Data Management
Acknowledgement: Shared by Peter Bamuhigire, techguypeter.com, +256 784 464178.
Use When
- Use this skill when the assignment explicitly needs data-management, governance, privacy, or information-system content.
- Load it when another proposal section needs this domain expertise.
Do Not Use When
- The task only needs formatting or proposer-profile selection.
- Another supporting skill is a closer fit for the assignment.
Required Inputs
| Artefact |
Source |
Required? |
If absent |
| Data purpose, sources, subjects, flows, and outputs |
ToR and system owners |
required |
Stop detailed design and issue a data-discovery request. |
| Law, consent, retention, access, and quality evidence |
Authoritative rules and client controls |
conditional |
Mark compliance and quality controls unassessed. |
Workflow
Stop or block the workflow when a required input, permission, or acceptance basis is missing. Recover by revising the scope, obtaining evidence, or returning the narrowest qualified draft before proceeding.
- Identify where data collection, governance, quality, or protection matters in the assignment.
- Read the local references only where they materially improve the output.
- Convert the guidance into proposal-ready controls, activities, and ownership logic.
- Integrate the result into the target section and check for consistency.
Quality Standards
- Translate theory into practical proposal language, outputs, and safeguards.
- Keep the approach specific to the client context and implementation reality.
- Preserve compatibility with existing repository workflows and file paths.
Anti-Patterns
- Naming governance or privacy frameworks without operational controls. Fix: name sources, owners, flows, access, and outputs.
- Collecting data without a decision use. Fix: map every dataset to a stated purpose.
- Promising compliance from memory. Fix: verify the jurisdiction and client policy.
- Treating missing values as zero. Fix: define validation, exception, and remediation rules.
- Migrating before reconciliation. Fix: profile, map, test, reconcile, and approve before cutover.
Outputs
| Artefact |
Consumer |
Acceptance condition |
| Data management plan |
Evaluator, data owner, delivery team |
Covers flows, ownership, quality, protection, retention, access, migration, and acceptance. |
Evidence Produced
| Evidence |
Consumer |
Acceptance condition |
| Data inventory and quality-control matrix |
Traceable register |
Every material source has owner, purpose, checks, exceptions, and disposition. |
Capability and Permission Boundaries
Read and search are required; any edit or external action remains within the explicit authority and permission boundary stated below.
Default to read-only inspection. Editing requires authority; personal or client data access must be least-privilege. Do not move, delete, publish, or certify data without explicit approval.
Degraded Mode
Without datasets, system access, or verified law, return a data-discovery and control plan with unassessed items. Never report unavailable quality or compliance checks as passed.
Decision Rules
| Condition |
Action |
Risk avoided |
| Existing data may answer the question |
Profile and assess fitness first |
Unnecessary collection |
| Decision needs new primary data |
Design proportionate collection and consent |
Data without purpose |
| Migration changes records |
Reconcile samples and require owner sign-off |
Silent loss or duplication |
Worked Example
For a beneficiary MIS, inventory enrolment, service, and outcome data; assign stewards; validate identifiers and dates; and reconcile migrated totals before acceptance.
SaaS Data Implementation Plan
For SaaS lifecycle-communications scope and for any SaaS implementation that depends on segmentation, behavioural triggers, identity resolution, and operating-rule governance, scope and price a dedicated Data Implementation Plan workstream:
- Identify schema: customer, account, user, role, segment, lifecycle stage, lifecycle program flags.
- Event schema: signup, activation, in-product actions, billing events, support events, customer-success events.
- Custom fields: vertical-specific fields (insurance: policy count; banking: customer count, transaction volume; healthcare: facility, provider category).
- Identity resolution: linking the same user across product, marketing automation, CRM, support.
- Consent and preference management: lawful basis, opt-in records, channel preferences, frequency caps.
- Segmentation: standard segments at launch (by tier, lifecycle stage, health, industry).
- Data hygiene: bounce handling, suppression, decay, re-verification.
This is engineering-grade work — price it as such, not inside a bundled "email setup" line.
References
Assignments involving system implementations, M&E frameworks, surveys, or institutional assessments all require a data management component. Proposals that demonstrate a structured approach to data collection, storage, quality, governance, and protection score higher — particularly with donors who have been burned by projects that produced unusable data.
