DHIS2 is an open-source, metadata-driven platform for collecting, aggregating, analysing and exchanging data, used in more than 80 countries covering some 2.4 billion people. Originally built for health, it is a strong candidate for the collection because its sector-agnostic core has demonstrably been reused for education, climate and agriculture data.
All DPGs in the DPGs for DPI Collection are assessed by the DPGA Secretariat against the DPGs for DPI criteria v2.0. Assessments use publicly available documentation and link to their evidence below. Assessed September 2026.
1 partially met
Layer 1
Recognised DPG
Layer 2
DPI Relevance
Layer 3
DPI Architecture Alignment

Does it provide a foundational DPI function, reusable across sectors, at population scale?
The platform is a generic, metadata-driven data collection, aggregation and exchange layer rather than a single-sector application, with documented use across health, education, climate and agriculture. Scale is well established: 80-plus country deployments covering over 2.4 billion people.
How the solution's architecture reflects the principles that distinguish DPI from conventional digitisation.
Can other systems connect without modifying the core, using documented open standards?
A comprehensive REST Web API is fully documented for external integrators. The platform supports HL7 FHIR, ADX, ICD-11, SNOMED and LOINC, and exchanges data as JSON, XML, CSV and ADX using standard formats.
Is it a modular building block that does one thing well, rather than a monolithic platform?
A modular app framework separates the DHIS2 Core platform from an ecosystem of independently developed apps. Because the platform is metadata-driven and highly configurable, it has been deployed in more than 80 countries without forking the codebase.
Can other public and private actors build on top of it?
Third parties build on DHIS2 through the App Hub, an SDK and extensive developer documentation, and hundreds of third-party apps and integrations exist. Governance sits with the University of Oslo and the global HISP network under a BSD licence, with no vendor lock-in.
Can it run in distributed or federated deployments suited to national infrastructure?
Each country owns and runs its own instance, so data sovereignty is inherent to the deployment model, and national deployments run in production with high-availability configurations. Deployment is primarily a single instance per country — data can be exchanged between instances, but the architecture is not federated in the strict sense.
Does it meet the security and privacy bar for population-scale infrastructure?
Security considerations are comprehensively documented for national-scale deployment, and a vulnerability disclosure policy is published. Privacy is addressed by design, with data protection documentation and adaptability to different jurisdictional requirements.
Criteria: DPGs for DPI Collection criteria v2.0 · Co-stewarded by CDPI, Co-Develop and the DPGA Secretariat.
Spot something out of date? Contact the DPGA