📖 ABSTRACT/OVERVIEW
Mobile health applications collect deeply personal health data from Nigerian users at scale, yet privacy engineering practices within the Nigerian mobile health application development sector are empirically unstudied and theoretically ungrounded. This dissertation develops and validates a Privacy-by-Design (PbD) implementation theory for Nigerian mobile health applications, contributing original theory and evidence-based guidance to health software engineering and privacy engineering research. A sequential mixed-methods research design is employed across three phases. Phase one conducts a systematic review of PbD frameworks and mobile health privacy literature, identifying the gap between international PbD guidance and the Nigerian regulatory and technical context. Phase two executes a technical privacy audit of 20 Nigerian mobile health applications using a structured PbD assessment instrument evaluating data minimisation, purpose limitation, consent architecture, and security-by-default implementation. Phase three conducts in-depth interviews with 18 mobile health application developers and 15 patient users across Lagos (South West), Enugu (South East), and Kaduna (North West). The technical audit reveals that 14 of 20 applications collect more personal data than functionally required, 12 lack granular user consent mechanisms, and only 3 implement meaningful data minimisation by design. Qualitative findings reveal that developers are aware of privacy obligations under the Nigeria Data Protection Regulation but lack engineering-level guidance for translating regulatory requirements into design decisions. An original Nigerian mHealth PbD framework is developed and validated. Keywords: privacy-by-design, mobile health, Nigeria, NDPR, privacy engineering
Need Complete Chapters of the Above Topic?
Get high-quality, Zero-AI research materials with current citations.
Request via WhatsApp 💬