NIGERIAMRS MOBILE APPLICATION PRIVACY POLICY
1. Introduction
This Privacy Policy explains how NigeriaMRS Mobile Application ("NigeriaMRS", "the Application", "we", "us", or "our") collects, uses, stores, protects, and otherwise processes personal data when you use the NigeriaMRS Mobile Application.
NigeriaMRS is a digital health information application designed to support authorized healthcare personnel and other approved users in accessing and managing health-related information and services.
We are committed to protecting the privacy, confidentiality, and security of personal data processed through NigeriaMRS and to complying with applicable data protection and privacy laws, including the Nigeria Data Protection Act, 2023 (NDPA) and applicable regulations and guidance issued by the Nigeria Data Protection Commission (NDPC).
The NDPA establishes requirements for fair, lawful, transparent, secure, and accountable processing of personal data and provides data subjects with rights over their personal information.
2. Data Controller
The organization responsible for determining the purposes and means of processing personal data through NigeriaMRS is Centre for Integrated Health Programs.
Where NigeriaMRS is operated on behalf of a government agency, healthcare organization, implementing partner, or other institution, that organization may act as the Data Controller for the personal data processed through the Application.
Where third parties process personal data on behalf of the Data Controller, such parties may act as Data Processors and are required to process personal data in accordance with applicable data protection requirements and contractual obligations.
3. Scope of this Privacy Policy
This Privacy Policy applies to personal data processed through:
- The NigeriaMRS Mobile Application;
- Associated NigeriaMRS backend systems;
- Application programming interfaces (APIs);
- Authorized healthcare information systems connected to NigeriaMRS;
- Authentication and user-management services; and
- Other services directly supporting the operation of NigeriaMRS.
This Policy applies to patients, healthcare workers, system administrators, authorized users, and other individuals whose personal data may be processed through the Application.
4. Information We Collect
Depending on how NigeriaMRS is configured and how you use the Application, we may process the following categories of information.
4.1 User Account Information
For authorized users, we may collect:
- Full name;
- Username or user ID;
- Email address;
- Telephone number;
- Organization or facility;
- Professional role;
- User role and permissions;
- Login and authentication information;
- Account status; and
- Audit information associated with account activity.
Passwords and authentication credentials are protected using appropriate technical security measures and should never be shared with another person.
4.2 Patient Information
Where NigeriaMRS is used to provide or support healthcare services, it may process patient information such as:
- Patient name;
- Patient identification number;
- Date of birth or age;
- Sex;
- Contact information;
- Address or location information;
- Healthcare facility information;
- Clinical history;
- Medical diagnoses;
- Treatment information;
- Laboratory results;
- Medication information;
- Appointment and visit information;
- HIV/TB or other programme-related information, where applicable;
- Treatment and clinical monitoring information; and
- Other information necessary for the provision, management, monitoring, reporting, or continuity of healthcare services.
Because health information can be highly sensitive, access is restricted to authorized users with a legitimate need to access the information.
4.3 Device and Technical Information
The Application may automatically process limited technical information required for security, troubleshooting, and operation, including:
- Device type;
- Operating system;
- Application version;
- Device identifiers, where technically required;
- IP address;
- Login date and time;
- Authentication events;
- Application errors and diagnostic information; and
- Security and audit logs.
We only collect technical information that is reasonably necessary for legitimate operational, security, and support purposes.
4.4 Location Information
NigeriaMRS does not continuously collect precise GPS location information unless a specific feature requires it and the relevant functionality has been enabled.
Where location information is required, the Application will request the appropriate permission and explain the purpose for which the information is required.
5. How We Use Personal Data
Personal data processed through NigeriaMRS may be used for the following purposes:
- To provide authorized healthcare and health information services;
- To support patient registration and identification;
- To support clinical and programme-related activities;
- To maintain accurate healthcare records;
- To facilitate continuity and coordination of care;
- To support healthcare programme monitoring and reporting;
- To authenticate and manage authorized users;
- To manage user roles and access privileges;
- To maintain system security;
- To detect and prevent unauthorized access or misuse;
- To maintain audit trails and accountability;
- To troubleshoot technical problems;
- To improve system performance and reliability;
- To comply with applicable legal and regulatory requirements;
- To support public health activities where legally authorized; and
- For other legitimate purposes communicated to data subjects or permitted by applicable law.
We will not use personal data for purposes that are incompatible with the purpose for which it was originally collected unless such processing is permitted or required by applicable law.
6. Lawful Basis for Processing
We process personal data only where there is a lawful basis for doing so under applicable data protection law.
