
Interoperability with CPIMS+
Overview, Rationale and Purpose
Program interventions have better outcomes when they are well integrated and coordinated.
The CPIMS+ is designed to be interoperable with other information management systems. The Primero team has developed guidance for safe, secure and sustainable interoperability. The resources adhere to information sharing protocols and reinforce good practice and principles, including need-to-know, do-no-harm, and data minimization principles.
Interoperability is the ability of data systems - like Primero - to exchange information and tasks with other systems. For Primero, this may be between modules and/or with other partner systems and may involve manual exchange of files, or automation using software. Primero does not automatically exchange information with external systems, but it does have APIs (application program interface) that can act as access points to securely communicate with other systems.
Safeguarding the collection, storage and sharing of beneficiary information is central to the mission of the CPIMS+. Digital systems are increasingly used to improve services and referral mechanisms, and data security and data privacy are critical. Where systems can become electronically interoperable in order to improve the delivery of services, measures must be taken to ensure children's rights are protected. This is our commitment.
Better integration of data systems can be a driver for better outcomes for children. The CPIMS+ is here to help.
Expectations & Prerequisites
1Essential building blocks
Before we get started, there are a few building blocks that are needed to be in place to ensure a successful integration. Below is a list of key documents/processes/structures/software functionality that should be in place to proceed:
- Information Sharing Protocol (ISP) to be in place or in development in line with local Standard Operating Procedures for Case Management
- Field-level Child Protection Inter-agency coordination structures in place required to support and maintain interoperability
- Strong case management capacity and interagency collaboration
- ICT considerations including troubleshooting support are available
- Stable security situation and operational context
- API available in other IMS system receiving/sending data from Primero (this is required)
2Identify in-country agency focal points for interoperability
If your programme is interested in interoperability between Primero and another IMS, a dedicated working group is critical for coordination. The in-country CPIMS+ Users and the other IMS administrators must agree to interoperability. A dedicated system administrator for CPIMS+ must be appointed to oversee the implementation of interoperability, testing, training and on-going support. Typically this would be the CPIMS+ System Administrator or a focal point(s) with a strong understanding of information management systems and child protection who is actively involved with inter-agency child protection case workers and managers. This in-country appointed focal point(s) will be requested to meet with the Primero and other IMS team for weekly 1 hour calls for ~9 weeks for the duration of interoperability implementation and participate in a system administrator training for interoperability. The focal point(s) will support end-to-end testing of data sharing between the 2 systems, and training end-users once the system is ready to go-live. Once interoperability is live, the focal point(s) will also be the user(s) who would support assigning referrals to the appropriate agency and troubleshoot any issues that end-users may face.
3Approved and Signed Information Sharing Protocol between participating agencies
All data sharing requests should be clearly outlined in the Data Protection Information Sharing Protocol (DPISP) which is a tool that is part of Information Management standards for case management. All child protection agencies are required to agree and sign a DPISP defining what information about children can be shared, when and with whom.
4Configuration Support
The in-country agencies will provide the technical teams from Primero and the other IMS with the following information to implement the interoperability solutions:
- Use cases when data should sent/received
- Workflows of which users and roles should send/receive data
- What data points would be shared and under which circumstances
5Budgeting
Responsibility for budgeting and financial resourcing for the interoperability solution should be agreed in advance. There are many available solutions. Reach out to your local team to explore options.
Timeline Considerations
The Primero Team offers support services to implement interoperability solutions. This must be done in close
coordination with the technical team of the partner solution.
The tasks in blue are led by the appointed inter-agency focal point.
1. Signed Data Protection and Information Sharing Protocol
2. Data flow and mapping specifications are finalized
3. Technical Implementation
Note: For any new implementation of interoperability we will replicate this technical process
4. Access is provided to test environments
5. Demonstration and testing by in-country agencies
6. System Administrator training on how to support after go-live, administer and monitor interoperability
7. Training on how to send and receive data between Primero and other IMS as well as refresher training as needed
8. Go-live with interoperability between Primero and partner IMS
Interested in having the Primero Team help with Interoperability?
The Primero Value-Added Services Menu is available to users of Primero case management software. The menu offers in-demand services that are centrally managed, quality-controlled, and aligned with global best practice. Each service includes technical support, training and inputs required to implement at scale. These are optional services, available at-cost to all partners. Reach out to the Primero Team to learn more.
Below you can find all technical documentation on interoperability projects that have been implemented with CPIMS+.
Technical Documentation on Interoperability with OsCAR in Cambodia

Requirements, Specifications & Training
Technical Documentation on Interoperability with UNHCR's ProGres v4