When to Read This Skill
- The assignment involves designing or implementing a management information system (MIS)
- The ToR mentions "data collection", "data management", "data quality", "data governance", or "data protection"
- The methodology includes surveys, assessments, or monitoring activities that generate data
- The assignment must comply with data protection legislation
- When the ToR asks for a standalone data management plan
Data Collection
Method Selection
| Method |
Best For |
Tools |
| Mobile data collection |
Field surveys, facility assessments, beneficiary registration |
ODK, KoBoToolbox, SurveyCTO |
| Paper-based forms |
Low-connectivity environments, sensitive data, legal requirements |
Standardised forms with clear coding |
| System-generated data |
Routine monitoring, transaction records, service delivery |
MIS, ERP, HMIS, EMIS |
| Administrative records |
Baseline data, historical trends, coverage statistics |
Government databases, reports |
| Key informant interviews |
Qualitative data, expert perspectives |
Interview guides, recording equipment |
Data Collection Standards
- Standardised tools: all data collection instruments piloted before deployment
- Enumerator training: minimum two days of training including field practice
- Quality checks: real-time validation in mobile tools, supervisor spot-checks for paper-based
- Consent: informed consent obtained and documented for all respondent data
- Unique identifiers: every record has a unique ID; no reliance on names alone
Data Quality Framework
The Five Dimensions of Data Quality
| Dimension |
Definition |
How to Verify |
| Validity |
Data measures what it is intended to measure |
Review instrument design, pilot testing |
| Reliability |
Consistent results across enumerators and time |
Inter-rater reliability tests, re-interviews |
| Completeness |
All required fields populated, no missing records |
Automated completeness checks, dashboard monitoring |
| Timeliness |
Data available when needed for decision-making |
Submission deadlines, real-time dashboards |
| Integrity |
Data protected from unauthorised alteration |
Access controls, audit trails, version control |
Data Quality Assurance Activities
- Pre-collection: instrument design review, pilot testing, enumerator certification
- During collection: daily data quality reports, supervisor verification, back-checks on 10% of submissions
- Post-collection: cleaning protocols (outlier detection, consistency checks, duplicate removal), validation against secondary sources
Data Governance
For system implementation and institutional assignments, propose a data governance structure:
- Data owner: the client department or unit responsible for each data set
- Data steward: the person responsible for data quality within each unit
- Access control: role-based access — who can view, edit, approve, and export
- Data dictionary: standardised definitions for all fields and indicators
- Retention and archival: how long data is kept, in what format, and when it is archived or destroyed
Data Protection Compliance
East African Data Protection Legislation
| Country |
Legislation |
Key Requirements |
| Uganda |
Data Protection and Privacy Act, 2019 |
Registration with PDPO, consent for processing, data minimisation, cross-border transfer restrictions |
| Kenya |
Data Protection Act, 2019 |
Registration with ODPC, consent, data subject rights, breach notification within 72 hours |
| Tanzania |
Personal Data Protection Act (under development) |
Follow emerging requirements; apply Kenya/Uganda standards as minimum |
| Rwanda |
Law Relating to the Protection of Personal Data and Privacy, 2021 |
Consent, purpose limitation, data subject rights, cross-border transfer restrictions |
Proposal Commitments
When processing personal data, the proposal should commit to:
- Data collection limited to what is necessary for the assignment (data minimisation)
- Informed consent obtained from all data subjects
- Data stored securely (encrypted at rest and in transit)
- Access restricted to authorised project personnel
- Data not transferred outside the country without appropriate safeguards
- Data retained only for the duration necessary, then securely destroyed
- Compliance with the applicable national data protection law
Generating a Standalone Section
When the ToR asks for a dedicated data management plan, generate a document covering:
- Data management approach and principles
- Data collection methods and tools
- Data quality assurance framework
- Data governance structure (roles, access controls, data dictionary)
- Data storage and security measures
- Data protection compliance (applicable legislation, consent, retention, destruction)
- Data analysis and reporting plan
- Data handover and sustainability
Follow east-african-english standards throughout.
