SS

South Sudan

East Africa

3Instruments
0Cases
2Regulators
10%Coverage
Overview

South Sudan has no comprehensive personal data protection law. A June 2026 verification search confirmed that no dedicated data protection statute is in force and that ATLPF holds no Instrument or Regulator record for the jurisdiction. The only closely related instrument identified is the Cybercrimes and Computer Misuse Provisional Order 2021, which obliges service providers to retain communications data for 180 days. That Order is a cybercrime and surveillance measure rather than a data protection instrument; commentators have criticised it for chilling free expression while failing to provide meaningful privacy or personal-data safeguards. Its data-retention mandate is therefore best understood as a countervailing surveillance provision rather than a protective one. Reporting indicates that South Sudan has drafted a dedicated data protection bill that is expected to advance, but as of June 2026 no such law has been enacted and no supervisory authority exists. The practical position for data handlers is that there is no statutory data protection regime, no registration or breach-notification framework, and no dedicated regulator.

Topic coverage
TopicInstrumentsCasesCoverage
Data Protection10
AI Governance00
Fintech10
Cybercrime10
Digital Rights20
Platform Liability00
Telecoms00

● Covered  ◐ Partially covered  ○ Not yet covered

Instruments
Notable gaps

No comprehensive data protection law and no supervisory authority. The 2021 Cybercrimes Order imposes data retention without corresponding privacy safeguards, and the reported data protection bill remains unenacted, with no confirmed text on file.