This submission responds to the South African Human Rights Commission’s (SAHRC) call for written submissions on the human rights impact of the expansion of data centres in South Africa.
About the Civic Tech Innovation Network
The CTIN, based at the Tayarisha Centre at the Wits University School of Governance welcomes the opportunity to respond to this call from the SAHRC. The CTIN is a pan-African network that brings together civic technology practitioners, open-data advocates, digital rights organisations and civic actors to make public power more accountable through technology-enabled transparency, participation and data-driven oversight.
Our motivation for contributing to feedback on this call is based on our appreciation not only of the national level significance of the construction of data centres, but on broader regional implications. We have an interest in contributing to policy-shaping dialogue in the context of digital governance, democracy and technology.
The CTIN is currently working in consortium with partners Wits Commercial Enterprise and OpenUp supported by CIVICUS to implement a project under the Digital Democracy Innovation in Sub-Saharan Africa (DDISA) Fund to support 100 community based organisations in the region with implementing digital democracy innovation initiatives. This includes projects focussed on digital governance, civic participation and public service access/monitoring.
Background
While data centres have the potential to strengthen Africa’s digital economy, their benefits are not automatic nor their impact neutral. Their value is informed by access to reliable and affordable electricity, effective regulation, robust environmental safeguards, and the extent to which local economies capture meaningful ownership and tax benefits. And, because data centres are capital-intensive and highly automated, they may create fewer permanent jobs than expected and create an unequal distribution of benefits. For instance, profits may flow primarily to foreign cloud providers and investors, leaving local communities to bear the costs of land use, noise pollution, electricity demand and water contamination. From a human rights perspective, there are also risks of reinforcing digital inequalities; facilities may be concentrated in major urban hubs. While this can have positive impacts for connected urban markets, rural and lower-income communities may be left behind.
Recognising the increasing environmental, economic and social footprint of data centres, it is important to outline whether and how accountability mechanisms can be factored into their development and rollout. Additionally, the question is not simply whether more data centres should be constructed, but rather under what frameworks and guidelines, under whose oversight and ownership, powered by what energy, and (perhaps most importantly) for whose benefit?
The purpose of this submission is to:
– Identify key risks to human rights resulting from data centre developments
– Consider opportunities associated with data centre development
– Propose recommendations for rights-based governance, oversight and accountability mechanisms for data centres and,
– (To a lesser extent) explore alignment (or misalignment) of current legal, regulatory and policy frameworks with constitutional obligations and international human rights standards
The Commission’s call explicitly highlights electricity and water usage, climate and environmental justice, and community consultation as key themes. In the context of electricity – it is noteworthy that South Africa currently has a power surplus, according to national power supplier, Eskom.
1. What’s a Data Centre When it’s at Home?
A data centre is a purpose-built physical facility, ranging from the size of a single room to a large campus, that houses and operates the IT infrastructure; servers, storage systems and networking equipment. This infrastructure in turn is required to process, store, and transmit digital data and operate applications and services for businesses, governments, and cloud providers. Data centres are engineered for high reliability and security, with power supplies, advanced cooling systems and fire suppression to ensure continuous operation.
The significance of data centres lies in being the backbone of the digital economy. Data centres centralise and secure critical business and public-sector data, enabling cloud computing and online services. They also support business continuity and availability, while providing reliable computing power required for everything from everyday enterprise operations to advanced workloads like artificial intelligence. In essence, data centres are the ‘physical homes’ of the internet and modern digital services, making them essential infrastructure for governance, commerce, and civic technology.
In 2026, it is estimated that there are in the region of 10,000 to 12,000 active data centres globally. However, estimates seem to vary widely. ABI Research forecasts that there will be 8,821 data centres in operation by the end of 2026 while other sources report higher counts: Cloudscene-based reporting and industry compilations cite over 11,800 operational data centres. A mid-2026 snapshot from Cloudscene lists 11,426 active data centres across 179 countries. While the spread may reflect different inclusion criteria, the rapid growth driven by artificial intelligence (AI), cloud computing, and digital transformation is clear.