1---2name: data-management3description: Use when a proposal covers data collection, quality, governance, MIS, surveys, protection, retention, or migration. Route outcome measurement to monitoring-and-evaluation; this skill governs the data lifecycle and controls.4---56# Data Management7Acknowledgement: Shared by Peter Bamuhigire, techguypeter.com, +256 784 464178.89<!-- dual-compat-start -->1011## Use When12- Use this skill when the assignment explicitly needs data-management, governance, privacy, or information-system content.13- Load it when another proposal section needs this domain expertise.1415## Do Not Use When16- The task only needs formatting or proposer-profile selection.17- Another supporting skill is a closer fit for the assignment.1819## Required Inputs20| Artefact | Source | Required? | If absent |21|---|---|---|---|22| Data purpose, sources, subjects, flows, and outputs | ToR and system owners | required | Stop detailed design and issue a data-discovery request. |23| Law, consent, retention, access, and quality evidence | Authoritative rules and client controls | conditional | Mark compliance and quality controls unassessed. |2425## Workflow2627Stop or block the workflow when a required input, permission, or acceptance basis is missing. Recover by revising the scope, obtaining evidence, or returning the narrowest qualified draft before proceeding.281. Identify where data collection, governance, quality, or protection matters in the assignment.292. Read the local references only where they materially improve the output.303. Convert the guidance into proposal-ready controls, activities, and ownership logic.314. Integrate the result into the target section and check for consistency.3233## Quality Standards34- Translate theory into practical proposal language, outputs, and safeguards.35- Keep the approach specific to the client context and implementation reality.36- Preserve compatibility with existing repository workflows and file paths.3738## Anti-Patterns39- Naming governance or privacy frameworks without operational controls. Fix: name sources, owners, flows, access, and outputs.40- Collecting data without a decision use. Fix: map every dataset to a stated purpose.41- Promising compliance from memory. Fix: verify the jurisdiction and client policy.42- Treating missing values as zero. Fix: define validation, exception, and remediation rules.43- Migrating before reconciliation. Fix: profile, map, test, reconcile, and approve before cutover.4445## Outputs46| Artefact | Consumer | Acceptance condition |47|---|---|---|48| Data management plan | Evaluator, data owner, delivery team | Covers flows, ownership, quality, protection, retention, access, migration, and acceptance. |4950## Evidence Produced51| Evidence | Consumer | Acceptance condition |52|---|---|---|53| Data inventory and quality-control matrix | Traceable register | Every material source has owner, purpose, checks, exceptions, and disposition. |5455## Capability and Permission Boundaries5657Read and search are required; any edit or external action remains within the explicit authority and permission boundary stated below.58Default to read-only inspection. Editing requires authority; personal or client data access must be least-privilege. Do not move, delete, publish, or certify data without explicit approval.5960## Degraded Mode61Without datasets, system access, or verified law, return a data-discovery and control plan with unassessed items. Never report unavailable quality or compliance checks as passed.6263## Decision Rules64| Condition | Action | Risk avoided |65|---|---|---|66| Existing data may answer the question | Profile and assess fitness first | Unnecessary collection |67| Decision needs new primary data | Design proportionate collection and consent | Data without purpose |68| Migration changes records | Reconcile samples and require owner sign-off | Silent loss or duplication |6970## Worked Example71For a beneficiary MIS, inventory enrolment, service, and outcome data; assign stewards; validate identifiers and dates; and reconcile migrated totals before acceptance.7273## SaaS Data Implementation Plan7475For SaaS lifecycle-communications scope and for any SaaS implementation that depends on segmentation, behavioural triggers, identity resolution, and operating-rule governance, scope and price a dedicated Data Implementation Plan workstream:7677- **Identify schema**: customer, account, user, role, segment, lifecycle stage, lifecycle program flags.78- **Event schema**: signup, activation, in-product actions, billing events, support events, customer-success events.79- **Custom fields**: vertical-specific fields (insurance: policy count; banking: customer count, transaction volume; healthcare: facility, provider category).80- **Identity resolution**: linking the same user across product, marketing automation, CRM, support.81- **Consent and preference management**: lawful basis, opt-in records, channel preferences, frequency caps.82- **Segmentation**: standard segments at launch (by tier, lifecycle stage, health, industry).83- **Data hygiene**: bounce handling, suppression, decay, re-verification.8485This is engineering-grade work — price it as such, not inside a bundled "email setup" line.8687<!