Requirements, Specifications & Training

Interoperability Tutorials on YouTube

Primero Support Hub
Updates
Data Visualization with PowerBI

Technical Documentation for PowerBI
Primero directly integrates with PowerBI and other data visualization tools. Reach out to your Primero Focal Point to learn more.
Technical Documentation on Interoperability with RapidPro

Technical Documentation for RapidPro
Primero directly integrates with RapidPro through the RapidPro UI. Reach out to your Primero Focal Point to learn more or click the link below to learn more about RapidPro.
Technical Documentation on Interoperability with Inform

Technical Documentation for InForm on Github
Technical Considerations and FAQ
Raised by the Primero Coordination Committee & CPIMS+ Steering Committee
What is the purpose of interoperability with other system(s) and what problem are you trying to solve making systems inter-operable?
Data sharing will improve the experience of field staff using the different systems who are trying to coordinate work to support children and vulnerable populations and ultimately improve services, responses, and case management to survivors and children. It will also prevent re-victimization where children do not need to repeat a traumatic incident to multiple service providers. There are multiple ways to conduct a referral such as by phone or email. Utilizing interoperability is only one standardized way with clear pathways for communication.
How will the data shared be used by other system(s)?
Safeguarding the collection and storage of beneficiary information and data security, confidentiality and protection of this information is critical in data sharing. The collection of information and personal data triggers delicate issues regarding what information can be shared, under what circumstances and with whom. As information systems are increasingly linked to services and referral mechanisms, clear protocols for sharing information must be developed. Where systems can become electronically interoperable, measures can be taken to ensure data security is upheld. For example these measures could include automatic triggers which ensure data is only shared with a child’s consent, and/or a set of defined data points where all participating agencies are aware of the information being shared on a need-to-know basis, and/or the use of an audit functionality to know who is permitting the sharing of data.
What is the benefit to end users?
Data sharing will improve the experience of field staff using the different systems who are trying to coordinate work to support children and vulnerable populations and ultimately improve services, responses, and case management to survivors and children. Interoperability will also help bridge the “gap" between child protection and refugee case management.
What is the benefit to women and girls or children?
It will prevent re-victimization where children, women and girls do not need to repeat a traumatic incident to multiple service providers. It will also ensure referrals are shared successfully with service providers and do not get lost in emails or over the phone. Case workers conducting referrals will know if referrals are accepted, or revoked. And lastly, it will streamline the process to more efficiently share the referral digitally through safe and secure digital means.
What are the risks for the end user or children?
There could be a risk in controlling who can access the data and lack of clarity on it. The CPIMS+ has an audit log which tracks all users and their activity within the system to ensure this risk is mitigated.
What are the decision-making bodies at each organization? Are representatives of these bodies included in the conversation? Is/are user organization(s) involved in the conversation?
Primero Coordination Committee focal points have been the decision-making bodies for each organization and have been included in all conversations to date, this includes the CPIMS+ SC Coordinator and members. Opportunities to ask questions and raise any concerns have been scheduled and all feedback has been tracked here, for example, when building interoperability with proGres v4. Specific discussions have also been had the CPIMS+ SC Meetings together with UNHCR and guidance jointly developed. CPIMS+ users who are not part of these forums can reach out to Marta Passerini, CPIMS IA Global Coordinator at mpasserini@unicef.org, for more information and to provide input.
Who (which individual(s)/role(s)) have access to Primero records shared with the other system? Can access be limited to certain individual(s) or role(s)?
The partner agency focal point who receives the referral, case worker completing the referral and the supervisor of the case worker only have access to the case record/referral in the system.
Beyond actor(s) implementing the other system, do other actor(s) have access to the records shared from Primero?
Data-points defined by the minimum data set can only be shared from Primero to an external system and vice versa, so the information sharing is limited to that referral in line with the local information sharing protocol. Within Primero only the case worker and their supervisor will be able to see information on the case.
The procedure for referring to UNHCR in proGres, for example, could look different in different contexts. If the CP or GBV focal point was to be the first point of referral then it would go directly to the individual. In other cases this goes to specific unit referral focal point designated that is responsible for dividing tasks amongst the team. This would be for example the case case for a referral for documentation or RSD noting that the sharing of a referral does not allow for access to a case file, only the referral form which outlines what service is needed. Any additional information that can be shared (as necessary and with the consent of the survivor) would only be shared once the individual responsible for providing the services has been assigned. These individuals are outlined in v4 SOPs and can be shared and updated with all partners participating with interoperable services and would be updated as part of referral pathways.