Forecasted number of Data Centres by Region: 2026 – 2034
| Region | 2026 | 2027 | 2028 | 2029 | 2030 | 2031 | 2032 | 3033 | 2034 |
| North America | 2,777 | 2,925 | 3,077 | 3,231 | 3,388 | 3,546 | 3,706 | 3,867 | 4,028 |
| Europe | 3,327 | 3,412 | 3,506 | 3,598 | 3,690 | 3,778 | 3,868 | 3,958 | 4,048 |
| Asia-Pacific | 1,778 | 1,833 | 1,897 | 1,952 | 2,010 | 2,066 | 2,123 | 2,180 | 2,237 |
| Latin America | 514 | 536 | 559 | 581 | 604 | 627 | 651 | 674 | 698 |
| Middle East & Africa | 425 | 455 | 486 | 517 | 549 | 581 | 613 | 644 | 675 |
| Total | 8,821 | 9,162 | 9,525 | 9,880 | 10,241 | 10,599 | 10,961 | 11,323 | 11,686 |
(Source: ABI Research)
2. Data Centre Expansion in South Africa
South Africa is increasingly positioned as a regional hub for data centres, driven by demand for cloud services, AI, digital government platforms and private sector digitisation (see data centres map). The National Policy on Data and Cloud (2024) seeks to establish a coordinated approach to data governance, cloud adoption and related infrastructure, including data.
According to a recent Financial Times article, South Africa is home to approximately 70% of Africa’s data centres, owing to its fibre infrastructure and mature financial sector. And, according to a Arizton Advisory and Intelligence, cloud computing and AI-driven investments are forecast to more than double South Africa’s data centre market to more than US $5 billion by 2031. In July 2026, the City of Cape Town reportedly gave the green light to Equinix, a United States company to build two facilities requiring about 170 megawatts. This load is reported to be close to the 189MW of total critical capacity currently operated by Africa’s largest data centre company, Teraco.
Some commentators refer to the business of data centres as a ‘gold rush’ which is indicative of the prospective value of these developments. While Eskom has about 2,000MW of capacity in cold storage that could be used, there are questions as to the extent to which proposed investments could overwhelm the current grid’s capacity.
The debate about whether South Africa can support power-intensive facilities alongside households and other businesses is ongoing. However, rapid expansion of data infrastructure risks outpacing a comprehensive approach to a human rights and environmental assessment. And while data centres are considered critical nodes in the digital ecosystem; they come with a laundry list of considerations in terms of climate justice. This includes their location, design, energy and water use, cybersecurity and governance models. They also impact the right to (clean) water, environment and health; rights to privacy, data protection and freedom of expression. Other socio-economic rights affected include the right to housing, land.
The SAHRC’s inquiry is therefore timely and necessary to ensure that the growth of data centres does not undermine constitutional principles or deepen existing inequalities.
It is also important to understand who the owners of data centres are; an exploration not within the scope of this submission.
3. Human Rights Impacts Associated with Data Centre Development
3.1 Environmental and Climate Justice Impacts
Data centres are energy-intensive and, in many cases, rely on significant water volumes for cooling. Globally, large scale facilities have the ability to consume as much water as 30,000 households, while global water demand could reach up to 1.8 trillion litres per year by 2030. Additionally, waste heat from AI data centres is creating local data heat island effects, raising land surface temperatures by about 2°C in areas in close proximity to facilities.
In South Africa; a context of electricity constraints (generally), water scarcity and climate vulnerability; the environmental footprint of data centres raises serious concerns for:
– Potential exacerbation of the impacts associated with El Nino conditions which include increased water scarcity and drought as well as increased pressure on energy supplies
– Section 24 of the Constitution (right to an environment not harmful to health or well-being);
– Climate justice and environmental justice, particularly for communities already facing energy poverty, water insecurity and inadequate infrastructure; and
– Socio-economic rights (e.g. water, health, housing) where data centre projects displace communities, distort local resource allocation or increase utility costs
The SAHRC should engage relevant departments such as the Department of Cooperative Governance to ensure that any data centre planning is integrated with national and provincial climate, energy and water strategies, and subject to rigorous environmental impact assessments (EIAs) that include cumulative and regional impacts.
3.2 Privacy, Data Protection and Cybersecurity
Data centres store, process and transmit vast amounts of personal and sensitive data, including information related to government services, health, education and finance. This raises issues under:
– Section 14 of the Constitution (right to privacy);
– The Protection of Personal Information Act (POPIA)
– The Cybercrimes Act
– International standards on data protection and cybersecurity
Key concerns include inadequate governance over who accesses data stored in South African data centres (state, private actors and foreign entities). At a regional level, weak oversight of cross-border data flows and potential transnational surveillance poses a threat as does insufficient transparency around cybersecurity practices, incident reporting and data breach management. There is also the risk that concentrated data infrastructure becomes a target for cyberattacks, undermining public trust and service delivery.
