The digitalization of public services is a positive step forward for Haiti. The Decree of January 6, 2016, recognizing the right of every citizen to interact with the Public Administration through electronic means, lays the foundation for a modern e-government framework that respects citizens' rights. It aims to reduce barriers to accessing public services, simplify administrative procedures, and improve transparency.
Modernization, however, also brings new challenges. The 2016 Decree establishes standards to ensure the security of electronic systems, the confidentiality of personal data, and the protection of privacy, while encouraging cooperation between administrative entities to ensure the interoperability of systems and applications. It also emphasizes bridging the digital divide and preserving bilingualism (Creole and French) in electronic services.
It is with this vision that several State agencies have begun modernizing to better serve the population. But trust in these services requires that users' rights be respected. The usefulness of these platforms requires that the transparency and protection standards already provided for by current legislation be effectively implemented from the design stage.
Personal data protection: a recognized right
The Presidential Order of April 30, 2018, on the protection of personal data recognizes citizens' right to the protection of their information. The principles it enshrines are internationally recognized: purpose limitation, proportionality, limited retention, confidentiality, security, right of access, and right of rectification. These principles are aligned with international standards, notably the EU's GDPR and the OECD Privacy Guidelines.
The data collected by government platforms is among the most sensitive in existence: the National Unique Identification Number (NINU), passport numbers, dates of birth, credit card details, personal addresses, and phone numbers — data intrinsically linked to each individual's identity. If accessed by unauthorized persons, they could be used for identity theft, document fraud, or unauthorized surveillance. The 2016 Decree anticipated this risk in Article 4(f) by requiring a level of security at least equal to that provided by non-electronic means.
Transparency, privacy policy, and data retention
Building user trust requires that privacy policies play a central role. They inform citizens of the nature of the data collected, its purpose, its retention period, and the persons authorized to access it. Yet, on several existing government platforms, these policies are absent, not provided for, or inaccessible — sometimes with footer links redirecting to entirely blank pages.
The principle of proportionality (data minimization) provided for by the 2018 Order specifies that "only the data strictly necessary for the purpose for which they are requested shall be required from citizens." Without a published privacy policy, citizens cannot verify whether this principle is respected.
The absence of a privacy policy also makes it difficult to identify how long submitted data will be retained. The 2018 Order requires (Article 3, paragraph 3) that data be "retained for a period established according to the purpose of the file." Personal data must not be kept indefinitely and must be deleted or anonymized once no longer necessary. A traveler filling an entry/exit form, or an entrepreneur registering a business online, has no way of knowing whether their data will remain for a month, a year, ten years, or indefinitely.
This lack of information prevents informed consent (Article 4(k) of the 2016 Decree), creates an accumulation risk (the longer data is retained, the more valuable a target it becomes), and makes the right of rectification (Article 3, paragraph 9, of the 2018 Order) impossible to exercise effectively.
Technological sovereignty and data localization
Certain government platforms are hosted on servers located in the United States. Since 2018, the U.S. CLOUD Act allows U.S. authorities to compel a U.S.-based service provider to grant access to data stored on its servers, even if the data concerns foreign nationals and even if the servers are physically located abroad. Data stored on a U.S. server is accessible to U.S. authorities; the foreign nationality of the data subject is not, in itself, a barrier.
This raises a sovereignty question. Haitian legislation guarantees citizens "the security and confidentiality of data contained in the files, systems, and applications of the public administration." Hosting government data on foreign servers, without disclosure, raises the question of compatibility with that guarantee. As a result, the Haitian government does not retain control over the data collected on its platforms.
To our knowledge, no bilateral CLOUD Act agreement between Haiti and the United States has been made public, and Haiti has not adopted a general data localization policy. The U.S. has concluded CLOUD Act agreements with the UK and Australia, reserved for partners providing sufficient privacy and civil-liberties guarantees. Other countries — Russia, China, India, Vietnam, Nigeria, Brazil, and, in the Caribbean, Jamaica, the Bahamas and Barbados — have adopted localization requirements or cross-border transfer rules.
The bilingualism requirement
The 2016 Decree provides, in Article 49, that "the electronic sites of administrative entities shall provide access to their content and services in Creole and French." Yet some government platforms are available in only one language, depriving a significant portion of the population of equal access — contrary to the principle of equal treatment enshrined in the same decree.
Domain name security and authentication of government websites
When a user enters a platform’s address, the DNS (Domain Name System) translates it into a technical location pointing to the correct server. DNS, as designed in the 1980s, has no built-in mechanism to verify the authenticity of its responses. DNSSEC (DNS Security Extensions) adds cryptographic signatures to DNS responses, letting the browser verify that the address genuinely comes from the legitimate domain holder.
Without DNSSEC, DNS cache poisoning attacks are possible: an attacker redirects users to a fake site mimicking the official one, capturing the personal information entered. We found that several government platforms lack DNSSEC, often with only two name servers hosted by the same provider — reducing resilience. An attacker who succeeds could clone a platform and collect, in real time, passport numbers, NINUs, dates of birth and credit card numbers, even relaying them to the real server to stay invisible.
The 2016 Decree addresses this at several levels. Article 17 requires secure electronic-signature systems attested by qualified certificates. An SSL certificate (the browser padlock) is a first line of defense but does not protect against DNS poisoning — an attacker can install a valid SSL certificate on a fraudulent domain. DNSSEC and SSL are complementary, not interchangeable. Article 4(f) requires "at least the same level of guarantee and security as that required for the use of non-electronic means": the site’s authenticity must be verifiable, which is precisely what DNSSEC ensures.
Citizens' rights over their data
Accessibility and rectification
The right of access lets citizens know what data the administration holds about them; the right of rectification lets them correct errors. The 2016 Decree (Article 9) and the 2018 Order (Article 3, paragraphs 5, 8 and 9) guarantee access limited to authorized services, accessibility to the data subject, and rectification on request.
However, our review did not identify any access mechanism — no contact form, correspondence address, or dedicated section — for exercising the right of rectification. As for inter-agency exchanges (IHSI, ONI, AGD, DGI), no data-sharing protocol is publicly documented, making the legal obligation to limit access unverifiable.
Data protection is not a one-time action: it requires a continuous chain of accountability, from collection to deletion, resting on three inseparable pillars — transparency, security and accessibility. Every e-governance platform should operate within a clear cycle: collection limited to the stated purpose, secure processing, documented and consented inter-agency sharing, time-limited retention, and deletion or anonymization on expiry.
Toward compliance
Citizens have avenues of recourse. The Office for the Protection of Citizens (OPC) ensures that citizens’ rights are respected in e-government matters. The Office of Management and Human Resources (OMRH), through its Unit for the Promotion of Electronic Administration, supports institutions and formulates recommendations to secure digital public services.
Digitalization is a promise. For it to hold, the platforms that collect the population’s personal data must provide the transparency and protection required by law.