-- dual-compat-end -->8889## References9091- [Proposal skills router](../../SKILL.md) for repository-wide routing and mandatory quality gates.92- Local `references/` files when detailed frameworks or examples are needed.93- Use [references/data-analytics-methodology-for-proposals.md](references/data-analytics-methodology-for-proposals.md) when the proposal94 involves dashboards, MIS analytics, BI, AI analytics, survey analysis, data platforms,95 routine monitoring, forecasting, or evidence-based decision support.96- [../references/saas-lifecycle-email-program-proposal-template.md](../../profiles-sectors/references/saas-lifecycle-email-program-proposal-template.md) for the Data Implementation Plan workstream framing.97- [../references/saas-multi-tenant-architecture-block.md](../../profiles-sectors/references/saas-multi-tenant-architecture-block.md) for tenant-context and data-partitioning concerns.98- [../saas-lifecycle-communications-as-deliverable/SKILL.md](../../saas-proposals/saas-lifecycle-communications-as-deliverable/SKILL.md) for the lifecycle communications skill.99100Assignments involving system implementations, M&E frameworks, surveys, or institutional assessments all require a data management component. Proposals that demonstrate a structured approach to data collection, storage, quality, governance, and protection score higher — particularly with donors who have been burned by projects that produced unusable data.101102## When to Read This Skill103104- The assignment involves designing or implementing a management information system (MIS)105- The ToR mentions "data collection", "data management", "data quality", "data governance", or "data protection"106- The methodology includes surveys, assessments, or monitoring activities that generate data107- The assignment must comply with data protection legislation108- When the ToR asks for a standalone data management plan109110## Data Collection111112### Method Selection113114| Method | Best For | Tools |115|---|---|---|116| Mobile data collection | Field surveys, facility assessments, beneficiary registration | ODK, KoBoToolbox, SurveyCTO |117| Paper-based forms | Low-connectivity environments, sensitive data, legal requirements | Standardised forms with clear coding |118| System-generated data | Routine monitoring, transaction records, service delivery | MIS, ERP, HMIS, EMIS |119| Administrative records | Baseline data, historical trends, coverage statistics | Government databases, reports |120| Key informant interviews | Qualitative data, expert perspectives | Interview guides, recording equipment |121122### Data Collection Standards123124- **Standardised tools**: all data collection instruments piloted before deployment125- **Enumerator training**: minimum two days of training including field practice126- **Quality checks**: real-time validation in mobile tools, supervisor spot-checks for paper-based127- **Consent**: informed consent obtained and documented for all respondent data128- **Unique identifiers**: every record has a unique ID; no reliance on names alone129130## Data Quality Framework131132### The Five Dimensions of Data Quality133134| Dimension | Definition | How to Verify |135|---|---|---|136| **Validity** | Data measures what it is intended to measure | Review instrument design, pilot testing |137| **Reliability** | Consistent results across enumerators and time | Inter-rater reliability tests, re-interviews |138| **Completeness** | All required fields populated, no missing records | Automated completeness checks, dashboard monitoring |139| **Timeliness** | Data available when needed for decision-making | Submission deadlines, real-time dashboards |140| **Integrity** | Data protected from unauthorised alteration | Access controls, audit trails, version control |141142### Data Quality Assurance Activities143144- Pre-collection: instrument design review, pilot testing, enumerator certification145- During collection: daily data quality reports, supervisor verification, back-checks on 10% of submissions146- Post-collection: cleaning protocols (outlier detection, consistency checks, duplicate removal), validation against secondary sources147148## Data Governance149150For system implementation and institutional assignments, propose a data governance structure:151152- **Data owner**: the client department or unit responsible for each data set153- **Data steward**: the person responsible for data quality within each unit154- **Access control**: role-based access — who can view, edit, approve, and export155- **Data dictionary**: standardised definitions for all fields and indicators156- **Retention and archival**: how long data is kept, in what format, and when it is archived or destroyed157158## Data Protection Compliance159160### East African Data Protection Legislation161162| Country | Legislation | Key Requirements |163|---|---|---|164| Uganda | Data Protection and Privacy Act, 2019 | Registration with PDPO, consent for processing, data minimisation, cross-border transfer restrictions |165| Kenya | Data Protection Act, 2019 | Registration with ODPC, consent, data subject rights, breach notification within 72 hours |166| Tanzania | Personal Data Protection Act (under development) | Follow emerging requirements; apply Kenya/Uganda standards as minimum |167| Rwanda | Law Relating to the Protection of Personal Data and Privacy, 2021 | Consent, purpose limitation, data subject rights, cross-border transfer restrictions |168169### Proposal Commitments170171When processing personal data, the proposal should commit to:172173- Data collection limited to what is necessary for the assignment (data minimisation)174- Informed consent obtained from all data subjects175- Data stored securely (encrypted at rest and in transit)176- Access restricted to authorised project personnel177- Data not transferred outside the country without appropriate safeguards178- Data retained only for the duration necessary, then securely destroyed179- Compliance with the applicable national data protection law180181## Generating a Standalone Section182183When the ToR asks for a dedicated data management plan, generate a document covering:1841851. Data management approach and principles1862. Data collection methods and tools1873. Data quality assurance framework1884. Data governance structure (roles, access controls, data dictionary)1895. Data storage and security measures1906. Data protection compliance (applicable legislation, consent, retention, destruction)1917. Data analysis and reporting plan1928. Data handover and sustainability193194Follow east-african-english standards throughout.195