Skip to main content
Opian Health
Legal

Data Protection Statement

Last updated April 2026

Introduction

This Data Protection Statement outlines how Opian thinks about health data sovereignty and protection in the context of our products and operations. This is distinct from our Privacy Policy, which covers opian.io only. This statement reflects Opian's commitment to protecting health data across all jurisdictions in which we operate.

Health data sovereignty as a principle

Opian operates on the principle that health data is a sovereign asset. Country health systems must own, control, and determine the use of their health data. This principle is foundational to all Opian products and operations.

We recognize that health data is sensitive, personal, and tied to national security and self-determination. Countries have the right and responsibility to:

  • Maintain health data within their own territory
  • Determine who has access to and how health data is used
  • Build national capacity to manage and protect health data
  • Authorize any cross-border data transfer with full knowledge and control

International data protection frameworks

Opian recognizes and aligns with international data protection commitments, including:

  • African Union Convention on Cyber Security and Personal Data Protection — Opian's operations in African countries comply with the AU's data protection and sovereignty principles.
  • National data protection frameworks — In each country where Opian operates, we comply with the national legal frameworks governing data protection and health information security.
  • WHO guidelines on data governance and protection — Opian aligns with WHO recommendations for data protection in health systems.

Opian's data protection posture

Country data stays in-country

All facility-level and patient-level health data remains within the country's borders and on infrastructure controlled by the country's ministry of health. Opian does not transfer health data across national borders without explicit ministry authorization.

On-premise deployment

Opian's platforms (ForLab+, Link) are designed for on-premise deployment on the country's own infrastructure. The system can run on the ministry's servers, regional networks, or facility-level hardware, depending on architecture and scale.

Offline-first architecture

All Opian systems are designed to operate offline and independently. This means:

  • Facilities can continue using the system even if internet or cloud connectivity is unavailable
  • Data is not transmitted to external cloud providers by default
  • Data syncing is optional and under the country's control

Link Hub on-premise options

Link Hub, Opian's clinical platform, supports fully on-premise installations with zero cloud dependency. A facility or regional health bureau can deploy Link entirely on local infrastructure and manage all patient data locally.

No cross-border health data transfer without authorization

Opian will not transfer health data across national borders without explicit, written authorization from the country's ministry of health. This applies to:

  • Individual patient records
  • Aggregated health statistics derived from national data
  • Facility-level operational data (consumption, diagnostics, outcomes)

Data protection responsibilities

While Opian commits to data sovereignty and protection, the country's ministry of health retains ultimate responsibility for:

  • Defining data governance policies and authorized uses
  • Implementing access controls and user authentication for health workers
  • Monitoring and auditing data access and use
  • Ensuring backup, recovery, and long-term data preservation
  • Enforcing confidentiality agreements with health workers and implementing partners

Data protection by design

All Opian systems are built with data protection as a core requirement, not an afterthought. This includes:

  • End-to-end encryption for data in transit (HTTPS minimum)
  • Encryption at rest for sensitive health data
  • Role-based access control for user types and facilities
  • Audit logging of data access and modifications
  • Secure data deletion and disposal procedures

Health data protection agreements

Opian enters into data protection agreements with each country's ministry of health that specify:

  • Ownership of health data and system infrastructure
  • Authorized users and access controls
  • Permitted uses of data (clinical care, planning, reporting, research)
  • Restrictions on cross-border data transfer
  • Audit and oversight mechanisms
  • Data retention, deletion, and transition procedures

Data breach response

In the event of a security incident or data breach, Opian will:

  • Immediately notify the country's ministry of health
  • Provide a detailed incident report including scope, cause, and remediation
  • Work with the ministry to notify affected individuals if required by law
  • Implement measures to prevent similar incidents in the future

Questions or concerns

If you have questions about Opian's data protection practices or wish to report a data protection concern, please contact:

Email: privacy@opian.io
Address: Opian Information Communication Tech PLC, Addis Ababa, Ethiopia

Last reviewed: April 2026