Do Primero user organization(s) have the right to opt-out on the data sharing with external system?
Yes, partners and agencies can opt-in and opt-out of interoperability. If a partner has signed the DPISP, the partner would still share data between partners but aligned to other working processes (email, phone, etc.).
How is consent collected from beneficiaries for data sharing with other system? Are staff trained to ask for consent specifically for data sharing with external actors? What tools exist (ie. tailored consent form)? What happens if they do not give their consent?
Consent is collected by the case worker from beneficiaries for all information shared. Consent is received in line with relevant case management guidance and minimum standards. Consent forms would only need to be modified if there was to be a change in information shared in line with the specific local case management needs, this would be reflected in the CPIMS+ but this is not an Information Management decisions but a Case Management one. If referrals were to be done by interoperability instead of paper forms but the content was exactly the same, then there would be no need for a change in consent script or form. Information would not be shared if the survivor does not give their consent. With the obvious limitations of best interest, that are outlined in CM SOPs.
Is interoperability with other system(s) enshrined in the Information Sharing Protocol (ISP)? Has the ISP been developed in a collaborative and inclusive manner with User organization(s)?
Because IO functionality exists does not mean it would necessarily be used in all contexts. The Information sharing protocols and CM SOPs in a context would outline how and what information is to be shared and if it’s decided at the local level that interoperability facilitates this, for example in a digitized referral then the modality could change but the ‘what’ would not. The purposes of information sharing should be considered as part of DPISP development in relation to any protection activities that involve the processing of personal, protection-related data. At all steps of an activity that involves processing of personal, protection-related data, there should be one or several specific purposes. These are defined and agreed between partners at an operational level, and endorsed at a management level.
How does interoperability with other system(s) affect the inter-agency process of data sharing for the purpose of monitoring and analysis of trends (ie. compilation, reporting and analysis)?
Interoperability will not impact trends analysis, interoperability facilitates actions we are taken as part of the case management processed by allowing systems to speak to each other, but in terms of data compilation the processes outline in the data protection and information sharing protocols would serve as a guide and are not IM specific.
What is/are the scenario(s) in which data needs to be shared with other system(s)?
Referrals for services are the most common use case of interoperability between Primero and external systems, as agreed to by the partners.
Which document defines what constitutes a referral? Is it global or country level?
What constitutes a referral is defined in the Inter-Agency Guidelines for Case Management forms and the Data Protection Information Sharing Protocol (DPISP) determines what information is shared.
How do we address challenges that we may encounter when discussing interoperability in specific contexts? (I.e. specific context-related risks and considerations for data sharing among UNICEF/UNHCR, INGOs/Implementing Partners and Governments)
In order for there to be a CPIMS+ roll-out it is important for there to be a Data Protection and Information Sharing protocol, the coordination body which has overseen this process (sometimes CPWG, sometimes CMTF etc) would be a suitable place to have such discussions noting that the risks of data sharing are not specific to just one or 2 IM systems, and therefore it is important to have an inter-agency and comprehensive approach.
Is development work needed to enable interoperability between systems? If so, how can it be done?
Yes, this will be done by the Primero development vendors. Once it's done the first time then this is easy to adapt for new contexts.
Does UNICEF have a data protection policy?
Primero is well-versed in data protection and ensure protocols are in place and confidentiality is maintained in an implementation. UNICEF has launched the Responsible Data for Children (RD4C) initiative that looks at data protection and privacy with field-informed, evidence-based, global public goods, tools and best practices to make informed decisions about children’s data. RD4C is led by DPAM and Robert MacTavish is the lead for Child Protection. RD4C includes guidance on how to design, support and implement programmes with these risks in mind, and how to promote appropriate data practices and systems. In addition to the public facing website, RD4C also has a UNICEF SharePoint which you can access here.
For each Primero/CPIMS+ implementation we conduct a data protection impact assessment (DPIA) with the purpose of identifying, evaluating and addressing the risks to children arising from managing sensitive case data. The outcomes of the DPIA should be an action plan and relevant information should be included in the Data Protection Information Sharing Protocol (DPISP). The DPISP we use in Primero is the template developed by the global Case Management Task Force, and assists Child Protection actors in defining what information about the child can be shared, when and with whom. All partners (case workers and supervisors) sign a data protection agreement . And we validate the findings of the DPIA between partners involved.
