Resources
A collection of legal and policy documents relevant to the governance of Ai, data, cybersecurity and digital rights.
Law, policy and institutional governance
Foundational South African legal and policy instruments relevant to the governance of Ai, data, cybersecurity and digital rights.
Constitution of the Republic of South Africa
Selected provisions on equality, dignity, privacy, expression and access to information.
Protection of Personal Information Act
South Africa’s central personal-data protection and privacy framework, including regulations.
Promotion of Access to Information Act
A primary source on transparency, accountability and access to information.
Cybercrimes Act
Core South African legislation on cyber offences, evidence and cybercrime-related obligations.
National Cybersecurity Policy Framework
The foundational national policy framework for South African cybersecurity governance.
National Policy on Data and Cloud
National policy on data governance, cloud adoption, interoperability, security and digital infrastructure.
National Integrated ICT Policy White Paper
A foundational source for communications, connectivity, digital development and ICT policy.
Information Regulator Resources
Guidance, codes, determinations, PAIA manuals and annual reports from South Africa’s Information Regulator.
South African AI Policy - Withdrawn
South Africa's Draft Ai Policy has now been withdrawn pending review.
King V Code
For boards, executives, governance professionals working at the intersection of corporate governance and technology.
King V Code on Corporate Governance 2025
South Africa's leading voluntary standard for corporate governance.
King V Code Foundational Concepts 2025
Supporting material foundational to an understanding of King V and its implications.
King V Code on a Page
A concise executive reference for the Code’s central concepts, principles and governance outcomes.
Cyber threats & Cyber resilience
Periodic reporting that traces enforcement, threats, emerging risks, rights impacts and institutional response.
2026 INTERPOL African Cyberthreat Assessment
The 2026 edition of INTERPOL’s regional cybercrime and threat assessment reporting.
CSIR Cybersecurity Skills Gap Survey 2024
A national survey report on the skills gap in cybersecurity in South Africa.
LONDA: Digital Rights and Inclusion in Africa
Country-level analysis of digital rights, inclusion, policy developments and civic participation.
AU Regional instruments & documents
African Union, African Commission and regional sources on Ai & data governance, cybersecurity and digital rights.
Malabo Convention
The AU Convention on Cyber Security and Personal Data Protection.
Digital Transformation Strategy for Africa
A continental strategy for digital transformation covering policy, infrastructure, skills, cybersecurity, privacy and emerging technology.
AU Data Policy Framework
A continental framework for trusted, interoperable and development-oriented data governance.
Continental Artificial Intelligence Strategy
An Africa-centred strategy for responsible, equitable and development-focused AI governance.
African Union Digital Education Strategy and Implementation Plan
The AU framework for accelerating the adoption of digital technologies across education and building digitally empowered citizens.
AU Interoperability Framework for Digital ID
A continental framework for interoperable digital identity credentials and trusted digital identification across African Union Member States.
African Digital Compact
A continental compact connecting digital inclusion, rights, security, data governance and artificial intelligence.
ACHPR Study on Human Rights and AI
Africa-focused study on human and peoples’ rights and artificial intelligence, robotics, and other new and emerging technologies in Africa.
International standards and implementation tools
Coverers global and comparative standards, guides and implementation tools reflecting emerging global norms & standards.
NIST AI Risk Management Framework
A voluntary standard to improve trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems.
NIST Cybersecurity Framework 2.0
Guidance to industry, government agencies, and other organizations to manage cybersecurity risks.
EU Artificial Intelligence Act
The EU AI Act is Europe's Ai regulation, laying down harmonised rules on artificial intelligence and regulating the Ai on a gradient risk basis.
OECD AI Principles and Policy Observatory
International AI principles, governance research, policy tools and comparative policy resources.
UNESCO Recommendation on the Ethics of Artificial Intelligence
The first global standard on AI ethics, provides that AI must respect human rights and human dignity.
ISO/IEC 42001
An international standard that specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS) within organizations.
ISO/IEC 23894
Provides guidance on how organizations that develop, produce, deploy or use products, systems and services that use Ai can manage risk specifically related to AI.
ISO/IEC 27001
The world's most popular standard for Information Security Management Systems; it provides a framework for managing information security risks (cyber-resilience).
United Nations Convention against Cybercrime
The first comprehensive global treaty on cybersecurity, which provides States with a range of measures to prevent and combat cybercrime. It also strengthen international cooperation.
Council of Europe, Budapest Convention on Cybercrime
An EU treaty on cybersecurity open to ratification by all States, which governs cybercrime, and seeks to strengthen international cooperation.
