African Digital Health Sovereignty Dataset (SGAF) (v1.0) : A Pan-African Audit of Data Governance Practices in 410 Digital Health Companies
收藏资源简介:
This dataset presents the results of a systematic, desk-based documentary audit of data governance practices across 410 digital health companies operating in 47 African markets, conducted in April 2026 using the Sovereignty Gap Audit Framework (SGAF). The Sovereignty Gap Audit Framework scores six dimensions of digital health data sovereignty, each on a 0-2 scale (maximum 12 points): D1 - Data Residency, D2 -Jurisdictional Anchor, D3 - Policy Transparency, D4 - Third-Party Analytics Disclosure, D5 - Infrastructure Independence, and D6 - Regulatory Compliance Citation. Companies are assigned to four governance bands: Critical (0-4), Moderate (5-7), Emerging (8 -10), and Sovereign (11-12). KEY FINDINGS:- 90% of active companies (294 of 327) score in the Critical band, no meaningful data governance- Mean SGAF score: 1.6 out of 12- No company across 410 audited entities achieves Sovereign governance (score 11-12)- Highest score achieved: 8/12- 87% of active companies cite no applicable data protection law despite 36 of 55 African Union member states having enacted data protection legislation- 21 of 24 companies reaching the Emerging band (≥8/12) are South African, a statistically significant pattern attributed to POPIA enforcement (the "POPIA effect"), replicated across an independent source dataset- Three distinct server jurisdiction failure modes identified: US cloud capture (CLOUD Act exposure, n=31), EU/UK capture (GDPR governance of African patients, n=6), and offshore default with no identifiable jurisdiction (n=244)- D6 (Regulatory Compliance Citation) functions as a jurisdictional proxy extending the methodology of Grundy et al. (2019, JAMA Network Open) to African digital health for the first time at continental scale DATASET COMPOSITION:- 410 companies across 47 African markets (pan-African scope)- 327 active (fully audited); 83 unknown status (pending October 2026 follow-up)- Sources: Ekundayo (2025) [DOI: 10.7910/DVN/SFCT6I], Okolo (2025) [DOI: 10.7910/DVN/Z0PKGO], PATH Africa-based Digital Health Entrepreneurs List 3 (2022), manual additions April 2026- QA verified: zero duplicate company names, all D1 - D6 scores sum to declared totals, all band assignments validated against score and operating status rules STRUCTURE:The dataset contains five sheets: Sheet1 (full 410-company audit data with all SGAF scores and evidence), Summary (key statistics and findings), README (dataset documentation), Field Definitions (column definitions and scoring logic), and Digital Health Registry (supplementary company metadata). LIMITATIONS:Scores reflect disclosed practices only, desk-based audit cannot verify undisclosed infrastructure. Absence of policy is scored as zero accountability, not as evidence of wrongdoing. The framework is preliminary and has not yet been externally validated. A 6 - month follow-up audit is planned for October 2026. This dataset is deposited on Zenodo (CERN infrastructure, EU jurisdiction) as a deliberate methodological choice: a dataset documenting African digital health data sovereignty should not itself be hosted on US cloud infrastructure subject to the CLOUD Act.