Depending on the circumstances, the lawful basis may include:
- Legal obligation;
- Performance of a contract;
- Consent, where required;
- Protection of vital interests;
- Public interest or exercise of official authority, where applicable; and
- Legitimate interests, where permitted by law and where those interests do not override the rights and freedoms of the data subject.
For health-related information, additional safeguards may apply because such information may constitute sensitive personal data.
Where consent is the lawful basis for processing, you may withdraw your consent where permitted by law. Withdrawal of consent will not affect processing that was lawfully carried out before withdrawal.
7. Health and Sensitive Personal Data
NigeriaMRS may process information relating to an individual's physical or mental health, treatment, diagnosis, laboratory results, medication, or other healthcare information.
Such information requires a high level of confidentiality and security.
Access to health information is therefore controlled through measures such as:
- User authentication;
- Role-based access control;
- Least-privilege access;
- User account management;
- Audit logging;
- Secure communication;
- Encryption where appropriate;
- System monitoring;
- Access reviews; and
- Other technical and organizational safeguards.
Users must only access patient information where they are authorized and have a legitimate professional or operational need to do so.
8. User Authentication and Access Control
NigeriaMRS uses access-control mechanisms to help ensure that personal data is only accessible to authorized users.
User access may be determined by:
- User role;
- Organization or facility;
- Assigned responsibilities;
- System privileges;
- Programmatic requirements; and
- Other authorization rules.
Users are responsible for maintaining the confidentiality of their login credentials and must not:
- Share usernames or passwords;
- Allow another person to use their account;
- Attempt to bypass access controls;
- Access records without authorization; or
- Use another person's account.
Where suspicious or unauthorized activity is identified, access may be suspended or revoked.
9. Confidentiality of Patient Information
Patient information accessed through NigeriaMRS is confidential.
Users must comply with applicable professional, organizational, ethical, and legal requirements governing confidentiality of health information.
Unauthorized disclosure, copying, downloading, photographing, transmission, or use of patient information is prohibited.
Where information must be shared with another organization or individual, such sharing must be authorized and conducted in accordance with applicable law and organizational policies.
10. Data Sharing and Disclosure
We may disclose or make personal data available to authorized parties where necessary and lawful.
These parties may include:
- Authorized healthcare facilities;
- Healthcare professionals;
- Government health authorities;
- Authorized public health programmes;
- System administrators;
- Authorized service providers;
- Data hosting and infrastructure providers;
- Technology and support providers;
- Auditors or compliance professionals; and
- Law enforcement or regulatory authorities where required or permitted by law.
We do not sell personal health information or personal data to third parties for advertising purposes.
Where third-party service providers process personal data on our behalf, appropriate contractual, technical, and organizational safeguards will be used to protect the information.
11. Third-Party Service Providers
NigeriaMRS may rely on trusted third-party providers for services such as:
- Cloud hosting;
- Database hosting;
- Authentication;
- Application monitoring;
- Security services;
- Infrastructure management;
- Technical support; and
- Other services required to operate the Application.
Third-party providers are expected to process personal data only for authorized purposes and to implement appropriate security safeguards.
A list of material third-party processors may be made available upon request where appropriate.
12. International Data Transfers
Where personal data is transferred, stored, or processed outside Nigeria, appropriate safeguards will be implemented in accordance with applicable Nigerian data protection requirements.
Such safeguards may include contractual protections, appropriate security measures, adequacy mechanisms, or other lawful transfer mechanisms.
Where required by law, users will be provided with appropriate information concerning such transfers.
13. Data Security
We implement reasonable technical and organizational measures designed to protect personal data against:
- Unauthorized access;
- Unauthorized disclosure;
- Accidental loss;
- Destruction;
- Alteration;
- Misuse;
- Unlawful processing; and
- Other security threats.
Security measures may include:
- Authentication and authorization controls;
- Role-based access control;
- Encryption in transit;
- Encryption at rest where appropriate;
- Secure API communication;
- Password protection and secure credential management;
- Audit logging;
- System monitoring;
- Vulnerability management;
- Security updates;
- Backup and recovery procedures;
- Access reviews; and
- Incident response procedures.
No electronic system can be guaranteed to be completely secure. However, we continuously seek to improve the security and resilience of NigeriaMRS.
14. Data Breach and Security Incidents
If we become aware of a personal data breach or security incident affecting personal data, we will assess and respond to the incident in accordance with applicable law and our incident-response procedures.
Where notification is required, we will notify the relevant regulatory authority and/or affected individuals within the applicable legal timeframe.
15. Data Retention
We retain personal data only for as long as reasonably necessary to fulfill the purposes for which it was collected, comply with legal and regulatory requirements, maintain healthcare records, resolve disputes, enforce agreements, maintain security, or satisfy legitimate operational requirements.