The SAHRC should consider whether and how data centre regulation can complement and strengthen POPIA compliance, ensure accountability for data processors and controllers, and protect against both state and non-state abuses.
3.3 Community Consultation, Public Participation and Land Rights
Research to date indicates that many data centre projects are located in or near communities where local consultation processes are weak, rushed or non-transparent. In the context of South Africa, this would undermine:
Section 233 of the Constitution and principles of administrative justice (fair, reasonable, procedurally lawful decision-making);
Rights to public participation in matters affecting the environment, land and development; and
Land and housing rights where communities face displacement, rezoning without consent, or loss of agricultural or communal land
To this end, where projects are underway or to be rolled out, the CTIN encourages the SAHRC to advocate for meaningful, early and inclusive consultation with affected communities in addition to establishing independent grievance mechanisms. Transparent disclosure of project plans, environmental assessments and expected socio-economic impacts must also form part of such processes.
3.4 Business and Human Rights Due Diligence
Data centre operators and their investors are businesses that must respect human rights as provided for under the Constitution, the UN Guiding Principles on Business and Human Rights (UNGPs) as well as emerging international norms on tech governance.
It must be noted that current frameworks often lack clear requirements for human rights impact assessments (HRIAs) in relation to data centre projects in addition to relative silence on labour conditions, supply chain practices and community impacts. The UNGPs, for instance, have been outlined as having limited utility for AI governance. Vijeyarasa (2025) emphasises that the UNGPs are widely regarded as the definitive normative framework governing the responsibilities of businesses with respect to human rights. However, the suitability of this soft law framework to address digital inequalities in and between the Global North and South is in question.
Concerns raised by Vijeyarasa (2025) include exploitation of workers in the global south, data owners and their digital vulnerability; climate injustice; and the rights and interests of the Global South’s innovators. While this particular paper concludes that the UNGPs are unfit for the purpose of responding to the human rights at risk of being violated in an AI-centric world, they constitute a useful framework.
This, however, is beyond the scope of the current submission. The SAHRC can play a pivotal role in urging regulators and industry to adopt mandatory human rights due diligence for data infrastructure.
4. Assessment of Current Legal, Regulatory and Policy Frameworks
4.1 Constitutional and Statutory Basis
The South African Constitution provides a robust foundation for rights-based governance of data centres, including:
– Section 24 (environment);
– Section 14 (privacy);
– Section 9 (equality and non-discrimination);
– Section 32 (access to information); and
– Sections 23–26 (labour, housing and related socio-economic rights)
The National Environmental Management Act (NEMA), the Electricity Regulation Act, POPIA and relevant water management legislation provide additional layers of protection, but these may not be adequate as they do not directly address issues related to data centre infrastructure; some of which may prove novel.
4.2 National Policy on Data and Cloud (2024)
The National Policy on Data and Cloud sets out a strategic framework for data governance, cloud adoption and related infrastructure. While it acknowledges the importance of data sovereignty and digital transformation, it does not explicitly articulate human rights obligations for data centre operators or require HRIAs or comprehensive environmental and social impact assessments. It also does not provide detailed governance mechanisms for community participation, transparency and accountability. This gap creates a risk that data centre expansion is driven primarily by economic and technological considerations, without adequate human rights safeguards.
4.3 Regulatory Gaps and Compliance Concerns
Key regulatory gaps include the lack of a dedicated data centre regulatory framework that integrates environmental, energy, water, privacy and community rights considerations. This is important given the challenges raised in earlier sections of this submission.
Reiterating concerns relating to data sovereignty; insufficient oversight of cross-border data flows and foreign ownership of critical data infrastructure constitute issues that warrant addressing.
And, as data centres are located within the municipal sphere; limited capacity within municipalities to assess complex data infrastructure projects warrants a further concern.
Several jurisdictions and international frameworks offer useful models for rights-based data centre governance. These include the UN Guiding Principles on Business and Human Rights which establish expected standards for human rights due diligence by companies. The EU Digital Strategies and Data Governance framework emphasises data sovereignty, environmental sustainability and transparency in digital infrastructure. African Union and regional instruments include the Malabo Convention on Cybersecurity and Data Protection, which provide regional benchmarks for data governance and rights protection.
