Law / South Sudan

South Sudan

3 of 7 named instruments researched to a stage, across two of the six areas of law we track: 3 in force. As of 20 September 2026.

  1. AI law none researched
  2. Privacy law none researched
  3. Scraping law 2
  4. Cybersecurity law 1
  5. Age gating law none researched
  6. News aggregation law none researched

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Scraping law2 instruments, 2 in force

Research summary (272 words)

South Sudan has no scraping-specific statute, so each dimension is governed by general law that predates any dedicated cybercrime framework. The Penal Code Act, 2008 makes it an offence to gain unauthorised access to, copy, or interfere with data, a programme, or a system held in a computer or computer network (ss. 388-394), and the National Communication Act, 2012 separately bars breaking into, eavesdropping on, or hacking into a communication or communication network without authorisation (ss.

96, 98(1)(e)); because both turn on acting without the owner's or the licensee's authority, reading a public, unauthenticated page does not fit a plain reading of either. No South Sudanese court decision on the enforceability of a browsewrap or clickwrap terms of service against a scraper has been located. South Sudan has no copyright statute, so it has no text-and-data-mining exception, and its law confers no sui generis database right.

South Sudan has no comprehensive data-protection statute, so a general personal-data reach over scraped public information is not established here. No statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Press reporting describes further computer-misuse legislation, a 2021 provisional order and a 2026 Cybercrime and Computer Misuse Act said to have replaced it on 18 February 2026, but no official gazette or government-published text of either has been located, so their provisions are not described here; under article 86(3) of the Transitional Constitution a provisional order the National Legislature does not ratify lapses with no retrospective effect, and whether the 2021 order was ever ratified is not established here.

Computer misuse

National Communication Act, 2012, confidentiality and unauthorised interception of communications

The National Communication Act, 2012 (Act 24 of 2012), ss. 96 and 98(1)(e)Official text of the National Communication Act

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived July 27, 2026. Publisher's page: https://mojca.gov.ss/wp-content/uploads/2023/03/National-Communication-Act-24-of-2012.pdf

In force. Binds public and private bodies.

What this law does

Section 96 of the National Communication Act, 2012 bars any person from disclosing or disseminating the contents of a message or communication, or opening postal material, except as the Act or its regulations specifically allow, and separately bars breaking into, eavesdropping on, illegally monitoring, or hacking into communications without authorisation from the National Communication Authority, the Attorney General, the Director of Public Prosecutions, or a court.

Section 98(1)(e) makes intercepting, interfering with, jamming, or hacking into a communication network, radio frequency, or frequency band allocated to another licensee an offence carrying imprisonment, a fine, or both, without the Act itself stating a specific term or amount.

What it requires

Penal Code Act, 2008, computer and electronic related offences

The Penal Code Act, 2008 (Act 9 of 2008), ss. 388-394 (Computer and Electronic Related Offences)Official text of the Penal Code Act, 2008 (Act 9 of 2008), reproduced by FAOLEX (Food and Agriculture Organization legal database)

In force since 22 August 2008. Binds public and private bodies.

What this law does

Sections 388 to 394 of the Penal Code Act, 2008 create a set of computer-misuse offences. Section 389 makes it an offence to gain access to, destroy, alter, copy, transfer, or interfere with data, a programme, or a system held in a computer or computer network without authority from its owner, and section 389(3) provides a defence where the accused was not motivated by malice and the conduct did not materially affect the data, programme, system, or the owner's interests.

Sections 390, 391, 393, and 394 separately criminalise introducing a computer virus, unauthorised manipulation of a proposed computer programme, and unauthorised use of a credit or debit card or of a password or PIN number.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (457 words)

The one located product-security or sector-cyber-resilience duty on a private operator sits inside the National Communication Act, 2012 (Act No. 24): Section 88(3) requires every Licensee holding a National Communication Authority (NCA) licence to construct, install or operate a communication network to provide protection, technical security and safety for its facilities, equipment and communication networks, so as to ensure system efficiency and reliability, and Section 88(1) places a parallel duty on the Authority and Licensees together to protect communication networks against intrusion and vandalism.

Section 11 gives the Authority its own regulatory mandate to take appropriate measures protecting the security of information and communication networks against intrusion when regulating Internet domain names and electronic signatures, a power the Authority holds rather than a duty stated directly on a private operator, so it is recorded here as regulatory context rather than as its own instrument.

No general product-security or connected-device market-placement duty reaching an ordinary software product or app, no duty to report an exploited vulnerability or a security incident to an authority or to users on any clock, and no reasonable-security or information-security-programme statute reaching a business simply because it holds covered data was located in any South Sudanese instrument checked.

No personal-data-protection or breach-notification statute for South Sudan was located either, so no privacy-topic cross-reference is available to record here.

The Cybercrimes and Computer Misuse Provisional Order, 2021 and the Cybercrime and Computer Misuse Bill, 2025 that succeeded it, and Chapter XXVII of the Penal Code Act, 2008 (Sections 388 to 393, computer and electronic related offences), are all offence statutes directed at the person who attacks a system, a court, a network or a cardholder rather than at the person who operates one; a Ministry of Justice and Constitutional Affairs announcement of the 2021 order's launch lists 35 such offences, from unauthorized data transmission and computer hacking to identity-related offences and disclosure of passwords, with sentences of four to twenty years.

All three stay filed under this jurisdiction's scraping-topic computer-misuse family and are not restated here. mojca.gov.ss, the Ministry of Justice and Constitutional Affairs' own site, answers with an expired TLS certificate rather than a page, and the Internet Archive mirror otherwise used to reach its published Acts was itself unreachable, so the Cybercrime and Computer Misuse Bill 2025's own text, and the Ministry's complete published list of laws, are not described here.

Enforcement of the Section 88(3) duty runs to the National Communication Authority alone, through Section 97's administrative process rather than through a criminal charge or a private right of action: no criminal offence listed at Section 98 reaches a Licensee's own failure to secure its network, and no provision giving a beneficiary a private right of action over that failure was located.

Sector security regimes

National Communication Act, 2012, Licensee Security Duty

National Communication Act, 2012 (Act No. 24), sec. 88National Communication Act

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived July 27, 2026. Publisher's page: https://mojca.gov.ss/wp-content/uploads/2023/03/National-Communication-Act-24-of-2012.pdf

In force. Binds private bodies.

What this law does

Section 88(3) requires every Licensee holding a National Communication Authority licence to construct, install or operate a communication network to provide protection, technical security and safety for its facilities, equipment and communication networks, so as to ensure system efficiency and reliability.

Section 88(1) places a parallel duty on the Authority and Licensees together to protect communication networks against intrusion and vandalism, and Section 88(2) lets the Authority establish protection and safety facilities in collaboration with Licensees toward that end. A Licensee that breaches the security duty is first given an opportunity to remedy the contravention within thirty days of notice, under Section 97(1).

On failure to remedy, Section 97(2) lets the Authority shorten, suspend or cancel the licence, or impose a financial penalty, with the specific penalty amounts left to regulations rather than stated in the Act itself. Section 1 commences the Act on the date of the President's signature, and neither the stored copy of the Act nor any secondary source located states that day-precise date.

What it requires

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.