South Africa’s Cloud-First Policy Comes With a Data-Sovereignty Warning

South Africa's final National Data and Cloud Policy promotes cloud-first government, but its security, sovereignty and implementation choices deserve equal attention.

South Africa's final National Data and Cloud Policy promotes cloud-first government, but its security, sovereignty and implementation choices deserve equal attention.
France’s SREN law treats cloud exit as a market rule: switching fees, portability, interoperability and contract transparency are no longer matters that customers can safely postpone until migration day. Law 2024-449 on securing and regulating the digital space was published…
The European Digital Identity Framework is not simply a government login application. It creates a cross-border trust architecture for wallets, credentials and the organisations that request them. Regulation (EU) 2024/1183—the updated eIDAS framework—applied from 20 May 2024. It requires Member…

Brazil’s data-protection authority has replaced an open-ended breach-notification standard with a defined three-business-day clock and a detailed test for deciding which incidents must be reported. Brazil’s Lei Geral de Proteção de Dados, or LGPD, has always required controllers to communicate…
From 29 April 2024, consumer connectable products placed on the UK market became subject to three deceptively simple security requirements. The difficult part is proving that the whole supply chain meets them. The United Kingdom’s Product Security and Telecommunications Infrastructure…
Chile’s Cybersecurity Framework Law creates a national regulator, defines essential services and requires an early incident alert within three hours. That first message is designed for speed, not forensic certainty. Chile published Law No. 21.663, the Cybersecurity Framework Law, on…

Tanzania's privacy regime is no longer a statute waiting for machinery. Its commission is operational, registration is live and enforcement has begun.

Nigeria's 2024 cybercrime amendment is usually discussed as a levy story, but its deeper effects reach traffic retention, sectoral monitoring and enforcement architecture.

The AfCFTA Digital Trade Protocol sets a shared direction for data flows, privacy, cybersecurity, digital identity and electronic trade across Africa.
The Digital Services Act, applicable from 17 February 2024, regulates intermediary services within the EU, imposing varying obligations based on service type and size. It mandates effective notice, classification, and moderation workflows while ensuring transparency in automated decision-making. Large platforms are held to higher standards, requiring systemic risk assessments and accountability measures.