Legal & policy

Resources

A collection of legal and policy documents relevant to the governance of Ai, data, cybersecurity and digital rights.

Law, policy and institutional governance

Foundational South African legal and policy instruments relevant to the governance of Ai, data, cybersecurity and digital rights.

legislation

Constitution of the Republic of South Africa

Selected provisions on equality, dignity, privacy, expression and access to information.

Constitution of the Republic of South Africa, 1996 ss 9, 10, 14, 16 and 32.
Explore source
legislation

Protection of Personal Information Act

South Africa’s central personal-data protection and privacy framework, including regulations.

Protection of Personal Information Act 4 of 2013.
Explore source
legislation

Promotion of Access to Information Act

A primary source on transparency, accountability and access to information.

Promotion of Access to Information Act 2 of 2000.
Explore source
legislation

Cybercrimes Act

Core South African legislation on cyber offences, evidence and cybercrime-related obligations.

Cybercrimes Act 19 of 2020.
Explore source
policy

National Cybersecurity Policy Framework

The foundational national policy framework for South African cybersecurity governance.

Department of Telecommunications and Postal Services, National Cybersecurity Policy Framework (GN 609 in GG 39475, 4 December 2015).
Explore source
policy

National Policy on Data and Cloud

National policy on data governance, cloud adoption, interoperability, security and digital infrastructure.

Department of Communications and Digital Technologies, National Policy on Data and Cloud (GN 2533 in GG 50741, 31 May 2024).
Explore source
Policy White Paper

National Integrated ICT Policy White Paper

A foundational source for communications, connectivity, digital development and ICT policy.

Department of Telecommunications and Postal Services, National Integrated ICT Policy White Paper (2016).
Explore source
guidance

Information Regulator Resources

Guidance, codes, determinations, PAIA manuals and annual reports from South Africa’s Information Regulator.

Information Regulator (South Africa), ‘Guidance and Publications’ <https://inforegulator.org.za/> accessed 17 August 2026.
Explore source
Withdrawn

South African AI Policy - Withdrawn

South Africa's Draft Ai Policy has now been withdrawn pending review.

Department of Communications and Digital Technologies, Draft South Africa National Artificial Intelligence Policy (2026).
Explore source

King V Code

For boards, executives, governance professionals working at the intersection of corporate governance and technology.

Cyber threats & Cyber resilience

Periodic reporting that traces enforcement, threats, emerging risks, rights impacts and institutional response.

AU Regional instruments & documents

African Union, African Commission and regional sources on Ai & data governance, cybersecurity and digital rights.

regional treaty

Malabo Convention

The AU Convention on Cyber Security and Personal Data Protection.

African Union Convention on Cyber Security and Personal Data Protection (adopted 27 June 2014).
Explore source
regional strategy

Digital Transformation Strategy for Africa

A continental strategy for digital transformation covering policy, infrastructure, skills, cybersecurity, privacy and emerging technology.

African Union, Digital Transformation Strategy for Africa (2020 to 2030) (2020).
Explore source
regional policy

AU Data Policy Framework

A continental framework for trusted, interoperable and development-oriented data governance.

African Union, AU Data Policy Framework (2022).
Explore source
regional strategy

Continental Artificial Intelligence Strategy

An Africa-centred strategy for responsible, equitable and development-focused AI governance.

African Union, Continental Artificial Intelligence Strategy (2024).
Explore source
regional strategy

African Union Digital Education Strategy and Implementation Plan

The AU framework for accelerating the adoption of digital technologies across education and building digitally empowered citizens.

African Union Digital Education Strategy and Implementation Plan (2023–2028).
Explore source
digital ID framework

AU Interoperability Framework for Digital ID

A continental framework for interoperable digital identity credentials and trusted digital identification across African Union Member States.

African Union Interoperability Framework for Digital ID (11 December 2023).
Explore source
regional policy

African Digital Compact

A continental compact connecting digital inclusion, rights, security, data governance and artificial intelligence.

African Union, African Digital Compact (2024).
Explore source
regional study

ACHPR Study on Human Rights and AI

Africa-focused study on human and peoples’ rights and artificial intelligence, robotics, and other new and emerging technologies in Africa.

African Commission on Human and Peoples’ Rights, Draft Study on Human and Peoples’ Rights and Artificial Intelligence, Robotics and Other New and Emerging Technologies in Africa (March 2025).
Explore source

International standards and implementation tools

Coverers global and comparative standards, guides and implementation tools reflecting emerging global norms & standards.

US voluntary standard

NIST AI Risk Management Framework

A voluntary standard to improve trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems.

US National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0) (2023).
Explore source
us voluntary standard

NIST Cybersecurity Framework 2.0

Guidance to industry, government agencies, and other organizations to manage cybersecurity risks.

US National Institute of Standards and Technology, Cybersecurity Framework 2.0 (2024).
Explore source
EU legislation

EU Artificial Intelligence Act

The EU AI Act is Europe's Ai regulation, laying down harmonised rules on artificial intelligence and regulating the Ai on a gradient risk basis.

Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence [2024] OJ L 2024/1689.
Explore source
guidance

OECD AI Principles and Policy Observatory

International AI principles, governance research, policy tools and comparative policy resources.

OECD Council Recommendation on Artificial Intelligence, OECD/LEGAL/0449 (2019, updated 2024).
Explore source
guidance

UNESCO Recommendation on the Ethics of Artificial Intelligence

The first global standard on AI ethics, provides that AI must respect human rights and human dignity.

UNESCO, Recommendation on the Ethics of Artificial Intelligence; UNESCO, (2021).
Explore source
AI governance standard

ISO/IEC 42001

An international standard that specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS) within organizations.

ISO/IEC 42001 — Artificial intelligence management system.
Explore source
AI risk management standard

ISO/IEC 23894

Provides guidance on how organizations that develop, produce, deploy or use products, systems and services that use Ai can manage risk specifically related to AI.

ISO/IEC 23894 — Information technology — Artificial intelligence — Guidance on risk management.
Explore source
information security standard

ISO/IEC 27001

The world's most popular standard for Information Security Management Systems; it provides a framework for managing information security risks (cyber-resilience).

ISO/IEC 27001 — Information security management systems.
Explore source
International Treaty

United Nations Convention against Cybercrime

The first comprehensive global treaty on cybersecurity, which provides States with a range of measures to prevent and combat cybercrime. It also strengthen international cooperation.

UN Convention Against Cybercrimes, 2024.
Explore source
International Treaty

Council of Europe, Budapest Convention on Cybercrime

An EU treaty on cybersecurity open to ratification by all States, which governs cybercrime, and seeks to strengthen international cooperation.

COE, Budapest Convention on Cybercrime (2012).
Explore source
No resources match this search or filter. Try a different keyword or select “all”.
Work with us

Needs Research Support?

Start a Conversation