional, and ethical conditions.

Stakeholder emphasisMain concernProtection focus
Technical contributorsSecure handling and infrastructureConfidentiality and operational safety
Governance actorsCompliance and oversightInstitutional accountability
Community practitionersVulnerability and trustRights protection and responsible use
Top Back to Top