The CTIN urges the Commission to consider undertaking in-depth research into the regulatory gaps (not only in relation to municipal competence) to inform a robust, fit-for-purpose, rights-centred framework for data centres in South Africa.
5. Recommendations
We propose the following for consideration by the Commission and relevant entities interested in ensuring that the emergence of data centres in South Africa is met with concrete measures aimed at safeguarding human and environmental rights.
5.1 Establish a Rights-Based Data Centre Governance Framework
The SAHRC should engage key Parliamentary committees and relevant organs of state to:
– Develop a dedicated Data Centre Governance Framework that explicitly requires human rights impact assessments (HRIAs) as a prerequisite for data centre approvals;
– Mandate comprehensive environmental and social impact assessments as part of the process;
– Set binding standards for energy efficiency, water use, emissions and waste management and embeds transparency, public participation and accountability obligations
– Ensure that this framework aligns with the Constitution, POPIA, NEMA and international human rights standards
5.2 Strengthen Community Consultation and Public Participation
– Require early, meaningful and inclusive consultation with affected communities, including marginalised groups, before any data centre project is approved
– Establish independent grievance and mediation mechanisms for communities to raise concerns about environmental, land, water or other rights impacts
– Ensure that environmental authorisations and planning decisions are publicly accessible, with clear reasons and appeal mechanisms
5.3 Protect Privacy, Data Protection and Cybersecurity
Mandate that data centre operators:
– Implement robust data protection and cybersecurity measures aligned with POPIA and international best practice;
– Provide transparent incident reporting and breach notification mechanisms; and limit access to data by state and private actors to what is strictly necessary and lawful
In addition, the SAHRC should consider issuing guidance or policy recommendations on privacy and data protection in the context of data infrastructure, including cross-border data flows.
5.4 Enforce Business and Human Rights Due Diligence
In relation to the private sector; the Commission can recommend;
– Mandatory human rights due diligence for data centre operators and investors, including:
– Regular monitoring of labour conditions, supply chain practices and community impacts;
– Open and public reporting on human rights performance; and
– Accountability mechanisms where harms occur.
The Commission should encourage regulators to incorporate United Nations Guiding Principles on Business and Human Rights aligned requirements into licensing, procurement and investment agreements.
5.5 Promote Transparency, Governance and Accountability
South Africa’s National Data Cloud Policy is intended to be executed through consultations with government, industry, and civil society. Structures such as the Data Advisory Council will oversee frameworks, standards, and collaboration efforts. The Commission can advocate for the establishment of an inter-agency oversight body (or strengthen an existing one) responsible for monitoring data centre development and its human rights and environmental impacts. This could include coordinating between departments (Communications and Digital Technologies, Environment, Energy, Water, Local Government); and publishing regular reports on compliance and emerging risks. It would also be vital to require public registers of data centre projects, including location, owner, energy and water use, and environmental authorisations.
5.6 Address Regulatory Gaps and Build Capacity
Lastly, an important task will be to identify and close regulatory gaps in current laws and policies, particularly regarding data sovereignty and foreign ownership of critical data infrastructure, cross-border data flows and surveillance risks. Also vital will be supporting capacity building for municipalities, regulators and civil society to monitor and assess complex data centre infrastructure projects.
Conclusion
The expansion of data centres in South Africa presents both opportunities and serious human rights risks. Without a rights-based governance framework, data infrastructure development can undermine environmental integrity, privacy, community rights and democratic accountability.
The SAHRC’s inquiry provides a critical opportunity to shape policy and regulatory responses that ensure data centres contribute to inclusive, sustainable and rights-respecting digital transformation. This submission urges the Commission to use its findings to issue policy guidance and recommendations to Parliament and relevant organs of state.
The CTIN recognises the value of convening diverse role-players where policy development is concerned with the aim of co-creating context-specific, effective solutions.
We therefore encourage the Commission to arrange stakeholder engagements that include communities, civil society, academics, industry and regulators. In addition, we encourage the Commission to advocate for a constitutional and human rights-aligned approach to data centre governance that prioritises environmental justice, privacy, participation and accountability. By doing so, the SAHRC can help ensure that South Africa’s digital infrastructure strengthens, rather than undermines, the country’s democratic and human rights commitments.