Retention periods may vary depending on:
- The type of information;
- The purpose for which it was collected;
- Applicable healthcare-record requirements;
- Legal and regulatory obligations;
- Programme requirements; and
- Security and audit requirements.
When personal data is no longer required, it will be securely deleted, anonymized, or otherwise disposed of in accordance with applicable requirements.
16. Data Accuracy
We take reasonable steps to ensure that personal data processed through NigeriaMRS is accurate, complete, and up to date for the purposes for which it is used.
Users may be required to correct or update information where inaccuracies are identified.
Where you believe information about you is inaccurate, you may contact the Data Controller using the contact details provided in this Policy.
17. Your Data Protection Rights
Subject to applicable law and any lawful limitations, data subjects may have rights including:
- The right to be informed about the processing of personal data;
- The right to request access to personal data;
- The right to request correction or rectification of inaccurate information;
- The right to request erasure of personal data where applicable;
- The right to restrict certain processing;
- The right to object to certain processing;
- The right to data portability where applicable;
- The right to withdraw consent where consent is the lawful basis;
- The right to object to certain automated decision-making;
- The right to lodge a complaint with the relevant data protection authority; and
- Other rights provided under applicable data protection law.
The NDPC identifies these rights, including access, rectification, objection, restriction, portability, erasure, and rights relating to automated decision-making, among the rights available to data subjects under the NDPA.
18. Cookies and Similar Technologies
The NigeriaMRS Mobile Application may use technically necessary technologies, identifiers, logs, or similar mechanisms required to:
- Maintain secure sessions;
- Authenticate users;
- Maintain application functionality;
- Detect security incidents;
- Monitor system performance; and
- Diagnose technical problems.
Where non-essential tracking technologies are used, appropriate information and choices will be provided in accordance with applicable law.
19. Offline Data and Device Storage
Where NigeriaMRS provides offline functionality, some information may temporarily be stored on the user's mobile device to enable authorized functionality.
Users should:
- Keep their devices secure;
- Use device-level authentication;
- Avoid sharing devices used to access NigeriaMRS;
- Report lost or stolen devices immediately; and
- Log out or lock the Application when it is not in use.
Where offline storage is implemented, appropriate technical controls should be applied to protect locally stored information.
20. Application Permissions
Depending on the features enabled in NigeriaMRS, the Application may request permissions such as:
- Internet/network access;
- Camera access;
- File or document access;
- Location access; or
- Other device permissions.
Permissions will only be requested where reasonably necessary for a specific Application function.
You may manage permissions through your device settings. Disabling certain permissions may prevent specific features from functioning correctly.
21. Links to Other Applications or Websites
NigeriaMRS may contain links or integrations to external applications, websites, or services.
We are not responsible for the privacy practices, security, or content of third-party services that we do not control.
Users should review the privacy policies of third-party services before providing personal information through those services.
22. Privacy by Design and Default
Privacy and data protection are incorporated into the design and operation of NigeriaMRS.
Where applicable, we seek to apply privacy-by-design and privacy-by-default principles, including:
- Data minimization;
- Purpose limitation;
- Least-privilege access;
- Role-based access;
- Security by design;
- Secure authentication;
- Appropriate encryption;
- Auditability;
- Controlled data sharing; and
- Appropriate retention and deletion practices.
The NDPC's guidance specifically recognizes privacy by design and default as an important requirement for software processing personal data.
23. Data Protection Impact Assessment
Where required by applicable law or where processing presents a high risk to individuals' privacy, an appropriate Data Protection Impact Assessment (DPIA) will be conducted.
The DPIA may consider:
- The categories of personal data processed;
- The sensitivity of health information;
- The purposes of processing;
- Potential risks to data subjects;
- Data flows;
- Third-party processors;
- Security controls;
- Data retention;
- Access controls; and
- Measures to mitigate identified privacy risks.
24. Changes to this Privacy Policy
We may update this Privacy Policy periodically to reflect:
- Changes to NigeriaMRS;
- Changes to applicable laws or regulations;
- Changes to data-processing activities;
- New security measures; or
- Changes in our organizational practices.
When significant changes are made, we will provide an appropriate notice through the Application or other suitable communication channels.
The "Last Updated" date at the beginning of this Policy indicates when the Policy was most recently revised.
25. Acceptance
By using NigeriaMRS, you acknowledge that you have been provided with information concerning the processing of personal data through the Application.
Where consent is required as the lawful basis for a particular processing activity, consent will be obtained separately and in an appropriate manner.
This Privacy Policy does not replace any specific consent notice, patient information notice, organizational privacy policy, healthcare confidentiality policy, or other legal notice that may apply to a particular processing activity.