We have resources on the Primero.org (https://www.primero.org/resources) for information management. UNICEF also developed Good Practice Principles on Information Handling and Management in Child Protection Information Management Systems. We have developed this security guidance for Primero which outlines the functional, platform security as well as requires for processes to ensure the sensitive nature of child records are kept safe and that both the system and partners ensure no harm is done. Also, in regards to the functional security, you will see in the guidance document that Primero offers role-based user access and audit logs (audit logs for v2) track activity or unusual interactions.
Consent and Assent in Interoperability between Primero’s CPIMS+ and UNHCR's proGres v4 Child Protection Module
The principle of consent and assent are key in the ability of proGres4 and Primero to comply with data subjects’ rights (an individual whose personal data is subject to processing). This means that consent and assent is not only a principle that is required before any personal and/or protection data is collected or shared, but also something which a data subject has the right to withdraw. This principle should be clearly outlined in the country level Data Protection and Information Sharing Protocol, therefore all related actions should align to this or any other country level protocols.
Therefore for the purposes of service provision and referral data sharing:
- Consent be obtained before making any referrals within or outside the organization, which will therefore also apply to all referrals between proGresV4 CP module and CPIMS+
- The Case Worker should clarify with the child and caregiver for how long this consent is valid and how to withdraw or revoke their consent at any time. In some cases, consent/assent may only be given for a one-off referral on the understanding that information about the case will not be shared after that particular referral has been made
- If consent is revoked it is important to note the CPIMS+ allows a case worker to revoke access to a referral to any users that a referral was shared with; however, there is no equivalent in proGresV4
If consent is withdrawn from a child/caregiver who is being case managed by a case worker using CPIMS+, the case worker will revoke all pending referrals in CPIMS+ and will also send written communication via a password protected email via a secure office email to the designated UNHCR focal point for proGresv4 who reviews all referrals from CPIMS+. The case worker will also call the UNHCR colleague within 24 hours if no confirmation of reception is received. The communication must include: 1) case number; 2) date in which consent was withdrawn; and 3) if the withdrawal is applicable to only some but not all services for which the referral was made - this must be specified (e.g. consent may be withdrawn for resettlement only). The UNHCR focal point for proGresv4 will then be required to terminate the specific referral in proGresv4.
If a child/caregiver is being case managed by UNHCR and consent is revoked, UNHCR must inform the designated CPIMS+ case worker who is reviewing that referral and send written communication via a password protected email via a secure office email. The UNHCR protection officer will also call the CPIMS+ case worker within 24 hours if no confirmation of reception is received. The CPIMS+ case worker will also “revoke” the referral from UNHCR into the CPIMS+. The communication must include: 1) case number; 2) date in which consent was withdrawn; and 3)if the withdrawal is applicable to only some but not all services which the referral was made for then this needs to be specified (e.g. consent may be withdrawn for FTR only).
The CPIMS+ case worker will then be required to make a note on the case on the reason for closure and close the case in CPIMS+.
Only, in exceptional circumstances, information disclosed by children can be shared against their wishes if it is considered – after careful evaluation - in their best interests to do so, usually if the child or another person is at risk of being harmed or harming themselves, or if sharing the data is determined to be in the child’s best interests. Exceptions to confidentiality should be outlined at the beginning of intake/assessment, when reviewing and obtaining consent/assent as well - and then reiterated later.
In such situations, the reasons for sharing Personal Data in such a manner must be clearly explained to the affected child. There is no hard or fast rule for disclosing information shared by a child. Information shared against or without explicit consent/assent should be in line with confidentiality and consent and assent principles and processes outlined in the country's Case Management Standard Operating Procedures and the Data Protection and Information sharing Protocol. Because sharing information in light of exceptions to confidentiality can be subjective, each case should be considered individually, and decisions to share information should be taken in line with country procedures and involve senior child protection colleagues.
Does UNHCR have a data protection policy?
Yes, here is the policy relating to protection of personal data:
1. Policy: https://www.refworld.org/cgi-bin/texis/vtx/rwmain?docid=55643c1d4
2. Guidance on Policy: https://www.refworld.org/docid/5b360f4d4.html
What constitutes a referral between Primero/CPIMS+ and proGresv4? For what specific service?
We would define a referral as follows: To make a referral is to “...proactively facilitate access to [...] services. Facilitating referral [...] may also involve ensuring that the person can physically reach and obtain access to the necessary services. At a minimum, it requires providing contact information on services of proven reliability”. There must be a legitimate purpose for a referral, consent/assent must normally be obtained from the referral subject, and the personal data provided should be limited to what is needed for the service to be provided. CPIMS+ Case Workers are able to request any service from a UNHCR Case Worker. UNHCR Case Workers are able to request CPIMS+ Case Workers for Alternative Care, Family Tracing and Reunification Services and Child Protection Services.
© Copyright 2026







